audit: ovn-central cert reeval + remediation plan + Stage-5 misses sweep
...
Re-evaluation of the prior (wrong) ovn-central "awaiting server certificate
data" diagnosis, from fresh live measurement + 3 source-level agents + an
adversarial review. Corrected root cause: ovn-central derives its cert CN from
a REVERSE lookup of its metal-internal address; metal-internal is the only
plane of six without reverse-DNS PTRs, so get_hostname() -> None -> empty
common_name -> vault issues no server cert -> ovn-central blocks. LP #2044324
is NO MATCH; no upstream fix / channel bump helps.
- ovn-central-cert-reeval-20260803.md -- root cause, evidence, what the
prior diagnosis got wrong, ranked remedies, why-no-PTR.
- ovn-central-cert-remediation-plan-20260803.md -- gated rdns_mode + re-fire
sequence with corrected (non-false-green) acceptance criteria.
- stage5-sweep-misses-20260803.md -- F1 metal-internal rdns outlier +
standup tooling never sets rdns_mode; F2 four hacluster units blocked on
stale pre-D-141 IPv6 VIP CIB resources; F3 octavia error is downstream of
neutron VIP TLS. Meta: incomplete-transition tails.
All findings MEASURED read-only this session; every remediation step is
operator-gated and NOT executed. SEC-033 (relation databag exposes vault
global-client key) noted for separate filing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf