| 2026-08-09 |

Roosevelt/future-held decisions review -- reevaluated vs current project state (two-pass, self + fable advisor)
...
Read-only decision package (mutates no ruling). Reevaluates all ~24 decisions/
sub-decisions held to Roosevelt / next-deployment / end-of-deployment review,
against current state (D-143 re-IP redeploy, geneve-over-v6 confirmed, deploy
method proven, the tailnet-collision lesson).
KEY FRAME: "next deployment" in these decisions = Roosevelt (the next DISTINCT
bare-metal build), NOT the intra-VR1 re-IP redeploy. The redeploy is a nested-VM
re-build, so it cannot exercise bare-metal/scale items -- but it IS a fresh-build
opportunity for build-process/credential/vault items.
HONEST YIELD: ~4 pull-forwards the redeploy makes actionable (D-137 credential
revocation=R7; D-142 vault-init QoL=R6; D-136 v6 octet-convention review; D-069
custodian assignment) + ~3 analysis-now (D-131 sub-4 node-DNS review; D-140
provider-capability read; D-068 V1-V5 probes) + 1 access-gated reconsideration
(D-129(iii) tagged-identity/star ACL -- the collision made the exposure concrete,
but the Headscale-access blocker persists). The majority (18 rows) genuinely stay
bare-metal/scale/version/Magnum-bound -- reevaluation CONFIRMS them.
Two-pass: fable advisor caught 4 unplaced/conflated inventory items (D-029,
D-068 items 2/3 unplaced; D-069 custodian-vs-auto-unseal conflation; D-136 CI-half
mis-grouped) -- all fixed, corrections in Section 8.
REVERT: git rm the review file; revert the CURRENT-STATE pointer block.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

D-143 RULED (GA-R5): VR1 re-IP 10.12.0.0/16 -> 10.13.0.0/16 -- AMENDS D-115 premise, TERMINATES D-101 v4-inherit; apex fork B2, lib-net (i)
...
Operator ruled the re-IP in two exchanges (option selections are the exact
utterances, recorded verbatim in the D-143 Status block):
- Exchange 1: "Accept evidence + adopt 10.13" -- adopts 10.13.0.0/16 (octet-
preserving 10.12.a.b->10.13.a.b) and ACCEPTS the tailnet+apex measurements as
sufficient for owed check #3 (VR0 internals, tailnet-only/unreachable).
- Exchange 2: C.1 "B2: new 'Cloud -- VR1 rebuild' role" (10.13 gets its own NetBox
role; Cloud stays 10.12-only, no live record re-labelled); C.3 "(i) Keep flat
defaults at 10.12; VR1 arms get full 10.13 blocks" (preserves lib-net.sh line-37
invariant).
Reconciliation: AMENDS D-115 (factual premise; role-based ruling holds),
TERMINATES D-101's v4-inherit clause, CONSISTENT-WITH D-124 (routes re-point) +
D-134 (survives, endorses the octet-preserving map).
Live evidence at ruling time (2026-08-09, operator-authorized read-only): apex
10.13=0/10.12=149; tailnet no 10.13 overlap, the 10.12 collision reproduced as
positive control. Check #3 accepted-not-run (recorded blind spot).
NOT EXECUTED (hard rule 1): B2 apex re-carve, lib-net.sh (i) + F13 comment fix,
R16 naming-collision DOCFIX, D-124 route re-point, R7 teardown revocation -- all
subsequent gated steps. CURRENT-STATE section-1 banner updated (GA-R1 C1);
next-free D now 144.
REVERT: remove the D-143 block from docs/design-decisions.md and revert the
CURRENT-STATE section-1 banner to "NOT YET RULED".
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-09 (part 2): open-items review bookend -- GA-R4 (sweep + ledger close + rotation + memory #25)
...
GA-R4 BOOKEND for the open-items-review session. Sweep proves the session's
substance is on a repo surface (docs/audit/queued-findings-20260809-open-items-review.txt).
