|
Stage-5 grounding audit: lens 5 + the three deliverables
VERDICT: Stage 5 would NOT run error-free today, and would fail early. The substrate underneath is excellent -- all three OpenTofu roots ZERO DIFF, 18 nodes Ready exact to D-121 Option C, MACs and power addresses matching lib-hosts, D-134 statics perfect, 17 fabrics, zero orphaned interfaces, both artifact paths serving, gauntlet ALL GREEN (81). What is not ready is the layer between the substrate and the deploy. LENS 5 (relaunched after an API error) returned the ordered precondition list and the largest runbook defect found: Step 4 says "follow phase-01 verbatim", and phase-01 ACTIVELY REFUSES dc1 -- its VIP guard greps bundle.yaml for eleven 10.12.4.x VIPs, dc1's live in an overlay on 10.12.64/68/72, so it takes the "ABORT: VIP guard failed" branch. After the ruled VIP extraction it aborts for dc0 too. It also carries hardcoded VR0 system_ids, a jumphost-local libvirt loop over disks that do not exist, and a 4-machine plan gate against a 9-machine bundle. Three Stage-5 gate commands cannot execute at all, measured against the juju actually installed (3.6.27): juju run used for a shell command when it is the action runner; download-backup given a backup-id when it takes a controller path; and the geneve gate grepping ovn-central for a config key the same runbook says does not exist. Four of the five VERIFY-LIVE gates the record says Stage 5 owes have NO step in the runbook -- including the keystone policyd-override check, which is RULED. Two convergent confirmations raise confidence in the whole set: the Ceph OSD blocker was found independently by two lenses using different methods, and the stale-clone blocker independently by this session and lens 5. DELIVERABLES: - docs/audit/stage5-readiness-20260727.md -- ordered precondition checklist, READ FIRST. 5 phases, each row with status/evidence/what-breaks. - docs/audit/stage5-committee-raw-20260727.md -- all 7 lenses verbatim. - docs/audit/queued-rulings-20260727.md -- 11 Stage-5-blocking + 4 standing questions, GA-R5 shape, one exchange each, blank utterance lines. NONE adopted; a batch answer rules NOTHING. MECHANICAL FIX TAKEN (exactly one, deliberately): the G3 gate row read OPEN with a standing FREEZE while its own cited evidence file records G3 CLOSED and the freeze lifted. Left standing, that clause would have blocked the very DOCFIX batch this audit queues. No ruling was required -- two surfaces already declared it closed. The 21-item DOCFIX remediation batch is LOGGED NOT EXECUTED. Nearly every runbook fix interlocks with an unanswered ruling, so landing them now would encode assumptions about questions the operator has not answered. Next-free numbers unchanged (D 138 / DOCFIX 205 / BUNDLEFIX 053) -- no number was assigned, correctly, since nothing was remediated. Revert: git revert this commit; the deliverables are new files and the CURRENT-STATE edits are additive plus the one G3 correction. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/queued-rulings-20260727.md 0 → 100644 |
|---|
| docs/audit/stage5-committee-raw-20260727.md |
|---|
| docs/audit/stage5-readiness-20260727.md 0 → 100644 |
|---|