| 2026-08-10 |

D-101 AMENDMENT RULED (GA-R5): metal-admin commissioning TARGETS IPv6 for the 10.13 redeploy (gated)
...
Operator reconsidered D-101's "PXE is v4-first" clause on the pass6 fresh-
feasibility evidence (not the prior ruling). GA-R5 exchange, exact utterance:
"Adopt v6 (gated on live test)".
RULED: metal-admin node commissioning for the 10.13 redeploy TARGETS IPv6 (UEFI
+ DHCPv6 + HTTP boot), GATED on a one-node canary (DHCPv6 -> UEFI HTTP boot ->
enlist -> commission -> READY, captured) with v4 fallback before any fleet
commit (hard rule 2 -- no fleet commit on an unproven-on-this-cloud path). The
ungated full-fleet option was NOT chosen.
Basis: pass6 research found no MAAS-side blocker at 3.7.2 for DHCPv6
commissioning (historical bugs closed 2017/3.1), rack<->region v6 feasible-now
(source prefers AF_INET6), and the only hard blocker is legacy-BIOS PXE (Intel
firmware) -- avoided by UEFI, which we set on the VR1 node VMs. D-101's clause
was an unmeasured judgement, not a capability ceiling.
Reconciliation: AMENDS D-101 (PXE-v4-first clause only; IPv6-primary principle +
family matrix unchanged -- this ADVANCES "v6 wherever possible"); CONSISTENT
D-139 (metal-admin plane stays dual-stack; only the boot-path family shifts);
moots the standalone "soften D-101 PXE wording" DOCFIX (this amendment IS that
correction, now ruled). provider-public needed NO reconsideration -- D-101
already rules it dual-stack + native v6 GUA ext_net (v4 retained for external
v4-internet only).
Owed at redeploy design time (logged, not built): UEFI (OVMF) node-VM loader;
DHCPv6 + MAAS HTTP-boot on the metal-admin commissioning range; the canary test
+ captured evidence as a new gate. Still-owed DOCFIX (independent of A): the
stale OVN "No" row in charm-ip-family-compatibility.md.
CURRENT-STATE updated in the same commit (GA-R1 C1). repo-lint 0-fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

IPv6 FEASIBILITY re-check (pass6, web-researched) -- CORRECTS pass5's reliance on prior rulings
...
Operator flagged that the pass5 IPv6 review followed prior rulings instead of
freshly assessing feasibility on the ruled links. Confirmed: pass5 cited
D-101/D-139 ("PXE v4-first", "provider dual because internet=v4") as the answer
and punted the researchable question. This pass researches ACTUAL platform
capability (upstream docs/source/bug-trackers, deployed versions: MAAS 3.7.2,
Juju 3.6.27, Caracal 2024.1, OVN 24.03.2, OPNsense 26.7, Ceph Reef), ruling-
independent, with real citations (WebSearch/WebFetch throughout).
Headline: IPv6 is substantially MORE feasible than the prior rulings held.
- metal-admin IPv6 commissioning FEASIBLE-WITH-WORK on UEFI (no MAAS blocker
@3.7.2; only LEGACY-BIOS PXE is a firmware blocker, avoidable via UEFI);
MAAS rack<->region v6 FEASIBLE-NOW (source prefers AF_INET6). -> D-101's
absolute "PXE v4-first" is an overstated judgement, not a capability limit.
- provider-public v6 FEASIBLE-NOW via direct GUA routing (v6 uses NO floating
IP); D-139's "dual because internet=v4" conflated provider-network family
(v6-capable now) with external v6 internet reachability (the only true v4 need).
- Octavia LB VIP v6 FEASIBLE-NOW; hacluster API-VIP FEASIBLE-WITH-WORK (one charm
bug LP#2111852); uplink edge FEASIBLE-WITH-WORK (OPNsense ready; routed not NAT66).
CONFIRMED still-hard (fresh check validated the ruling): juju LP#1723240 live-
verified still open in 3.6.27 (D-141 holds); external v6 internet (deferred).
NEW: Ceph binds one family per daemon -> v6 cross-DC replication needs the whole
cluster single-family (DEC-24 constraint, previously unassessed).
Findings CHALLENGE D-101 (PXE) and D-139 (provider-public) framings -- surfaced
for operator RECONSIDERATION, NOT ruled (GA-R5). Two DOCFIX candidates flagged
(stale OVN "No" row vs the repo's own geneve proof; soften D-101 "PXE v4-first").
pass5 note annotated as CORRECTED. D-144 owed section + CURRENT-STATE updated
(GA-R1 C1). Deliverables: pass6-w1/w2/w3 + pass6-ipv6-feasibility-note. repo-lint
0-fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

