diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 9480faa..36602fe 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -269,10 +269,14 @@ serving archive + UCA 200), while its dormant fallback debmirror is dormant only ACCIDENTALLY (timer `enabled` with EMPTY next-elapse because the unit sits in failed/Result=signal, so a `reset-failed` re-arms a 330G->949G pull; the ruling is not - enforced by anything). STILL OPEN: the node-side half of bullet 5 -- nodes are READY - (powered off) by the READY-handoff ruling, so a node-side probe needs either a gated - rescue-boot check or, per GA-R6 E3, its own gate row targeted at Stage 5 first boot. That - is an operator decision; there is NO conditional close. + enforced by anything). **The node-side half of bullet 5 is SPLIT OUT to new gate row G17 + by operator ruling 2026-07-27 (GA-R5, utterance quoted in the G17 row) -- NOT closed + conditionally, which GA-R6 E3 forbids.** Nodes are powered off in `Ready` by the + READY-handoff ruling, so no node-side probe can run inside Stage 4; G17 carries it to + Stage 5 first boot. What REMAINS in Stage 4 for bullet 5 is the RACK-side half only: the + artifact source answers on its own address with an attested-current sync. dc1's proxy + already satisfies that (PASS). dc0 does NOT yet -- its sync must be re-run and read OK + before bullet 5 can be marked met. - **Bullet 6 "NTP from the DC's own OPNsense edge working" is STALE and unsatisfiable as written** -- SUPERSEDED by D-129(iv), RULED 2026-07-21 ("Keep MAAS hierarchy (Recommended)", no NTP role on the edge). The bullet survives in FOUR surfaces @@ -741,6 +745,7 @@ | G14 | 12 OPEN SEC rows (SEC-001, -003..-008, SEC-012, -013, -014, plus SEC-015 + SEC-016 opened 2026-07-23 for dc1 credentials; SEC-010/-011 CLOSED) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012/-016 carry the same libvirt-group SCOPE hardening question; SEC-016 also a snap-refresh re-assert (queued to DC standup DoD) | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3). **COUNT RECONCILED 2026-07-27: 21 open**, measured `bash scripts/ledger-scan.sh` (SEC-001, -003..-008, -012..-025; SEC-024 opened 2026-07-26, SEC-025 opened 2026-07-27 for the consolidated NetBox GUI admin password). Earlier figures in this cell (19 at 2026-07-25) are history. The row's own title text ("12 OPEN SEC rows") is the 2026-07-23 figure and is SUPERSEDED by this cell -- the gate is the ledger, not the count. Since 07-23: SEC-017 (caveman supply-chain), -018/-019 (per-DC MAAS API keys), -020 (MAAS region superuser passwords), and **-021/-022/-023 opened 2026-07-25** from the D-137 credential research -- dc0 custody defects (a consolidated credential ABSENT from its recorded location + per-DC power-key divergence), UNAUDITED shadow `*-creds/` stores on voffice1 (a scope gap in `creds-audit` itself, which has no remote capability), and sprawl-glob blind spots incl. a PREDICTED Stage-5 `~/admin-openrc` exposure. All three are logged-not-actioned (hard rule 1); remediation is coupled to the unruled D-137 forks. Creation-point research capture: `docs/audit/creds-creation-points-20260725.md` -- 55 MINT sites inventoried, and **12 declared secrets have NO mint command anywhere in the repo** (`ssh-keygen` returns ZERO hits repo-wide; six SSH keypairs + the OPNsense root password/hash are operator-terminal mints recorded only in a manifest comment, i.e. NOT reproducible if the jumphost is rebuilt -- a Roosevelt-transfer defect, not just hygiene). It also names three credential DIRECTORIES outside the SEC-009 `*-creds/` convention and outside `creds-audit` entirely: `~/vault-init/` (Vault 