diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 34fc4db..707064f 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -184,7 +184,8 @@ were wrong; its instrument found the cause). D-131 PARTIALLY RULED (sub-1 RULED 2026-07-21: the forwarder is the STANDING per-DC pattern, repo-carried + part of DC standup definition-of-done; - sub-2..4 OPEN -- status line in design-decisions.md is the + sub-2 RULED 2026-07-21: metal-admin-only scope; sub-3..4 OPEN -- + status line in design-decisions.md is the authority). SEC-014 OPENED (rack cluster secret exposure during diagnosis). Queued delivery: incident docs SHIPPED 2026-07-21 (two appendix-A entries, platform-traps 1e second diff --git a/docs/changelog-20260721-tenant-review-pin.md b/docs/changelog-20260721-tenant-review-pin.md index 55bafa4..a7c80d1 100644 --- a/docs/changelog-20260721-tenant-review-pin.md +++ b/docs/changelog-20260721-tenant-review-pin.md @@ -32,3 +32,19 @@ ledger block per the standing counter discipline). - **Revert:** git revert this commit (records only; no live surface or script was touched). + +## 3. Queue pass opened: D-131 sub-2 RULED (metal-admin-only forwarder scope) + +- Operator directed a working pass through the open decision queue; order + presented (D-131 subs -> D-129 subs -> D-071 points -> D-068 -> G12 prep + -> netem finals -> SEC-014), one ruling per exchange (GA-R5). +- D-131 sub-2 RULED: "Metal-admin only (Recommended)" (question + utterance + quoted in the D-131 Status block, the ruling authority). Scope of the + rack node-DNS forwarder is fixed at the metal-admin alias only; edge + keeps its own WAN-side DNS; SEC-010 untouched. Revisit trigger recorded: + a D-129 (iii)/(iv) consolidation ruling. +- Same-commit status coupling (GA-R1 C1): CURRENT-STATE D-131 sentence and + the ledger machine-block D-131 line updated to sub-3..4 open. No live + surface touched -- dc0-node-dns.service already runs metal-admin-only, + so the ruling codifies the running shape; zero config delta. +- **Revert:** git revert this commit (records only). diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 5e50671..22a0282 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -4214,7 +4214,13 @@ mechanism for rack-only DCs: site-keyed repo-carried delivery (unit + config + install/check script + harness, folding in rack-legs persistence per D-128 register item 20), applied to dc0 and part of every future DC standup's definition-of-done; Roosevelt default unless the LP -outcome (sub-decision 4, OPEN) rules otherwise. Sub-decisions 2-4 remain OPEN. +outcome (sub-decision 4, OPEN) rules otherwise. Sub-decision 2 RULED 2026-07-21 (GA-R5): +question as presented = "should the rack node-DNS forwarder serve metal-admin only (the +current, proven scope), or be extended to the edge / other planes?"; operator selection, +exact utterance: "Metal-admin only (Recommended)". Scope is therefore FIXED at metal-admin +only (dnsmasq bound to the single metal-admin alias; edge keeps its own WAN-side DNS; +SEC-010 untouched); revisit only if a D-129 (iii)/(iv) ruling later consolidates site +services onto the edge. Sub-decisions 3-4 remain OPEN. **Context (measured, 2026-07-21).** MAAS 3.7's rack-only controllers serve node DNS from the `maas-agent` resolver, which on an internet-isolated rack SERVFAILs ALL queries -- including its @@ -4237,7 +4243,7 @@ **Open sub-decisions:** 1. Adopt the forwarder as the STANDING per-DC pattern (repo-carried, site-keyed unit + module or script delivery, harness) vs treat as temporary until the MAAS agent defect is fixed upstream. -2. Whether the forwarder should serve the edge/other planes too, or metal-admin only (current). +2. RULED 2026-07-21 (Status block above): metal-admin only. 3. dhcpd still prepends the rack IP to option 6 despite `allow_dns=false` (relies on client SERVFAIL failover -- works, proven, but is an extra moving part): investigate template behavior; possibly LP material of its own. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index a94cfd6..64851ee 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -35,7 +35,8 @@ - **PROPOSED / OPEN decisions:** D-068 (Vault substrate hardening, Roosevelt), D-071 (routine update cadence + Juju controller patch policy), D-129 (OPNsense edge plugin/add-on base profile -- OPEN / partially ruled, four sub-decisions), D-131 (node-facing DNS strategy for - rack-only controllers -- PARTIALLY RULED: sub-1 ruled + delivered 2026-07-21, sub-2..4 open; + rack-only controllers -- PARTIALLY RULED: sub-1 ruled + delivered 2026-07-21, sub-2 ruled + 2026-07-21 (metal-admin only), sub-3..4 open; now surfaced by the scan itself after the PARTIAL fix). Status lines in `docs/design-decisions.md` are the only ruling authority. - **OPEN security rows:** 10 open per `bash scripts/ledger-scan.sh` (re-verified at stage close;