IPv6-unlock design note (pass5, read-only) -> recorded under D-144 owed items
...
Focused 3-worker read-only pass enumerating the address-family surfaces of the
flat Option-1 topology (D-144) and which the collapse unlocks for IPv6.
Honest headline: the collapse unlocks LITTLE new IPv6. Of a 19-surface family
matrix, only the MAAS power-dial reach path is a clean collapse-caused v6 unlock
-- and it is UNVERIFIED, gated on DEC-15. No proposed v6 flip conflicts with a
standing ruling.
Genuine unlocks (design inputs folded into D-144's owed DECs):
- DEC-15: power-dial reach CAN go v6 (qemu+ssh to vcloud sshd off any plane
bridge) -- prefer v6, verify the address.
- DEC-14/16: the (a) control + SEC-010 successor are v6-native by construction
(nftables `inet`); and the UNRULED D-124 transit-overlay family (v6 candidate
f00::/40 reserved in the apex) should be decided on the same leg they govern.
- DEC-24: cross-DC replication carrier + its still-open D-139 v6-route are the
SAME leg -- resolve together.
NOT unlocked by the collapse (different layers, do NOT credit D-144): D-139's
plane family matrix, the geneve-over-v6 fix, and the LXD-container/juju LP#1723240
gap (D-141). metal-admin PXE stays v4 by ruling; v6-only MAAS commissioning is
UNVERIFIED (not asserted impossible). Uplink NAT stays v4 (simulated ISP).
Deliverables: pass5-w1/w2/w3 + ipv6-unlock-design-note-20260810.md. D-144 owed
section + CURRENT-STATE updated (GA-R1 C1). Read-only; nothing ruled or built.
repo-lint 0-fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

D-144 RULED (GA-R5, 3 exchanges): container-layer elimination ADOPTED -- supersedes D-123 Model B
...
Rulings landed 2026-08-10, each its own GA-R5 exchange with the operator's exact
utterance (no batching):
- DEC-01 "New D-144, supersedes D-123" -> mint D-144, flatten Model B to
Option 1 for the 10.13 redeploy
- DEC-11 "(B) shared-outer + per-DC-flat" -> tofu root shape
- DEC-13 ".8 / vr1-dcN-client" -> client-VM octet+name (D-134 amendment)
D-144 (docs/design-decisions.md): full entry with the three exchanges, the shape
adopted, the accepted power-key blast-radius tradeoff named in the body (GA-R3 A1),
the reconciliation ledger, and the OWED items (DEC-15 power-key mechanism incl.
reach + SEC-034; DEC-14/16 the (a) control; DEC-08/09 rack/D-131 retirement,
live-re-measure-gated; DEC-24 dc0<->dc1 mesh + cross-DC Ceph path; 13 owed
artifacts + 9 owed live measurements). This ruling DECIDES the shape and builds
NOTHING -- Model B stays the LIVE shape until the redeploy executes (hard rule 1).
Reconciliation recorded in D-144's ledger + append-only cross-notes:
D-123 SUPERSEDED, D-125 TERMINATED, D-128 AMENDED (Plane-2 shrink); D-134 gains a
dated .8 amendment. Precedent for mint-not-amend: D-143.
CURRENT-STATE.md updated in the same commit (GA-R1 C1): container-elim block flips
"[ARCH] ruling OWED" -> "CORE RULED / D-144 ADOPTED", next-free now D-145.
repo-lint 0-fail; ledger-scan confirms D-144 registered.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-09 |

container-elim planning pass RAN (phases 0-4 + advisor): FINAL-PLAN + operator-report + D-144 framing (READ-ONLY)
...
Multi-agent read-only planning pass for the dc0/dc1 container-layer elimination
in the 10.13 redeploy. Phases 0-4 (4 sonnet workers + 1 administrator/phase) +
a final advisor review; agents recorded as "the administrator"/"the advisor"
(no model name asserted, operator instruction). NOTHING built or executed
against the cloud -- produced a plan; every owed artifact is LOGGED, not built.
Phase-0 operator gate: confirmed Option 1 (flat node VMs on vcloud libvirt + a
small per-DC vr1-dcN-client VM) + cross-DC handling (a) -- directional, not the
GA-R5 [ARCH] ruling.
Deliverables (docs/audit/container-elim-pass/):
- operator-report.md -- the single consolidated report
- FINAL-PLAN.md -- 104-row change-set + L0-L5 module design +
Part-A/B sequencing + D-144 decision package
- FINAL-advisor-review.md -- verdict SOUND + 2 verified follow-ups
(DEC-15 reach; DEC-24 dc0<->dc1 mesh/Ceph path)
- pass0..4 worker + admin docs (20)
Key findings: the container layer is the one violation of the repo's
IaC->procedure boundary (inner root's qemu+ssh provider); root topology (B)
shared-outer + per-DC-flat recommended; three isolation controls owed incl. the
MAAS power-key blast radius (flattening makes SEC-012/016 per-DC separation
vacuous absent a mitigation); 13 owed artifacts; 9 owed live measurements.
OWED (operator, GA-R5): the Tier-1 package -- DEC-01 adopt as new D-144
(supersedes D-123 Model B; D-143 precedent) + amendments D-128/D-134/D-131 +
DEC-15/14/16/11/08/24. Model B stays the LIVE shape until D-144 is ruled.
CURRENT-STATE.md updated in the same commit (GA-R1 C1): the container-elim block
flips SCOPED/NOT-YET-RUN -> RAN + owed-ruling pointer. repo-lint 0-fail.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
savegame 2026-08-09 (part 3): ledger close -- D-143 re-IP ruled + Roosevelt-held review + advisor-label correction + Fable-5 recheck + container-elim pass scoped (GA-R4)
...
Bounded (15-line) close block for the post-part-2 work this session. All part-3
deliverables are in committed durable docs (D-143 in design-decisions.md; the two
reviews + the container-elim-pass folder under docs/audit/), so no separate sweep
file is needed -- nothing was transcript-only. Ledger at 296 lines (<300; no
rotation needed). Durability: this host 0 uncommitted / 0 unpushed at e20f8ae;
voffice1 synced.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

