diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 165c8c8..4707b38 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1777,6 +1777,32 @@ is still re-scanned, which is the entire point.** The amendment's concern was legitimate (the DEFAULT path does reconfigure networking) and the vendor's own control is sufficient. **REMAINING: dc0 storage-02/03/04, then all of dc1** (apply + the same re-commission). +- **JUJU CONTROLLER ADDRESSING RULED 2026-07-29, and the octet map becomes a STANDING CROSS-DC + STANDARD -- recorded as a D-134 AMENDMENT (2026-07-29), which is the authority.** + Question as presented: the D-104 controller VM auto-enlisted but D-134's bands cover no such + node (`.4-.49` utility, `.50-.99` VIP, `.100-.200` NODES split into three OpenStack ROLE + sub-bands). A MEASURED occupancy table was put to the operator -- dc0 metal-admin has only + NINE allocated addresses; `.1` is held by nothing, `.2` rack leg, `.3` D-131 forwarder, `.4` + mirror/proxy, and `.5-.49` entirely free and RESERVED in MAAS -- with three options. + **Operator answer, exact utterance: "Rule .5 for the juju controller, with the other utility + nodes. These assignments will follow all DC deployments to make sure standardized + configuration is upheld through multiple datacenter stand ups."** + **(1) `-juju-01` takes octet `.5`** on every plane, inside the reserved utility band, so + MAAS never auto-allocates there. This resolves the node-vs-utility tension in favour of + FUNCTION: the utility band is now the band for PER-DC INFRASTRUCTURE the OpenStack nodes + consume, host-level (mirror) or MAAS-managed (controller) alike; `.100-.200` stays for + OpenStack ROLE nodes. + **(2) THE LOAD-BEARING HALF -- the octet map is a STANDING CROSS-DC STANDARD, not a per-DC + choice.** Every DC's `juju-01` is `.5`, artifact service `.4`, rack leg `.2`, forwarder `.3`. + A new per-DC infrastructure service takes the next free utility octet AND THE SAME ONE IN + EVERY DC -- assigning it once assigns it everywhere. **Divergence between DCs at the same + octet is a DEFECT, not a local decision**, which is what makes `dc-plane-ipam.sh check + ` meaningful ACROSS sites rather than merely per-site. Roosevelt analog: the MAP + transfers, not just the method. + **Scope: this assigns the octet and sets the standing rule. It does NOT create the MAAS + record, the `juju-controller-` tag, or the tofu MAC pin** -- all still gated. And the + controller CANNOT be commissioned yet: its `power_type` measured EMPTY at enlistment, the + same state that blocked all nine role nodes on 2026-07-20. - **THREE PLATFORM BEHAVIOURS GRADUATED to `references/platform-traps.md`** at session close, having been recorded only in this status document (which is consolidated over time, so a durable trap does not belong here alone): MAAS auto-reserves `::1`-`::ffff:ffff` on EVERY diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 736e7cd..bf88f9a 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -5372,6 +5372,55 @@ --- +## D-134 -- AMENDMENT (2026-07-29): the per-DC Juju controller takes utility-band .5, and the octet map is a STANDING cross-DC standard + +**Status: RULED 2026-07-29** (operator, GA-R5). + +**Question as presented.** The D-104-amendment controller VM (`-juju-01`) was built and +auto-enlisted into MAAS, but D-134's bands cover no such node: `.4-.49` is UTILITY, +`.50-.99` VIP, and `.100-.200` is NODES split into control `.100-.119` / compute +`.120-.149` / storage `.150-.200` -- all three role sub-bands being OpenStack roles a Juju +controller is not. A measured occupancy table was put to the operator (dc0 metal-admin: only +NINE addresses actually allocated; `.1` held by nothing, `.2` rack leg, `.3` D-131 DNS +forwarder, `.4` mirror/proxy, `.5-.49` entirely free and RESERVED in MAAS) with three +options: (a) `.5`, in the utility band beside the mirror/proxy -- groups by FUNCTION, but +crosses D-134's stated node/utility split by KIND, since the utility band today holds only +host-level services while the controller is a MAAS-deployed node; (b) `.103`, the first free +address in the control band -- keeps every MAAS machine inside `.100-.200` at the cost of +sitting in a band named for OpenStack control nodes; (c) a new named sub-band inside +`.100-.200`. + +**Operator answer, exact utterance: "Rule .5 for the juju controller, with the other utility +nodes. These assignments will follow all DC deployments to make sure standardized +configuration is upheld through multiple datacenter stand ups."** + +**RULED (1) -- the address.** `-juju-01` takes octet **.5** on every plane it is +attached to, immediately after the `.4` artifact service, inside the D-134 utility band. The +band is RESERVED in MAAS, so MAAS never auto-allocates there and a static assignment is +deliberate and collision-free. This RESOLVES the node/utility tension in favour of function: +the utility band is hereby the band for PER-DC INFRASTRUCTURE that the OpenStack nodes +consume, whether that infrastructure is host-level (the mirror) or a MAAS-managed machine +(the controller). `.100-.200` remains the band for OpenStack ROLE nodes specifically. + +**RULED (2) -- and this is the load-bearing half: THE OCTET MAP IS A STANDING CROSS-DC +STANDARD.** The assignments are not per-DC choices to be re-made at each standup; they +FOLLOW ALL DC DEPLOYMENTS so that standardized configuration is upheld through multiple +datacenter stand ups. Consequences that bind future work: + + - Every DC's `juju-01` is `.5`. Every DC's artifact service is `.4`. Every DC's rack leg is + `.2` and its node-DNS forwarder `.3`. A new DC does not get to choose. + - A new per-DC infrastructure service takes the NEXT free utility octet and takes THE SAME + one in every DC. Assigning it in one DC assigns it in all of them. + - Divergence between DCs at the same octet is a DEFECT, not a local decision. This is what + makes `dc-plane-ipam.sh check ` meaningful across sites rather than per-site. + - Roosevelt analog: this is the transferable half. The rehearsal's value is that the map, + not merely the method, carries forward -- a Roosevelt DC standup reads the same table. + +**Scope note.** This amendment assigns an octet and establishes the standing rule; it does +NOT by itself create the MAAS record, the tag, or the tofu pin. Those remain separate gated +work, and the controller VM cannot be commissioned until it has a `power_type` (measured +EMPTY at enlistment -- the same state that blocked all nine role nodes on 2026-07-20). + ## D-134 -- AMENDMENT (2026-07-27): the bands become ENFORCED in MAAS, via a DC-aware tool; and v6 gains band discipline **Status:** RULED 2026-07-27 (operator, GA-R5). Question as presented, verbatim: "R4 --