diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index bc9967b..f650de4 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -61,6 +61,14 @@ > D-069 custodian) + ~3 analysis-now (D-131 sub-4, D-140 provider-read, D-068 probes) + 1 access- > gated reconsideration (D-129(iii) tailnet ACL); the majority (18 rows) genuinely stay bare-metal/ > scale-bound. `docs/audit/roosevelt-held-decisions-review-20260809.md`. +> **TWO OPERATOR-PREVIEWED CHANGES TO THE REDEPLOY (2026-08-09, Roosevelt-review Section 0.1 -- +> flagged, NOT yet ruled/designed):** (1) the dc0/dc1 CONTAINER LAYER is being ELIMINATED in this +> rebuild ("pull all deeper layers up one, simplify the wiring") -- an [ARCH] change to the +> D-122/D-123 Model-B containment that alters the D-143 EXECUTION topology; owed its own decision +> at redeploy planning. (2) A PRE-ROOSEVELT BARE-METAL TEST on a small hardware set follows this +> redeploy (specs in days); this teardown/redeploy is the test of the module-deployment project, +> and it compresses the Roosevelt-review Group-4 horizon from far-future to weeks-away (re-run that +> assessment against real hardware sheets when they land). > > **dc0 checkpoint scope (operator 2026-08-08): "activate + smoke-test"** -- networks + Octavia (1 test > LB) + Designate (1 test zone) + wrap gates (cloud-assert BOM, controller backup, verify-live diff --git a/docs/audit/open-items-review-20260809.md b/docs/audit/open-items-review-20260809.md index 2d01019..72ac070 100644 --- a/docs/audit/open-items-review-20260809.md +++ b/docs/audit/open-items-review-20260809.md @@ -480,12 +480,12 @@ ## 8. Advisor review + consensus (two-pass, corrections visible) -*(Terminology note, corrected 2026-08-09 on operator instruction: this review used the -`advisor()` tool -- a stronger reviewer model that sees the full transcript. Its backing -model identity is NOT exposed by the tool; earlier drafts called it "the fable advisor" -following this repo's inherited memory convention, which is unverified. Corrected here to -"the advisor" -- a specific-but-unverified model name is exactly the fabricated-value class -the repo posture forbids.)* +*(Terminology note, RESOLVED 2026-08-09. The two advisory passes on this review used the +`advisor()` tool, which was configured as **Opus 5** at the time -- confirmed by the operator, +who then moved the advisor to **Fable 5** (`/advisor` output in-transcript). Earlier drafts +mislabelled it "the fable advisor" following this repo's inherited memory convention; that was +wrong (it was Opus 5). Do NOT retro-label these passes as Fable. "The advisor" = the +`advisor()` tool; name a model only when its configuration is confirmed.)* The review ran two adversarial advisor passes over the same items. The value of the structure is that the corrections are RECORDED, not that the final list looks clean. diff --git a/docs/audit/roosevelt-held-decisions-review-20260809.md b/docs/audit/roosevelt-held-decisions-review-20260809.md index 3090750..59388be 100644 --- a/docs/audit/roosevelt-held-decisions-review-20260809.md +++ b/docs/audit/roosevelt-held-decisions-review-20260809.md @@ -41,6 +41,35 @@ v6 re-carve. Those are the genuine pull-forwards. The recommendation groups below split exactly on that line. +### 0.1 UPDATE 2026-08-09 -- operator preview of TWO material near-term changes (reframes the horizon) + +When asked whether hardware specs exist (the discriminating question for Group 4), the +operator answered **"Not yet"** -- so **Group 4 stands as written for THIS redeploy** (still +generic nested VMs). But the answer previewed two structural changes that reframe the review: + +1. **The dc0/dc1 CONTAINER LAYER is being ELIMINATED in this rebuild.** Operator: the nested + containment layer "will not provide the testing environment I was assuming ... has only + caused more trouble than beneficial data ... pull all deeper layers up one and simplify + the wiring." This is an **[ARCH] substrate change** to the D-122/D-123 Model-B nested + containment -- it changes the re-IP (D-143) EXECUTION topology, not just the addresses. + **OWED (flagged, not designed here):** it warrants its own decision/amendment at redeploy + planning (a D-123 amendment or new D-number -- architectural consequence + Roosevelt-delta, + GA-R3). Captured so it is not lost; the design is the next planning session's, with the + operator's topology detail. +2. **A PRE-ROOSEVELT BARE-METAL TEST is imminent** -- "a smaller set of hardware ... specs + within