| 2026-07-26 |

audit: transcribe the full 55-row credential inventory in-repo (matrix seed)
...
The capture's body previously said the per-row tables lived in the session
transcript. The operator is clearing that session to start the build, so the
matrix SEED would have been lost and would have cost another full inventory
run to re-derive.
Appendix now carries all of it: section A (25 scripted MINT rows), section B
(30 runbook/prose MINT rows), section D (charm-minted, with the keystone admin
password called out as in-scope per the materialization ruling), section E
(MATERIALIZE/UPLOAD checked and excluded, with file:line so the exclusions are
auditable), and section G (coverage boundary, incl. what was deliberately not
opened). Corrected the body pointer that referenced the transcript.
Notable rows the build will need: A6 the MAAS rack-enrollment secret (a mint
nothing else records), B5-B12 the eight Octavia PKI artifacts, B13 the overlay
that lands a CA key + plaintext passphrase inside the repo clone, B14 the
juju-<dc> superusers stored nowhere, B22 the per-DC power key whose dc0 copy is
missing (SEC-021), and A21-A25 which DUPLICATE A11-A14 -- one credential set,
two creation locations, do not double-count.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137: repo-carried build spec for the fresh-session handoff
...
Operator directed the build to a fresh session. The design and committee review
lived in a plan file under ~/.claude/plans/ -- outside the repo -- so a session
bootstrapping via the GA-R4 path (CURRENT-STATE -> session-ledger ->
ledger-scan) would never have surfaced it. That is a real durability gap given
repo-is-authoritative, so the spec now lives at
docs/D-137-implementation-plan.md (precedent: docs/D-068-vault-migration-plan-draft.md).
Carries the five ruled decisions and their consequences, the matrix schema
(logical keys only per the SEC-004 ruling), the checker model with file:line
precedents (provider-bundle-check for structure, sandbox-fidelity-check:131-143
for both-bounds), the three tiers, inherited constraints (metadata-only
source-grep guard, gauntlet excerpt regex, preflight 0/1/2, L1/L10), the file
list, and the acceptance test.
Explicitly instructs the next session NOT to make the first run green: the
acceptance test is that the checker REPRODUCES SEC-021/-022/-023 and the
predicted admin-openrc case as NAMED failures. A checker that passes on today's
tree is wrong. Going green is a separate remediation project.
CURRENT-STATE item 9 + the ledger addendum point at it. Auto-memory pointer
updated: policy authority is D-137 per sub-ruling 4, with a verify-first caveat
that creds-audit CLEAN is not evidence of completeness.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137 sub-ruling 5 RULED + D-137 ADOPTED: implementation unblocked
...
Question as presented: "D-137 ruling 5 of 5 -- identity fold-in ... the matrix
has a principal column, which would make the conflation machine-detectable.
Fold it in, or keep it separate?" Operator selection, exact: "Fold in as a
D-137 invariant (Recommended)".
D-137 gains the invariant ONE IDENTITY SERVES ONE PRINCIPAL TYPE, enforced by
the matrix principal column: a credential serving both human and service is a
FAIL, not an observation. The SEC-020 conflation becomes machine-detectable and
needs no separate D-number -- the question SEC-020 left proposable-but-unassigned
is absorbed here. First run is expected RED by design: admin serves a human GUI
row and a service API row simultaneously, which is the defect.
ALL FIVE SUB-RULINGS RULED -> Status flips to ADOPTED 2026-07-26. Each was its
own operator exchange, committed and pushed before the next was asked (GA-R5).
Also fixes the Status LINE to lead with ADOPTED so ledger-scan attributes it
correctly (it keys on the last **Status:** line, and the entry was still being
counted as an open decision); scan now shows 4 open decisions. Ledger machine
block re-seeded, POST-CLOSE ADDENDUM added per the 07-18/07-21 precedent.
Implementation is UNBLOCKED but NOT STARTED.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137 sub-ruling 4 RULED (GA-R5): D-137 is the credential-lifecycle authority
...
