diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 719e3fa..37e76f2 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -462,7 +462,9 @@ -> 1/1/0 netem-wire STOP -> targeted netem apply 1/0/0 exact -> 0/1/0 office1 residual -> G16 state surgery -> zero diff converged 2026-07-21 -> 5/0/0 dc1 substrate adds (G12 step A, saved-plan applied exact -2026-07-22) -> zero diff converged (this entry). +2026-07-22) -> zero diff converged -> 0/1/0 office1 qga channel (G13 +bundle, saved-plan applied exact 2026-07-23) -> zero diff converged +(`docs/audit/outer-plan-20260723-postqga-converged.txt`, this entry). ## 6. Open gates @@ -485,7 +487,7 @@ | G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`), and the edge itself now egresses 0% loss after the v4 addressing. Step D COMPLETE incl. commissioning: ALL 9 NODES READY 2026-07-21 (two stacked faults diagnosed + fixed -- `docs/audit/commissioning-diag-20260721.txt`; section 1). Step E (netem) DONE 2026-07-21: sudo fragment installed+verified, module local-mode amendment, targeted apply 1/0/0 exact (operator-ruled at the 1/1/0 STOP), placeholder profile live on virbr5, virbr7/virbr3 untouched (`docs/audit/stepE-netem-20260721.txt` + `outer-{plan,apply}-20260721-netem*.txt`). **G10 CLOSED 2026-07-21** | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator + session | CLOSED 2026-07-23 (operator-ruled "Merge to main + full close"; commissioning 9/9 READY, merge commit on `main`, branch retired) -- [R] leg CLOSED 2026-07-21: addressing RATIFIED (D-124 amendment 2026-07-21, utterance quoted). [V] leg IN PROGRESS (branch `dc-dc-g12-dc1-substrate`): apex confirm-free DONE 2026-07-21 -- planes/uplink already assigned+consistent, transit 172.31.0.4/30 + rack 10.12.68.2 FREE (`docs/audit/dc1-apex-confirm-20260721.txt`); importer per-site dc1 support shipped (harness 117/117) with live dry-run preflight PASS (`docs/audit/dc1-rack-import-dryrun-20260721.txt`). vars + substrate root + lib-net dc1 arm COMMITTED 2026-07-22 (successor session landed the disconnected item 3 + the harness reconcile as changelog item 4): six harnesses reconciled to the ratified dc1 arm, phase-00 PLANES parity guard added, rbd-mirror/radosgw cross-DC reminder fixed; gauntlet **ALL GREEN (76)** (`docs/audit/gauntlet-20260722-g12-reconcile.txt`), repo-lint 0-fail. Apex `--commit` EXECUTED 2026-07-22 (operator-gated): 172.31.0.4/30 + 10.12.68.2/22 CREATED, post-commit read-back idempotent (`docs/audit/dc1-rack-import-commit-20260722.txt`). dc1 svc key minted (creds-audit CLEAN), tfvars authored (local), **outer step-A apply DONE 2026-07-22**: saved plan 5/0/0 exact, converged ZERO DIFF (section 5), vvr1-dc1 RUNNING, prior guests untouched (as-executed log dc1-deploy; changelog-20260722-g12-dc1-build.md). **Step B COMPLETE 2026-07-22**: cloudinit-vm interface_macs port + voffice1 dc1-transit NIC (0/2/0 exact, MACs pinned both domains, post-bounce battery ALL PASS, converged zero diff -- `docs/audit/outer-plan-20260722-voffice1-dc1nic.txt`), transit LIVE (voffice1 .5/30 <-> rack .6/30, dc1-key ssh proven), rack ENROLLED (region lists vvr1-dc1 `nmpcq4`), SEC-010 applied+verified BOTH ends, OPNsense 26.7 base staged via hash-verified copy of dc0's proven artifact; named gate EXIT 0 `docs/audit/dc1-stepB-check-20260722-final.txt` (changelog-20260722 items 5-8, three queued findings). **Step C COMPLETE 2026-07-22**: inner apply FROM voffice1 -- plan 28/0/0 exact (54 pinned MACs verified in-capture), one fix-forward (serial-log staging dir absent on dc1; queued to standup