- Ledger: 15-line close appended; the two 2026-08-07 blocks rotated to
docs/archive/session-ledger-rotated-20260809.md (oldest-first); file 285 lines (<300).
- Sweep FIRST SURFACE: FS1 the repeatable method for the 2 completed re-IP live-free
checks (apex dump from vcloud + tailnet enum from office1-tailscale); FS2 access facts
(VR0 tailnet-only/unreachable from vcloud; tailnet also carries Roosevelt 10.17.x +
willamette, all clear of 10.13); FS3 raw captures ephemeral.
- Memory: instrument-currency #25 (P5 gate read on the wrong host -> "12 findings"
manufactured-decision framing, caught by the advisor) + MEMORY.md index.
- CURRENT-STATE: sweep pointer added (L10/GA-R1 C1).
OWNED (also in open-items-review Section 8): P5-wrong-host framing (#25); "sums to 28"
was 24; SEC-021(a) overstated (S2 still red); shred-hazard on a likely-live token;
CLOBBERED session-ledger-rotated-20260809.md with a Write (overwrote a tracked file I had
not read) -- caught in git status, restored from HEAD + appended.
REVERT: git rm the sweep file; revert the ledger/archive/CURRENT-STATE hunks. The
prior review commit f4aee80 is independent and stays.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

open-items review (D/SEC/DOCFIX/BUNDLEFIX) vs the hardened end goal -- two-pass (self + fable advisor), live-grounded
...
WHAT: a read-only decision package reviewing all open items against project state
and the hardened end goal (re-IP redeploy on 10.13, IPv6-primary, min-delta-to-
Roosevelt). Rules nothing; mutates no authoritative status. New file
docs/audit/open-items-review-20260809.md + a pointer in CURRENT-STATE (GA-R1 C1).
CONCLUSION: backlog is overwhelmingly correctly-deferred (5 open D at Roosevelt/
end-of-deploy/v1-close; 28 SEC rows = rotation obligations + accepted postures,
no defects). The re-IP GA-R5 ruling (would be D-143) is the ONLY item gating the
end goal. Two re-IP-coupled gaps to build: R7 teardown credential-revocation
checklist; R16 10.13 naming-collision DOCFIX.
LIVE CONFIRMATION (operator-authorized discovery, read-only):
- re-IP owed check #2 (NetBox apex): PASS -- 10.13 = 0 objects, 10.12 = 149 control.
- re-IP owed check #1 (Headscale/tailnet): PASS -- no 10.13 overlap; the exact
10.12 collision reproduced as positive control (vopenstack-jesse-tailscale).
- check #3 (VR0 internals): not completable from vcloud (tailnet-only) -> operator
accept-or-run option.
- creds-matrix P5 (authoritative on voffice1, clone==HEAD): 11 findings (6 accepted
+ 5 dc1 forward-register, grew by design 101->121 rows) -- NOT a silent gate growth.
- DC-substrate credential residency measured live (R7 premise).
- dc0 checkpoint: 66 machines/162 units active (matches record).
TWO-PASS: fable advisor caught (1) a P5 instrument mismatch (vcloud vs voffice1 --
framing inverted from "silent growth" to "grew by design"); (2) a false "sums to
28" completeness claim (was 24) -> re-partitioned + new bucket 3b' (dc1 material on
persistent hosts retires at v1 close, not the re-IP); (3) a shred-hazard on a likely-
live dc1 edge token -> reframed to declare-only. Corrections recorded in Section 8.
REVERT: git rm docs/audit/open-items-review-20260809.md and revert the CURRENT-STATE
pointer block (lines added under the reip-prep pointer). No other surface touched.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
savegame 2026-08-09: geneve-over-v6 root-cause + D-139 amendment + executable gate -- GA-R4 bookend + sweep
...
