D-129(iii) amendment: per-DC Tailscale operator-access rulings (a-d), both DCs
Record four GA-R5 rulings (2026-08-07) that pull the gap-21 per-DC Tailscale
subnet-router forward to close phase-03 Horizon properly (operator: "pull the
tailscale steps forward"; "plan and push to both DC0 and DC1"):
  (a) dedicated VM at utility .7 (10.12.8.7 / 10.12.68.7)
  (b) STAR -- operator->DC only (the Headscale ACL / security boundary)
  (c) SINGLE router, HA scale-up PINNED
  (d) SNAT ON now, source-IP preservation PINNED

These are D-129(iii) implementation sub-decisions (not a new D-number). Also:
correct the D-107 citation defect (D-107 is airgap/mirror/NTP, governs no
Tailscale; D-129(iii) governs); extend D-134's standing octet map to .7;
update the gap-21 register row and CURRENT-STATE (phase-03 does NOT close this
session -- Step 3.3 Horizon splits to its own gate row, gated on the tailnet
build + vault CA on the workstation + a browser login over the tailnet).

Records only -- no code, no cloud change. The build (site-tailscale.sh + the
.7 VM per DC + Headscale star ACL/autoApprovers + SEC row) is next.
repo-lint 0 fail; Decision C reconciliation measured read-only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
1 parent ab505ef commit b859e2628dc63cb95ca06f520d7c721f042815fd
@JANeumatrix JANeumatrix authored 3 hours ago
Showing 4 changed files
View
docs/CURRENT-STATE.md
View
docs/changelog-20260806-step34-g3-probe.md
View
docs/dc-dc-deployment-workflow.md
View
docs/design-decisions.md