DoD), resume 10/0/0 exit 0; 28/28 in state, convergence ZERO DIFF (`docs/audit/inner-converge-20260722-dc1-stepC.txt`), **10/10 domains RUNNING inside vvr1-dc1**, edge at the 26.7 FreeBSD login prompt (D-112 datapoint #2); dc1 inner tfstate ON voffice1 (site backup set). **D-125 egress gate PASS 2026-07-22** (two identical runs, dc0 criteria exact, isolation confirmed -- `docs/audit/d125-egress-gate-20260722-dc1.txt`). **Edge bootstrap + v4 addressing COMPLETE 2026-07-23** (changelog-20260723-g12-dc1-edge.md): D-112(c) console bootstrap done (SSH + dc1 edge key materialized; payload needed `util.inc`/`shell_safe()` -- dc0 lesson iv the `.b64` artifact lacked), key-only SSH VERIFIED (`15.1-RELEASE-p1`); D-113(a2) API key MINTED via the vendor model + smoke test `GET core/firmware/status` exit 0 `product_abi 26.7` (second 26.7 datapoint); edge ADDRESSED -- WAN `172.30.3.2/24` gw `172.30.3.1` (egress 1.1.1.1 0% loss), LAN `192.168.1.1` -> `10.12.64.1/22` (ruled provider-public gw), API answers at the new LAN; interim reach leg removed, rack provider-public leg `10.12.64.2/22` LIVE on virbr4. Creds consolidated to `~/vr1-dc1-creds/opnsense-api.txt` (creds-audit CLEAN, 5 entries); rack edge-key copy shredded (**SEC-015** transient, remediated). Two queued findings: bootstrap `.b64` missing `util.inc`; `opnsense-bootstrap-apikey.sh` scp had a transient post-restart-sshd failure (readiness-wait/retry candidate). **Rack standup + region MAAS config DONE 2026-07-23** (changelog-20260723 items 7-11): dc-rack-net.sh dc1 arm shipped (harness 18/18, gauntlet 76 GREEN) + INSTALLED on the rack (check 10/10, forwarder answers authoritative maas-internal SOA -- D-131 fix; `docs/audit/dc1-rack-net-install-20260723.txt`); region MAAS on metal-admin subnet 11 -- D-120 range 10.12.68.100-.200, D-131 dns_servers=10.12.68.3 allow_dns=false, DHCP dhcp_on=true primary_rack=nmpcq4 (dhcpd verified RUNNING on virbr6, no Temporal incident); **dc1 enlistment PROVEN** via canary (machines 11->12 in ~2 min). **SEC-016 RULED + WIRED 2026-07-23** (operator: "Mint a dedicated dc1 power key" -- per-DC isolation; dedicated key authorized on the rack + installed in the region MAAS snap with per-host ssh config, dc0's SEC-012 key untouched). **COMMISSIONING 9/9 READY 2026-07-23** (`docs/audit/dc1-commissioning-verify-20260723.txt`): all 9 nodes PXE-enlisted by pinned 52:54:01:d1 MACs, `power_type=virsh` set + verified by real query-power-state (SEC-016 path proven), commissioned to **ALL 9 READY in ~3.5 min** (no timeout, no SERVFAIL), shapes EXACT to D-121 Option C (3x16cpu/64GiB + 2x12cpu/48GiB + 4x8cpu/24GiB). dc0's two stacked faults pre-empted by pinned MACs + the dc-rack-net forwarder. **G12 [V] leg (the dc1 build) is COMPLETE.** NEXT: G12 close-out only -- consolidate this session's changelogs (GA-R2), final gauntlet + repo-lint, GA-R7 memory review, skill sweep, **operator-gated merge of `dc-dc-g12-dc1-substrate` -> `main`** (merge commit), branch retirement; then G12 CLOSES. NOTE open SEC rows now include SEC-014/-015/-016 (G14 row count stale -- reconcile in the close). | -| G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | OPEN -- plugin leg PARTIAL 2026-07-23 (operator-approved run, logged window ops-sec010-reassert): os-qemu-guest-agent 1.3 INSTALLED + verified by firmware-info read-back; os-iperf REFUSED by the edge ("Installation out of date. The update to opnsense-26.7.1 is required" -- upgradestatus log). NEW measured blocker: the 26.7.1 minor update (its own gated maintenance decision; natural bundle