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
geneve-over-v6 REBUILD RECIPE consolidated (item 3): container v6 carve + unbracket override + overlay_ip_version + gate
...
No fixed ovn-chassis revision pinned by search (charm-ovn-chassis LP #1968355 family, inconclusive) -> the reliable rebuild fix is a persistent post-deploy unbracket override (re-assert after config-changed), re-verified by scripts/geneve-encap-assert.sh. D-139's metal-admin-leg-IPv4 gate specced (build at rebuild, needs live cloud). One executable recipe in the root-cause record; CURRENT-STATE owed-list points to it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
D-139 AMENDMENT (2026-08-09, GA-R5): geneve-over-v6 confirmed viable; containerized chassis need carved v6 + unbracketed encap
...
Operator ruling (verbatim): 'D-139 amendment' (vs a new D-number). Records the 2026-08-09 live finding: geneve-over-IPv6 forwards on OVS 3.3/OVN 24.03/kernel 5.15 (VM-to-VM 8/8) once (i) containerized ovn-chassis take a carved v6 data-tenant address and (ii) ovn-encap-ip reaches OVS unbracketed (ovn-chassis 24.03 brackets it -> ofport -1). v4-forced is off the table. Gate scripts/geneve-encap-assert.sh (family + tunnel ofport) is the proof, wired into phase-04 Step 12.2. CURRENT-STATE section 1 updated (D-number OWED -> RULED).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

geneve-over-v6 root-caused (bracket bug) + LIVE-CONFIRMED; executable encap gate + phase-04 fix
...
Live diagnosis on vr1-dc0 (D-138): the v6 geneve tunnel failed with ofport -1 because ovn-chassis 24.03 sets ovn-encap-ip BRACKETED ([2602:...]), which OVS geneve rejects. Delivered unbracketed -> tunnel instantiates -> real VM->VM cross-compute ping over geneve-over-IPv6 = 8/8, 0% loss. So v6-only data-tenant is viable and v4-forced is off the table (OVS 3.3.0/OVN 24.03.2/kernel 5.15). A first same-day test wrongly concluded 'v6 broken' from an OVN localport source (never tunnels by design) -- retracted.
scripts/geneve-encap-assert.sh (+ harness 16/16, manifest pinned): asserts C1 encap family consistency (--expect-family v6) AND C2 every geneve tunnel ofport>=0 (the bracket-bug check a family-only gate misses). phase-04 Step 12.2 rewritten (family-only -> family+tunnel-health, ULA->GUA) + Step 6 caveat. CURRENT-STATE section 1 + root-cause record updated; GUA-carve proposal (DC1 gap + matrix + scan) added. repo-lint 0-fail; gauntlet ALL GREEN (103).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-08 (part 3): amphora build FIXED + geneve-over-v6 wrap-gate ROOT-CAUSED
...
GA-R4 bookend for the dc0-activation part-3 session.
- Body: docs/changelog-20260808-amphora-geneve.md (amphora two-layer fix [loop-device
passthrough + retrofit ubuntu-mirror->dc0 mirror; image 775ebeba ACTIVE], o-hm0 MTU PASS,
1-test-LB blocked by geneve-over-v6, delivery).
- Sweep: docs/audit/queued-findings-20260808-amphora-geneve.txt (FIRST SURFACE: live mutations
w/ reverts, test LB/net/amphora LEFT LIVE [teardown owed], retrofit diag traps).
- CURRENT-STATE part-3 progress block + session-closed pointer.
- session-ledger: bounded close summary; machine-derived block RE-SEEDED from ledger-scan
(SEC 29->28 [SEC-031 closed], DOCFIX 210->214, BUNDLEFIX 053->059); rotated 08-06 x2 ->
archive/session-ledger-rotated-20260809.md (ledger 283 lines).
Gates: repo-lint 0-fail (1 legacy warn); gauntlet ALL GREEN (102); ledger-scan reconciled
(4 open decisions, SEC 28, next-free D-143/DOCFIX-214/BUNDLEFIX-059, no new numbers).
