|
Pre-ruling measurements for R6-R15: measure before asking, all ten
Operator: "Measure all the rest then we can work through them with relevant data at hand." Taken directly by the session rather than delegated, after the UNMEASURED-gap sweep showed lens findings need measuring before they become questions. Capture: docs/audit/r6-r15-measurements-20260727.txt. THE TWO RESULTS THAT CHANGE A QUESTION'S SHAPE: R6/R11 -- vault's ENTIRE HA apparatus exists only in dc-ha-scaleup.yaml. Base vault is num_units:1 with an EMPTY options block: no vip, no hacluster, no relation. The overlay INTRODUCES the vault-hacluster application (not present in base at all), sets cluster_count:3, adds the vault:ha relation -- and still no vip. Applying the overlay therefore creates a 3-node pacemaker cluster with nothing to manage. The blast radius is what makes it sharp: 23 relations consume vault:certificates, plus barbican-vault:secrets-storage. Vault is the CA for the whole cloud and every consumer binds a unit address. Of the 12 base hacluster subordinates exactly ONE principal lacks a vip (designate), and octavia carries a proper triple -- so this is a 2-app gap, not a pattern. R10 -- the question largely DISSOLVES. Preflight has been run on the wrong host. Measured: vcloud has neither maas nor juju nor openstack; voffice1 has maas AND juju. So P3's 33 warns and P4's "MAAS unreachable" both clear simply by running preflight on the D-128 Plane-2 host where it belongs. Only the octavia-pki absence and the 7 credential findings are host-independent. Same "tool absence reported as something else" class as U6, now three instances. OTHERS: R7 the octavia CA subject is a baked VR0-DC0 literal while the SAN is already derived by design (DOCFIX-067) -- the two halves differ in severity. R8 the v4-only lb-mgmt shape is already pre-analysed in-repo with LP #1911788 and #1913409 cited and a drafted block ready (NOT verified upstream by me). R9 only 8 of 28 lib-net consumers call the DC selector; the 20 that do not include the entire phase-02..phase-06 family. R12 chronyc appears ZERO times in CURRENT-STATE, confirming G17 omits the time check. R13 30 rows / 16 ids are operator-terminal, of which SEVEN are keypairs whose loss is unrecoverable-in-place. R14 the matrix has no exception field at all. R15 81 harnesses on disk and 81 reported, with 81 pinned nowhere executable. METHOD NOTE, recorded because it nearly published a wrong figure: parsing creds-matrix.tsv with awk -F'\t' returned ZERO operator-terminal rows, contradicting lens 7's 30. The file is SPACE-ALIGNED, not tab-separated. Re-measured correctly it is 30/16 and lens 7 was right. A disagreement with a prior finding was treated as a reason to re-check my instrument rather than to publish the new number. Revert: git revert this commit; the capture is new and CURRENT-STATE additive. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/r6-r15-measurements-20260727.txt 0 → 100644 |
|---|