|
CORRECTION: no autostart setting was changed, and D-127 already rules it
Operator asked directly whether I had changed autostart. I had NOT -- item 21
logged it under hard rule 1 and started the two VMs by hand. The question, asked
to scope a power-settings-matrix session, prompted the check that shows I FRAMED
THE FINDING WRONGLY.
D-127 ("VR1 host-level VM autostart policy") already rules this, autostart is
TOFU-MANAGED, and every measured value is an explicit per-instance decision with
its reason in-line: main.tf:413/:540 containment VMs false ("MANUAL (gated
bring-up), never on host boot"); main.tf:102/:178 office1-opnsense and voffice1
true ("foundational"); DC edges true ("comes up with its containment VM"); node
VMs false ("MAAS-power-controlled"). The module variable's own description forbids
relying on its default. Calling it "a standing exposure" implied nobody had
decided. A session told to "fix autostart" would fight a ruling -- and now that P8
exists, a virsh autostart change would also surface as substrate DRIFT.
WHAT SURVIVES, narrower and real: vr1-dc0-maas-01 and vr1-dc0-juju-01 are created
by the vr1_dc0_node for_each, so they inherit the NODE justification
"MAAS-power-controlled". TRUE for the juju controller (subtle-grouse, a dc0-region
machine, power_type=virsh). CIRCULAR for the MAAS region VM: hot-kid's power is
owned by the OFFICE1 region -- the region D-132 q1 is migrating away from. Retire
Office1 and nothing owns the dc0 region VM's power while it does not autostart.
That is an ordering exposure in the migration, not an autostart bug. LOGGED, NOT
FIXED.
WHY THE OPERATOR'S MATRIX IS THE RIGHT INSTRUMENT: autostart is a boolean that
cannot express WHO OWNS a VM's power or WHAT HAPPENS WHEN THAT OWNER GOES AWAY --
the questions that surface the circularity, and they recur at every DC standup.
Seed inventory measured: 4 outer domains, 12 dc0 inner, 11 dc1 inner; exactly four
carry autostart=enable (voffice1, office1-opnsense, both DC edges).
repo-lint 0 fail.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260731-snap-proxy-apply-ipv6.md |
|---|