Scope + prep the container-layer-elimination pass (multi-agent, phases 0-4) as a cold-start handoff for a NEW session
...
Operator directed: scope this pass now, defer EXECUTION to a fresh session (this
session is large). Read-only planning pass -- produces a plan/change-set/module
design; no teardown, no mutation.
New folder docs/audit/container-elim-pass/:
- SCOPE-AND-EXECUTION-PLAN.md: self-contained handoff -- bootstrap, grounded
current-state (Model-B container layer = vvr1-dcN containment VM + inner libvirt
+ 6 plane bridges + transit; opentofu/main.tf:26-33), the LOCKED decisions,
phase 0-4 definitions, orchestration flow, context discipline, deliverables,
governing constraints.
- phase-prompts.md: draft sonnet-worker + fable-administrator prompts per phase,
ready to adapt & spawn.
LOCKED from the 2026-08-09 scoping exchange: phases 0-4 (adopted); module =
layered system (IaC OpenTofu modules + procedure/runbook modules); target topology
= Phase 0 proposes -> operator confirms before Phase 1 (HARD GATE); fleet = standard
3-5 sonnet workers + 1 fable administrator/phase; final fable advisor review;
read-only; agents write durable docs + return bounded summaries (context
discipline); operator gets ONE report at the end.
Goal/framing: plan the dc0/dc1 container-layer elimination for the 10.13 redeploy
AND turn the redeploy steps into a repeatable layered module workflow feeding the
pre-Roosevelt bare-metal test. The container-elim itself remains an OWED [ARCH]
decision (D-123 amendment or new D-number) that Phase 4 frames and the operator rules.
CURRENT-STATE pointer added (GA-R1 C1). NOT YET RUN.
REVERT: git rm -r docs/audit/container-elim-pass/ and revert the CURRENT-STATE pointer.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

Fable 5 advisor recheck: results CONFIRMED + edits (C.2 seen-and-rejected, advisor-identity resolved, D-137 precision, redeploy previews captured)
...
Operator moved the advisor from Opus 5 to Fable 5 and requested a recheck. Fable 5
independently re-verified and CONFIRMED this session's findings (SEC partition=28,
P5=11 with the 101->121-by-design reconstruction, live-check positive controls,
D-143 reconciliation verbs). No result overturned. Edits it surfaced:
- D-143 C.2: added the SEEN-AND-REJECTED note (operator "Octet-preserving confirmed")
-- the contiguous-/19 regularization alternative was considered and not taken.
- Advisor-identity notes RESOLVED (open-items + roosevelt Section 8, memory): the
drafting passes were Opus 5 (NOT "fable" -- that inherited label was wrong); the
recheck pass is Fable 5 (operator-configured, /advisor in-transcript). Do not
retro-label the Opus-5 rounds as Fable.
- D-137 precision: the teardown discharges only the REVOCATION leg (DC-substrate);
the ROTATION leg for persistent-host creds stays at v1 close.
- Roosevelt review Section 0.1 (+ CURRENT-STATE): captured two operator-previewed
changes to the redeploy -- (1) ELIMINATING the dc0/dc1 container layer this rebuild
(an [ARCH] D-122/D-123 change altering D-143 execution topology; owed a decision at
redeploy planning), and (2) a PRE-ROOSEVELT BARE-METAL TEST following the redeploy
(specs in days), which compresses the Group-4 horizon to weeks-away. Hardware specs
"not yet" -> Group 4 STANDS for this redeploy.
REVERT: git revert this commit.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