with the qga channel retrofit, since the update restart IS the "next scheduled restart"). qga agent remains non-functional until that retrofit (channel missing, by design) | +| G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | CLOSED 2026-07-23 (operator-approved full maintenance bundle, logged window ops-sec010-reassert): qga channel retrofitted via outer tofu saved-plan apply 0/1/0 exact (`docs/audit/outer-plan-20260723-office1-qga.txt`; the apply's edge bounce = the ruled "next scheduled restart"; MACs were pinned 07-22 so the in-place-update trap class was closed); edge updated 26.7 -> 26.7.1 via REST (no reboot required; os-iperf had been REFUSED on 26.7 pending exactly this update); both plugins installed=1 by firmware-info read-back, `guest-ping` -> `{"return":{}}`, agent reports both legs, egress 0% loss, outer plan re-converged ZERO DIFF (`docs/audit/outer-plan-20260723-postqga-converged.txt`). Named close capture: `docs/audit/g13-close-20260723.txt` | | G14 | 12 OPEN SEC rows (SEC-001, -003..-008, SEC-012, -013, -014, plus SEC-015 + SEC-016 opened 2026-07-23 for dc1 credentials; SEC-010/-011 CLOSED) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012/-016 carry the same libvirt-group SCOPE hardening question; SEC-016 also a snap-refresh re-assert (queued to DC standup DoD) | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-23 (12 open) | | G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 remains PROPOSED/OPEN (items 2-3 + the item-1 re-scoped migration plan) | | G16 | office1 edge `channels = []` state reconcile (the D-129 module-schema residual) | [R] operator rules the mechanism; then [V] the converged re-plan capture | operator + session | CLOSED 2026-07-21: RULED "State surgery (Recommended)" (GA-R5, session changelog item 16); executed per G6 precedent -- channels null -> [] injected, serial 29 -> 30, backup kept, guests untouched (office1-opnsense Id 2 running throughout); convergence = ZERO DIFF (`docs/audit/outer-plan-20260721-postG16-converged.txt`); section 5 re-recorded | @@ -501,7 +503,7 @@ | LXD | 5.21.5-f2a1a0e (5.21/stable, held) | `ssh voffice1 'snap list lxd'` | voffice1 | | Kernel (host) | 6.8.0-136-generic | `uname -r` | vcloud | | Kernel (voffice1) | 6.8.0-136-generic | `ssh voffice1 'uname -r'` | voffice1 | -| OPNsense edge | 26.7 (FreeBSD base 15.1) | not re-measured (gated API creds); per confirmed as-built `docs/vr1-office1-as-built.md:42`, 2026-07-18 | office1-opnsense | +| OPNsense edge | 26.7.1 (FreeBSD base 15.1) | MEASURED 2026-07-23 via the gated API (`GET core/firmware/status` -> product_version 26.7.1, capture `docs/audit/g13-close-20260723.txt`); updated 26.7 -> 26.7.1 in the G13 bundle. DC edges (vr1-dc0/dc1) remain 26.7 | office1-opnsense | | NetBox (Office1 apex) | 4.6.4 per as-built `docs/vr1-office1-as-built.md:44`; service UP verified (HTTP 302) this session | `ssh office1-netbox 'curl ... localhost:8000'` | office1-netbox | | Juju | NOT part of VR1 substrate yet (arrives Stage 5). Last recorded VR0 value 3.6.25 -- historical, unverified here | n/a | n/a | diff --git a/docs/audit/g13-close-20260723.txt b/docs/audit/g13-close-20260723.txt new file mode 100644 index 0000000..f195457 --- /dev/null +++ b/docs/audit/g13-close-20260723.txt @@ -0,0 +1,15 @@ +== G13 close verification 2026-07-23T05:07:39Z -- office1-opnsense (all read-only) == +-- 1. plugins installed (firmware info read-back) -- +os-qemu-guest-agent ('1', '1.3') +os-iperf ('1', '1.0_2') +-- 2. product version -- +None +-- 3. qga channel + agent -- +2 +{"return":{}} + +-- 4. edge egress -- +round-trip min/avg/max/stddev = 4.167/4.249/4.345/0.073 ms +-- 5. outer plan converged: see outer-plan-20260723-postqga-converged.txt (No changes) -- +-- 2 (corrected extraction, same endpoint): product_version -- +26.7.1 diff --git a/docs/audit/outer-plan-20260723-office1-qga.txt b/docs/audit/outer-plan-20260723-office1-qga.txt new file mode 100644 index 0000000..0da9dc6 --- /dev/null +++ b/docs/audit/outer-plan-20260723-office1-qga.txt @@ -0,0 +1,90 @@ +module.netem_vr1_dc0_vr1_dc1.terraform_data.netem: Refreshing state... [id=1ea36d3f-e7af-984c-8157-152724a0b85a] +module.vvr1_dc0.libvirt_cloudinit_disk.seed: Refreshing state... [id=ff281478c6083cc3] +module.vvr1_dc1.libvirt_cloudinit_disk.seed: Refreshing state... [id=41e9ec4b712038fc] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=a4694210c663c9ce] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.vr1_dc1_uplink.libvirt_network.site_wan: Refreshing state... [id=4aad75c2-924f-410c-96bb-fa9217f8b4ea] +module.vr1_dc0_uplink.libvirt_network.site_wan: Refreshing state... [id=f3500153-e4de-45f1-8854-9c92974a6094] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.vvr1_dc1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-cloudinit.iso] +module.vvr1_dc0.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-cloudinit.iso] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.vvr1_dc0.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-disk.qcow2] +module.vvr1_dc1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.vvr1_dc0.libvirt_domain.vm: Refreshing state... [name=vvr1-dc0] +module.vvr1_dc1.libvirt_domain.vm: Refreshing state... [name=vvr1-dc1] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] + +Note: Objects have changed outside of OpenTofu + +OpenTofu detected the following changes made outside of OpenTofu since the +last "tofu apply" which may have affected this plan: + + # module.voffice1.libvirt_domain.vm has changed + ~ resource "libvirt_domain" "vm" { + ~ id = 5 -> 10 + name = "voffice1" + # (11 unchanged attributes hidden) + } + + # module.vvr1_dc1.libvirt_domain.vm has changed + ~ resource "libvirt_domain" "vm" { + ~ id = 8 -> 9 + name = "vvr1-dc1" + # (11 unchanged attributes hidden) + } + + +Unless you have made equivalent changes to your configuration, or ignored the +relevant attributes using ignore_changes, the following plan may include +actions to undo or respond to these changes. + +───────────────────────────────────────────────────────────────────────────── + +OpenTofu used the selected providers to generate the following execution +plan. Resource actions are indicated with the following symbols: + ~ update in-place (current -> planned) + +OpenTofu will perform the following actions: + + # module.office1_opnsense.libvirt_domain.vm will be updated in-place + ~ resource "libvirt_domain" "vm" { + ~ devices = { + ~ channels = [ + + { + + source = { + + unix = { + + mode = "bind" + } + } + + target = { + + virt_io = { + + name = "org.qemu.guest_agent.0" + } + } + }, + ] + # (3 unchanged attributes hidden) + } + id = 2 + name = "office1-opnsense" + # (10 unchanged attributes hidden) + } + +Plan: 0 to add, 1 to change, 0 to destroy. + +───────────────────────────────────────────────────────────────────────────── + +Saved the plan to: office1-qga-20260723.tfplan + +To perform exactly these actions, run the following command to apply: + tofu apply "office1-qga-20260723.tfplan" diff --git a/docs/audit/outer-plan-20260723-postqga-converged.txt