diff --git a/docs/dc-dc-deployment-workflow.md b/docs/dc-dc-deployment-workflow.md index caea81e..2d5d898 100644 --- a/docs/dc-dc-deployment-workflow.md +++ b/docs/dc-dc-deployment-workflow.md @@ -43,8 +43,8 @@ | **Reuse vs new** | NEW. No VR0-DC0 analog -- that testcloud IS the single vcloud host, already prepared; this is preparing the host to carry TWO independent DC substrates plus Office1. | | **Authoring status** | **Runbook WRITTEN 2026-07-09: `runbooks/dc-dc-phase0-vcloud-prep.md`** -- command-level steps (host identify -> measure CPU/RAM/disk/nested-KVM/MTU -> enable nested KVM -> prepare pool paths -> install/confirm OpenTofu -> tfvars -> init/validate/plan/apply -> post-apply gate verify), each MUTATION individually gated per this repo's discipline. Flags a real open structural question up front (the `provider "maas"` block in `main.tf` is unconditional even though this stage only touches libvirt resources -- may force `maas_api_url`/`maas_api_key` to be set at `plan` time with nothing yet using them; noted as a possible DOCFIX candidate, not silently worked around). NOT YET EXECUTED against real infrastructure -- this is the first runbook that will be, tomorrow morning, per the operator's own stated plan. `opentofu/` SCAFFOLD started 2026-07-09: `modules/dc-planes` (six per-DC planes) + `modules/mesh-link` (dark-fiber legs) + `modules/dc-storage-pool` wired for DC1 + Office1 -- see `opentofu/README.md` for what's built vs deliberately deferred (node-VM/domain resources, DC2 CIDRs, netem). UNVALIDATED: no `tofu` binary available to run `scripts/opentofu-validate.sh` yet -- this runbook's Step 8 is the first real run. | -**State:** **DONE -- executed 2026-07-10** (first DC-DC runbook run against real -infrastructure; vcloud host, OpenTofu v1.12.3). As-built: nested KVM already-on; +**State:** executed 2026-07-10 (first DC-DC runbook run against real +infrastructure; vcloud host -- tofu pin authority: `docs/CURRENT-STATE.md` section 7). As-built: nested KVM already-on; `underlay_mtu=9000` (jumbo, operator ruling -- the isolated planes/mesh are host-internal virtio bridges, jumbo-capable regardless of the 1500 ISP uplink); Ceph size=3 disk-budget plausibility PASS (4.60 TiB margin); 13 libvirt objects @@ -357,8 +357,8 @@ this delivery. 2. **OpenTofu** -- **STATUS CORRECTED 2026-07-13. The "UNVALIDATED / no tofu binary" framing below is now FALSE and must not be relied on:** - - **A `tofu` binary EXISTS on the jumphost: OpenTofu v1.12.3.** The tree can - self-check. The whole "authored in a session with no binary" caveat that + - **A `tofu` binary EXISTS on the jumphost** (version pin authority: + `docs/CURRENT-STATE.md` section 7 ONLY). The tree can self-check. The whole "authored in a session with no binary" caveat that rides along with every OpenTofu instruction in this repo is now closed as a *capability* statement. - **The tree VALIDATES: 10/10 modules**, root + every module standalone @@ -872,7 +872,7 @@ | DR mechanism seed | DONE (`dc-dc-replication-DR-seed.md`), superseded-carrier corrected into D-108 | | Stage 0-7 runbooks | Stage 0 DONE (ratification). **Stages 1-7 ALL WRITTEN 2026-07-09** (gap #9 CLOSED) -- `runbooks/dc-dc-phase0-vcloud-prep.md` through `dc-dc-phase6-designate-cos-magnum.md`. Stage 1 EXECUTED 2026-07-10. **Stage 2's runbook REWRITTEN 2026-07-13 to the D-114 model** (one `voffice1` site containment VM + MAAS-composed LXD VMs, replacing the three sibling service VMs and their Option A/B fork); it is PARTIALLY EXECUTED, and its MAAS/LXD command lines are marked PENDING VERIFICATION rather than guessed. Stages 3-7 NOT executed, and D-114 GATES them behind Office1 completing. See gaps #12-15 above for real design gaps the authoring pass surfaced. | | **D-114 site containment VM (`voffice1`)** | **BUILT + RUNNING 2026-07-13.