Correct unverified "fable advisor" label -> "the advisor" across this session's records (operator-flagged)
...
The advisor() tool exposes no backing-model identity; "fable advisor" was an
inherited repo memory convention, not a measured fact. Asserting a specific model
name is the fabricated-value class the repo posture forbids (and the same
assert-without-verifying class instrument-currency memory tracks).
Corrected in THIS session's records: open-items-review + roosevelt-held-decisions-
review (Section 8 headers + terminology notes), CURRENT-STATE pointers, the
open-items sweep file, and the session-ledger close block -> "the advisor". Memory
instrument-currency #25 + MEMORY.md index corrected, plus a standing TERMINOLOGY
CAVEAT added so future entries say "the advisor," not a model name.
NOT rewritten (append-only history; prior sessions, may have had their own basis):
prior-session records (#23/#24 memory, the geneve changelogs/root-cause/CURRENT-STATE
pivot banner, gua-carve proposal) and the already-pushed commit messages f4aee80/
809903d/40d8a46. Those stand as history; this correction supersedes the label going forward.
REVERT: git revert this commit (restores the "fable advisor" wording).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

Roosevelt/future-held decisions review -- reevaluated vs current project state (two-pass, self + fable advisor)
...
Read-only decision package (mutates no ruling). Reevaluates all ~24 decisions/
sub-decisions held to Roosevelt / next-deployment / end-of-deployment review,
against current state (D-143 re-IP redeploy, geneve-over-v6 confirmed, deploy
method proven, the tailnet-collision lesson).
KEY FRAME: "next deployment" in these decisions = Roosevelt (the next DISTINCT
bare-metal build), NOT the intra-VR1 re-IP redeploy. The redeploy is a nested-VM
re-build, so it cannot exercise bare-metal/scale items -- but it IS a fresh-build
opportunity for build-process/credential/vault items.
HONEST YIELD: ~4 pull-forwards the redeploy makes actionable (D-137 credential
revocation=R7; D-142 vault-init QoL=R6; D-136 v6 octet-convention review; D-069
custodian assignment) + ~3 analysis-now (D-131 sub-4 node-DNS review; D-140
provider-capability read; D-068 V1-V5 probes) + 1 access-gated reconsideration
(D-129(iii) tagged-identity/star ACL -- the collision made the exposure concrete,
but the Headscale-access blocker persists). The majority (18 rows) genuinely stay
bare-metal/scale/version/Magnum-bound -- reevaluation CONFIRMS them.
Two-pass: fable advisor caught 4 unplaced/conflated inventory items (D-029,
D-068 items 2/3 unplaced; D-069 custodian-vs-auto-unseal conflation; D-136 CI-half
mis-grouped) -- all fixed, corrections in Section 8.
REVERT: git rm the review file; revert the CURRENT-STATE pointer block.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

D-143 RULED (GA-R5): VR1 re-IP 10.12.0.0/16 -> 10.13.0.0/16 -- AMENDS D-115 premise, TERMINATES D-101 v4-inherit; apex fork B2, lib-net (i)
...
Operator ruled the re-IP in two exchanges (option selections are the exact
utterances, recorded verbatim in the D-143 Status block):
- Exchange 1: "Accept evidence + adopt 10.13" -- adopts 10.13.0.0/16 (octet-
preserving 10.12.a.b->10.13.a.b) and ACCEPTS the tailnet+apex measurements as
sufficient for owed check #3 (VR0 internals, tailnet-only/unreachable).
- Exchange 2: C.1 "B2: new 'Cloud -- VR1 rebuild' role" (10.13 gets its own NetBox
role; Cloud stays 10.12-only, no live record re-labelled); C.3 "(i) Keep flat
defaults at 10.12; VR1 arms get full 10.13 blocks" (preserves lib-net.sh line-37
invariant).
Reconciliation: AMENDS D-115 (factual premise; role-based ruling holds),
TERMINATES D-101's v4-inherit clause, CONSISTENT-WITH D-124 (routes re-point) +
D-134 (survives, endorses the octet-preserving map).
Live evidence at ruling time (2026-08-09, operator-authorized read-only): apex
10.13=0/10.12=149; tailnet no 10.13 overlap, the 10.12 collision reproduced as
positive control. Check #3 accepted-not-run (recorded blind spot).
NOT EXECUTED (hard rule 1): B2 apex re-carve, lib-net.sh (i) + F13 comment fix,
R16 naming-collision DOCFIX, D-124 route re-point, R7 teardown revocation -- all
subsequent gated steps. CURRENT-STATE section-1 banner updated (GA-R1 C1);
next-free D now 144.
REVERT: remove the D-143 block from docs/design-decisions.md and revert the
CURRENT-STATE section-1 banner to "NOT YET RULED".
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-09 (part 2): open-items review bookend -- GA-R4 (sweep + ledger close + rotation + memory #25)
...
GA-R4 BOOKEND for the open-items-review session. Sweep proves the session's
substance is on a repo surface (docs/audit/queued-findings-20260809-open-items-review.txt).
- Ledger: 15-line close appended; the two 2026-08-07 blocks rotated to
docs/archive/session-ledger-rotated-20260809.md (oldest-first); file 285 lines (<300).
- Sweep FIRST SURFACE: FS1 the repeatable method for the 2 completed re-IP live-free
checks (apex dump from vcloud + tailnet enum from office1-tailscale); FS2 access facts
(VR0 tailnet-only/unreachable from vcloud; tailnet also carries Roosevelt 10.17.x +
willamette, all clear of 10.13); FS3 raw captures ephemeral.
- Memory: instrument-currency #25 (P5 gate read on the wrong host -> "12 findings"
manufactured-decision framing, caught by the advisor) + MEMORY.md index.
- CURRENT-STATE: sweep pointer added (L10/GA-R1 C1).
OWNED (also in open-items-review Section 8): P5-wrong-host framing (#25); "sums to 28"
was 24; SEC-021(a) overstated (S2 still red); shred-hazard on a likely-live token;
CLOBBERED session-ledger-rotated-20260809.md with a Write (overwrote a tracked file I had
not read) -- caught in git status, restored from HEAD + appended.
REVERT: git rm the sweep file; revert the ledger/archive/CURRENT-STATE hunks. The
prior review commit f4aee80 is independent and stays.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