a few days so we can plan deployment ... a good test of the module deployment + project we are developing during the teardown and redeploy." **This COMPRESSES the + Group-4 horizon:** the "next distinct deployment" is no longer far-future Roosevelt but a + near-term bare-metal test. The Group-4 bare-metal/hardware items (D-133 part-2, D-059, + D-100, D-129 metal-edge profile, D-104 HA, D-052 planes) keep their deferral (specs not + here yet) but their REVIEW POINT is now weeks away, not "someday." Re-run this Group-4 + assessment against the real hardware sheets when they arrive -- several may move to + pull-forwards for the bare-metal test. + +Net: this redeploy's yield is unchanged (Group 4 stands, no specs), but the container-layer +elimination is a new owed [ARCH] item for the redeploy plan, and the bare-metal test makes a +Group-4 re-run imminent rather than distant. + --- ## 1. GROUP 1 -- PULL FORWARD to the 10.13 redeploy (fresh-build items, not bare-metal-bound) @@ -51,8 +80,12 @@ - **D-137 -- "real credential hardening (rotation, revocation, non-shared tokens)" deferred to post-teardown cycles.** The re-IP TEARDOWN *is* the post-teardown cycle D-137 named. This is the same finding as open-items-review **R7** (the teardown runbook has no - credential-revocation checklist). **Recommendation:** build the revocation/rotation step - into the teardown, so the redeploy re-mints on a clean slate. Actionable now (build R7). + credential-revocation checklist). **Recommendation:** build the revocation step into the + teardown, so the redeploy re-mints on a clean slate. Actionable now (build R7). **Precision + (advisor-flagged):** the teardown discharges only the REVOCATION leg for the DC-substrate + material (Section 3b); the ROTATION leg for the persistent-host credentials (Section 3a -- + Office1/vcloud-resident) still lands at v1 close. D-137 is not fully discharged by the + redeploy. - **D-142 -- vault-init QoL sweep, "implement + test on the next opportunity."** The next opportunity is literally the redeploy's Vault standup. Same as open-items-review **R6**. **Recommendation:** fix R1's `-m` model-target DEFECT before the next Vault init, put R2's @@ -218,10 +251,13 @@ ## 8. Advisor review + consensus (corrections visible) -*(Terminology note, corrected 2026-08-09 on operator instruction: "the advisor" = the -`advisor()` tool, a stronger reviewer model whose backing identity the tool does not expose. -Earlier drafts said "fable advisor" per this repo's inherited memory convention, which is -unverified -- corrected to avoid asserting a specific model name I cannot confirm.)* +*(Terminology note, RESOLVED 2026-08-09. The DRAFTING advisory pass on this review ran while +the `advisor()` tool was configured as **Opus 5** (confirmed by the operator). A later RECHECK +pass -- after the operator moved the advisor to **Fable 5** (`/advisor` output in-transcript) +-- re-verified this review's findings (SEC partition, Group-4 reasoning, the D-129(iii) model) +and confirmed them; its one discriminating question ("do hardware specs exist yet?") produced +Section 0.1. Earlier drafts mislabelled the Opus-5 passes "fable advisor" per an inherited +memory convention; that was wrong. Name a model only when its configuration is confirmed.)* **What the advisor caught on the drafted review, and what changed:** 1. **Unplaced inventory items (the same completeness class as last review's "sums to 28").** diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 8346acd..7dd90e8 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -8100,6 +8100,12 @@ 10.13".** CONSEQUENCE: the tailnet + apex measurements are ACCEPTED as sufficient for owed check #3 (the VR0-internal MAAS/neutron sweep is NOT required before the re-carve); the re-IP is ADOPTED; the mapping is the octet-preserving `10.12.a.b -> 10.13.a.b` shift (C.2). + **C.2 alternative SEEN-AND-REJECTED (confirmed 2026-08-09, advisor-flagged):** the + ruling-prep's alternative -- regularize dc0's non-contiguous plane offsets (4/8/12/16 then + 32/36) into a contiguous /19 block symmetric with dc1 -- was considered and NOT taken. It + breaks octet-preservation and diverges further from the VR0/Roosevelt template; the + octet-preserving shift is confirmed (operator: "Octet-preserving confirmed"), and D-134's + standing cross-DC octet map endorses it. - **Exchange 2 (the two structural sub-forks; C.1 governs C.3).** - **C.1 apex fork.** Question: "the live cloud stays on 10.12 untouched. Where does the