5 unseal shares + root token), `~/octavia-pki/` (8 PKI artifacts incl. CA private keys), `~/tenant-/`; plus `overlays/octavia-pki.yaml`, which lands a CA key + plaintext passphrase INSIDE the repo clone (gitignored -- and SEC-004 says the repo is still PUBLIC) | | G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 items 2-3 RULED 2026-07-21; item 1: plan DRAFTED + Q1/Q2-structure/Q3 ALL RULED 2026-07-23 (three amendments, utterances quoted; monthly-review lines delivered). Sole D-068 remainder: Q2 path selection at Roosevelt Vault design time -- G15 is otherwise decision-complete | | G16 | office1 edge `channels = []` state reconcile (the D-129 module-schema residual) | [R] operator rules the mechanism; then [V] the converged re-plan capture | operator + session | CLOSED 2026-07-21: RULED "State surgery (Recommended)" (GA-R5, session changelog item 16); executed per G6 precedent -- channels null -> [] injected, serial 29 -> 30, backup kept, guests untouched (office1-opnsense Id 2 running throughout); convergence = ZERO DIFF (`docs/audit/outer-plan-20260721-postG16-converged.txt`); section 5 re-recorded | +| G17 | **Per-DC artifact source reachable FROM A NODE** -- the node-side half of Stage 4 DoD bullet 5, split out of Stage 4 by operator ruling rather than closed conditionally | [V] a NAMED executable check run from a node that has actually booted an OS on its real NICs, per DC, each capturing: dc0 -> `curl -sI http://10.12.8.4/` returns 200 from the node (the D-135 item-1 full mirror); dc1 -> the node resolves and fetches through the apt proxy at `10.12.68.4:3142` (the D-135-AMENDED ruled artifact path -- dc1 has NO node-facing mirror, so checking it as one would fail by design). The natural trigger is Stage 5 first boot, when Juju provisions the nodes and they run apt for real; a gated MAAS rescue-boot is the alternative if it must be answered sooner | session (each boot operator-approved) | **OPEN 2026-07-27.** WHY THIS EXISTS: the DoD bullet reads "per-DC mirror reachable from nodes", but the READY-handoff ruling (2026-07-23, DOCFIX-200) leaves all 18 nodes powered off in `Ready` -- MAAS-deploy is SKIPPED and Juju provisions at Stage 5 -- so no node-side probe can run inside Stage 4 at all. GA-R6 E3 forbids a conditional close, so the remainder splits here. RULING (GA-R5). Question as presented 2026-07-27: "The node-side half of bullet 5. Nodes are powered off by the READY-handoff ruling, so no node-side probe can run as things stand. Either a gated rescue-boot check on one node per DC now (closes it inside Stage 4), or split it into its own gate row targeted at Stage 5 first boot (GA-R6 E3 explicitly permits this; a conditional close is not permitted)." Operator answer, exact utterance: **"split it into its own gate row"**. SCOPE NOTE: what stays in Stage 4 is the RACK-side half -- the artifact source answers on its own address with an attested-current sync -- which is what `dc-mirror.sh check` / `dc-cache-proxy.sh check` verify (both fixed this session to stop false-greening; capture `docs/audit/stage4-mirror-gate-20260727.txt`). G17 is NOT a Stage-5 precondition and must not be conflated with one: Stage 5's own bootstrap needs OPEN edge egress for the juju agent stream + snaps (D-135 items 2-3 unbuilt), which is a different path from the apt artifact source this gate covers. | ## 7. Version pins (measured; the authority for every pin) diff --git a/docs/changelog-20260727-creds-consolidation.md b/docs/changelog-20260727-creds-consolidation.md index a47b9fd..634342c 100644 --- a/docs/changelog-20260727-creds-consolidation.md +++ b/docs/changelog-20260727-creds-consolidation.md @@ -227,6 +227,54 @@ changes -- the check returns to passing unconditionally on last-sync. No live state was altered by this item; both racks were read only. +## 8. G17 opened by ruling; DoD bullets 5 and 6 repaired (DOCFIX-204) + +**RULING (GA-R5), 2026-07-27.