Revert: git revert this commit (records only; live mutations + reverts are in the changelog).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-08 |

geneve-over-v6 root-cause: verify on compute-01 (amphora host) + tighten evidence
...
Advisor-flagged corrections to cd1f9cd's root-cause record (claims now measured, not inferred):
- data-tenant confirmed the SAME dual-stack plane on both node types (lib-net.sh PLANE_CIDRS
10.12.16.0/22=data-tenant, in SPACES6); divergence is address-family SELECTION, not a binding
error (both chassis types bind data-tenant).
- tunnel state re-read on vr1-dc0-compute-01 (ovn-chassis/1, the amphora's ACTUAL host): its
v6 local encap has IPv4 remote_ip to the 3 control chassis -> cross-family, same pattern.
- softened the bfd_status claim to AMBIGUOUS (OVN geneve may not populate BFD); decisive
evidence is the encap-family split + 100% ICMPv6 loss. compute<->compute v6 path noted UNTESTED.
- dropped the pre-allocated "D-143" (number assigned at ruling per grep-for-next-free).
Revert: git revert this commit (records only; no live cloud state changed).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

geneve-over-v6 wrap-gate ROOT-CAUSED (FAIL): OVN encap family split control(v4)/compute(v6)
...
The dc0 "verify-live geneve-over-v6" checkpoint gate FAILS, root-caused this session
via the 1-test-LB smoke test. Measured: OVN geneve encap IPs are split across address
families -- containerized control-node chassis (octavia LXD) have IPv4-only data-plane
addresses (10.12.16.x, D-134 auto-picked) -> IPv4 encap; carved compute metal uses IPv6
(2602:f3e2:f02:30::x). Cross-family geneve tunnels never form (bfd_status empty) -> 100%
cross-node overlay loss -> amphora unreachable from o-hm0 -> LB stuck PENDING_CREATE.
Roosevelt-delta: v6 builds must give containerized OVN chassis a v6 data-tenant address
so encap is family-consistent with metal. Candidate D-143 (PROPOSED, operator ruling owed).
Fix NOT applied (substantial + rebuild-relevant). Full record:
docs/audit/geneve-over-v6-rootcause-20260808.md. CURRENT-STATE progress block updated
(clears repo-lint L10 for the audit file).
Revert: git revert this commit (records only; no live cloud state changed).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

bookend: land prior part-2 GA-R4 close + dc0-activation part-3 progress (amphora FIXED, LB blocked on v6 overlay)
...
Lands the prior session's savegame residue (GA-R4 part-2 close block in
session-ledger.md, the 2026-08-08 ledger rotation to archive/, and the
dc0-activation-checkpoint queued-findings sweep) which was left uncommitted
pending the operator's push decision (now pushed: a25ed99..a6340e6).
CURRENT-STATE.md gets this session's (part 3) measured status update, which
also clears repo-lint L10 for the docs/audit/ sweep file:
- amphora build RESOLVED (was part-2 retrofit exit-1 INCIDENT): root cause
loop-devices-absent-in-LXD + dib-apt-targets-unreachable-public-archive;
fix = loop passthrough + retrofit ubuntu-mirror -> dc0 mirror. Image
775ebeba... ACTIVE+tagged octavia-amphora.
- G18 OWED#3 (o-hm0 MTU) PASS.
- 1 test LB blocked on geneve-over-v6 overlay (o-hm0->amphora 100% ICMPv6
loss); UNDER INVESTIGATION (== the verify-live geneve-over-v6 wrap gate).
Revert: git revert this commit (records only; no live cloud state changed by
this commit -- the live mutations are logged for the forthcoming changelog).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
changelog: amphora retrofit build INCIDENT (Item 7) + MODEL=vr1-dc0 fix
...
