diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 2a077cf..6778adc 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2729,6 +2729,33 @@ measured plan is **56 apps / 108 relations**; `docs/dc-dc-buildout-design.md:12` records the repo was seeded at `8813efc` specifically so `bundle.yaml` + `phase-01..08` could be reused. **Provider capabilities must be READ (`references/opentofu-provider-docs.md`), never recalled.** + **>>> PRE-DEPLOY ITEMS 1-3 PROCESSED 2026-08-02. <<<** + **(1) PREFLIGHT RE-RUN for dc0 on voffice1 with `MAAS_PROFILE=vr1-dc0-region`: EXIT 1 with + EXACTLY 11 `[FAIL]` lines, and they are EXACTLY the ruled-accepted P5 set** (dc0 + `opnsense-api.txt`; five dc1 SEC-027/-028 rows; three S5 power-key asymmetries; S6 identity + conflation; E4 x2). **ZERO new findings, so no fresh GA-R5 exchange is owed** and the RED + stays ruled-accepted. **P8 is clean after this morning's guard fix** (it false-FAILed here + before), and **P9 warns correctly off-rack** with the exact command -- preflight runs on + voffice1, which is never a rack, so "could not look" is the right verdict there and NOT a + substitute for running the gate on the rack. + **(2) MIRROR SYNC RE-TRIGGERED and RUNNING** (`dc0-mirror-sync`, status `RUNNING + 2026-08-02T08:22:47Z`, progressing through Packages/Translation/DEP-11). The 08-02 failure was + purely upstream-unreachable during the edge outage; content was verified INTACT throughout + (236/236 Ubuntu + 2/2 UCA indices). It completes on its own and writes `OK` to + `last-sync.status`; **`dc-mirror.sh check dc0` stays RED until it does**, which is the + attested-currency gate working as designed rather than a fault. + **(3) THE EDGE dnsmasq QUESTION IS SETTLED ON MEASUREMENT, and the agent was right to refuse + to settle it on reasoning.** Measured on the rebuilt edge: `vtnet0` carries `inet 10.12.4.1/22` + and **`inet6` LINK-LOCAL ONLY (`fe80::5054:ff:fe6d:a927`), no global**, and no `radvd`. So the + v4 `dhcp-range 192.168.1.100-.199` is not on the interface's subnet and dnsmasq will not serve + it, and the v6 `dhcp-range ...constructor:vtnet0,slaac` has **no global prefix to construct + from**. **INERT TODAY, measured.** **THE RESIDUAL RISK IS LATENT AND REAL, and it is the v6 + half, not the stale v4 one everybody looks at:** provider-public HAS a GUA prefix + (`2602:f3e2:f02:10::/64`) which OpenStack will use, so **if `vtnet0` ever gains a global v6 the + `constructor:` range self-activates and the edge begins advertising SLAAC on the segment + carrying the provider network.** A `constructor:` range is not stale config -- it follows the + interface. Logged, not changed: the edge has no ruled DHCP role and removing it is a config + decision. **>>> dc0 EDGE REBUILT 2026-08-02 AND EGRESS IS FULLY RESTORED: `dc-egress-check dc0` PASS 8/8, exit 0. <<<** Capture `docs/audit/dc0-edge-rebuild-20260802.txt` (683 lines). Executed by a gated agent. `tofu -replace` on both edge resources, **asserted on `tofu show -json` rather