** Question as presented: "The node-side half of bullet 5. Nodes +are powered off by the READY-handoff ruling, so no node-side probe can run as things stand. +Either a gated rescue-boot check on one node per DC now (closes it inside Stage 4), or split it +into its own gate row targeted at Stage 5 first boot (GA-R6 E3 explicitly permits this; a +conditional close is not permitted)." Operator answer, exact utterance: **"split it into its +own gate row"**. Recorded in the **G17** row of `docs/CURRENT-STATE.md`, which is the authority; +committed and pushed before any dependent work (GA-R5). + +**G17 -- "Per-DC artifact source reachable FROM A NODE"**, [V], OPEN. Per DC: dc0 -> `curl -sI +http://10.12.8.4/` returns 200 from a booted node; dc1 -> apt fetches through the proxy at +`10.12.68.4:3142`, because dc1's ruled artifact path is the CACHING PROXY and it has no +node-facing mirror (D-135 amendment) -- checking it as one fails by design. Natural trigger is +Stage 5 first boot. The row states explicitly that G17 is NOT a Stage-5 precondition and must +not be conflated with one: Stage 5's bootstrap needs OPEN edge egress for the juju agent stream +and snaps (D-135 items 2-3 unbuilt), which is a different path from the apt artifact source. + +What REMAINS in Stage 4 for bullet 5 is the rack-side half -- the source answers on its own +address with an attested-current sync. dc1's proxy already PASSES; dc0 does not yet, pending +the sync re-run (item 7). + +**DOCFIX-204 -- bullet 6 was unsatisfiable, and its stale text had spread to four surfaces.** +"NTP from the DC's own OPNsense edge working" is SUPERSEDED by D-129(iv) (RULED 2026-07-21, +"Keep MAAS hierarchy (Recommended)", no NTP role on the edge). The DoD asked you to confirm the +edge is the time source, which the ruling had already refused -- so the bullet could never be +met by a correctly-built DC. Repaired in: + +- `runbooks/dc-dc-phase3-maas-enlist-deploy.md` DoD -- bullet 6 STRUCK with its supersession + cited; bullet 5 rewritten per-DC with the split recorded. +- the same runbook's **Step 7, rewritten**. It had THREE defects, each recorded rather than + quietly patched because the old text is the kind that gets followed: it still branched on + gap #5 ("if the mirror does not exist yet, STOP") which D-135 resolved; it applied one mirror + check to both DCs, which fails on dc1 by design; and both its checks said "from a deployed + node", which the READY-handoff ruling makes impossible in this stage. Now it invokes the two + site checkers (with the hard-rule-2 note to take rack transit IPs from `lib-hosts.sh`, never + memory) and carries the MAAS-hierarchy time check as a Stage-5/G17 observation. +- `docs/dc-dc-deployment-workflow.md:206` -- the Gate cell also still said "Nodes deployed", + contradicting DOCFIX-200's READY handoff. Both fixed. +- `docs/dc-dc-buildout-design.md:120` -- corrected with the supersession noted inline. +- `runbooks/dc-dc-phase4-juju-bundle-per-dc.md:26` -- prerequisites said "nodes Deployed", + which is precisely the expectation DOCFIX-200 removed to stop Stage 5 breaking; plus a new + block making this stage the OWNER of G17's captures, with the warning that first boot is the + observation window and missing it forces a deliberate rescue-boot. + +Revert: `git revert` this commit's doc/runbook changes; the