|
D-138 ADOPTED: the cloud-facing client lives IN the DC; SEC-026 opened
GA-R5, before dependent work. Operator utterance: "Move the cloud-facing client into the DC (Recommended)". Resolves the contradiction the Stage-5 bootstrap failure exposed: SEC-010 + D-052 make metal-admin DC-local and forbid the route juju needs, while D-100 names Juju as fiber traffic and D-128 puts the client on voffice1. SEC-010's "pinning is free" was priced against tools that proxy at the app layer; juju dials the machine at L3 and was not in scope. The client moves; the boundary does not. SEC-010, D-052 and D-125 are UNCHANGED -- nothing punctured, no plane opened. D-128 is amended to exclude cloud-facing tools. Scope was set by enumeration first: keystone's VIP is on provider-public, so routing would have opened two planes per DC across a dozen ports. SEC-026 opened for the consequence: a MAAS admin-scoped key becomes resident on a DC-local host, over a region shared by both DCs. Isolation is the control -- each DC's client host gets ONLY its own credential. Counters: 22 open SEC, next-free D 139. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260730-stage5-open.md |
|---|
| docs/design-decisions.md |
|---|
| docs/security-ledger.md |
|---|