diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 97035c3..718af50 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -945,6 +945,38 @@ exposure to decide at Step 4.2's `--dry-run`** -- that tag is MEASURED ABSENT from this region too (`maas-role-tags.sh` creates control/compute/storage/juju-controller-* and `dc-region-topology.sh` creates `openstack-vr1-dc0`; no bare `openstack`). + **>>> BUNDLE DEPLOY ATTEMPT 1 FAILED 2026-07-31 -- A REAL BUNDLE/OVERLAY DEFECT, AND + NOTHING IS HALF-APPLIED. <<<** Capture `docs/audit/stage5-dc0-deploy-attempt1-20260731.txt`. + Verdict: `ERROR cannot deploy bundle: cannot deploy application "barbican": unknown option + "prefer-ipv6"`. **MEASURED AFTER THE FAILURE, not assumed: `juju status -m vr1-dc0` reads + `Model "vr1-dc0" is empty`, 0 applications / 0 machines** -- juju validated the whole bundle + and aborted atomically before creating anything. Steps 1-3.5 all remain good. + **THE DRY-RUN PASSED AND THE DEPLOY DID NOT, AND THAT IS THE LOAD-BEARING LESSON.** + `juju deploy --dry-run` resolved all 56 charms, planned 108 relations and exited 0 + (capture `docs/audit/stage5-dc0-bundle-dryrun-20260731.txt`). **It does NOT validate charm + CONFIG OPTION NAMES against each charm's schema**, so a green `--dry-run` is NOT a gate on + option validity. Note also the measured plan is **56 apps / 108 relations**, NOT the + `50 apps / 97 relations` preflight P6's reminder text still quotes -- a stale reference; + GA-R1 rule 2 says the captured output wins. + **ROOT CAUSE, MEASURED AGAINST CHARMHUB'S OWN `config-yaml` AT EACH PINNED CHANNEL** (the + vendor schema, not a repo comment): `overlays/vr1-dc0-vips.yaml` applies `prefer-ipv6: true` + to ALL THIRTEEN VIP apps (R2, RULED 2026-07-27), but only **SEVEN charms declare the + option** -- `ceph-radosgw`, `cinder`, `glance`, `keystone`, `neutron-api`, + `nova-cloud-controller`, `openstack-dashboard`. **SIX DO NOT** -- `barbican`, `designate`, + `magnum`, `octavia`, `placement`, `vault`. + **IT WAS NEVER REMOVED -- IT WAS NEVER THERE.** barbican returns NO at `2023.2/stable`, + `2023.1/stable` AND `ussuri/stable`, so this is not an obsoleted option that newer charms + dropped; `prefer-ipv6` simply belongs to a SUBSET of the OpenStack charms, and R2's uniform + application was never valid for these six. This is the "RULED IS NOT BUILT -- CHECK THE + ARTIFACT" class again: the ruling was never compared against the charms' actual schemas, and + **no gate in this repo reads a charm config schema.** + **THE FIX IS NOT OBVIOUS AND IS NOT TAKEN HERE (hard rule 1 + ruled surface).** + `provider-bundle-check` invariant 9 COUPLES the two: "prefer-ipv6 makes HAProxy bind + `:::port` in ADDITION to `*:port`, so the two must travel together" (`:30-33`). So simply + deleting `prefer-ipv6` from the six would trip that gate, and it raises the real question: + whether those six charms' v6 VIP legs can bind at all without it. **That is an R2 / D-136 + ruling-surface question needing a GA-R5 exchange**, presented to the operator with the + measurement above rather than decided mid-deploy. - Project: Omega Cloud, VR1 DC-DC rehearsal -- a two-DC + Office1-headend virtual rehearsal on KVM (vcloud host), rehearsing the future bare-metal diff --git a/docs/audit/stage5-dc0-bundle-dryrun-20260731.txt b/docs/audit/stage5-dc0-bundle-dryrun-20260731.txt new file mode 100644 index 0000000..ba798dc --- /dev/null +++ b/docs/audit/stage5-dc0-bundle-dryrun-20260731.txt @@ -0,0 +1,328 @@ +WARNING These fields + unmarshal document 0: yaml: unmarshal errors: + line 62: field name not found in type charm.bundleData + line 87: field variables not found in type charm.bundleData +will be ignored during deployment +Located charm "barbican" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "barbican-vault" in charm-hub, channel 2024.1/stable +Located charm "ceph-mon" in charm-hub, channel squid/stable +Located charm "ceph-osd" in charm-hub, channel squid/stable +Located charm "ceph-radosgw" in charm-hub, channel squid/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "ceph-rbd-mirror" in charm-hub, channel squid/stable +Located charm "cinder" in charm-hub, channel 2024.1/stable +Located charm "cinder-backup" in charm-hub, channel 2024.1/stable +Located charm "cinder-ceph" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "designate" in charm-hub, channel 2024.1/stable +Located charm "designate-bind" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "glance" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "glance-simplestreams-sync" in charm-hub, channel 2024.1/stable +Located charm "keystone" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "magnum" in charm-hub, channel 2024.1/stable +Located charm "magnum-dashboard" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "memcached" in charm-hub, channel latest/stable +Located charm "mysql-innodb-cluster" in charm-hub, channel 8.0/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "neutron-api" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "neutron-api-plugin-ovn" in