G17 row and the DOCFIX-204 edits +are text-only, and no live state was touched. + --- ## Findings LOGGED, not actioned (hard rule 1) diff --git a/docs/dc-dc-buildout-design.md b/docs/dc-dc-buildout-design.md index c9175a6..57d0fb8 100644 --- a/docs/dc-dc-buildout-design.md +++ b/docs/dc-dc-buildout-design.md @@ -117,7 +117,12 @@ Build: per DC, MAAS commissions and deploys the node VMs; provider NIC left RAW (br-ex discipline, D-100); the VLAN-103 metal-internal bridge stack pre-built by MAAS. Gate: nodes deployed; the six planes present per node with correct fabrics/VLANs; provider -NIC raw; PXE (v4) working; per-DC mirror reachable from nodes; NTP from edge working. +NIC raw; PXE (v4) working; per-DC artifact source reachable. (DOCFIX-204, 2026-07-27: +this line formerly read "per-DC mirror reachable from nodes; NTP from edge working". +The node-side half is gate G17 -- powered-off nodes cannot be probed in Stage 4 under +the READY-handoff ruling -- and the edge-NTP clause is SUPERSEDED by D-129(iv), which +keeps the MAAS hierarchy as time authority. docs/CURRENT-STATE.md is the status +authority for both.) Owns: D-103, D-100 (br-ex), D-107 (mirror + NTP). ### Phase 4 -- Juju controller + OpenStack bundle (per DC) diff --git a/docs/dc-dc-deployment-workflow.md b/docs/dc-dc-deployment-workflow.md index dcf2ad5..a7b4a18 100644 --- a/docs/dc-dc-deployment-workflow.md +++ b/docs/dc-dc-deployment-workflow.md @@ -203,7 +203,7 @@ |---|---| | **Goal** | Bring the discovered node VMs to a deployed OS, ready for Juju. | | **Build** | Per DC: MAAS commissions + deploys the node VMs; provider NIC left RAW (br-ex discipline, D-100); VLAN-103 metal-internal bridge stack pre-built by MAAS. | -| **Gate** | Nodes deployed; six planes present per node with correct fabrics/VLANs; provider NIC raw; PXE (v4) working; per-DC mirror reachable; NTP from edge working. | +| **Gate** | Nodes READY + carved + tagged (NOT "deployed" -- MAAS-deploy is SKIPPED per the 2026-07-23 READY-handoff ruling / DOCFIX-200; Juju provisions at Stage 5); six planes present per node with correct fabrics/VLANs; provider NIC raw; PXE (v4) working; per-DC artifact source answering on its own address with an attested-current sync (dc0 = D-135 item-1 mirror, dc1 = the D-135-AMENDED apt caching proxy -- the two DCs differ BY RULING). Node-side reachability and the node time source are gate **G17**, split out 2026-07-27 (operator ruling, GA-R5) because powered-off nodes cannot be probed in this stage. `NTP from edge` was STRUCK -- superseded by D-129(iv) 2026-07-21, which keeps the MAAS hierarchy as time authority and gives the edge no NTP role (DOCFIX-204). | | **Owns** | D-103, D-100 (br-ex), D-107 (mirror + NTP). | | **Reuse vs new** | PARTIAL reuse. `runbooks/phase-00-teardown-maas-reset.md` carries the MAAS commission/deploy + br-ex discipline this repo already validated for a single rack; the per-DC multi-rack registration is new, the deploy mechanics are precedent. | | **Authoring status** | **Runbook WRITTEN 2026-07-09: `runbooks/dc-dc-phase3-maas-enlist-deploy.md`.** Adapts `phase-00-teardown-maas-reset.md`'s validated single-rack commission/deploy/carve mechanics per DC, run once per `$DC` (dc1/dc2). Requires `lib_net_select_dc "$DC"` first (DOCFIX-151); explicitly documents that `lib_hosts_select_dc "$DC"` is EXPECTED to fail for both DCs until this stage's own real host enrollment populates `lib-hosts.sh` -- a deliberate chicken-and-egg, not a bug. Surfaces 7 real gaps in a named section (no OpenTofu module stands up a per-DC MAAS rack controller VM itself; `reenroll-hosts.sh`/`carve-host-interfaces.sh`/`phase-00-maas-standup.sh` are