diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 23b1e65..a1ad5a7 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1156,8 +1156,36 @@ runs where `maas` lives, so the branch is required there. tfstate sha256s re-verified UNCHANGED across the switch. **Return it to `main` at merge** -- a working host left on a retired branch is precisely the Phase-0 defect. - **NOT YET DONE, and each is an operator-gated live mutation:** the v6 carve on the 12 plane - fabrics, the band reservations, the rack-bridge v6 legs, and the apex population. + **carve-v6 + reserve SHIPPED 2026-07-27, dry by default** (harness **25/25**, gauntlet ALL + GREEN 83). Both IDEMPOTENT and both READ BACK every write -- the precedent being + `opnsense-plugins.sh apply`, which ALWAYS silently dry-ran, voiding every prior "applied" + claim from it. Two bugs caught pre-ship, NEITHER by review: `printf '%x' 50` yields `32`, so + the v6 bands would have landed at `::32-::63` -- a plausible-looking band that is NOT the one + ruled (the ruling mirrors the DIGITS, v4 `.50` -> `::50`); and `shift 2` with a single + argument fails, leaving `$@` holding the action so `check` alone reported "unknown option". + **REAL FINDING -- R4 CANNOT BE FULLY EXECUTED FOR dc1:** `reserve vr1-dc1` REFUSES (exit 1) + because `FIP_POOL_START/END` are UNSET for dc1 in `lib-net.sh` BY DESIGN ("UNSET so any use + fails loud"), while R4's ruled scope explicitly includes "plus the FIP pool". Mirroring dc0's + shape would be an inferred value (hard rule 2), so the tool refuses and says so. **dc1's FIP + pool needs a ruling** before R4 closes for that site. +- **dc0 v6 CARVE EXECUTED 2026-07-27 (operator-gated: "Run carve-v6 vr1-dc0 --commit").** + Capture `docs/audit/dc0-v6-carve-20260727.txt`. Pre-apply re-verified in the SAME session + first (the G8 precedent): plan unchanged at 6/1/0. **Result 6 applied / 1 skipped / 0 errors, + every create READ BACK on its intended vlan.** MAAS subnets **18 -> 24**, v6 **1 -> 7**. Each + v6 plane landed on the SAME vlan as its v4 twin, so the plane is genuinely dual-stack on one + L2 rather than a parallel fabric: `f02:10::/64` on vr1-dc0-provider-public (5189), `:220::/64` + on fabric-4 (5005), `:221::/64` metal-internal (5190), `:230::/64` data-tenant (5191), + `:240::/64` storage (5192), `:250::/64` replication (5193). The provider GUA VIP `/64` + (`f02:11::/64`) was deliberately NOT created -- it holds hacluster-managed API VIPs, not node + addresses. **IDEMPOTENCY PROVEN LIVE, not just in fixture:** `--commit` ran TWICE (the second + to read the script's true exit code rather than a pipeline's) and the post-state carries ZERO + duplicate CIDRs. **Nothing else moved:** 18 Ready + 2 Deployed unchanged, no node touched, no + tfstate involved, and dc1 still measures 6 v6 planes ABSENT -- only dc0 was authorised. + `dc-plane-ipam check vr1-dc0` now reports the six v6 planes `[ok]`; its remaining reds are the + 12 unreserved D-134 bands. + **STILL NOT DONE, each an operator-gated live mutation:** dc1's v6 carve, the band + reservations both DCs, the v6 bands (forced to follow each DC's carve), the rack-bridge v6 + legs, and the apex population. - Position inside Stage 3: deploy step A EXECUTED 2026-07-19 (6/0/6 exact; convergence zero -- `docs/audit/outer-plan-20260719-postA-converged.txt`). **Deploy step B diff --git a/docs/audit/dc0-v6-carve-20260727.txt b/docs/audit/dc0-v6-carve-20260727.txt new file mode 100644 index 0000000..690cf80 --- /dev/null +++ b/docs/audit/dc0-v6-carve-20260727.txt @@ -0,0 +1,61 @@ +carve-v6 vr1-dc0 --commit -- AS-EXECUTED, 2026-07-28T06:26:20Z +Operator-gated single mutation. Run from voffice1 (D-128 Plane-2 host). +NOTE: no run-logged.sh window was opened (P0-4 class); this capture + the +changelog are the as-executed record. + +PRE: 18 subnets, 1 v6 (Office1's 2602:f3e2:f01:100::/64 only) + dc-plane-ipam check vr1-dc0 = 6 pass / 18 fail + pre-apply re-verify in the SAME session: planned=6 skipped=1 errors=0 (unchanged) + +== dc-plane-ipam check vr1-dc0 == + apex record: netbox/draft/vr1-office1-current-20260725.json + +-- v4 planes (from lib-net) -- + [ok] v4 provider-public 10.12.4.0/22 present (fabric=vr1-dc0-provider-public) + [ok] v4 metal-admin 10.12.8.0/22 present (fabric=fabric-4) + [ok] v4 metal-internal 10.12.12.0/22 present (fabric=vr1-dc0-metal-internal) + [ok] v4 data-tenant 10.12.16.0/22 present (fabric=vr1-dc0-data-tenant) + [ok] v4 storage 10.12.32.0/22 present (fabric=vr1-dc0-storage) + [ok] v4 replication 10.12.36.0/22 present (fabric=vr1-dc0-replication) + +-- v6 planes (from the apex) -- + [ok] v6 data-tenant fd50:840e:74e2:230::/64 present + [ok] v6 metal-admin fd50:840e:74e2:220::/64 present + [ok] v6 metal-internal fd50:840e:74e2:221::/64 present + [ok] v6 provider-public 2602:f3e2:f02:10::/64 present + [note] provider-public 2602:f3e2:f02:11::/64 provider VIP block, MAAS subnet=no (not asserted) + [ok] v6 replication fd50:840e:74e2:250::/64 present + [ok] v6 storage fd50:840e:74e2:240::/64 present + +-- D-134 reserved bands (v4) -- + [FAIL] provider-public util band 10.12.4.4-10.12.4.