creds consolidation batch: SEC-021(b) dc0 power key, SEC-025 NetBox GUI, V2 ruled deferral
Operator asked whether vcloud holds a consolidated set of login creds for every account that
exists, and what is missing / needs creating / was never moved in. Audited, then cleared the
consolidation batch on operator direction ("clear the whole consolidation batch first").

The audit's own headline: creds-audit read CLEAN on all three sites while the matrix returned
13 findings -- and the two most consequential gaps were in NEITHER surface. They were found by
enumerating the accounts that ACTUALLY EXIST. Absence of a ROW is invisible to the register,
which generalises D-137's founding argument one level up.

VERIFIED POSITIVE (both previously only asserted):
- MAAS account set COMPLETE: all 6 live accounts accounted for; admin + operator passwords on
  vcloud, juju-vr1-dc0/dc1 random+unstored BY RULING with API keys present, MAAS +
  maas-init-node MAAS-internal.
- tier-3 V1 now MEASURES maas-admin-password byte-identical to the headend source-of-record,
  so SEC-020's stale-trap risk is clear as of this date.

DONE:
- dc0 SEC-012 power key consolidated to vcloud + .pub DERIVED (SEC-021(b) as written).
  MEASURED FIRST, because the naming looked like a defect and was not: the headend
  maas-virsh_ed25519 and the snap's id_ed25519 are the SAME key; it IS dedicated (distinct
  from the dc0 service key, which is what SEC-012 requires); and dc0 using the snap's default
  identity is SEC-016's RULED design. So no re-mint, no live power path touched.
- dc1 svc .pub backfilled to the headend store (public-key material, sha256-verified).
- NetBox web-GUI admin password consolidated -- a HUMAN login that had never left the VM it
  was minted on, the third instance of the SEC-009/SEC-020 miss class. SEC-025 OPENED for the
  at-rest exposure the copy CREATES, not the gap it closed. Open rows 20 -> 21.
- V2 taught the ruled-deferral state: SEC-006's standing "revoke at completion of this
  deployment" ruling is now ACKNOWLEDGED (still naming the credential live and exposed)
  instead of failing every run. Reissuing the token would have CONTRAVENED that ruling, so the
  register was what needed to change. Match demands the cased state word AND explicit operator
  ruling attribution, and cannot cross a ledger table cell -- T58/T59 lock the evasion out.
- Added --ledger (default unchanged): V2 read the register via --repo, which the harness must
  point at the real repo for S4, so V2 had shipped with ZERO harness cases. T56-T59 added.

Findings 13 -> 7. Matrix 82 rows, harness 60/60 (was 56), creds-audit CLEAN x3, gauntlet ALL
GREEN (81), repo-lint 0-fail. The register is NOT green and is not expected to be.

RESIDUAL, all recorded: dc0-edge-api x2 (the opnsense-api.txt re-mint is a live edge mutation,
deliberately EXCLUDED from this batch), S5 x3 (RULED by SEC-016 -- needs a ruled-exception
mechanism, operator decision), S6 conflation x1 (the SEC-020 defect), E4 x2 (Stage-5/6 rows).

LOGGED NOT ACTIONED (hard rule 1): no registered root/console credential at EITHER DC edge
(measured absence of row/manifest/SEC row; what those passwords ARE is UNKNOWN and
deliberately unprobed per hard rule 2 -- vector is the LAN-reachable GUI and serial console,
not SSH, which is key-only and proven); plus the two structural blind spots that let it hide
-- S5 compares only cardinality=per-DC while all six per-site rows are office1-only, and
vm-secret-locations declares no rack/edge/cloud/unit/client location though the checker
accepts them.

Revert: per-item reverts in docs/changelog-20260727-creds-consolidation.md. The headend, snap
and NetBox VM source copies were never modified, so every file move is reversible by deletion.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 4d62f66 commit c13cfe45b5715faf0531aa24588f0f823f6980ed
@JANeumatrix JANeumatrix authored 5 hours ago
Showing 11 changed files
View
creds-manifests/vr1-dc0.manifest
View
creds-manifests/vr1-office1.manifest
View
creds-matrix-notes.md
View
creds-matrix.tsv
View
docs/CURRENT-STATE.md
View
docs/audit/creds-consolidation-audit-20260727.txt 0 → 100644
View
docs/changelog-20260727-creds-consolidation.md 0 → 100644
View
docs/security-ledger.md
View
docs/session-ledger.md
View
scripts/creds-matrix.py
View
tests/creds-matrix/run-tests.sh