not `$DC`-parameterized; node count/sizing now RULED (D-121/R-3 = 9/DC), so that sub-gap is closed; DC2 additionally blocked at the selector layer; no identified owner for the per-DC artifact mirror; MAAS status for VM-host-discovered domains unconfirmed; `HOST_TAG`/fabric-name literals are DC0-specific). NOT YET EXECUTED. | diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 15a9e65..5c349d0 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -45,7 +45,11 @@ exposure the copy CREATES, not the gap it closed. (SEC-024, 2026-07-26, was the previous addition.) The SEC register of record is `docs/security-ledger.md`; row-level dispositions live THERE only (GA-R4/F3) -- this block carries pointer + count, never rows. -- **Next-free numbers:** D = **138**, DOCFIX = **204**, BUNDLEFIX = **053**. +- **Next-free numbers:** D = **138**, DOCFIX = **205** (204 assigned 2026-07-27 -- the stale + "NTP from edge" Stage-4 gate bullet, superseded by D-129(iv), repaired across four surfaces), + BUNDLEFIX = **053**. +- **Gates:** G17 OPENED 2026-07-27 by operator ruling (node-side artifact reachability split out + of Stage 4; the gate table in `docs/CURRENT-STATE.md` is the authority). - **Standing numbering rule:** never write an identifier-shaped token (D-/DOCFIX-/BUNDLEFIX-NNN) ABOVE the real high-water mark anywhere in `docs/` or `runbooks/` prose -- historically a decoy token in prose inflated the next-free counter (hardened in DOCFIX-174). diff --git a/runbooks/dc-dc-phase3-maas-enlist-deploy.md b/runbooks/dc-dc-phase3-maas-enlist-deploy.md index f547034..e768823 100644 --- a/runbooks/dc-dc-phase3-maas-enlist-deploy.md +++ b/runbooks/dc-dc-phase3-maas-enlist-deploy.md @@ -395,31 +395,55 @@ --- -## Step 7 -- Per-DC mirror + edge NTP verify (READ-ONLY) +## Step 7 -- Per-DC artifact source + time authority verify (READ-ONLY) -Per gap #5: CONFIRM the per-DC artifact mirror this D-107 gate item -requires actually exists and where, before running a reachability check -against it. If it does not exist yet, STOP this sub-check, log the gap -(it blocks the "airgap nodes pull only from an in-DC mirror" posture -D-107 requires), and do not fabricate a mirror endpoint to check against. +**REWRITTEN 2026-07-27 (DOCFIX-204).** As originally written this step was +unrunnable and, in one half, contradicted a later ruling. Both defects are +recorded here rather than quietly patched, because the step's old text is the +kind that gets followed: -**CHECK (once the real mirror address is known) -- reachable from a deployed node** +1. Gap #5 (no owner for the per-DC artifact mirror) is **RESOLVED** -- D-135 + built it, so the "if it does not exist yet, STOP" branch is history. But the + two DCs deliberately have **DIFFERENT** artifact paths (D-135 AMENDMENT + 2026-07-24), and a single mirror check applied to both fails on dc1 by design. +2. The edge-NTP half is **SUPERSEDED by D-129(iv)** (RULED 2026-07-21, "Keep MAAS + hierarchy (Recommended)" -- no NTP role on the edge). It asked you to confirm + the edge is the time source, which the ruling explicitly refused. +3. Both checks said "from a deployed node". Under the READY-handoff ruling + (DOCFIX-200) nodes are never deployed in this stage -- they stay powered off + in `Ready` and Juju provisions them at Stage 5. The node-side half is + therefore tracked at gate **G17**, not here. + +**CHECK -- the artifact source answers on its own address, with an ATTESTED-CURRENT +sync.