diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 0674185..5019a8a 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2481,6 +2481,11 @@ `office1_svc` pubkey; (d) REBUILD the 9 nodes+juju+.7 FRESH into it -- delete each from Office1 `admin`, then power/enlist/commission/deploy/carve into `vr1-dc1-region`, naming each `vr1-dc1--NN` (D-134 amdt); the aux-carve + lib-hosts octet/MAC map already cover every host.** + **NEXT (NetBox, do not miss -- operator-flagged 2026-08-07): record this session's new IPAM objects + into `office1-netbox` (the live VR1 apex, DOCFIX-195) -- the dc0 `.7` (10.12.8.7/10.12.4.7), dc1 + `.6` region VM (10.12.68.6/10.12.64.6) + the new `vr1-dc1-region`, dc1 `.7` when live + (10.12.68.7/10.12.64.7), the D-134 utility-band `.4-.9` assignments, and the dc0 renames. Full + enumeration: changelog-20260807 Item 11. Load via `netbox/*.py --commit` (dry-run + fidelity-check).** F-CV1: designate _admin backend DOWN -- **RESOLVED 2026-08-06 (BUNDLEFIX-056, operator-approved fix EXECUTED + VERIFIED).** Root cause (governing = D-052 + generic binding rule + the D-020 amendment's ruled .62 triple, NOT D-141): designate's bundle bindings OMITTED public + internal, diff --git a/docs/changelog-20260807-dc0-tailscale-provisioning.md b/docs/changelog-20260807-dc0-tailscale-provisioning.md index 96f8751..eafdde6 100644 --- a/docs/changelog-20260807-dc0-tailscale-provisioning.md +++ b/docs/changelog-20260807-dc0-tailscale-provisioning.md @@ -282,6 +282,32 @@ REVERT: `maas logout vr1-dc1-region` (drops the profile); kill the tunnel PID on voffice1. +## Item 11 -- NetBox-PENDING: new IPAM objects this session (record into office1-netbox, the live apex) + +`office1-netbox` (10.10.1.10) is the LIVE VR1 IPAM apex and takes all NetBox writes during VR1 +(DOCFIX-195; only the write-back to `netbox.baldurkeep.com` is deferred to end-of-deployment). This +session created/changed IPAM facts NOT yet reflected in office1-netbox -- enumerated here so the +next session records them (and nothing is lost by the end-of-deployment write-back). Load via the +netbox tooling (`netbox/*.py --commit`, dry-run first, fidelity-check after), NEVER against the apex +directly if a guard applies: + +- **dc0 utility `.7`** -- `vr1-dc0-tailscale-01` ip-addresses: metal-admin **10.12.8.7**, + provider-public **10.12.4.7** (Deployed; the Tailscale subnet router). +- **dc1 utility `.6`** -- `vr1-dc1-maas-01` ip-addresses: metal-admin **10.12.68.6**, + provider-public **10.12.64.6** (Deployed; runs the NEW `vr1-dc1-region` MAAS region+rack). +- **dc1 utility `.7`** -- `vr1-dc1-tailscale-01` PLANNED: metal-admin **10.12.68.7**, + provider-public **10.12.64.7** (not yet deployed -- rebuilt into vr1-dc1-region later; record when live). +- **NEW MAAS region `vr1-dc1-region`** on the `.6` (`10.12.68.6:5240`) -- if office1-netbox models + per-DC regions/controllers, add it (dc0's region is `vr1-dc0-region` on `10.12.8.6`). +- **D-134 utility octet band `.4-.9` now PARTLY ASSIGNED** (were RESERVED): `.4` artifact + (mirror/cache), `.5` Juju controller, `.6` MAAS region, `.7` Tailscale -- both DCs. Reflect the + assignments against each DC's metal-admin + provider-public prefixes. +- **Device renames** (dc0-region, cosmetic to NetBox if it tracks by name): `known-marten`-> + `vr1-dc0-tailscale-01`, `subtle-grouse`->`vr1-dc0-juju-01`. + +This item is the FIRST SURFACE for the NetBox-pending list; it is also flagged in the next-session +NEXT (CURRENT-STATE + ledger). No live NetBox change made this session. + ## Where the dc1-region workstream stands (handoff) DONE: region VM bootstrapped (Items 7-8) + MAAS LIVE (Item 9) + profile registered (Item 10). REMAINING, diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 536a3dc..6f35fe6 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -293,4 +293,5 @@ - dc1 RULED "No migration. Build region on DC1 correctly." + "Rebuild fresh into dc1-region"; then BUILT it: `.6` (`vr1-dc1-maas-01`) power->recommission->carve (10.12.68.6/10.12.64.6, `--profile admin`)->deploy jammy; **vr1-dc1-region MAAS LIVE** (maas 3.7.2 + postgresql 16.14; the shared vr1-office1-svc key is ON VCLOUD `~/vr1-office1-creds/office1_svc_ed25519`; reached the .6 from vcloud; snap egress via snapd proxy; operator-authorised credential one-shot, creds 0600 on the .6, never in context; `10.12.68.6:5240/MAAS/`->301). PROFILE registered+verified (voffice1 tunnel -L 5243; rack vr1-dc1-maas-01, 0 machines). - OWNED: nearly read "powered off" as "not enlisted" (measured first); advisor caught the unverified provider-public leg + the missing bookend; a false-negative `curl -x` 400 vs snap-egress-works (tested definitively); `run-logged.sh` NOT opened (O3, 3rd consecutive). - OWED: consolidate the .6 MAAS creds to `~/vr1-dc1-creds/` (SEC-020); RE-OPEN the voffice1:5243 tunnel after any reboot before `maas vr1-dc1-region ...`. -- NEXT (dc1, `--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01`, tunnel up): `dc-region-topology.sh apply` (6-plane) -> `maas-region-power-key.sh` (.6 snap) + `dc-plane-ipam.sh` + DHCP + jammy image sync -> import office1_svc pubkey -> REBUILD 9 nodes+juju+.7 fresh in (delete from Office1 admin -> enlist/commission/deploy/carve, name vr1-dc1--NN). Separately dc0 Step 3.3 on a TAGGED key + Headscale. Status ONLY in CURRENT-STATE.md. +- NEXT (dc1, `--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01`, tunnel up): `dc-region-topology.sh apply` (6-plane) -> `maas-region-power-key.sh` (.6 snap) + `dc-plane-ipam.sh` + DHCP + jammy image sync -> import office1_svc pubkey -> REBUILD 9 nodes+juju+.7 fresh in (delete from Office1 admin -> enlist/commission/deploy/carve, name vr1-dc1--NN). Separately dc0 Step 3.3 on a TAGGED key + Headscale. +- NEXT (NetBox, operator-flagged -- do not miss): record this session's new IPAM objects into `office1-netbox` (live apex, DOCFIX-195) -- dc0 .7 + dc1 .6 region VM + new vr1-dc1-region + dc1 .7 (when live) + D-134 utility `.4-.9` assignments + dc0 renames. Enumerated: changelog-20260807 Item 11. Status ONLY in CURRENT-STATE.md.