charm-hub, channel 2024.1/stable +Located charm "nova-cloud-controller" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "nova-compute" in charm-hub, channel 2024.1/stable +Located charm "octavia" in charm-hub, channel 2024.1/stable +Located charm "octavia-dashboard" in charm-hub, channel 2024.1/stable +Located charm "octavia-diskimage-retrofit" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "openstack-dashboard" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "ovn-central" in charm-hub, channel 24.03/stable +Located charm "ovn-chassis" in charm-hub, channel 24.03/stable +Located charm "ovn-chassis" in charm-hub, channel 24.03/stable +Located charm "placement" in charm-hub, channel 2024.1/stable +Located charm "hacluster" in charm-hub, channel 2.4/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Located charm "rabbitmq-server" in charm-hub, channel 3.9/stable +Located charm "vault" in charm-hub, channel 1.8/stable +Located charm "mysql-router" in charm-hub, channel 8.0/stable +Changes to deploy bundle: +- upload charm barbican from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application barbican from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm hacluster from charm-hub for base ubuntu@22.04/stable from channel 2.4/stable with architecture=amd64 +- deploy application barbican-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- upload charm mysql-router from charm-hub for base ubuntu@22.04/stable from channel 8.0/stable with architecture=amd64 +- deploy application barbican-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm barbican-vault from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application barbican-vault from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm ceph-mon from charm-hub for base ubuntu@22.04/stable from channel squid/stable with architecture=amd64 +- deploy application ceph-mon from charm-hub on ubuntu@22.04/stable with squid/stable +- upload charm ceph-osd from charm-hub for base ubuntu@22.04/stable from channel squid/stable with architecture=amd64 +- deploy application ceph-osd from charm-hub on ubuntu@22.04/stable with squid/stable +- upload charm ceph-radosgw from charm-hub for base ubuntu@22.04/stable from channel squid/stable with architecture=amd64 +- deploy application ceph-radosgw from charm-hub on ubuntu@22.04/stable with squid/stable +- deploy application ceph-radosgw-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- upload charm ceph-rbd-mirror from charm-hub for base ubuntu@22.04/stable from channel squid/stable with architecture=amd64 +- deploy application ceph-rbd-mirror from charm-hub on ubuntu@22.04/stable with squid/stable +- upload charm cinder from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application cinder from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm cinder-backup from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application cinder-backup from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm cinder-ceph from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application cinder-ceph from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application cinder-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application cinder-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- deploy application dashboard-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm designate from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application designate from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm designate-bind from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application designate-bind from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application designate-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application designate-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm glance from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application glance from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application glance-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application glance-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm glance-simplestreams-sync from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application glance-simplestreams-sync from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm keystone from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application keystone from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application keystone-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application keystone-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm magnum from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application magnum from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm magnum-dashboard from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application magnum-dashboard from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application magnum-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application magnum-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm