OWNED: the ovn-central binding fix did NOT resolve the cert issue; hypothesis was wrong
juju bind ovn-central metal-internal applied (EXIT 0, bundle+live). Post-bind the
cert handler re-ran and the SAME skip warnings persist (internal/admin/public, no
local address found); vault still issues only ca+client.cert, no server cert;
ovn-central still awaiting server certificate data.

So moving the default binding did NOT make internal/admin/public resolve -- those
endpoint spaces are not tied to the default binding (they need os-*-network config
or dedicated bindings ovn-central lacks). The default-on-metal-admin was NOT the
cause; the real fault is the server-cert request/response (core of LP #2044324),
which the binding doesn't touch. The D-052 amendment ruling was taken on a wrong
premise I supplied -- owned.

Keep-or-revert the binding is an open operator call (harmless either way,
ovn-central was already broken). Actual cert remedy unresolved: bounce units /
investigate server-cert request format vs vault charm / escalate LP / accept
degraded. Awaiting direction.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 53e046e commit ff8e0d519a438ddc024558e3cac4879b61c5d910
@JANeumatrix JANeumatrix authored 2 hours ago
Showing 1 changed file
View
docs/CURRENT-STATE.md