Octavia CORE activated; amphora image blocked on octavia-diskimage-retrofit exit 1
(dib-in-LXD-container hypothesis, rebuild-relevant). LB smoke test blocked until fixed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
changelog: Octavia configure-resources fired + verified (Item 6); G18 OWED#1/#2 captured
...
Live: operation 67 completed, octavia/0 active, lb-mgmt-net + fc00:5b7a:7bdc:bd86::/64
+ lb-mgmt-sec-grp created, o-hm0 up, mgmt router external_gateway_info=None (isolated).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
G18 RULED (GA-R5, option b): Octavia lb-mgmt recorded out of apex scope + D-139 /64 reserved
...
Gate G18 CLOSED 2026-08-08. Operator ruled option (b): the charm-created Octavia
lb-mgmt-net (IPv6-ULA fc00::/64, charm-generated per R8, regenerates per deploy) is
deliberately charm-owned and OUT of apex scope; the separate D-139 apex GUA lb-mgmt
/64 is kept reserved (distinct MAAS-underlay object, no charm consumer). R8 not
reopened. lb-mgmt is v6-ULA, outside the 10.12->10.13 v4 re-IP. Primary record in
CURRENT-STATE G18 row; annotations on D-101/R8 + D-139. No new D-number. Prep package
docs/audit/g18-lb-mgmt-ipam-ruling-prep-20260808.md. Also: changelog Items 3-5
(live network-create, G18 ruling, Designate real-Stage-7 decision).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
dc0-activation: phase-04 network scripts MAAS_PROFILE-aware (DOCFIX-213, F3/D-138) + re-IP ruling-prep package
...
phase-04-network-create.sh + phase-04-network-verify.sh honour MAAS_PROFILE
(default admin=VR0/office1; VR1 overrides to the DC regional, e.g. vr1-dc0-region)
instead of hardcoding 'maas admin'. Fixes F3: the dc0 rack has openstack+cloud L3
but no maas profile, and the maas two-source gate needs both on one host. Operator
directive: each DC has its site regional maas; racks register up to the DC regional.
Harnesses extended with EXPECT_PROFILE proof (failability verified out-of-band).
Also lands docs/audit/reip-1013-ga-r5-ruling-prep-20260808.md (Task #6 background
analysis) + a CURRENT-STATE pivot pointer to it (L10 coupling).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-08: dc0 .7 tailscale FIXED (advertise-only) + 10.13 re-IP PIVOT + dc0 checkpoint plan
...
GA-R4 bookend + sweep for the session that fixed the dc0 .7 tailscale install
(advertise-only, --authkey=file:, check guards -- committed 02e0b12/faef662) and
surfaced the 10.12->10.13 re-IP pivot.
- CURRENT-STATE: 2026-08-08 pivot callout -- 10.12 collides with the live IPv4
cloud; drive dc0 to full deployment as a CHECKPOINT, then teardown+redeploy on
10.13; the re-IP is a D-115 supersession + D-101 termination, NOT YET RULED.
- Sweep docs/audit/queued-findings-20260808-...reip-pivot.txt (F1-F16): the pivot,
the D-115 conflict, MAAS profiles missing on the racks (fix existing+rebuild),
no service migration (DC0>MAAS-regional>MAAS-rack), dc0 live inventory,
checkpoint scope, + instrument-currency #22 (F3 wrong-store retraction; pkill
self-match).
- 10.13 NetBox subnetting DRAFT (Task #2; octet-preserving proposal, not ruled).
- changelog-20260807 F3 retraction/correction; bounded ledger close summary.
Gauntlet ALL GREEN (102); repo-lint 0 fail. Tasks #1-#4 pinned.
Status ONLY in CURRENT-STATE.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-07 |

site-tailscale: advertise-only subnet router + authkey=file: + check guards
...
Fixes the 2026-08-07 install incident where bringing .7 up as a subnet router
with --accept-routes blackholed its own L3 (it imported a route sending its
own return traffic for the advertised /22 into tailscale0) and locked us out.