** `module "voffice1"` (`modules/cloudinit-vm` off `modules/base-image`, Ubuntu 24.04 noble) is instantiated and applied; the domain is up on `office1-local`, DHCP from the edge's Kea, `expose_nested_virt = true`. **Remaining:** MAAS-region + LXD (5.21 LTS track) ON it, the LXD-KVM-host registration back into MAAS, and the MAAS-COMPOSED service machines (NetBox/GitBucket/Tailscale). The first LXD VM that boots inside it is the **L3 nesting proof that gates DC1**. | -| `opentofu/` (networks/pools/node-VM PXE/cloud-init-VM patterns) | **VALIDATED 2026-07-13** (OpenTofu v1.12.3 now on the jumphost): root + **10/10 modules** pass `scripts/opentofu-validate.sh`. **APPLIED for real** -- state holds the DC1 planes, pools, 3 mesh links, `office1-network`, the OPNsense edge, and (2026-07-13, D-114) the `ubuntu_noble_base` image + the **`voffice1` containment VM**. **`modules/cloudinit-vm` is now instantiated for real** and gained `expose_nested_virt`. **DOCFIX-194 fixed 2 modules that had NEVER been parsed** (`node-vm`, `netem-link`) because root does not call them and root-only validation skips uncalled modules. `tofu plan`/`apply` for the Stage 3 DC substrate is still UNEXERCISED. | +| `opentofu/` (networks/pools/node-VM PXE/cloud-init-VM patterns) | **VALIDATED 2026-07-13** (tofu binary on the jumphost; pin authority `docs/CURRENT-STATE.md` section 7): root + **10/10 modules** pass `scripts/opentofu-validate.sh`. **APPLIED for real** -- state holds the DC1 planes, pools, 3 mesh links, `office1-network`, the OPNsense edge, and (2026-07-13, D-114) the `ubuntu_noble_base` image + the **`voffice1` containment VM**. **`modules/cloudinit-vm` is now instantiated for real** and gained `expose_nested_virt`. **DOCFIX-194 fixed 2 modules that had NEVER been parsed** (`node-vm`, `netem-link`) because root does not call them and root-only validation skips uncalled modules. `tofu plan`/`apply` for the Stage 3 DC substrate is still UNEXERCISED. | | OPNsense image+config mechanism (`modules/opnsense-edge`) | **BUILT + INSTANTIATED + RUNNING 2026-07-12/13.** `office1-opnsense` is UP: routing, NAT, egress 0.0% loss, serial console, SSH-key managed, **Kea DHCP serving on udp/67**. Four boot bugs closed (DOCFIX-188/190/191/192) + DHCP added (DOCFIX-193). The module's `config_seed`/cdrom wiring is now DEAD WEIGHT -- see the config.xml row. | | OPNsense config.xml design (`templates/opnsense-config.xml.tmpl`) | **SUPERSEDED 2026-07-13 by D-113(a2): edge config is done over the REST API** (`scripts/opnsense-api.sh`), proven end-to-end (read AND write) against the live edge. **DANGER: a full rendered config.xml push would CLOBBER the now-API-managed DHCP** -- do not run the old scp/install/reboot path. The config-ISO path is INERT (D-112: the Importer can never fire on a nano image). **DONE (reconciled 2026-07-16):** `templates/opnsense-config.xml.tmpl` is DELETED and the module's `config_seed`/cdrom + `config_iso_path` are RETIRED; edge config is the REST-API bootstrap. (Boot-measured `WAN_IF`/`LAN_IF` are still applied over the API at deploy time -- a deploy-time step, not an authoring gap.) | | MAAS VM-host registration (`modules/maas-vm-host`) | BUILT 2026-07-09, UNVALIDATED -- needs a real MAAS zone/pool + vcloud power_address, see `opentofu/README.md` | diff --git a/opentofu/README.md b/opentofu/README.md index 7720c50..916d48d 100644 --- a/opentofu/README.md +++ b/opentofu/README.md @@ -37,8 +37,9 @@ > where the per-module prose below disagrees; that prose is kept for its provider-research value, not as > current instantiation state. -**Stage-1 history (still true):** first real `tofu` run 2026-07-10 on the vcloud host (OpenTofu -v1.12.3), executing `runbooks/dc-dc-phase0-vcloud-prep.md`. The root module + the four Stage-1 module +**Stage-1 history (still true):** first real `tofu` run 2026-07-10 on the vcloud host (the tofu +version of that run is historical; the CURRENT pin lives ONLY in `docs/CURRENT-STATE.md` section 7), +executing `runbooks/dc-dc-phase0-vcloud-prep.md`. The root module + the four Stage-1 module types (`dc-planes`, `dc-storage-pool`, `mesh-link`, `office1-network`) passed `init`/`validate`/`plan` and were `apply`-ed clean (13 libvirt objects, all MTU 9000). DOCFIX-179 fixes: per-module `required_providers` (child modules do NOT inherit provider SOURCE mapping -- without their own