open-items review (D/SEC/DOCFIX/BUNDLEFIX) vs the hardened end goal -- two-pass (self + fable advisor), live-grounded
...
WHAT: a read-only decision package reviewing all open items against project state
and the hardened end goal (re-IP redeploy on 10.13, IPv6-primary, min-delta-to-
Roosevelt). Rules nothing; mutates no authoritative status. New file
docs/audit/open-items-review-20260809.md + a pointer in CURRENT-STATE (GA-R1 C1).
CONCLUSION: backlog is overwhelmingly correctly-deferred (5 open D at Roosevelt/
end-of-deploy/v1-close; 28 SEC rows = rotation obligations + accepted postures,
no defects). The re-IP GA-R5 ruling (would be D-143) is the ONLY item gating the
end goal. Two re-IP-coupled gaps to build: R7 teardown credential-revocation
checklist; R16 10.13 naming-collision DOCFIX.
LIVE CONFIRMATION (operator-authorized discovery, read-only):
- re-IP owed check #2 (NetBox apex): PASS -- 10.13 = 0 objects, 10.12 = 149 control.
- re-IP owed check #1 (Headscale/tailnet): PASS -- no 10.13 overlap; the exact
10.12 collision reproduced as positive control (vopenstack-jesse-tailscale).
- check #3 (VR0 internals): not completable from vcloud (tailnet-only) -> operator
accept-or-run option.
- creds-matrix P5 (authoritative on voffice1, clone==HEAD): 11 findings (6 accepted
+ 5 dc1 forward-register, grew by design 101->121 rows) -- NOT a silent gate growth.
- DC-substrate credential residency measured live (R7 premise).
- dc0 checkpoint: 66 machines/162 units active (matches record).
TWO-PASS: fable advisor caught (1) a P5 instrument mismatch (vcloud vs voffice1 --
framing inverted from "silent growth" to "grew by design"); (2) a false "sums to
28" completeness claim (was 24) -> re-partitioned + new bucket 3b' (dc1 material on
persistent hosts retires at v1 close, not the re-IP); (3) a shred-hazard on a likely-
live dc1 edge token -> reframed to declare-only. Corrections recorded in Section 8.
REVERT: git rm docs/audit/open-items-review-20260809.md and revert the CURRENT-STATE
pointer block (lines added under the reip-prep pointer). No other surface touched.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
savegame 2026-08-09: geneve-over-v6 root-cause + D-139 amendment + executable gate -- GA-R4 bookend + sweep
...
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
geneve-over-v6 REBUILD RECIPE consolidated (item 3): container v6 carve + unbracket override + overlay_ip_version + gate
...
No fixed ovn-chassis revision pinned by search (charm-ovn-chassis LP #1968355 family, inconclusive) -> the reliable rebuild fix is a persistent post-deploy unbracket override (re-assert after config-changed), re-verified by scripts/geneve-encap-assert.sh. D-139's metal-admin-leg-IPv4 gate specced (build at rebuild, needs live cloud). One executable recipe in the root-cause record; CURRENT-STATE owed-list points to it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
D-139 AMENDMENT (2026-08-09, GA-R5): geneve-over-v6 confirmed viable; containerized chassis need carved v6 + unbracketed encap
...
Operator ruling (verbatim): 'D-139 amendment' (vs a new D-number). Records the 2026-08-09 live finding: geneve-over-IPv6 forwards on OVS 3.3/OVN 24.03/kernel 5.15 (VM-to-VM 8/8) once (i) containerized ovn-chassis take a carved v6 data-tenant address and (ii) ovn-encap-ip reaches OVS unbracketed (ovn-chassis 24.03 brackets it -> ofport -1). v4-forced is off the table. Gate scripts/geneve-encap-assert.sh (family + tunnel ofport) is the proof, wired into phase-04 Step 12.2. CURRENT-STATE section 1 updated (D-number OWED -> RULED).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