- install: DROP --accept-routes (a subnet router advertises, it does not need
to consume routes); pass the pre-auth key via --authkey=file:<path> so the
secret never lands on argv / in ps (the key leaked that way during the
incident).
- check: add two assertions, each with a failing-direction fixture --
own-subnet-not-routed-via-tailscale0 (the blackhole guard) and control-plane
reachability (live HTTP from $LOGIN_SERVER, not just DNS).
Validated LIVE: advertise-only re-join brought .7 up Running/Online (TSIP
100.64.0.57) with its own subnet NOT hijacked and no lockout; route now awaits
Headscale approval. Harness 27/0, gauntlet ALL GREEN (102), repo-lint 0-fail.
Body: docs/changelog-20260807-dc0-tailscale-install.md (UPDATE section).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

site-tailscale: prep verb + untagged VR1 (office1-mirrored) + forwarding assertion
...
Extends scripts/site-tailscale.sh to three verbs (prep|install|check) so the
per-DC .7 subnet router is brought up exactly as the working Office1 router.
- prep <site>: install the tailscale .deb from a rack-staged copy ($TS_DEB;
the .7 has no external egress) + enable IP forwarding (/etc/sysctl.d/
99-tailscale.conf, sysctl --system) and ASSERT it took.
- tag now OPTIONAL: TS_TAG defaults empty = untagged (office1-mirrored, VR1);
install omits --advertise-tags and adds --accept-routes (office1 RouteAll);
TS_TAG=tag:subnet-router restores the D-129(iii) tagged design (Roosevelt).
- check now ASSERTS IP forwarding -- the load-bearing subnet-router property
that 'tailscale up --advertise-routes' warns-and-succeeds without, so the
route could be approved while nothing forwards to Horizon (advisor 2026-08-07).
Harness: 23/23 (new failing-direction fixtures prep-noforward, check-noforward,
check-tag-notag, prep-fromdeb, install-tag-happy). Gauntlet ALL GREEN (102);
repo-lint 0 fail.
Records the operator's untagged/office1-mirror deferral as a D-129(iii)
amendment ([OPS], tags/autoApprovers/star ACL -> bare-metal) with the verbatim
utterance. Body: docs/changelog-20260807-dc0-tailscale-install.md.
Live install NOT yet executed (staged .deb -> dpkg -> prep -> install ->
operator Headscale approval -> check).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
savegame 2026-08-07 (part 2): bookend + sweep -- dc1 region standup + SEC-031 edge rebuilt
...
GA-R4 bookend for the dc1-region-sequence session (F NetBox importer; dc1 region
topology/IPAM/DHCP-cutover/power-key; SEC-031 edge rebuild + runbook/tool). Bounded
ledger summary + rotation (2026-08-05 x2 archived, now 283 lines). Sweep
docs/audit/queued-findings-20260807-dc1-region-sequence.txt: 3 FIRST SURFACE
(console-driver harness owed; run-logged gap; jammy source-index trap). CURRENT-STATE
records the standup progress (steps a-b done, D/E remaining). Gates: repo-lint 0-fail,
gauntlet ALL GREEN (102), ledger-scan SEC 29->28.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
SEC-031 CLOSED: dc1 edge rebuilt + procedure captured as runbook + tool
...
Rebuild the damaged dc1 OPNsense edge via the proven dc0 procedure (operator-
directed). dc-egress-check dc1 8/8; .6 region reaches the internet (ping 1.1.1.1,
curl images.maas.io 200) -- unblocks jammy image sync. Edge-only tofu -replace
(machine-asserted 2/0/2, nodes protected) -> console bootstrap -> WAN/LAN
addressing -> automatic outbound NAT.