Question as presented: "D-137 ruling 4 of 5 -- policy home. Where does the
credential-lifecycle RULE live as authority?" Operator selection, exact:
"D-137 is the authority (Recommended)".
D-137 becomes the policy authority; the SEC-009 standing-convention block in
docs/security-ledger.md demotes to a pointer, and the ledger returns to being
purely a register of exposures and rotation obligations -- its stated purpose
and the GA-R4/F3 intent. Gates can then cite a D-number rather than an exposure
register. Satisfies the GA-R3 A1 test: a Roosevelt session greps
design-decisions before touching a built surface, so the rule must live there.
Implementation care recorded: the demotion MOVES the convention text, it does
not delete it. SEC-009's block carries the founding history (the NetBox-token
miss) which stays in the ledger as history while the RULE moves to D-137.
D-137 stays PROPOSED; sub-ruling 5 OPEN; nothing built until all five.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137 sub-ruling 3 RULED (GA-R5): remote discovery = declared locations only
...
Question as presented: "D-137 ruling 3 of 5 -- remote discovery scope ... The
tension is tenant isolation on a commercial multi-tenant cloud." Operator
selection, exact: "Declared locations only (Recommended)". Dated 2026-07-26 --
this session crossed the date boundary; sub-rulings 1-2 were pushed 2026-07-25.
A declared list (creds-manifests/vm-secret-locations, <host-role> <path>) bounds
--remote absolutely; it never walks outside the list. No tenant surface touched,
D-069 custody boundary and hard-isolation posture preserved, fast on a live
region.
Records a faithful-implementation note (NOT an override): the list must be
populated with everything already known to hold credential material or the
ruling leaves measured defects uncovered -- per-site creds folders on the
headend as well as the jumphost (SEC-022 shadow stores), the region secrets
dir (SEC-020), and the three directories outside the SEC-009 convention found
by the creation-point inventory. Accepted residual: a secret minted at an
undeclared location stays invisible, so adding a row is part of DoD for any new
mint site.
D-137 stays PROPOSED; sub-rulings 4-5 OPEN; nothing built until all five.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|
| 2026-07-25 |

D-137 sub-ruling 2 RULED (GA-R5): derive manifests from the matrix
...
Question as presented: "D-137 ruling 2 of 5 -- derivation ... How do the
matrix and the manifests relate?" Operator selection, exact: "Derive
manifests from matrix (Recommended)".
Matrix becomes SINGLE SOURCE; --render regenerates creds-manifests/*.manifest
and the gauntlet fails on rendered-vs-checked-in drift. Kills the dual
maintenance the committee flagged as the GA-F06 staleness risk.
Accepted cost recorded at ruling time: manifests become generated artifacts,
so their governance prose (SEC linkage, mint dates, off-manifest carve-outs,
un-consolidated findings) must become matrix FIELDS or be regenerated into the
rendered header -- not silently dropped. That prose is load-bearing: it is what
recorded the dc0 edge-keypair backfill debt.
D-137 stays PROPOSED; sub-rulings 3-5 OPEN; nothing built until all five.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137 sub-ruling 1 RULED (GA-R5): enforcement = blocking in preflight
...
Question as presented: "D-137 ruling 1 of 5 -- enforcement strength. This
decides whether the rule binds or merely advises, and it gates rulings 2-5."
Operator selection, exact: "Blocking in preflight".
Consequence: the credential check lands as a new Pn in scripts/preflight.sh
and HARD-FAILS on any expected-but-absent, undeclared, or per-DC-asymmetric
credential -- no deploy proceeds past a credential gap. Not adopted: the
PreToolUse guard (an agent is constrained at the deploy gate, not at write
time) and advisory-only, which is precisely the posture that failed -- the
phase-3 prose rule was advisory and never fired at either DC standup.
D-137 stays PROPOSED. Sub-rulings 2-5 (derivation, --remote scope, policy
home, identity fold-in) are OPEN and NOTHING is built until all five are
ruled, one exchange each per GA-R5.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

audit: credential creation-point inventory -- 12 declared secrets have NO mint command
...