b/docs/audit/outer-plan-20260723-postqga-converged.txt new file mode 100644 index 0000000..c905941 --- /dev/null +++ b/docs/audit/outer-plan-20260723-postqga-converged.txt @@ -0,0 +1,30 @@ +module.netem_vr1_dc0_vr1_dc1.terraform_data.netem: Refreshing state... [id=1ea36d3f-e7af-984c-8157-152724a0b85a] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=a4694210c663c9ce] +module.vvr1_dc0.libvirt_cloudinit_disk.seed: Refreshing state... [id=ff281478c6083cc3] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.vr1_dc1_uplink.libvirt_network.site_wan: Refreshing state... [id=4aad75c2-924f-410c-96bb-fa9217f8b4ea] +module.vvr1_dc1.libvirt_cloudinit_disk.seed: Refreshing state... [id=41e9ec4b712038fc] +module.vr1_dc0_uplink.libvirt_network.site_wan: Refreshing state... [id=f3500153-e4de-45f1-8854-9c92974a6094] +module.vvr1_dc1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-cloudinit.iso] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.vvr1_dc0.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-cloudinit.iso] +module.vvr1_dc0.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-disk.qcow2] +module.vvr1_dc1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-disk.qcow2] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.vvr1_dc0.libvirt_domain.vm: Refreshing state... [name=vvr1-dc0] +module.vvr1_dc1.libvirt_domain.vm: Refreshing state... [name=vvr1-dc1] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] + +No changes. Your infrastructure matches the configuration. + +OpenTofu has compared your real infrastructure against your configuration and +found no differences, so no changes are needed. diff --git a/docs/changelog-20260723-queue-pass.md b/docs/changelog-20260723-queue-pass.md index d181bb8..2232615 100644 --- a/docs/changelog-20260723-queue-pass.md +++ b/docs/changelog-20260723-queue-pass.md @@ -140,6 +140,39 @@ - REVERT (installed half): remove os-qemu-guest-agent via the same firmware API (`POST core/firmware/remove/os-qemu-guest-agent`). +## Item 10 -- G13 CLOSED: office1 edge maintenance bundle (operator-approved) + +- RULING (GA-R5): question "Run the office1 edge maintenance bundle now (qga + channel + 26.7.1 update + finish os-iperf)?" -- operator answer, exact + utterance (option selected): "Approve full bundle (Recommended)". +- EXECUTED (logged window ops-sec010-reassert; each mutation gated): + 1. `expose_qga_channel = true` on `module.office1_opnsense` + (opentofu/main.tf); validate PASS; saved plan **0/1/0 exact** -- only + the channel block, in-place (`docs/audit/outer-plan-20260723-office1-qga.txt`); + applied; edge bounced and returned in ~5s answering ping. Channel in the + live domain XML, `state=connected`; `guest-ping` -> `{"return":{}}`; + `domifaddr --source agent` reports vtnet0/vtnet1 -- the dc0-equivalent + D-129 proof, first time on office1. + 2. Firmware update via `POST core/firmware/update`: 26.7 -> **26.7.1**, + package-level only (no reboot required; upgradestatus DONE, web GUI + restarted). Egress re-verified 0% loss. + 3. `opnsense-plugins.sh apply vr1-edge` re-run: **os-iperf installed=1** + (the 26.7 refusal from Item 9 resolved by the update); + os-qemu-guest-agent still installed=1. + 4. Outer plan re-converged **ZERO DIFF** + (`docs/audit/outer-plan-20260723-postqga-converged.txt`); section-5 + history chain re-recorded. +- Named close capture: `docs/audit/g13-close-20260723.txt` (plugins + read-back, product_version 26.7.1, channel count, guest-ping, egress). + G13 row CLOSED in CURRENT-STATE; as-built edge row updated (same commit). +- VERSION-DRIFT