|
Stage 5 BLOCKED: no juju-client->node-plane path; D-134 .5 now BUILT both DCs
Bootstrap attempted and failed. Machine selection was correct (7n87bt, the tagged VM) and MAAS deployed jammy end to end -- confirming the --bootstrap-base ubuntu@22.04 pin against a live deploy. juju then could not SSH the machine and released it. Root cause: voffice1 has NO route to any DC node plane and two deliberate controls forbid one -- SEC-010's transit FORWARD-drop on the rack, and libvirt's blanket reject into the isolated plane bridges. The DC edge has no metal-admin leg. Nothing regressed; this path never existed. This is a contradiction between RULED surfaces: SEC-010/D-052 make metal-admin DC-local and forbid the region routing to 10.12.8.0/22, while D-100 says the fiber carries Juju traffic and D-128 puts the juju client on voffice1. SEC-010's "pinning is free" justification was priced against MAAS, which proxies at the app layer; juju dials the machine at L3 and was not in scope. Needs a ruling, not a firewall edit. No reachability change made. BUILT, both DCs (operator: "Fix now: static .5 + v6, re-bootstrap"): the controller VMs held AUTO v4-only addresses; now static 10.12.8.5 + fd50:840e:74e2:220::5 and 10.12.68.5 + fd50:840e:74e2:320::5. v6 prefixes confirmed by VLAN pairing, not inferred. D-134's amendment was ruled-but-not-built until now. Capture: docs/audit/stage5-bootstrap-reachability-20260730.txt Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/stage5-bootstrap-reachability-20260730.txt 0 → 100644 |
|---|
| docs/changelog-20260730-stage5-open.md |
|---|