| 2026-08-05 |

Close-fix 2026-08-05: add Body changelog, verify root CA (openssl), reconcile D-142 scan-visibility + durability
...
Advisor-caught close gaps against the repo's own convention:
- Body: NEW docs/changelog-20260805-vault-init-ovn-resolved.md (prior closes cite a
changelog Body: line; the 08-05 close block had Sweep: but no Body:). Ledger + CURRENT-STATE
now cite it.
- Root CA: decoded the ACTUAL pasted PEM with openssl on the rack (not a self-decode).
Confirms notBefore Aug 5 02:05:57 2026 / notAfter Aug 2 01:06:27 2036 GMT; adds sha256
75:DF:33:97:...:35:A1. as-exit as-built + CURRENT-STATE updated to measured fact.
- D-142 Status now leads "PROPOSED / OPEN" so ledger-scan surfaces it (was invisible; scan
keys the open list off the Status token) -> reconciles the close block's "4 open decisions".
- Durability line completed: voffice1 PULLED to sync (was 3321c57, 4 behind); dc0 rack
~/repo-stage unaffected (docs-only; preflight sha verified); gauntlet not owed (docs-only).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

Stage 5 dc0: vault init DONE + ovn-central RESOLVED; D-142 vault-init QoL saved
...
Live (operator-run one-shot, recorded no-secrets): phase-02-vault-bringup Steps
2.1-2.3 on the dc0 rack (-m vr1-dc0), vault active/idle, root CA generated
(valid 2026-08-05 -> 2036-08-02). ovn-central/3,4,5 ALL active -- OVN NB/SB
cluster formed; the multi-session cert saga is closed by the two fixes landed
this cycle (dc-node-etchosts Step 1.2b CN delivery + D-052 '' -> metal-admin).
Engineering saved (PROPOSED, not executed -- operator: run current commands now,
test QoL next opportunity):
- D-142 PROPOSED: vault-init workflow QoL sweep (APPROVED-IN-PRINCIPLE, IMPL
DEFERRED; R2 off-host transport UNRESOLVED). Distinct from D-068 (substrate) /
D-011.6 (manual-unseal bar).
- docs/audit/vault-init-qol-proposal-20260805.md: R1-R5 + full hidden-prompt
safety analysis + tee-write residual + pre-init writability probe + R3 harness
constraints + operator's verbatim safety constraint.
- runbook-fold-register F13: -m openstack -> -m vr1-dc0 / run-location = DC rack
(D-138) on phase-02-vault-bringup (scope stretch stated).
CURRENT-STATE + as-exec updated (L10 coupling). Security hygiene: child token in
operator paste was ttl=10m/expired -> benign, not stored. Remaining (separate):
ceph-mon/2 + ceph-radosgw/0 allocating (apt-wedge) cascade.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

D-052 RE-AMENDMENT: ovn-central '' default metal-internal -> metal-admin + network binding reference
...
- ROOT: the '' default is the MANAGEMENT binding (primary NIC + juju agent<->controller),
universal '' = metal-admin across all 56 apps. The 08-03 amendment ('' -> metal-internal,
never deployed until 08-04) left ovn-central single-legged on the isolated metal-internal
plane -> no route to controller (10.12.8.5:17070 unreachable) -> agent-binary download failed
-> ovn-central never started. Its cert rationale was already withdrawn; cert CN is fixed
independently by the /etc/hosts postruncmd (dc-node-etchosts.sh, Step 1.2b).
- bundle.yaml: ovn-central '' -> metal-admin; functional endpoints (certificates, ovsdb*,
coordinator) STAY metal-internal. provider-bundle-check 55/55, repo-lint 0 fail.
- D-052 RE-AMENDMENT 2026-08-05 recorded (GA-R5, operator utterance quoted). Scope: ovn-central
only; every other binding re-verified correct vs dataflow (ruled exceptions: D-072 dashboard,
D-106 designate:dnsaas).
- NEW docs/network-space-binding-reference.md: 6-plane roles + CIDRs + RHOSP analogs, the ''
management-binding rule, full 56-app placement matrix, dataflow confirmation, ruled exceptions.
- Stage 5 remains OPEN. NEXT: re-stage bundle to rack, re-home ovn-central on the live model,
then vault init (operator-only) -> ovn cert -> converge.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-04 |

Stage 5 dc0 redeploy: Path M teardown (clean) + ovn-central cert DELIVERY bug fixed
...
- Path M teardown of vr1-dc0 complete + clean: graceful drain (36->15) + juju
resolved --no-retry (error-unit wedge, 15->3) + --force --no-wait (agents-stopped
tail, 3->0). NO orphan (controller healthy), M.5 cascade clean (10 machines
UNCHANGED, 9 Ready + 1 Deployed). Both --force and resolved operator-ruled (GA-R5).
- dc-node-etchosts.sh: render runcmd: -> postruncmd: -- juju model-config forbids a
top-level runcmd in cloudinit-userdata. The 08-04 fix proved the CONCEPT live but
never the DELIVERY (harness graded cloud-init YAML, which accepts runcmd, not juju
acceptance). Harness switched to postruncmd + NEW T10 (juju-accepted key, rejects
bare runcmd), MUTATION-PROVEN, 10/10. Step 1.2b now live-passing; re-staged to rack.
- M.6 rebuild to the deploy step: add-model (cred vr1-dc0-cred), spaces PASS 0 fatal,
egress 8/8 PASS, dry-run PASS (9 machines, per-DC tags). Stage 5 remains OPEN.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|