|
R13 RULED: register-first credential fixes, no new tool (D-137 sub-ruling 6)
GA-R5: question and exact utterance quoted, dated, pushed before dependent work. Operator utterance: "Register-first, no new tool: fix the staging AND flip the 7 keypairs (Recommended)". Measuring showed R13 was THREE problems, not the two the queued framing carried. The third is the sharpest and had not been surfaced as a decision at all: THE REGISTER MIS-STAGES WHAT STAGE 5 ACTUALLY MINTS. The vault-init, Octavia-PKI and admin-openrc rows are cardinality=singleton with mint-stage in vr0-phase01/02/03, and creds-manifests/stages-reached marks all three pending -- so flipping stage5 to reached never makes them expected. The measured consequence is a FALSE GREEN over the largest minting event of the deployment: P5 reports "[ok] E1 18 expected artifact(s) deferred as not-yet-minted". R7 made this MORE urgent rather than less: per-DC independent Octavia PKI means two CA mints where the register expects none. The retroactive half needs no new tooling, which is what made register-first the efficient answer: S4 ALREADY resolves runbook:<path>:<line> references, so recording each mint as a numbered runbook step and flipping mint-ref from operator-terminal converges the debt using machinery that exists and is tested. 30 rows / 16 ids carry that ref today and grep -rnI "ssh-keygen" returns ZERO hits repo-wide. Priority within that half is the SEVEN unrecoverable-in-place keypairs, where irreproducibility is an operational risk rather than hygiene: both edge keys (SEC-007/-015 make edge SSH the ONLY management path to the DC edges), both svc keys, both power keys, and office1-svc-key. A jumphost rebuild today locks the operator out of both DC edges. creds-mint.sh STAYS QUEUED for its own ruling and is deliberately not built here. It is orthogonal -- it would prevent the NEXT unregistered mint but makes no existing key reproducible and fixes no staging. Bundling it would have made the urgent no-tool work wait on unscoped tooling work. Carried caveat for whoever executes this: the T24 finding-class baseline covers TIER 1 ONLY, so a tier-2/3 regression introduced by these matrix edits would not turn the gauntlet red on its own. PROCESS NOTE, owned: the first attempt at this commit tripped repo-lint L5 by titling the sub-ruling "### D-137 SUB-RULING 6" -- a heading LEADING with a D-number counts as a second definition unless it also contains AMENDMENT or RESOLVED. That is the same rule I hit on R5 and then documented. The lint gating caught it before the commit landed this time, so nothing was pushed red; the heading is now "### SUB-RULING 6 (D-137)", matching the convention. Revert: git revert this commit; the sub-ruling is additive. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/design-decisions.md |
|---|