diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 432e286..fcb395d 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2445,10 +2445,18 @@ the operator (neither voffice1's default nor `vr1-dc0_svc` authenticates; NOT fished). Then `site-tailscale.sh install` + browser-login `https://10.12.8.58` closes Step 3.3. **dc1 RULED 2026-08-07 (GA-R5, verbatim "No migration. Build region on DC1 correctly."):** dc1 - `.7` is GATED behind building the dedicated `vr1-dc1-region` on `vr1-dc1-maas-01` (N3; MEASURED: - `vr1-dc1-region` NOT registered, dc1 rack `nmpcq4` + 9 nodes still in the Office1 `admin` region) -- - do NOT enlist dc1 `.7` into the Office1 region. lib-hosts already carries `vr1-dc1-tailscale-01` - (octet 7, MAC `52:54:00:f9:d6:df`) so the aux-carve reuses on dc1 once its region exists. + `.7` is GATED behind building the dedicated `vr1-dc1-region` on `vr1-dc1-maas-01`. MEASURED: + `vr1-dc1-region` NOT registered; dc1's FULL node set is in the Office1 `admin` region -- the 9 + role nodes + juju-01 `Ready` (`big-trout`=control-01 `...d1:01:01` ... `square-ferret`=juju-01 + `...53:12:70`), the region VM `.6` (`normal-piglet` `...ff:5c:02`) and tailscale `.7` + (`tight-flea` `...f9:d6:df`) BOTH `Failed commissioning`. This is the SAME state dc0 was in + pre-migration. **NODE-HANDLING RULED 2026-08-07 (GA-R5, verbatim "Rebuild fresh into + dc1-region"):** build `vr1-dc1-region`, then power/enlist/commission/deploy the 9 nodes + juju + FRESH into it (they carry no workloads, pre-Stage-5) -- NOT the dc0 delete+re-enlist migration. + Region-VM `.6` bootstrap path mined from `changelog-20260730-dc0-region-migration.md` (deploy + via Office1 -> install+init MAAS snap -> import a PER-DC key, fixing F2). NO runbook yet (sweep + F1). lib-hosts carries `vr1-dc1-tailscale-01` (octet 7, MAC `52:54:00:f9:d6:df`); the aux-carve + reuses on dc1 once its region exists. F-CV1: designate _admin backend DOWN -- **RESOLVED 2026-08-06 (BUNDLEFIX-056, operator-approved fix EXECUTED + VERIFIED).** Root cause (governing = D-052 + generic binding rule + the D-020 amendment's ruled .62 triple, NOT D-141): designate's bundle bindings OMITTED public + internal, diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 9ac140a..bd91a19 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -6147,6 +6147,35 @@ addressing scheme). Evidence: this session's phase-03 core-verify thread; MAAS `ipranges` + device interface `mode` captured live, no secrets. +## D-134 -- AMENDMENT (2026-08-07): MAAS HOSTNAME naming convention -- machines carry their vr1---NN name, set after enlistment + +**Status: RULED 2026-08-07** (operator, GA-R5). After a session left the dc0 Tailscale `.7` +VM at its random MAAS name (`known-marten`) and rationalised the skip off the juju +controller's own un-renamed state (a DEVIATION used as precedent), the operator corrected -- +exact utterances: **"You are not following naming conventions."** and, asked to make it +standing, **"Record that as the preferred naming convention going forward."** + +**The convention (per-DC node IDENTITY standard, alongside this decision's octet map):** every +VR1 DC machine's MAAS hostname is SET to its convention name `vr1---NN`, which equals +its libvirt domain name and its `power_id` (`scripts/lib-hosts.sh:26`). MAAS assigns a RANDOM +name that is re-minted on every (re-)enlistment -- which is exactly why the carve/power tooling +resolves machines by pinned BOOT MAC and never by name (`lib-hosts.sh:110-112`) -- but "random +by default" is NOT "leave it random": the role is read off the name in `juju status`, +dashboards and MAAS views, so the standing practice is to rename to convention after +commission/deploy. **Definition-of-done for a DC standup: zero non-`vr1--*` hostnames in +that DC's region** (`maas machines read`). + +**Applied 2026-08-07 (dc0):** `known-marten`->`vr1-dc0-tailscale-01`, +`subtle-grouse`->`vr1-dc0-juju-01`; the 9 role nodes already carried convention names (all 11 +now `vr1-dc0-*`). dc1's nodes (still random-named in the Office1 region) get their `vr1-dc1-*` +names