Read-only research capture seeding the D-137 credential matrix. Nothing built;
the five D-137 forks remain unruled.
FINDING 1 (qualifies the premise that creation points are already known):
`grep -rnI "ssh-keygen" .` returns ZERO hits repo-wide -- no mkpasswd, pwgen,
uuidgen, random_password or tls_private_key either. Yet the manifests declare
six SSH keypairs plus the OPNsense root password/hash, whose only provenance
record is a manifest COMMENT. Twelve standing credentials therefore have no
reproducible mint. If the jumphost is rebuilt, no repo artifact says how to
recreate them -- a Roosevelt-transfer defect, not merely hygiene. Consequence
for the design: mint-ref must admit three provenance kinds (script:line,
runbook:step, operator-terminal), and the operator-terminal rows are the debt
the matrix exists to surface, not parse errors.
FINDING 2: three credential DIRECTORIES sit outside the SEC-009 per-site creds
convention and outside creds-audit entirely -- the Vault init directory (5
unseal shares + root token), the Octavia PKI directory (8 artifacts including
two CA private keys), and the per-tenant directories. All are named in
CLAUDE.md, so they are known; they are simply uncontrolled. Materially extends
SEC-023. Also flags overlays/octavia-pki.yaml, which lands a CA key blob plus a
plaintext passphrase inside the repo clone, gitignored -- with SEC-004 the repo
still PUBLIC.
FINDING 4 corroborates SEC-020 independently: phase-4 runbook:128 mints the
juju-<dc> superusers with no --password (stored nowhere), and
site-headend-install.sh:452 uses --password in argv.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

SEC-021/-022/-023: live credential defects found during D-137 matrix research
...
Recorded, NOT actioned (hard rule 1). Open SEC rows 16 -> 19. These surfaced
while gathering inputs for the credential matrix and are live defects
independent of any D-137 ruling.
SEC-021 dc0 custody defects. (a) changelog-20260719-dc0-deploy-stepB.md:263
records the dc0 edge REST API credential consolidated to
~/vr1-dc0-creds/opnsense-api.txt; that file exists for office1 and dc1 only --
no dc0 copy -- and creds-audit vr1-dc0 says CLEAN because it was never
manifested. A changelog asserting consolidation is not evidence it survived.
Not a lockout: the dc0 edge SSH key is present, D-112(c) SSH is the primary
path. (b) dc0 power key = maas-virsh_ed25519 on voffice1 vs dc1's declared
vr1-dc1-maas-power_ed25519{,.pub} on vcloud -- name/host/custody divergence.
SEC-022 two UNAUDITED shadow *-creds/ stores on voffice1 holding real key
material. creds-audit.sh:29-31 resolves under $HOME on the host it runs on
(vcloud) and has no ssh, so an entire parallel store is structurally
invisible. A scope gap in the control, not a one-off: D-128 puts Plane-2
execution on voffice1.
SEC-023 sprawl globs (creds-audit.sh:72-73) miss admin.pass, *.apikey, *.key,
*.pem, *_ed25519, maas-api-key.txt. Plus a PREDICTED exposure recorded before
it exists: phase-03-admin-openrc.sh:32,72 writes OS_PASSWORD into
$HOME/admin-openrc at Stage 5, home root, matching no glob.
Also reconciles the CURRENT-STATE G14 evidence cell to a measured 19 (it read
12 from 07-23) since this commit adds three of them, and re-seeds the ledger
machine block.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

D-137 PROPOSED: credential mint-and-consolidate pipeline -- make consolidation structural [ARCH]
...
Operator ask: a better method for minting/saving credentials, plus "a durable
rule to make sure when accounts are created there is a consolidation that
happens every time so credentials aren't misplaced or lost."
PROPOSED only -- no tooling built, no enforcement wired, no SEC-009 demotion.
Three forks are presented for ruling, one exchange each (GA-R5).