** Run the site's own checker; do not hand-roll a curl. Both were fixed on +2026-07-27 to assert on sync status instead of merely printing it -- a PASS from +before that date does not mean what it appears to. + ```bash -# from the deployed node, or via its MAAS-reported address: -curl -sI http:/// | head -1 +# dc0 -- D-135 item 1: a full debmirror served by nginx on the D-134 utility .4 +ssh -i ~/vr1-dc0-creds/vr1-dc0_svc_ed25519 -J voffice1 jessea123@ \ + 'sudo bash -s' -- check dc0 < scripts/dc-mirror.sh + +# dc1 -- D-135 AMENDMENT: the ruled path is an apt CACHING PROXY, not a mirror. +# dc1's debmirror is PAUSED and dormant as the fallback; checking it as a mirror +# is expected to FAIL and is NOT this gate. +ssh -i ~/vr1-dc1-creds/vr1-dc1_svc_ed25519 -J voffice1 jessea123@ \ + 'sudo bash -s' -- check dc1 < scripts/dc-cache-proxy.sh ``` +Take the rack transit IP from `scripts/lib-hosts.sh` (`VIRSH_POWER_ADDRESS`), never +from memory -- hard rule 2. -**CHECK -- NTP from `$DC`'s own OPNsense edge (D-107: nodes get chrony from -their DC edge, which syncs upstream; Office1 is NOT in this path)** +**CHECK -- time authority is the MAAS hierarchy (D-129(iv), NOT the edge).** MAAS +serves NTP to the nodes it manages; the edge carries no NTP role. This is a +node-side observation, so it runs when a node has actually booted an OS -- i.e. +at Stage 5 first boot, alongside G17, not in this stage: ```bash +# on a booted node (Stage 5), confirm the source is the MAAS hierarchy: chronyc sources -# or, if chrony is not yet configured on a freshly-deployed node: timedatectl show -p NTP -p NTPSynchronized ``` -Confirm the source is `$DC`'s own edge address (measured, not assumed) -- -not Office1, not a public pool directly (D-107: the edge is the only -component with controlled internet egress; nodes are airgapped at the node -boundary). +Confirm the source is the MAAS-served address (measured, not assumed) -- NOT the +DC edge, which D-129(iv) removed from this path. --- @@ -477,16 +501,33 @@ - Provider NIC raw (Step 5 GATE: `enp1s0`/equivalent carries no config beyond what MAAS's own br-ex build applies). - PXE (v4) working (Step 6). -- Per-DC mirror reachable from nodes (Step 7 -- CONDITIONAL on gap #5 being - resolved; if the mirror does not exist yet, this GATE bullet is honestly - NOT MET and Stage 4 is not complete for `$DC`, full stop, regardless of - how clean the MAAS-side steps came out). -- NTP from the DC's own OPNsense edge working (Step 7). +- Per-DC artifact source reachable ON ITS OWN ADDRESS, with an ATTESTED-CURRENT + sync (Step 7). **SPLIT 2026-07-27 (operator ruling, GA-R5 -- recorded in the + G17 gate row of `docs/CURRENT-STATE.md`, which is the authority).** Gap #5 is + resolved -- D-135 built the artifact source per DC -- but the original bullet + said "reachable FROM NODES", and the READY-handoff ruling (DOCFIX-200) leaves + every node powered off in `Ready`, so a node-side probe cannot run in this + stage at all. GA-R6 E3 forbids a conditional close, so the node-side half + moved to its own gate row **G17** (trigger: Stage 5 first boot). What this + bullet now requires, per DC: + - dc0 -- `dc-mirror.sh check dc0` PASS, which as of 2026-07-27 ASSERTS on + `last-sync.status` rather than merely printing it. It previously passed on a + `FAIL` status; do not trust any pre-2026-07-27 PASS for this bullet. + - dc1 -- `dc-cache-proxy.sh check dc1` PASS. dc1's ruled artifact path is the + apt CACHING PROXY, not a mirror (D-135 AMENDMENT 2026-07-24); its debmirror + is paused and dormant as the fallback. Checking dc1 as a mirror fails by + design and is not this bullet. +- ~~NTP from the DC's own OPNsense edge working (Step 7).~~ **STRUCK -- SUPERSEDED + by D-129(iv), RULED 2026-07-21: "Keep MAAS hierarchy (Recommended)", no NTP + role on the edge.