R13 RULED: register-first credential fixes, no new tool (D-137 sub-ruling 6)
GA-R5: question and exact utterance quoted, dated, pushed before dependent work.
Operator utterance: "Register-first, no new tool: fix the staging AND flip the 7
keypairs (Recommended)".

Measuring showed R13 was THREE problems, not the two the queued framing carried.
The third is the sharpest and had not been surfaced as a decision at all:

THE REGISTER MIS-STAGES WHAT STAGE 5 ACTUALLY MINTS. The vault-init, Octavia-PKI
and admin-openrc rows are cardinality=singleton with mint-stage in
vr0-phase01/02/03, and creds-manifests/stages-reached marks all three pending --
so flipping stage5 to reached never makes them expected. The measured consequence
is a FALSE GREEN over the largest minting event of the deployment: P5 reports
"[ok] E1 18 expected artifact(s) deferred as not-yet-minted". R7 made this MORE
urgent rather than less: per-DC independent Octavia PKI means two CA mints where
the register expects none.

The retroactive half needs no new tooling, which is what made register-first the
efficient answer: S4 ALREADY resolves runbook:<path>:<line> references, so
recording each mint as a numbered runbook step and flipping mint-ref from
operator-terminal converges the debt using machinery that exists and is tested.
30 rows / 16 ids carry that ref today and grep -rnI "ssh-keygen" returns ZERO
hits repo-wide.

Priority within that half is the SEVEN unrecoverable-in-place keypairs, where
irreproducibility is an operational risk rather than hygiene: both edge keys
(SEC-007/-015 make edge SSH the ONLY management path to the DC edges), both svc
keys, both power keys, and office1-svc-key. A jumphost rebuild today locks the
operator out of both DC edges.

creds-mint.sh STAYS QUEUED for its own ruling and is deliberately not built here.
It is orthogonal -- it would prevent the NEXT unregistered mint but makes no
existing key reproducible and fixes no staging. Bundling it would have made the
urgent no-tool work wait on unscoped tooling work.

Carried caveat for whoever executes this: the T24 finding-class baseline covers
TIER 1 ONLY, so a tier-2/3 regression introduced by these matrix edits would not
turn the gauntlet red on its own.

PROCESS NOTE, owned: the first attempt at this commit tripped repo-lint L5 by
titling the sub-ruling "### D-137 SUB-RULING 6" -- a heading LEADING with a
D-number counts as a second definition unless it also contains AMENDMENT or
RESOLVED. That is the same rule I hit on R5 and then documented. The lint gating
caught it before the commit landed this time, so nothing was pushed red; the
heading is now "### SUB-RULING 6 (D-137)", matching the convention.

Revert: git revert this commit; the sub-ruling is additive.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 6059561 commit d423024e58455e76e4dbe1e880fa63d7b4a050cc
@JANeumatrix JANeumatrix authored 1 hour ago
Showing 2 changed files
View
docs/CURRENT-STATE.md
View
docs/design-decisions.md