Measured diagnosis: the existing SEC-009 control CANNOT DETECT THE FAILURE
CLASS IT WAS BUILT FOR, because creds-audit is DECLARATION-based -- the
manifest IS the declaration, so an undeclared secret is structurally
invisible and a green CLEAN is not evidence nothing was missed.
- creds-audit vr1-office1 read CLEAN on 2026-07-15 while four secrets minted
on the region VM on 2026-07-13 (site-headend-install.sh:416-455) sat
undeclared; admin.pass surfaced only 2026-07-25 (SEC-020), 12 days later,
and only because a task went looking.
- No --all (creds-audit.sh:25 takes one mandatory site).
- Enforcement is PROSE in exactly one place (phase-3 runbook:498), absent from
preflight/cloud-assert/repo-lint/gauntlet -- and it did not fire at EITHER
DC standup (dc0 3 + dc1 1 undeclared at this session's open).
- No D governs credential mint/custody generally (D-069 = Vault unseal keys,
D-126 = per-env key isolation), so the rule lives only in the security
ledger -- a register of exposures, which no gate can cite as authority.
Proposal: mint-and-consolidate as ONE operation (creds-mint.sh), plus the
DISCOVERY inversion (creds-audit --all/--remote against declared VM secret
locations -- the only piece that would have caught admin.pass), plus gate
wiring, plus a site-headend-install.sh amendment at the source.
The SEC-020 identity-conflation question stays SEPARATE (not batched, GA-R5)
and remains D-unassigned.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

session-ledger: 2026-07-25 close bookend (SEC-020 MAAS admin recovery, 15 lines)
...
GA-R4 rule 1 bounded summary for the MAAS admin-account recovery session.
Landed EARLY per the 07-21 precedent -- this ledger carries FOUR
"disconnected before its bookend" entries and this is a background session,
so durable-early beats narrating a close that may not happen. Further work
this session appends a POST-CLOSE ADDENDUM.
Also FLAGS, without acting on it, a pre-existing GA-R4 F1 breach: the live
ledger was already 370 lines at session OPEN against the 300-line cap, so
rotation of the oldest closed-session summaries is OWED. Not done here --
that is a judgment call about what to archive, it predates this session, and
unilaterally rotating 90+ lines of other sessions' summaries is exactly the
record-churn the GA-R7 circuit-breaker warns about. Better placed at the
imminent Stage 4 close, with the operator aware.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|

SEC-020: MAAS admin-account recovery -- consolidate `admin`, mint `operator`, creds-audit CLEAN x3
...
Operator task: recover the MAAS admin accounts and save the creds retrievably.
The task premise was FALSIFIED by measurement before any mutation: the ledger's
2026-07-25 "MAAS web-GUI login does NOT exist / never minted" was wrong. The
`admin` password was minted 2026-07-13 by site-headend-install.sh:452 and is
MEASURED working (login 204 vs 400 wrong-password control). It was merely
root-only on voffice1 and un-consolidated -- the SEC-009 miss class, not a
missing account. Scope re-ruled by the operator after that finding:
"New account + consolidate only" -- no existing password rotated.
- NEW MAAS superuser `operator` for human GUI login; password generated on
vcloud, set via stdin (never argv -- SEC-018 discipline; changepassword has
no --password and createadmin --password would expose it).
- `admin` password CONSOLIDATED byte-identical (sha256-verified) to
~/vr1-office1-creds/. NOT rotated, so the VM copy REMAINS source-of-record;
a future rotation must update both or the VM copy becomes a stale trap.
- juju-vr1-dc0/dc1 untouched BY RULING: their SEC-018/019 API keys are
load-bearing for the blocked Stage-5 bootstrap.
- Manifest backfill -> creds-audit CLEAN on all three sites (was RED: dc0 3 +
dc1 1 undeclared), closing the dc0 edge-keypair queued finding named in
vr1-dc1.manifest:18-20.
