audit: ovn-central cert reeval + remediation plan + Stage-5 misses sweep
Re-evaluation of the prior (wrong) ovn-central "awaiting server certificate
data" diagnosis, from fresh live measurement + 3 source-level agents + an
adversarial review. Corrected root cause: ovn-central derives its cert CN from
a REVERSE lookup of its metal-internal address; metal-internal is the only
plane of six without reverse-DNS PTRs, so get_hostname() -> None -> empty
common_name -> vault issues no server cert -> ovn-central blocks. LP #2044324
is NO MATCH; no upstream fix / channel bump helps.

- ovn-central-cert-reeval-20260803.md      -- root cause, evidence, what the
  prior diagnosis got wrong, ranked remedies, why-no-PTR.
- ovn-central-cert-remediation-plan-20260803.md -- gated rdns_mode + re-fire
  sequence with corrected (non-false-green) acceptance criteria.
- stage5-sweep-misses-20260803.md          -- F1 metal-internal rdns outlier +
  standup tooling never sets rdns_mode; F2 four hacluster units blocked on
  stale pre-D-141 IPv6 VIP CIB resources; F3 octavia error is downstream of
  neutron VIP TLS. Meta: incomplete-transition tails.

All findings MEASURED read-only this session; every remediation step is
operator-gated and NOT executed. SEC-033 (relation databag exposes vault
global-client key) noted for separate filing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 5c9da99 commit eb63339a03eaa1250d3d52b02955a3204dc383a7
@JANeumatrix JANeumatrix authored 21 hours ago
Showing 3 changed files
View
docs/audit/ovn-central-cert-reeval-20260803.md 0 → 100644
View
docs/audit/ovn-central-cert-remediation-plan-20260803.md 0 → 100644
View
docs/audit/stage5-sweep-misses-20260803.md 0 → 100644