D-138 ADOPTED: the cloud-facing client lives IN the DC; SEC-026 opened
GA-R5, before dependent work. Operator utterance: "Move the cloud-facing
client into the DC (Recommended)".

Resolves the contradiction the Stage-5 bootstrap failure exposed: SEC-010 +
D-052 make metal-admin DC-local and forbid the route juju needs, while D-100
names Juju as fiber traffic and D-128 puts the client on voffice1. SEC-010's
"pinning is free" was priced against tools that proxy at the app layer; juju
dials the machine at L3 and was not in scope.

The client moves; the boundary does not. SEC-010, D-052 and D-125 are
UNCHANGED -- nothing punctured, no plane opened. D-128 is amended to exclude
cloud-facing tools. Scope was set by enumeration first: keystone's VIP is on
provider-public, so routing would have opened two planes per DC across a
dozen ports.

SEC-026 opened for the consequence: a MAAS admin-scoped key becomes resident
on a DC-local host, over a region shared by both DCs. Isolation is the
control -- each DC's client host gets ONLY its own credential.

Counters: 22 open SEC, next-free D 139.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent c42f782 commit fac29d2a33ed88e481de28ee15b37b3f264fefc3
@JANeumatrix JANeumatrix authored 9 hours ago
Showing 4 changed files
View
docs/CURRENT-STATE.md
View
docs/changelog-20260730-stage5-open.md
View
docs/design-decisions.md
View
docs/security-ledger.md