NOTE (logged, no action): office1 edge now 26.7.1; the two + DC edges remain 26.7 -- whether to roll 26.7.1 to them is a future gated + maintenance question (they have no current install-blocker forcing it). +- REVERT: channel -- remove `expose_qga_channel` from main.tf + gated 0/1/0 + apply (bounces the edge). Plugins -- `POST core/firmware/remove/`. + Firmware -- effectively one-way (no API downgrade); the operator accepted + this in the bundle approval. + ## Non-items (verified/logged, nothing executed) - Netem runbook Step-11 DOCFIX flagged at step E: ALREADY delivered at stage diff --git a/docs/vr1-office1-as-built.md b/docs/vr1-office1-as-built.md index e0cb0dc..fbd4677 100644 --- a/docs/vr1-office1-as-built.md +++ b/docs/vr1-office1-as-built.md @@ -39,7 +39,7 @@ | Host | Address | What runs on it | Level | |---|---|---|---| | **vcloud** | `10.17.11.248` (lab), `10.10.0.10` on `virbr2`, `172.30.1.1` on `virbr11` | libvirt/KVM hypervisor; OpenTofu runs from here | L1 (itself a KVM guest) | -| **office1-opnsense** | LAN `10.10.0.1` / WAN `172.30.1.2` | **OPNsense 26.7** (FreeBSD base **15.1**-RELEASE-p1; both bumped from 26.1.11 / FreeBSD 14.3 on 2026-07-18; 0 outdated pkgs) edge router: routing, NAT, **Kea DHCP**, firewall. Plugins: `os-git-backup` (UNCONFIGURED); `os-qemu-guest-agent` INSTALLED 2026-07-18 but NON-FUNCTIONAL (daemon off + no libvirt guest-agent channel -- functional enablement DEFERRED to next edge restart, D-129); `os-iperf` re-install pending (first attempt lost to the firmware lock). See `docs/opnsense-edge-addon-review-20260718.md` + D-129. | L2 | +| **office1-opnsense** | LAN `10.10.0.1` / WAN `172.30.1.2` | **OPNsense 26.7.1** (FreeBSD base **15.1**-RELEASE-p1; 26.7 -> 26.7.1 minor update 2026-07-23 via the REST API, no reboot needed) edge router: routing, NAT, **Kea DHCP**, firewall. Plugins: `os-git-backup` (UNCONFIGURED); `os-qemu-guest-agent` **FUNCTIONAL 2026-07-23** (D-129 qga channel retrofitted via outer tofu 0/1/0 apply -- the edge bounce WAS the ruled "next scheduled restart"; `guest-ping` answers, `domifaddr --source agent` reports both legs); `os-iperf` **INSTALLED 2026-07-23** (was refused on 26.7 -- the edge required the 26.7.1 update first). Evidence: `docs/audit/g13-close-20260723.txt`. See D-129 / gate G13 (CLOSED). | L2 | | **voffice1** | `10.10.0.20` (Kea reservation) | **MAAS 3.7.2** region+rack + PostgreSQL 16.14; **LXD 5.21.5** (registered to MAAS as VM host `office1-lxd`) | L2 | | **office1-netbox** | `10.10.1.10` | **NetBox 4.6** (netbox-docker; `/opt/netbox-docker`, `docker compose up -d`) on `:8000`; **`restart: unless-stopped`** on all 5 services (2026-07-17 -- survives instance reboot) | L3 (LXD VM) | | **office1-tailscale** | `10.10.1.11` / tailnet **`100.64.0.53`** (`fd7a:115c:a1e0::35`) | **Tailscale 1.98.8**, subnet router advertising `10.10.0.0/22`. Joined the **SELF-HOSTED** control plane `https://tailscale.baldurkeep.com:443` | L3 (LXD VM) | diff --git a/opentofu/main.tf b/opentofu/main.tf index 80efbee..80d743a 100644 --- a/opentofu/main.tf +++ b/opentofu/main.tf @@ -110,6 +110,10 @@ # 11 GiB. Removed in DOCFIX-189. lan_network_name = module.office1_network.network_name wan_network_name = "office1-wan" + # D-129 qga channel retrofit (G13): applied at the 2026-07-23 operator-approved + # maintenance bundle -- the apply bounces the edge (the ruled "next scheduled + # restart"), bundled with the 26.7.1 firmware update. + expose_qga_channel = true } # ---- The D-100 dark-fiber mesh triangle: DC1<->DC2, DC1<->Office1,