when they are REBUILT FRESH into `vr1-dc1-region` (operator ruling "Rebuild fresh into +dc1-region", 2026-08-07). + +**Roosevelt-delta (the A1 test):** every DC standup names its machines to convention; a +Roosevelt build session greps this before treating a random MAAS name as acceptable. [ARCH], +onto D-134 (the per-DC identity standard) rather than a new number -- naming is the sibling of +the octet map this decision already governs. + ## D-135: ADOPTED (AMENDED 2026-07-24) -- VR1 per-DC artifact mirror realization (D-107 build-out, staged) [ARCH] **Status:** ADOPTED 2026-07-23 (Stage 4, branch dc-dc-stage4-phase3-maas-deploy). Two diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 86815d9..7a2dd2a 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -293,4 +293,5 @@ - TWO JOIN PREREQS remain (off-session): a TAGGED pre-auth key + Headscale autoApprovers/ACL; SSH access via `vr1-office1-svc` (region injects only that key -- operator holds it). - OWNED: nearly read the prior close's "powered off" as "not enlisted" (measured `known-marten` first); the advisor caught the unverified provider-public leg (then measured both legs live) and the missing bookend; `run-logged.sh` NOT opened (O3, 2nd consecutive -- a background agent cannot drive its interactive subshell). - Gates: repo-lint 0 fail (1 legacy warn); gauntlet ALL GREEN 101 (docs-only edits since). Sweep: `docs/audit/queued-findings-20260807-dc0-tailscale-provisioning.txt` (F1-F4 FIRST SURFACE: no per-DC MAAS-region-build runbook; the vr1-office1-svc inject vs SEC-012/016; phase-3 aux-deploy DOCFIX). Body: `docs/changelog-20260807-dc0-tailscale-provisioning.md`. -- NEXT: build `vr1-dc1-region` (no runbook -- F1) for dc1; and once a TAGGED key + Headscale access -> `site-tailscale.sh install` on dc0 .7 -> browser login `https://10.12.8.58` closes Step 3.3. Status ONLY in CURRENT-STATE.md. +- POST-BOOKEND (same session): operator naming correction -> renamed dc0 known-marten->vr1-dc0-tailscale-01 + subtle-grouse->vr1-dc0-juju-01 (all 11 dc0-region names now vr1-dc0-*); recorded the standing convention as **D-134 AMENDMENT 2026-08-07** ("Record that as the preferred naming convention going forward") + lib-hosts comment. dc1 node-handling RULED "Rebuild fresh into dc1-region" (build region, then power/enlist/commission/deploy the 9 nodes+juju FRESH into it -- NOT delete+re-enlist). +- NEXT: **dc1-region workstream** -- author the region-standup runbook (F1; mine `changelog-20260730-dc0-region-migration.md` for the region-VM bootstrap, EXCLUDE migration parts), bootstrap `vr1-dc1-maas-01` (.6, `normal-piglet` Failed-commissioning), init `vr1-dc1-region` with a PER-DC key (fixes F2), then REBUILD the 9 nodes+juju+.7 fresh into it. Separately, dc0 Step 3.3 closes once a TAGGED key + Headscale access -> `site-tailscale.sh install` on dc0 .7 -> browser login `https://10.12.8.58`. Status ONLY in CURRENT-STATE.md. diff --git a/scripts/lib-hosts.sh b/scripts/lib-hosts.sh index 7d28db3..aa8a85d 100644 --- a/scripts/lib-hosts.sh +++ b/scripts/lib-hosts.sh @@ -108,9 +108,13 @@ # host_sysid : resolve the LIVE MAAS system_id by hostname (never # hardcode it). Echoes the system_id, or empty if the host is not enrolled. # VR0 ONLY: VR0 hostnames are stable (hostname == domain name == power_id). -# For VR1 DC nodes the MAAS hostname is a RANDOM name RE-MINTED on every -# (re-)enlistment (measured: the 2026-07-21 pod-delete recovery renamed all 9) -# -- use host_sysid_by_bootmac() there instead. +# For VR1 DC nodes MAAS ASSIGNS a RANDOM name, RE-MINTED on every (re-)enlistment +# (measured: the 2026-07-21 pod-delete recovery renamed all 9) -- so RESOLUTION +# must use host_sysid_by_bootmac() here, never the hostname. BUT the operator +# convention (D-134 amendment 2026-08-07) is to SET the hostname back to +# vr1---NN (== domain == power_id) after commission/deploy for +# operability; "random by default" is not "leave it random". Standup DoD: zero +# non-vr1--* hostnames in the DC's region. host_sysid() { local hn="$1" maas "${MAAS_PROFILE:-admin}" machines read 2>/dev/null \