- Root cause recorded: `admin` doubles as the automation identity (19 `maas
admin` call sites in 4 scripts), so automation never needed the password and
nothing forced it into the folder. Proposable as the next-free D-number
[ARCH]; NOT assigned (GA-R3 doubt-resolves-DOWN).
- Falsified ledger claim struck+corrected; machine-derived block re-seeded
(was stale on every line: SEC 12->16, next-free D 133->137, DOCFIX 200->204).
Evidence: docs/audit/maas-admin-recovery-20260725.txt (generated, no secret
values; scanned for password bytes = 0 hits with a planted-control check).
repo-lint 0 fail; gauntlet ALL GREEN (79).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
|
skill: stage-close sweep keeps the authoritative dir current + regenerates the Chat snapshot
...
SKILL.md stage-close rule now states the authoritative, versioned skill is the
.claude/skills/openstack-cloud-ops/ dir (SKILL.md + references), kept current at each
stage-close sweep, and the dated single-file Chat-upload snapshot is REGENERATED from it
then (a derived artifact, never the source; the stale Chat mount is a known failure mode).
Regenerated openstack-cloud-ops-consolidated-20260725.md from the updated skill so the two
stay in sync. ASCII/LF verified; repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
settings: allowlist read-only whole-host budget calculator
...
From the /fewer-permission-prompts pass: adds Bash(python3
scripts/dc-dc-whole-host-budget.py*) -- a read-only capacity calculator, sibling of
the already-allowed provider-bundle-check.py. Edit was operator-approved earlier this
session; committing now for a clean tree.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
session-ledger: 2026-07-25 close block (GA-R4, 14 lines)
...
Bounded session-close summary at the ledger tail (machine-derived fence untouched).
LEAD item = the MAAS web-GUI login gap (operator locked out; SEC-018/019 are
API/Juju-only, service accounts have random unstored passwords) -- flagged as the
IMMEDIATE-NEXT to process first on the fresh session. Records the completed record
phase (rulings/D-136/DOCFIX-201-203), DC0 mirror complete, and the pending gated
execution path. Durable for /clear.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
DOCFIX-203: mark D-134's superseded original band table in place
...
The 2026-07-23 AMENDMENT header says it supersedes the original D-134 band table,
but the original carried no in-place marker -- a reader grepping D-134 hits the
original first and gets the REJECTED bands (control .10-.19 / compute .20-.49 /
storage .201-.254). The Chat seat did exactly this 2026-07-25. Added a SUPERSEDED
marker immediately above the original, pointing at the authoritative contiguous
table; original kept as history. Single text addition, no behavioural effect.
repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
DOCFIX-202: demote buildout-scope section 5 to a D-111 pointer
...
docs/dc-dc-netbox-buildout-scope.md section 5 framed the per-DC v6 subcarve
(sub-decision 1) as open/un-ratified at lines 5/132/138, contradicting the
ratified pointer already at line 146 ("RATIFIED as D-111 2026-07-11"). D-111 is
ADOPTED and names this exact sub-decision; the stale open framing misled the Chat
seat 2026-07-25 (treated the subcarve as a blocking trust gate). Demoted the three
sites to acknowledge D-111; reasoning kept as history. Single-file text; no
behavioural effect. repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|

D-136 PROPOSED (NetBox-coupled render pipeline) + Ruling 3 + DOCFIX-201
...
Register append + CURRENT-STATE same commit (GA-R1/C1); DOCFIX-201's docs/audit
edits ride the same CURRENT-STATE touch (L10).
- D-136 PROPOSED [ARCH]: NetBox-coupled per-DC render pipeline; option (C)
recommended (values-file back half now for both DCs, NetBox front half for
Roosevelt); non-gating for dc1; prerequisite = extend sandbox-fidelity-check.py.
- Ruling 3 (GA-R5) recorded INLINE in D-136 with the verbatim question + utterance
("Your question about 1 or 2, go with 1. Base bundle and everything else is
applied via overlay") -- committee BLOCKER-1 fix (durable home, not the
delete-after-use pack file).
