|
Reissue backup custody: transferred to vcloud, and REGISTERED
Operator: 'Update the matrix as needed. Transfer the artifacts to the vcloud. keep the pin that during the secrets workflow planning that the creds and certs from this step need to be included.' CUSTODY (Step 1.0-REISSUE.4, executed): both pre-reissue archives pulled from the headend to the jumphost SEC-009 creds folders, sha256 compared and IDENTICAL at both ends (e30cab7f...3487 dc0, 17c831da...6fe3 dc1), 0600, each listing 15 entries including the deploy overlay and the CA serial. Headend staging copies removed; ~/octavia-pki/backups/ gone; no .reissue-* residue. The sha256 compare happens BEFORE the delete because a truncated scp would otherwise leave a verified-looking backup of nothing. REGISTER: two octavia-reissue-backup rows (per-DC, jumphost, consolidated, templated filename <site>-octavia-pki-<stamp>.tar.gz), the DERIVED manifests updated to match (D-137 ruling 2 -- manifests are generated, not hand-authored), and a new n-reissue-backup note. It is deliberately a SEPARATE id from n-pki-backup: that one is the generation-time workspace archive, this one is per-ROTATION and additionally carries the deploy overlay, which the generation archive does not -- restoring only the workspace would leave the half that actually reaches the charm unrecoverable. Measured after: tier1 101 rows / SAME 5 pre-existing findings; tier2 the same 7, with NO reissue-attributable finding -- and tier2 FOUND both archives at their declared location, which is the point of registering them. Harness 65/65. HAZARD RECORDED: these archives contain controller-ca.cert.srl, the CA's issuance state. Restoring one over a workspace that has issued since rolls the serial BACKWARDS and the next mint reuses a serial the estate already holds. Serials burned 2026-07-30: ...250E (dc0), ...674DE (dc1). PINNED: the note carries the operator's standing requirement that the creds and certs from this step be included in the secrets-storage workflow planning, with the full scope enumerated. The jumphost creds folder is the INTERIM home only. gauntlet ALL GREEN (89); repo-lint 0 fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| creds-manifests/vr1-dc0.manifest |
|---|
| creds-manifests/vr1-dc1.manifest |
|---|
| creds-matrix-notes.md |
|---|
| creds-matrix.tsv |
|---|
| docs/CURRENT-STATE.md |
|---|