diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index e0c7c9e..fcfd8af 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2013,6 +2013,23 @@ at `life: dead`** -- that moved it BACK to `dying` and re-armed the undertaker loop. It did not help and it changed state. Both are now written into Path M as explicit prohibitions. + **>>> PHASE-02 COMPLETE (vault active, root CA issued); CERT CASCADE MOSTLY SETTLED; ONE REAL + FINDING: ovn-central x3 NOT GETTING A SERVER CERT. <<<** (2026-08-03.) After operator-run + init/unseal/authorize/generate-root-ca, vault/0 is **active "Unit is ready" (active: true)** + and the cascade ran: **25 units active, ZERO error**. `neutron-api-plugin-ovn`, `ovn-chassis` + and `ovn-chassis-octavia` all went active on their certs. **ovn-central/0,1,2 remain `waiting` + "'certificates' awaiting server certificate data" (~15 min).** MEASURED, not assumed: + the container holds BOTH addresses (eth0 10.12.8.185 metal-admin, eth1 10.12.12.122 + metal-internal); network-get resolves both cert bindings; ovn-central PUBLISHED a valid request + (`sans: ["10.12.12.122","10.12.8.185"]`, a `certificate_name`); and vault published back `ca` + + `client.cert` + `client.key` **but NO per-unit server cert** -- which is exactly what + ovn-central is waiting on. The benign `Skipping ... internal/admin/public space, no local + address found` warnings are NOT the cause (those endpoint spaces are unused; the real request + carries the right SANs). So vault CAN sign (its other consumers are active) but has not produced + ovn-central's SERVER cert. LOGGED, awaiting operator direction on remedy (nudge vault to + reprocess / investigate the server-cert request handshake). Expected-tail blocked units + unchanged (ceph-rbd-mirror cross-DC, designate Stage 7, octavia awaiting-configure); nova-compute + "services not running" appeared and self-cleared (transient). **>>> PRE-VAULT-INIT END STATE REACHED; VAULT PREFLIGHT PASSES `PROCEED` 2026-08-03. <<<** After the stall fix, the model converged: `scripts/phase-02-vault-preflight.sh vr1-dc0` (staged + sha256-verified on the rack, `90910dfb`) reports **PROCEED** -- mysql cluster 3/3