Fix the root gap the operator flagged: the dc0 rebuild lived only as an audit
capture, forcing dc1 to reconstruct it. Now a first-class runbook
(runbooks/dc-edge-rebuild.md, site-parameterised) + a site-agnostic tool
(scripts/opnsense-console-rebuild.py, replaces per-DC one-off drivers). SEC-031
closed; CURRENT-STATE + changelog Item 4 updated. Also lands the Stage-5 dc1
region-standup captures (topology, DHCP handover).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

NetBox util-host importer + as-built utility hosts landed into office1-netbox
...
Close the tool gap on the operator-flagged NetBox-pending list: the D-134
utility RANGES were in the apex but no importer recorded the individual
utility-HOST addresses. New netbox/dc-util-hosts-import.py (DERIVES plane CIDRs
from lib-net + host octet from lib-hosts; whole-plan preflight; range
precondition; dns-collision guard; SANDBOX + upstream-write gates; dry-by-
default) + harness tests/dc-util-hosts-import/ (19/19).
Landed 8 ip-address objects (ids 187-194; apex ip-addresses 186->194, idempotent
re-run EXISTS/0): dc0 .5 juju-01, .6 maas-01, .7 tailscale-01; dc1 .6 maas-01
(both planes each). dns_name carries the ruled vr1-dc<N>-<role>-NN names -> dc0
renames recorded by construction.
Deferred as findings: the .4 artifact host (metal-admin-only, per-DC divergent,
no repo name -- needs an operator naming ruling) and dc1 .5/.7 (record when
live). Gauntlet ALL GREEN (102); repo-lint 0-fail/1-legacy-warn. Revert = NetBox
DELETE of ids 187-194. Body: changelog-20260807-dc1-region-sequence.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
NetBox-pending: queue this session's new IPAM objects for office1-netbox (operator-flagged)
...
office1-netbox (10.10.1.10) is the live VR1 IPAM apex (DOCFIX-195); this
session's new objects are not yet in it. Enumerated in changelog Item 11
(dc0 .7 + dc1 .6 region VM + new vr1-dc1-region + dc1 .7-when-live +
D-134 utility .4-.9 assignments + dc0 renames) and flagged as a
do-not-miss NetBox item in the next-session NEXT (CURRENT-STATE + ledger)
so it isn't lost before the end-of-deployment write-back.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
vr1-dc1-region profile registered + verified; session close consolidated
...
Registered the vr1-dc1-region profile on voffice1 (dc0-pattern tunnel
-L 5243:10.12.68.6:5240 via the rack; apikey piped .6->`maas login -`
stdin, never exposed). Verified: rack vr1-dc1-maas-01 (qtw8pm), 0 machines
(empty -- the 9 nodes+juju+.7 get rebuilt in). changelog Item 10 + a
handoff block enumerating the remaining config/rebuild chain.
Consolidated this session's ledger block to a bounded GA-R4 summary
(dc0 .7 carved-and-ready + D-134 naming amendment + vr1-dc1-region LIVE);
ledger 296/300, repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

vr1-dc1-region MAAS is LIVE -- region init done on the .6 (operator-authorised one-shot)
...
Located the shared vr1-office1-svc key ON VCLOUD (~/vr1-office1-creds/
office1_svc_ed25519, fingerprint matches the injected key -- operator's
"what was used on DC0"); reached the .6 from vcloud (key stays local,
ProxyCommand via voffice1->rack). Snap egress works via the snapd proxy
10.12.68.2:8000. Installed maas 3.7.2 + postgresql 16.14. Operator
authorised ("You run it"); ran the file-staged credential one-shot (creds
generated + stored 0600 on the .6, NEVER in my context): DB role+db,
maas init region+rack, createadmin. http://10.12.68.6:5240/MAAS/ -> 301.
OWED: consolidate the .6 creds to ~/vr1-dc1-creds/ (SEC-020/D-137).
