|
audit: ovn-central cert reeval + remediation plan + Stage-5 misses sweep
Re-evaluation of the prior (wrong) ovn-central "awaiting server certificate data" diagnosis, from fresh live measurement + 3 source-level agents + an adversarial review. Corrected root cause: ovn-central derives its cert CN from a REVERSE lookup of its metal-internal address; metal-internal is the only plane of six without reverse-DNS PTRs, so get_hostname() -> None -> empty common_name -> vault issues no server cert -> ovn-central blocks. LP #2044324 is NO MATCH; no upstream fix / channel bump helps. - ovn-central-cert-reeval-20260803.md -- root cause, evidence, what the prior diagnosis got wrong, ranked remedies, why-no-PTR. - ovn-central-cert-remediation-plan-20260803.md -- gated rdns_mode + re-fire sequence with corrected (non-false-green) acceptance criteria. - stage5-sweep-misses-20260803.md -- F1 metal-internal rdns outlier + standup tooling never sets rdns_mode; F2 four hacluster units blocked on stale pre-D-141 IPv6 VIP CIB resources; F3 octavia error is downstream of neutron VIP TLS. Meta: incomplete-transition tails. All findings MEASURED read-only this session; every remediation step is operator-gated and NOT executed. SEC-033 (relation databag exposes vault global-client key) noted for separate filing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/audit/ovn-central-cert-reeval-20260803.md 0 → 100644 |
|---|
| docs/audit/ovn-central-cert-remediation-plan-20260803.md 0 → 100644 |
|---|
| docs/audit/stage5-sweep-misses-20260803.md 0 → 100644 |
|---|