geneve-over-v6 root-caused (bracket bug) + LIVE-CONFIRMED; executable encap gate + phase-04 fix
...
Live diagnosis on vr1-dc0 (D-138): the v6 geneve tunnel failed with ofport -1 because ovn-chassis 24.03 sets ovn-encap-ip BRACKETED ([2602:...]), which OVS geneve rejects. Delivered unbracketed -> tunnel instantiates -> real VM->VM cross-compute ping over geneve-over-IPv6 = 8/8, 0% loss. So v6-only data-tenant is viable and v4-forced is off the table (OVS 3.3.0/OVN 24.03.2/kernel 5.15). A first same-day test wrongly concluded 'v6 broken' from an OVN localport source (never tunnels by design) -- retracted.
scripts/geneve-encap-assert.sh (+ harness 16/16, manifest pinned): asserts C1 encap family consistency (--expect-family v6) AND C2 every geneve tunnel ofport>=0 (the bracket-bug check a family-only gate misses). phase-04 Step 12.2 rewritten (family-only -> family+tunnel-health, ULA->GUA) + Step 6 caveat. CURRENT-STATE section 1 + root-cause record updated; GUA-carve proposal (DC1 gap + matrix + scan) added. repo-lint 0-fail; gauntlet ALL GREEN (103).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-08 (part 3): amphora build FIXED + geneve-over-v6 wrap-gate ROOT-CAUSED
...
GA-R4 bookend for the dc0-activation part-3 session.
- Body: docs/changelog-20260808-amphora-geneve.md (amphora two-layer fix [loop-device
passthrough + retrofit ubuntu-mirror->dc0 mirror; image 775ebeba ACTIVE], o-hm0 MTU PASS,
1-test-LB blocked by geneve-over-v6, delivery).
- Sweep: docs/audit/queued-findings-20260808-amphora-geneve.txt (FIRST SURFACE: live mutations
w/ reverts, test LB/net/amphora LEFT LIVE [teardown owed], retrofit diag traps).
- CURRENT-STATE part-3 progress block + session-closed pointer.
- session-ledger: bounded close summary; machine-derived block RE-SEEDED from ledger-scan
(SEC 29->28 [SEC-031 closed], DOCFIX 210->214, BUNDLEFIX 053->059); rotated 08-06 x2 ->
archive/session-ledger-rotated-20260809.md (ledger 283 lines).
Gates: repo-lint 0-fail (1 legacy warn); gauntlet ALL GREEN (102); ledger-scan reconciled
(4 open decisions, SEC 28, next-free D-143/DOCFIX-214/BUNDLEFIX-059, no new numbers).
Revert: git revert this commit (records only; live mutations + reverts are in the changelog).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-08 |

geneve-over-v6 root-cause: verify on compute-01 (amphora host) + tighten evidence
...
Advisor-flagged corrections to cd1f9cd's root-cause record (claims now measured, not inferred):
- data-tenant confirmed the SAME dual-stack plane on both node types (lib-net.sh PLANE_CIDRS
10.12.16.0/22=data-tenant, in SPACES6); divergence is address-family SELECTION, not a binding
error (both chassis types bind data-tenant).
- tunnel state re-read on vr1-dc0-compute-01 (ovn-chassis/1, the amphora's ACTUAL host): its
v6 local encap has IPv4 remote_ip to the 3 control chassis -> cross-family, same pattern.
- softened the bfd_status claim to AMBIGUOUS (OVN geneve may not populate BFD); decisive
evidence is the encap-family split + 100% ICMPv6 loss. compute<->compute v6 path noted UNTESTED.
- dropped the pre-allocated "D-143" (number assigned at ruling per grep-for-next-free).
Revert: git revert this commit (records only; no live cloud state changed).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

geneve-over-v6 wrap-gate ROOT-CAUSED (FAIL): OVN encap family split control(v4)/compute(v6)
...
The dc0 "verify-live geneve-over-v6" checkpoint gate FAILS, root-caused this session
via the 1-test-LB smoke test. Measured: OVN geneve encap IPs are split across address
families -- containerized control-node chassis (octavia LXD) have IPv4-only data-plane
addresses (10.12.16.x, D-134 auto-picked) -> IPv4 encap; carved compute metal uses IPv6
(2602:f3e2:f02:30::x). Cross-family geneve tunnels never form (bfd_status empty) -> 100%
cross-node overlay loss -> amphora unreachable from o-hm0 -> LB stuck PENDING_CREATE.
Roosevelt-delta: v6 builds must give containerized OVN chassis a v6 data-tenant address
so encap is family-consistent with metal. Candidate D-143 (PROPOSED, operator ruling owed).
Fix NOT applied (substantial + rebuild-relevant). Full record:
docs/audit/geneve-over-v6-rootcause-20260808.md. CURRENT-STATE progress block updated
(clears repo-lint L10 for the audit file).
Revert: git revert this commit (records only; no live cloud state changed).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

