Stage 5 dc0 F-CV1: research resolves :public -- fix BOTH endpoints (D-020 triple + charm supports it)
Operator asked to investigate designate's tenant surface + charm docs before
ruling on :public. Conclusion: fix BOTH :public and :internal.

Evidence: (1) D-020 AMENDMENT (2026-07-27, operator GA-R5) gave designate the
established provider/admin/internal triple; that ruling implies the bindings, so
the current metal-admin-fallback bundle is a conformance defect. (2) The DEPLOYED
charm-designate metadata declares extra-bindings public/admin/internal (read in
full on the unit -- authoritative; a WebFetch on master wrongly said none, a
small-model error). Charm description: "Multi-tenant ... REST API" -> tenant-facing
by design. (3) Every sibling binds public->provider-public + internal->metal-internal;
designate is the lone deviation, no ruled exception.

Feasibility confirmed: all 3 units hold provider-public + metal-internal addresses
(juju bind not refused); cert covers metal-internal, will reissue for provider-public.

Proposed gated fix (D-072/BUNDLEFIX-011 precedent): bundle bindings
+public:provider-public +internal:metal-internal, live juju bind, verify by
haproxy readback + cert SAN re-read + haproxy sweep. Awaiting operator go-ahead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
1 parent 71d8ee9 commit bc1d59dbbe9485150fdfd87d04ad99fee77a1781
@JANeumatrix JANeumatrix authored 9 hours ago
Showing 1 changed file
View
docs/audit/stage5-dc0-phase03-coreverify-20260806.txt