- CURRENT-STATE Stage-4: bullet (a) vault-VIP D-020 fix + per-DC widen, bullet (c)
artifact-shape RULED, coupling bullet -> PROPOSED as D-136, FOLLOW-UP gate
blockers (pre-flight-checks CHECK 1, provider-bundle-check vault VIP, VIP_OCTET_MAX).
- DOCFIX-201: dual-VIP decision is D-020 not D-036, SEVEN sites (7th caught by the
pack-review committee; verify -> 0 VIP-context D-036 remain).
- Chat correction (2026-07-25): D-136 open Q5 rewritten -- Jenkins IS the runner
(gap void); real requirements webhooks + status-back; placement OPEN.
repo-lint 0 fail. No cloud state mutated. D-136 PROPOSED -- operator rules the
mechanism (GA-R5).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
Ruling 2 recorded (GA-R5): keystone policy-override VERIFY-LIVE gate
...
Operator ruling 2026-07-25. Question: add a VERIFY-LIVE gate that policyd-override
lands on every keystone unit after dc-ha-scaleup scales keystone to 3 (a broken
override is atomic -- whole policy discarded, silently reverting every tenant
domain-manager to a plain user). Utterance (verbatim): "dc-ha-scaleup: Yes to the
verify-live".
CURRENT-STATE Stage-4 VERIFY-LIVE gate added: juju status shows PO: on EVERY
keystone unit after scale-up, never PO (broken):. Protects D-051/D-064 (SCS Domain
Manager). Verbatim also in changelog item 13 (durable home). GA-R5: recorded before
the deploy.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
fix(lint): reword D-101 ruling-note header to clear L5 collision
...
5cf15b3 pushed with a repo-lint L5 FAIL (owned -- lint was not gated before the
commit). L5 counts `^##+ D-NNN` headers unless they contain AMENDMENT/RESOLVED;
the ruling note led with `### D-101 --` (a confirmation, not an amendment), so it
collided with the `## D-101:` definition. Reworded to `### RULING NOTE 2026-07-25
-- D-101 ...` so it no longer leads with the identifier. Content unchanged;
repo-lint 0 fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|

Ruling 1 recorded (GA-R5): address-family policy (D-101 confirmed, no amendment)
...
Operator ruling 2026-07-25. Question: v4-only vs dual-stack for dc1 phase-4.
Utterance (verbatim): "Dual stack to be used where IPv4 is required, IPv6 where
IPv6 only makes sense." Clarifying: "Dual stack deployment for DC0 and DC1. This
is the deployment when the dual-stack is added".
- docs/design-decisions.md: dated RULING NOTE under ## D-101 with the verbatim
question + utterance (confirms D-101's matrix; changes nothing).
- docs/CURRENT-STATE.md: resolve-before-deploy bullet (b) RESOLVED -- v4-only
phasing CLOSED for both DCs; VIP-overlay reconciliation now non-deferrable.
- changelog item 12.
The verbatim is transcribed into durable committed homes (D-101 note + changelog),
NOT left in the delete-after-use _handoff-not-committed/ pack (committee BLOCKER-1).
GA-R5: this ruling lands before the dependent VIP-reconciliation / deploy work.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
skill: consolidated openstack-cloud-ops snapshot for Chat/project upload
...
The Chat-side skill mount is stale (130 lines vs the repo SKILL.md 244 + 6
references; docs/audit/skill-divergence-20260725.md) -- it caused a failed clone
and a wrongly-shaped first handoff-pack draft this session. Chat's skill surface is
single-file, so this flattens SKILL.md + all references/ into ONE uploadable
document the operator can drop into the Chat project to replace the stale mount.
Point-in-time snapshot at HEAD 951ba9c; the authoritative copy stays
.claude/skills/openstack-cloud-ops/. Regenerate from the skill dir on change.
ASCII + LF byte-verified. Not loaded as a skill (loose file, not a skill dir).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
|
|

audit: full decision reconciliation record (IP/VLAN/node/decision-status)
...