bookend: land prior part-2 GA-R4 close + dc0-activation part-3 progress (amphora FIXED, LB blocked on v6 overlay)
...
Lands the prior session's savegame residue (GA-R4 part-2 close block in
session-ledger.md, the 2026-08-08 ledger rotation to archive/, and the
dc0-activation-checkpoint queued-findings sweep) which was left uncommitted
pending the operator's push decision (now pushed: a25ed99..a6340e6).
CURRENT-STATE.md gets this session's (part 3) measured status update, which
also clears repo-lint L10 for the docs/audit/ sweep file:
- amphora build RESOLVED (was part-2 retrofit exit-1 INCIDENT): root cause
loop-devices-absent-in-LXD + dib-apt-targets-unreachable-public-archive;
fix = loop passthrough + retrofit ubuntu-mirror -> dc0 mirror. Image
775ebeba... ACTIVE+tagged octavia-amphora.
- G18 OWED#3 (o-hm0 MTU) PASS.
- 1 test LB blocked on geneve-over-v6 overlay (o-hm0->amphora 100% ICMPv6
loss); UNDER INVESTIGATION (== the verify-live geneve-over-v6 wrap gate).
Revert: git revert this commit (records only; no live cloud state changed by
this commit -- the live mutations are logged for the forthcoming changelog).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
changelog: amphora retrofit build INCIDENT (Item 7) + MODEL=vr1-dc0 fix
...
Octavia CORE activated; amphora image blocked on octavia-diskimage-retrofit exit 1
(dib-in-LXD-container hypothesis, rebuild-relevant). LB smoke test blocked until fixed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
changelog: Octavia configure-resources fired + verified (Item 6); G18 OWED#1/#2 captured
...
Live: operation 67 completed, octavia/0 active, lb-mgmt-net + fc00:5b7a:7bdc:bd86::/64
+ lb-mgmt-sec-grp created, o-hm0 up, mgmt router external_gateway_info=None (isolated).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
G18 RULED (GA-R5, option b): Octavia lb-mgmt recorded out of apex scope + D-139 /64 reserved
...
Gate G18 CLOSED 2026-08-08. Operator ruled option (b): the charm-created Octavia
lb-mgmt-net (IPv6-ULA fc00::/64, charm-generated per R8, regenerates per deploy) is
deliberately charm-owned and OUT of apex scope; the separate D-139 apex GUA lb-mgmt
/64 is kept reserved (distinct MAAS-underlay object, no charm consumer). R8 not
reopened. lb-mgmt is v6-ULA, outside the 10.12->10.13 v4 re-IP. Primary record in
CURRENT-STATE G18 row; annotations on D-101/R8 + D-139. No new D-number. Prep package
docs/audit/g18-lb-mgmt-ipam-ruling-prep-20260808.md. Also: changelog Items 3-5
(live network-create, G18 ruling, Designate real-Stage-7 decision).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
dc0-activation: phase-04 network scripts MAAS_PROFILE-aware (DOCFIX-213, F3/D-138) + re-IP ruling-prep package
...
phase-04-network-create.sh + phase-04-network-verify.sh honour MAAS_PROFILE
(default admin=VR0/office1; VR1 overrides to the DC regional, e.g. vr1-dc0-region)
instead of hardcoding 'maas admin'. Fixes F3: the dc0 rack has openstack+cloud L3
but no maas profile, and the maas two-source gate needs both on one host. Operator
directive: each DC has its site regional maas; racks register up to the DC regional.
Harnesses extended with EXPECT_PROFILE proof (failability verified out-of-band).
Also lands docs/audit/reip-1013-ga-r5-ruling-prep-20260808.md (Task #6 background
analysis) + a CURRENT-STATE pivot pointer to it (L10 coupling).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

savegame 2026-08-08: dc0 .7 tailscale FIXED (advertise-only) + 10.13 re-IP PIVOT + dc0 checkpoint plan
...
GA-R4 bookend + sweep for the session that fixed the dc0 .7 tailscale install
(advertise-only, --authkey=file:, check guards -- committed 02e0b12/faef662) and
surfaced the 10.12->10.13 re-IP pivot.
- CURRENT-STATE: 2026-08-08 pivot callout -- 10.12 collides with the live IPv4
cloud; drive dc0 to full deployment as a CHECKPOINT, then teardown+redeploy on
10.13; the re-IP is a D-115 supersession + D-101 termination, NOT YET RULED.
- Sweep docs/audit/queued-findings-20260808-...reip-pivot.txt (F1-F16): the pivot,
the D-115 conflict, MAAS profiles missing on the racks (fix existing+rebuild),
no service migration (DC0>MAAS-regional>MAAS-rack), dc0 live inventory,
checkpoint scope, + instrument-currency #22 (F3 wrong-store retraction; pkill
self-match).
- 10.13 NetBox subnetting DRAFT (Task #2; octet-preserving proposal, not ruled).
- changelog-20260807 F3 retraction/correction; bounded ledger close summary.
Gauntlet ALL GREEN (102); repo-lint 0 fail. Tasks #1-#4 pinned.
Status ONLY in CURRENT-STATE.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
| 2026-08-07 |