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] provider-public vip band 10.12.4.50-10.12.4.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] metal-admin util band 10.12.8.4-10.12.8.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] metal-admin vip band 10.12.8.50-10.12.8.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] metal-internal util band 10.12.12.4-10.12.12.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] metal-internal vip band 10.12.12.50-10.12.12.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] data-tenant util band 10.12.16.4-10.12.16.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] data-tenant vip band 10.12.16.50-10.12.16.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] storage util band 10.12.32.4-10.12.32.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] storage vip band 10.12.32.50-10.12.32.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] replication util band 10.12.36.4-10.12.36.49 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + [FAIL] replication vip band 10.12.36.50-10.12.36.99 NOT reserved (D-134 is RULED; MAAS may hand these out mid-deploy) + +RESULT: pass=12 fail=12 +FAIL: dc-plane-ipam check vr1-dc0 -- 12 assertion(s) failed + +POST-STATE: + subnets 18 -> 24 v6 1 -> 7 duplicate cidrs: NONE + 2602:f3e2:f01:100::/64 id=3 vlan=5001 fabric=fabric-0 + 2602:f3e2:f02:10::/64 id=23 vlan=5189 fabric=vr1-dc0-provider-public + fd50:840e:74e2:220::/64 id=21 vlan=5005 fabric=fabric-4 + fd50:840e:74e2:221::/64 id=22 vlan=5190 fabric=vr1-dc0-metal-internal + fd50:840e:74e2:230::/64 id=20 vlan=5191 fabric=vr1-dc0-data-tenant + fd50:840e:74e2:240::/64 id=25 vlan=5192 fabric=vr1-dc0-storage + fd50:840e:74e2:250::/64 id=24 vlan=5193 fabric=vr1-dc0-replication + + machines: 18 Ready + 2 Deployed (office1 guests) -- UNCHANGED, no node touched + dc1: still 6 v6 planes ABSENT -- correctly untouched, dc0 only was authorised + +IDEMPOTENCY PROVEN LIVE: --commit ran TWICE (second time to read the true +exit code rather than a pipeline's). Zero duplicate CIDRs afterwards. diff --git a/docs/changelog-20260727-stage5-phase0.md b/docs/changelog-20260727-stage5-phase0.md index 9ef2a2a..a8d2d04 100644 --- a/docs/changelog-20260727-stage5-phase0.md +++ b/docs/changelog-20260727-stage5-phase0.md @@ -263,3 +263,40 @@ **Revert.** `git revert ` and delete `tests/HARNESS-MANIFEST`. The gauntlet returns to reporting ALL GREEN over whatever harnesses happen to exist. + +## 9. LIVE MUTATION -- dc0 v6 plane carve (6 MAAS subnets created) + +**What.** `bash scripts/dc-plane-ipam.sh carve-v6 vr1-dc0 --commit` on voffice1. +Created six IPv6 plane subnets in MAAS: `2602:f3e2:f02:10::/64` (provider-public) and +`fd50:840e:74e2:{220,221,230,240,250}::/64` (metal-admin, metal-internal, data-tenant, +storage, replication). Each on the SAME vlan as its v4 twin. + +**Why.** R2 RULED dual-stack for both DCs this deployment; measured, MAAS carried ZERO +v6 on any of the 12 DC plane fabrics. The v6 carve is also FORCED SEQUENCING for R4 -- +a reserved range cannot be created on a subnet that does not exist. + +**Authorisation.** Operator, exact utterance: "Run carve-v6 vr1-dc0 --commit". dc0 only; +dc1 was NOT authorised and was not touched. + +**Evidence.** Pre-apply re-verify in the SAME session (G8 precedent) showed the plan +unchanged: planned=6 skipped=1 errors=0. Apply: **6 applied, 1 skipped, 0 errors, every +create READ BACK on its intended vlan**, exit 0. Post-state: subnets 18 -> 24, v6 1 -> 7, +**zero duplicate CIDRs** (proven despite `--commit` running twice). Machines 18 Ready + 2 +Deployed, UNCHANGED. dc1 still measures 6 v6 planes absent. + +**Blast radius.** Additive MAAS records only. No node, no tfstate, no running service. +The provider GUA VIP `/64` was deliberately not created. + +**Revert.** +``` +ssh voffice1 'for c in 2602:f3e2:f02:10::/64 fd50:840e:74e2:220::/64 \ + fd50:840e:74e2:221::/64 fd50:840e:74e2:230::/64 fd50:840e:74e2:240::/64 \ + fd50:840e:74e2:250::/64; do + id=$(maas admin subnets read | python3 -c "import json,sys;print(next((x[\"id\"] for x in json.load(sys.stdin) if x[\"cidr\"]==\"$c\"),\"\"))") + [ -n "$id" ] && maas admin subnet delete "$id"; done' +``` +Read the subnet's occupancy BEFORE deleting -- the 2026-07-21 pod-delete incident +cascaded to 9 machine records because an association check ran too late. These subnets +have no allocations today, but check rather than assume. + +**Capture.** `docs/audit/dc0-v6-carve-20260727.txt`.