diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index b8bf159..81032c7 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -63,10 +63,19 @@ `docs/audit/d125-egress-gate-20260720{,-matrix}.txt`. One earlier run failed ICMP-to-internet on the same path and is recorded UNEXPLAINED in the session changelog (start there if a DC edge shows first-boot egress - failure). REMAINING: edge re-address over REST - (LAN 10.12.4.1/22, WAN static on 172.30.2.0/24) + D-129 plugins, MAAS - reach + `TF_VAR_maas_api_key` + region-side metal-admin DHCP naming - this rack primary_rack (step D), netem (E). + failure). **Edge ADDRESSED 2026-07-20** via the NEW operator-ruled + `opnsense-set-interface-v4` pair (D-113 amendment re-measured and still + true on 26.7 -- base-iface addressing is not REST-covered): WAN + `172.30.2.2/24` + default gw `172.30.2.1` (was dhcp, which could never + work on a /24 with no DHCP server), LAN `192.168.1.1/24` -> + `10.12.4.1/22` (ruled provider-public gateway). Verified on the kernel; + **the edge itself egresses to 1.1.1.1 at 0% loss**, and the API answers + at the new LAN address. Interim bootstrap address removed; virbr5 now + carries only the ruled `10.12.4.2/22`. REMAINING: D-129 edge plugin + profile on 26.7 (`opnsense-plugins.sh apply vr1-edge`, operator-gated + firmware mutation) + the qga channel question; then MAAS reach + + `TF_VAR_maas_api_key` + region-side metal-admin DHCP naming this rack + primary_rack (step D), and netem (step E). - The grounding audit is COMPLETE and EXITED (2026-07-19): Phases 1-6 all closed (charter `148dcef`; rulings `docs/audit/ga-rulings.md`; the Phase-5 sweep ran as six operator-gated batches in one session; exit @@ -253,7 +262,7 @@ | G7 | New captured plan == the expected triple recorded in section 5 | [V] re-plan to a capture file after G5+G6 | session | CLOSED 2026-07-19: capture `docs/audit/outer-plan-20260719-postG6.txt` = 6/0/6, equals section 5 exactly | | G8 | Same-session pre-apply re-verify: 6 planes still empty | [V] run in the SAME session as the apply | session | CLOSED 2026-07-19: verified in the apply session itself (all six 0 leases; only office1 nets attached) immediately before step A | | G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | CLOSED 2026-07-19: G8 same-session planes check passed (6x 0 leases, 0 attachments); saved plan == 6/0/6 applied in the logged dc0-deploy window; convergence re-plan = no differences; vvr1-dc0 running, prior guests untouched | -| G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`). REMAINING: edge REST config + D-129 plugins, MAAS reach + key + region-side metal-admin DHCP (step D), netem (step E) | +| G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`), and the edge itself now egresses 0% loss after the v4 addressing. REMAINING: D-129 plugin profile on 26.7, MAAS reach + key + region-side metal-admin DHCP (step D), netem (step E) | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator | HELD (`docs/dc0-deploy-readiness.md:100-103`) | | G13 | D-129 residuals | [R] operator-gated live plugin install on the edge; qga channel retrofit at next scheduled edge restart; 4 sub-decisions (section 8) | operator | OPEN / PARTIALLY RULED (`docs/design-decisions.md:4017`) | diff --git a/docs/changelog-20260719-dc0-deploy-stepB.md b/docs/changelog-20260719-dc0-deploy-stepB.md index 69203cc..9003979 100644 --- a/docs/changelog-20260719-dc0-deploy-stepB.md +++ b/docs/changelog-20260719-dc0-deploy-stepB.md @@ -355,6 +355,55 @@ addresses were removed; the only residue is `/tmp/noble.img` on the rack (kept deliberately: it is the base for any future throwaway probe). +## 11. NEW TOOLING + edge re-addressed: opnsense-set-interface-v4 pair (53/53) + +- **RULING RECORD (GA-R5), 2026-07-20.** Question as presented: base-iface + IPv4 is not REST-covered on 26.7 (measured); how should LAN 10.12.4.1/22 + and WAN 172.30.2.2/24 + gw 172.30.2.1 be set -- build the v4 setter pair + / console menu now / console now + build at stage close? Operator answer, + exact utterance (option selected): "Build the v4 setter pair + (Recommended)". Classification: OPS tooling under the existing D-113 + amendment; no new D-number (GA-R3). +- **D-113 AMENDMENT RE-MEASURED ON 26.7** (feeds the item-8 review): the + amendment was measured on 26.1 only. On this 26.7 edge: + `interfaces/settings/get` returns ONLY global offload flags, while + `interfaces/overview/list` and `interfaces/lan/get` both return 404 + "Endpoint not found". Base-interface addressing is still legacy + `/interfaces.php`. The amendment now holds on TWO majors, measured. +- SHIPPED: `scripts/opnsense-set-iface-v4.php` + + `scripts/opnsense-set-interface-v4.sh` + `tests/opnsense-set-interface-v4/` + (53/53 PASS first run; gauntlet 70 -> **71 harnesses ALL GREEN**; + repo-lint 0 fail). Mirrors the proven v6 sibling exactly -- vendor Config + singleton (never a config.xml push), dry-by-default, interface-count + guard, fresh read-back verify, `sh -s` for the tcsh trap, KERNEL as + ground truth. Two deliberate improvements over the v6 sibling: + (i) the GATEWAY half (creates/updates at most ONE `gateway_item`, + count-guarded exactly like the interface count, opt-in via a 5th arg); + (ii) the interface's DEVICE is MEASURED from the edge's own config + instead of the v6 sibling's hardcoded `lan->vtnet0 / wan->vtnet1` sed -- + that mapping is per-edge and hardcoding it is a hard-rule-2 violation + waiting to happen. Harness pins BOTH (test 12 fails if the hardcode + returns). **LOGGED FINDING:** backport the measured-device fix to the v6 + sibling at stage close. +- APPLIED to vr1-dc0-opnsense, WAN first per the script's own ordering + warning (re-addressing the LAN drops the session you arrived on): + - WAN: dhcp -> `172.30.2.2/24` + `WAN_GW` = 172.30.2.1 default. Note the + edge had shipped with WAN on **dhcp**, which could NEVER have worked -- + the uplink /24 has no DHCP server (same fact that broke probe run 1). + Verified on the kernel: `inet 172.30.2.2`, `default 172.30.2.1 UGS + vtnet1`, and **the EDGE ITSELF pings 1.1.1.1 at 0% loss** -- the D-125 + chain now proven through the real OPNsense edge, not just a probe. + - LAN: `192.168.1.1/24` -> `10.12.4.1/22` (the D-115/lib-net ruled + provider-public gateway). Session dropped as designed; edge verified at + the new address from the rack: `inet 10.12.4.1 netmask 0xfffffc00`. + - Post-move reconciliation at the NEW address: API `GET + core/firmware/status` -> 200 `CORE_ABI 26.7`; edge egress still 0% loss. +- CLEANUP: the interim `192.168.1.2/24` on the rack's provider-public + bridge is REMOVED (virbr5 now carries only the ruled `10.12.4.2/22`). +- **Revert:** re-run the setter with the previous values + (`--commit lan 192.168.1.1 24`, `--commit wan ...`); the + gateway item is named `WAN_GW` and is the only one this tool created. + ## 8. STAGE-CLOSE QUEUE ITEM (operator directive, 2026-07-20): OPNsense 26.7 review - Operator directive (verbatim intent): at the proper time/place, review the