Stage deploy artifacts on the rack; SEC-029 for the PKI overlay residency
Operator-ruled: 'Copy dc0's PKI overlay to the dc0 rack (Recommended)'.
bundle.yaml + machines + vips staged with digests compared; the octavia-pki
overlay copied 0600 with sha256 equal end to end.

D-138 means the deploy cannot run from voffice1 at all -- no L3 path to the
controller API on the provider plane -- so the overlay must be DC-resident.
Per-DC isolation holds by construction: each rack gets only its own overlay.

SEC-029 records that reissue must now update BOTH copies or the rack deploys a
superseded cert. dc1's rows are the forward register.

creds-matrix 65/65; repo-lint 0 fail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent c0840a8 commit d870d7679e2c32b3956ac507af43b6c3b2dc1a84
@JANeumatrix JANeumatrix authored 18 hours ago
Showing 4 changed files
View
creds-manifests/vm-secret-locations
View
creds-matrix-notes.md
View
creds-matrix.tsv
View
docs/security-ledger.md