** The replacement check is that the node's time source is the + MAAS hierarchy (see Step 7). This bullet was unsatisfiable as written: it + required the edge to be the time source, which the ruling explicitly refused. -All six true, for every node Step 2 discovered for `$DC` -> Stage 4 complete -for that DC. Run the whole runbook again with the other `$DC` value for the -second DC; the two DCs' completions are independent (D-100: no shared -control plane), so one can be done before the other. +All bullets true, for every node Step 2 discovered for `$DC` -> Stage 4 complete +for that DC (with the node-side reachability half tracked separately at G17). +Run the whole runbook again with the other `$DC` value for the second DC; the two +DCs' completions are independent (D-100: no shared control plane), so one can be +done before the other. > **CREDS-CONSOLIDATION CLOSE-OUT (SEC-009 enforcement -- non-negotiable).** Standing up a DC MINTS > secrets on its VMs and on the jumphost -- MAAS API key, per-DC NetBox token (if any), node/edge SSH diff --git a/runbooks/dc-dc-phase4-juju-bundle-per-dc.md b/runbooks/dc-dc-phase4-juju-bundle-per-dc.md index a890b53..00afe4f 100644 --- a/runbooks/dc-dc-phase4-juju-bundle-per-dc.md +++ b/runbooks/dc-dc-phase4-juju-bundle-per-dc.md @@ -22,12 +22,35 @@ **Prerequisites (must be true entering this stage, per DC):** Stage 4 (`runbooks/dc-dc-phase3-maas-enlist-deploy.md`) done for that DC -- nodes -Deployed; six planes present with correct fabrics/VLANs; provider NIC raw; -PXE (v4) working; that DC's own artifact mirror reachable; NTP from that -DC's edge working; `scripts/lib-hosts.sh`'s per-DC host data populated (that +**READY** (NOT Deployed: MAAS-deploy is SKIPPED per the 2026-07-23 READY-handoff +ruling / DOCFIX-200 -- THIS runbook is what provisions them, and expecting +Deployed nodes here is exactly the breakage that ruling prevented); six planes +present with correct fabrics/VLANs; provider NIC raw; PXE (v4) working; that +DC's own artifact source reachable on its own address (dc0 = the D-135 item-1 +mirror, dc1 = the D-135-AMENDED apt caching proxy consumed via +`juju apt-http-proxy` -- the two DCs differ BY RULING, so do not assume a +mirror at dc1); `scripts/lib-hosts.sh`'s per-DC host data populated (that stage's own follow-up delivery) so `lib_hosts_select_dc "$dc"` no longer fails loud for it. +**THIS STAGE OWES GATE G17 (inherited from Stage 4, split out 2026-07-27 by +operator ruling -- see the G17 row in `docs/CURRENT-STATE.md`, the authority).** +Stage 4 could not verify that a NODE reaches its DC's artifact source, or that a +node's time source is the MAAS hierarchy, because under the READY-handoff ruling +its nodes never boot an OS. **First boot in this stage is the first moment either +is observable, so capture both then** -- per DC, from a booted node: + +- dc0: `curl -sI http://10.12.8.4/` returns 200. +- dc1: apt fetches through the proxy at `10.12.68.4:3142` (NOT a mirror -- D-135 + amendment). +- both: `chronyc sources` shows the MAAS-served time source, NOT the DC edge + (D-129(iv) removed the edge from that path). + +Capture the output to a dated file and cite it in the commit that closes G17. If +first boot happens without these captures being taken, the observation window has +passed and G17 needs a deliberate rescue-boot to answer -- so take them the first +time. + !!! Every command block in the referenced `phase-01..08` runbooks that reads `scripts/lib-net.sh` or `scripts/lib-hosts.sh` values (VIP bands, host octets, `KEYSTONE_VIP_DEFAULT`, etc.) MUST be preceded, in THIS stage's