site-tailscale: advertise-only subnet router + authkey=file: + check guards
...
Fixes the 2026-08-07 install incident where bringing .7 up as a subnet router
with --accept-routes blackholed its own L3 (it imported a route sending its
own return traffic for the advertised /22 into tailscale0) and locked us out.
- install: DROP --accept-routes (a subnet router advertises, it does not need
to consume routes); pass the pre-auth key via --authkey=file:<path> so the
secret never lands on argv / in ps (the key leaked that way during the
incident).
- check: add two assertions, each with a failing-direction fixture --
own-subnet-not-routed-via-tailscale0 (the blackhole guard) and control-plane
reachability (live HTTP from $LOGIN_SERVER, not just DNS).
Validated LIVE: advertise-only re-join brought .7 up Running/Online (TSIP
100.64.0.57) with its own subnet NOT hijacked and no lockout; route now awaits
Headscale approval. Harness 27/0, gauntlet ALL GREEN (102), repo-lint 0-fail.
Body: docs/changelog-20260807-dc0-tailscale-install.md (UPDATE section).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|

site-tailscale: prep verb + untagged VR1 (office1-mirrored) + forwarding assertion
...
Extends scripts/site-tailscale.sh to three verbs (prep|install|check) so the
per-DC .7 subnet router is brought up exactly as the working Office1 router.
- prep <site>: install the tailscale .deb from a rack-staged copy ($TS_DEB;
the .7 has no external egress) + enable IP forwarding (/etc/sysctl.d/
99-tailscale.conf, sysctl --system) and ASSERT it took.
- tag now OPTIONAL: TS_TAG defaults empty = untagged (office1-mirrored, VR1);
install omits --advertise-tags and adds --accept-routes (office1 RouteAll);
TS_TAG=tag:subnet-router restores the D-129(iii) tagged design (Roosevelt).
- check now ASSERTS IP forwarding -- the load-bearing subnet-router property
that 'tailscale up --advertise-routes' warns-and-succeeds without, so the
route could be approved while nothing forwards to Horizon (advisor 2026-08-07).
Harness: 23/23 (new failing-direction fixtures prep-noforward, check-noforward,
check-tag-notag, prep-fromdeb, install-tag-happy). Gauntlet ALL GREEN (102);
repo-lint 0 fail.
Records the operator's untagged/office1-mirror deferral as a D-129(iii)
amendment ([OPS], tags/autoApprovers/star ACL -> bare-metal) with the verbatim
utterance. Body: docs/changelog-20260807-dc0-tailscale-install.md.
Live install NOT yet executed (staged .deb -> dpkg -> prep -> install ->
operator Headscale approval -> check).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
savegame 2026-08-07 (part 2): bookend + sweep -- dc1 region standup + SEC-031 edge rebuilt
...
GA-R4 bookend for the dc1-region-sequence session (F NetBox importer; dc1 region
topology/IPAM/DHCP-cutover/power-key; SEC-031 edge rebuild + runbook/tool). Bounded
ledger summary + rotation (2026-08-05 x2 archived, now 283 lines). Sweep
docs/audit/queued-findings-20260807-dc1-region-sequence.txt: 3 FIRST SURFACE
(console-driver harness owed; run-logged gap; jammy source-index trap). CURRENT-STATE
records the standup progress (steps a-b done, D/E remaining). Gates: repo-lint 0-fail,
gauntlet ALL GREEN (102), ledger-scan SEC 29->28.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|
SEC-031 CLOSED: dc1 edge rebuilt + procedure captured as runbook + tool
...
Rebuild the damaged dc1 OPNsense edge via the proven dc0 procedure (operator-
directed). dc-egress-check dc1 8/8; .6 region reaches the internet (ping 1.1.1.1,
curl images.maas.io 200) -- unblocks jammy image sync. Edge-only tofu -replace
(machine-asserted 2/0/2, nodes protected) -> console bootstrap -> WAN/LAN
addressing -> automatic outbound NAT.
Fix the root gap the operator flagged: the dc0 rebuild lived only as an audit
capture, forcing dc1 to reconstruct it. Now a first-class runbook
(runbooks/dc-edge-rebuild.md, site-parameterised) + a site-agnostic tool
(scripts/opnsense-console-rebuild.py, replaces per-DC one-off drivers). SEC-031
closed; CURRENT-STATE + changelog Item 4 updated. Also lands the Stage-5 dc1
region-standup captures (topology, DHCP handover).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fg98z7QyzwYUs8fsWCn728
|