4-lens read-only recon of every ruled decision vs the authoritative surfaces
(office1-netbox apex snapshot, lib-net/lib-hosts, bundle/overlays, MAAS carve).
Headline: IP prefix-layer COMPLETE + drift-free; VLANs correctly absent
(untagged-per-fabric, D-133 -- MAAS construct, not NetBox); the GAP is sub-prefix
-- the D-134 per-DC bands + the 33 VIP addresses live only in prose/overlays, not
the apex (blocks the NetBox->deploy coupling). Node/MAC/power config drift-free;
Fork-3 role tags + 10th controller VM pending gated (deploy-blocking).
Decision-status integrity flagged STALE surfaces (fixes QUEUED, operator-deferred):
CURRENT-STATE section 4 comprehensively stale (HIGH), G14 SEC count 12->15,
phase-4 runbook designate line. Reconciliation backlog (P0-P2) + the "what else to
queue" answer in the record; extend sandbox-fidelity-check.py first (gates the
apex recons).
CURRENT-STATE updated same change set (GA-R1/C1) with a pointer + a section-4-stale
warning. No cloud state mutated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
dc-mirror: note mirror.uoregon.edu as preferred upstream (future)
...
Operator perf note (2026-07-25): mirror.uoregon.edu/ubuntu/ is the closest/fastest
mirror for this deployment -> prefer it over archive.ubuntu.com for the MAIN archive
debmirror in a future mirror-tuning pass. Header comment ONLY (not applied; does not
change the generated sync unit). Scoped to the main archive -- the UCA cloud-archive
host is separate and uoregon does not mirror it.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|

netbox: office1-record dumper (source separation) + current apex snapshot
...
Operator-directed: one dump script per SOURCE so a credential/URL can never be
confused (the token never travels -- read from env).
- netbox/office1-record-dump.py (NEW): READ-ONLY dumper for the office1-netbox
RECORD -- the VR1 working apex (10.10.1.10:8000, 4.6.4, v2 token). This is what
every VR1 system actually consumes (DOCFIX-195) and what the dc0/dc1 buildout
edited -- i.e. the CURRENT in-cloud NetBox state.
- netbox/prod-draft-dump.py: docstring clarified -- it pulls ONLY the FROZEN v1
reference (netbox.baldurkeep.com), not the working apex.
- tests/office1-record-dump/run-tests.sh (NEW): offline harness 5/5 (slim /
prefix-scope rewrite / range key / source-target).
- netbox/draft/vr1-office1-current-20260725.json (NEW): the current snapshot --
139 prefixes / 11 sites (incl. vr1-dc0/dc1/off1), dc1 bands 10.12.64/68/72.0/22
present; differs from the 90-prefix frozen reference. For the Chat design
session (NetBox->deploy coupling) which has no live infra.
READ-ONLY: nothing written to NetBox. repo-lint 0-fail.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
| 2026-07-24 |

vr1-dc1 bundle render (9-node role-separated) + expansion review record
...
Render (committee Fork-2 hand-render), validated by the extended checker:
- bundle.yaml: machines "8"-"11" (tags=openstack) -> "0"-"8" role+DC tags (block
style); every `to:` re-homed (quorum trio -> control 0/1/2; nova-compute 3->2 on
compute 3/4; ceph-osd -> storage 5-8; scaled apps + utilities -> control);
ovn-chassis -> the 2 dc1 compute provider MACs (52:54:01:d1:04:02/05:02).
- overlays/vr1-dc1-machines.yaml (NEW): per-DC retag (machines-overlay merge is
VERIFY-LIVE at `juju deploy --dry-run`).
- overlays/dc-ha-scaleup.yaml: tokens rendered to logical control ids 0/1/2
(DC-neutral); header updated; stale ceph-osd-3 comment -> 4.
- provider-bundle-check.py: ovn-chassis MAC check skips the VR0 Pattern-A set on a
role-separated bundle (the validator CAUGHT a real YAML flow-comma render bug).