NEXT: register vr1-dc1-region profile + config via tested tools + rebuild
9 nodes+juju+.7 fresh into it. changelog Item 9 + CURRENT-STATE + ledger.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
dc1 .6 region VM DONE to Deployed jammy (carved, both legs live) -- ready for MAAS install one-shot
...
Extended aux-carve for -maas-01 (9fea7c1); carved the .6 in Office1
(--profile admin, all 3 racks; metal-admin 10.12.68.6 + provider-public
10.12.64.6, pass=6/0); MAAS-deployed jammy -> Deployed, power on, both
legs ping 0% from the rack (transient power/virsh flakes cleared on
re-query).
NEXT is the MAAS region install/init on the .6 -- OPERATOR ONE-SHOT
(createadmin=SEC-020 + reaching the .6 needs the operator's
vr1-office1-svc key). Then register vr1-dc1-region + config via tested
tools + rebuild 9 nodes+juju+.7 fresh into it. changelog Item 8 +
CURRENT-STATE + ledger NEXT.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

dc1-region workstream START: .6 region VM bootstrapped to Ready + MAAS 3.7 procedure researched
...
Operator ruled dc1 node-handling "Rebuild fresh into dc1-region". Measured:
dc1's full set is in the Office1 region (9 nodes+juju Ready; .6/.7 Failed
commissioning on unset-power). Bootstrapped the .6 region VM (Office1-side,
like dc0 hot-kid): power set, renamed normal-piglet->vr1-dc1-maas-01
(convention), recommissioned -> Ready (a transient virsh-login error
cleared on retry).
Researched + recorded the MAAS 3.7 region+rack install/init (changelog
Item 7; matches Office1 3.7.2 + PostgreSQL 16; external DB required;
createadmin=SEC-020 operator one-shot). Remaining next-session: extend
aux-carve for -maas-01 + carve .6 (10.12.68.6 + 10.12.64.6) before deploy
(hot-kid under-carve lesson); deploy jammy; MAAS init one-shot; register
region + config via tested tools; rebuild 9 nodes+juju+.7 fresh into it.
CURRENT-STATE dc1 block + ledger NEXT updated. repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
D-134 amendment: MAAS hostname naming convention (standing) + dc1 rebuild-fresh ruling
...
Operator: "Record that as the preferred naming convention going forward."
Recorded the VR1 MAAS hostname convention (set vr1-<dc>-<role>-NN ==
libvirt domain == power_id after commission/deploy; random-by-default is
not leave-it-random; standup DoD = 0 non-vr1-<dc>-* names) as a D-134
AMENDMENT (per-DC identity standard; ARCH, no new number) + lib-hosts
comment.
dc1 node-handling RULED "Rebuild fresh into dc1-region" (build region,
then power/enlist/commission/deploy the 9 nodes+juju FRESH into it, not
delete+re-enlist) -> CURRENT-STATE dc1 block + ledger NEXT.
repo-lint 0 fail; gauntlet ALL GREEN (101).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
dc0 MAAS hostname convention: rename tailscale + juju controller (operator correction)
...
Operator: "You are not following naming conventions." Renamed the two
random-named vr1-dc0-region machines to convention (hostname == libvirt
domain == power_id, lib-hosts:26): known-marten->vr1-dc0-tailscale-01,
subtle-grouse->vr1-dc0-juju-01. All 11 dc0-region machines now vr1-dc0-*.
Cosmetic to tooling (carve/power resolve by boot MAC); load-bearing for
operability. changelog Item 6 + CURRENT-STATE note.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
Session bookend 2026-08-07 (dc0 tailscale .7 carved-and-ready): GA-R4 + sweep
...
Bounded ledger summary + rotation (08-04 block -> archive, 296/300); sweep
docs/audit/queued-findings-20260807-dc0-tailscale-provisioning.txt (F1-F4
first-surface); CURRENT-STATE + changelog ping-verification edits (both .7
legs live). Deliverable d36d815..c8ddfb6 already pushed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|