Validated: base + FULL dc1 deploy input (3 overlays, --dc vr1-dc1) PASS; harness
15/15; gauntlet ALL GREEN (78); repo-lint 0-fail.
Expansion review (3 read-only reviewers) recorded in
docs/audit/stage5-expansion-review-20260724.md: relations/bindings/subordinates
HOLD under role-sep (uniform 6-NIC, SEC-011); no channel/pin change; open
resolve-before-deploy items (vault VIP, v4-vs-dual-stack phasing) + deploy-gate
script gaps + VERIFY-LIVE gates. NetBox->deploy coupling routed to Chat as a new
PROPOSED D-number (Fork-2 escalation). No cloud state mutated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|

provider-bundle-check: overlay merge + per-DC VIP bands + placement invariants
...
The committee's non-negotiable placement "spine" so the vr1-dc1 render is
machine-checked, not eyeballed. The checker was placement-blind (D-052 bindings
+ mysql=3 only), so any render could silently ship decorative HA.
- --overlay FILE: juju-like merge -> validates the EFFECTIVE deploy input
- --dc vr1-dc0|vr1-dc1: per-DC VIP bands (default dc0 = base; un-param run
byte-identical to before). Closes the dc1-VIP-outside-the-check gap.
- placement invariants (fire only on a role-separated machines block, self-skip
on the base bundle): no dangling to:; LXD->control, ceph-osd->storage,
nova-compute->compute; num_units>=2 spread across that many DISTINCT machines
(anti-affinity); ceph-osd==storage count, nova-compute==compute count.
Harness 15/15 (7 new behavioral cases); gauntlet ALL GREEN (78); repo-lint 0 fail.
Machines-block overlay merge is confirmed at `juju deploy --dry-run` (VERIFY-LIVE).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|

Stage-5 dc1: committee review + Fork-1 ruling (D-104 amendment) + BUNDLEFIX-052
...
Track-2 bundle-render blocker, committee-adjudicated (4 read-only lenses:
Roosevelt-delta / HA-DR / operational-risk / Juju-MAAS-mechanism). Every
load-bearing claim re-verified against the repo before adoption.
- Committee record: docs/audit/committee-20260724-track2-bundle-render.md
- Fork 1 RULED (operator, GA-R5): dedicated 10th per-DC controller VM ->
D-104 amendment. Capacity gate PASS (measured): 10-node x 2-DC =
854/1024 GiB (83%, FIT, 170 GiB headroom);
docs/audit/stage5-controller-capacity-20260724.txt
- BUNDLEFIX-052: removed an orphaned `bindings:` block absorbed into
ceph-rbd-mirror (clobbered its D-108 replication bindings + injected a
phantom `dashboard` endpoint -> juju deploy reject). provider-bundle-check PASS.
- CURRENT-STATE Stage-4 bullet updated same change set (GA-R1/C1).
No cloud state mutated. Fork 2/3 = OPS committee-unanimous, executed under gating.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|
Session bookend 2026-07-24: DC1 proxy-build started, BLOCKED on bundle rework
...
CURRENT-STATE + ledger handoff for a fresh session (context exhausted). DC1
Stage-5 deploy setup done (MAAS creds SEC-018/-019, Juju on voffice1, vr1-maas
cloud + credentials, VIP overlay, phase-4 Step 2.0). Committee-reviewed BLOCKER:
committed bundle.yaml is still VR0 4-node hyperconverged; VR1 dc1 needs 9-node
role-separated HA (D-121 Option C) -- architecture decided, deploy artifacts
(bundle/overlays/runbook) never rendered to it. DNS confirmed green for bootstrap
(D-131 forwarder resolves external; hang can't recur) with a hard egress-OPEN
ordering caveat. Owned: fabricated "D-193" in analysis (corrected to D-121; not
persisted). NEXT SESSION: render the vr1-dc1 role-separated HA bundle + wire
overlays + de-stale phase-4, then bootstrap.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VUjEb7onHpdqFHUnio6iVw
|