memcached from charm-hub for base ubuntu@22.04/stable from channel latest/stable with architecture=amd64 +- deploy application memcached from charm-hub on ubuntu@22.04/stable with latest/stable +- upload charm mysql-innodb-cluster from charm-hub for base ubuntu@22.04/stable from channel 8.0/stable with architecture=amd64 +- deploy application mysql-innodb-cluster from charm-hub on ubuntu@22.04/stable with 8.0/stable +- deploy application ncc-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm neutron-api from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application neutron-api from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application neutron-api-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application neutron-api-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm neutron-api-plugin-ovn from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application neutron-api-plugin-ovn from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm nova-cloud-controller from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application nova-cloud-controller from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application nova-cloud-controller-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- upload charm nova-compute from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application nova-compute from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm octavia from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application octavia from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm octavia-dashboard from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application octavia-dashboard from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- upload charm octavia-diskimage-retrofit from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application octavia-diskimage-retrofit from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application octavia-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application octavia-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm openstack-dashboard from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application openstack-dashboard from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application openstack-dashboard-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- upload charm ovn-central from charm-hub for base ubuntu@22.04/stable from channel 24.03/stable with architecture=amd64 +- deploy application ovn-central from charm-hub on ubuntu@22.04/stable with 24.03/stable +- upload charm ovn-chassis from charm-hub for base ubuntu@22.04/stable from channel 24.03/stable with architecture=amd64 +- deploy application ovn-chassis from charm-hub on ubuntu@22.04/stable with 24.03/stable +- deploy application ovn-chassis-octavia from charm-hub on ubuntu@22.04/stable with 24.03/stable using ovn-chassis +- upload charm placement from charm-hub for base ubuntu@22.04/stable from channel 2024.1/stable with architecture=amd64 +- deploy application placement from charm-hub on ubuntu@22.04/stable with 2024.1/stable +- deploy application placement-hacluster from charm-hub on ubuntu@22.04/stable with 2.4/stable using hacluster +- deploy application placement-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- upload charm rabbitmq-server from charm-hub for base ubuntu@22.04/stable from channel 3.9/stable with architecture=amd64 +- deploy application rabbitmq-server from charm-hub on ubuntu@22.04/stable with 3.9/stable +- upload charm vault from charm-hub for base ubuntu@22.04/stable from channel 1.8/stable with architecture=amd64 +- deploy application vault from charm-hub on ubuntu@22.04/stable with 1.8/stable +- deploy application vault-mysql-router from charm-hub on ubuntu@22.04/stable with 8.0/stable using mysql-router +- add new machine 0 +- add new machine 1 +- add new machine 2 +- add new machine 3 +- add new machine 4 +- add new machine 5 +- add new machine 6 +- add new machine 7 +- add new machine 8 +- add relation nova-cloud-controller:memcache - memcached:cache +- add relation vault-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation vault:shared-db - vault-mysql-router:shared-db +- add relation mysql-innodb-cluster:certificates - vault:certificates +- add relation keystone-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation keystone-mysql-router:shared-db - keystone:shared-db +- add relation keystone:certificates - vault:certificates +- add relation keystone:ha - keystone-hacluster:ha +- add relation glance-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation glance-mysql-router:shared-db - glance:shared-db +- add relation glance:identity-service - keystone:identity-service +- add relation glance:certificates - vault:certificates +- add relation glance:ha - glance-hacluster:ha +- add relation glance-simplestreams-sync:identity-service - keystone:identity-service +- add relation glance-simplestreams-sync:certificates - vault:certificates +- add relation ncc-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation ncc-mysql-router:shared-db - nova-cloud-controller:shared-db +- add relation nova-cloud-controller:identity-service - keystone:identity-service +- add relation nova-cloud-controller:amqp - rabbitmq-server:amqp +- add relation nova-cloud-controller:image-service - glance:image-service +- add relation nova-cloud-controller:neutron-api - neutron-api:neutron-api +- add relation nova-cloud-controller:cloud-compute - nova-compute:cloud-compute +- add relation nova-cloud-controller:cinder-volume-service - cinder:cinder-volume-service +- add relation nova-cloud-controller:certificates - vault:certificates +- add relation nova-cloud-controller:ha - nova-cloud-controller-hacluster:ha +- add relation nova-compute:amqp - rabbitmq-server:amqp +- add relation nova-compute:image-service - glance:image-service +- add relation placement-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation placement-mysql-router:shared-db - placement:shared-db +- add relation placement:identity-service - keystone:identity-service +- add relation placement:placement - nova-cloud-controller:placement +- add relation placement:certificates - vault:certificates +- add relation placement:ha - placement-hacluster:ha +- add relation neutron-api-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation neutron-api-mysql-router:shared-db - neutron-api:shared-db +- add relation neutron-api:identity-service - keystone:identity-service +- add relation neutron-api:amqp - rabbitmq-server:amqp +- add relation neutron-api:certificates - vault:certificates +- add relation neutron-api-plugin-ovn:neutron-plugin - neutron-api:neutron-plugin-api-subordinate +- add relation neutron-api-plugin-ovn:ovsdb-cms - ovn-central:ovsdb-cms +- add relation neutron-api-plugin-ovn:certificates - vault:certificates +- add relation ovn-central:certificates - vault:certificates +- add relation ovn-chassis:ovsdb - ovn-central:ovsdb +- add relation ovn-chassis:nova-compute - nova-compute:neutron-plugin +- add relation ovn-chassis:certificates - vault:certificates +- add relation neutron-api:ha - neutron-api-hacluster:ha +- add relation cinder-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation cinder-mysql-router:shared-db - cinder:shared-db +- add relation cinder:identity-service - keystone:identity-service +- add relation cinder:amqp - rabbitmq-server:amqp +- add relation cinder:image-service - glance:image-service +- add relation cinder:certificates - vault:certificates +- add relation cinder-ceph:storage-backend - cinder:storage-backend +- add relation cinder-ceph:ceph - ceph-mon:client +- add relation cinder-ceph:ceph-access - nova-compute:ceph-access +- add relation cinder:ha - cinder-hacluster:ha +- add relation cinder-backup:backup-backend - cinder:backup-backend +- add relation cinder-backup:ceph - ceph-mon:client +- add relation ceph-mon:osd - ceph-osd:mon +- add relation ceph-mon:client - nova-compute:ceph +- add relation ceph-mon:client - glance:ceph +- add relation ceph-radosgw:mon - ceph-mon:radosgw +- add relation ceph-radosgw:identity-service - keystone:identity-service +- add relation ceph-radosgw:certificates - vault:certificates +- add relation ceph-radosgw:ha - ceph-radosgw-hacluster:ha +- add relation ceph-rbd-mirror:ceph-local - ceph-mon:rbd-mirror +- add relation dashboard-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation dashboard-mysql-router:shared-db - openstack-dashboard:shared-db +- add relation openstack-dashboard:identity-service - keystone:identity-service +- add relation openstack-dashboard:certificates - vault:certificates +- add relation openstack-dashboard:ha - openstack-dashboard-hacluster:ha +- add relation octavia-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation octavia-mysql-router:shared-db - octavia:shared-db +- add relation octavia:identity-service - keystone:identity-service +- add relation octavia:amqp - rabbitmq-server:amqp +- add relation octavia:neutron-api - neutron-api:neutron-load-balancer +- add relation octavia:certificates - vault:certificates +- add relation octavia-dashboard:dashboard - openstack-dashboard:dashboard-plugin +- add relation ovn-chassis-octavia:ovsdb - ovn-central:ovsdb +- add relation ovn-chassis-octavia:ovsdb-subordinate - octavia:ovsdb-subordinate +- add relation ovn-chassis-octavia:certificates - vault:certificates +- add relation octavia-diskimage-retrofit:juju-info - glance-simplestreams-sync:juju-info +- add relation octavia-diskimage-retrofit:identity-credentials - keystone:identity-credentials +- add relation octavia:ha - octavia-hacluster:ha +- add relation barbican-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation barbican-mysql-router:shared-db - barbican:shared-db +- add relation barbican:identity-service - keystone:identity-service +- add relation barbican:amqp - rabbitmq-server:amqp +- add relation barbican:certificates - vault:certificates +- add relation barbican:secrets - barbican-vault:secrets +- add relation barbican-vault:certificates - vault:certificates +- add relation barbican-vault:secrets-storage - vault:secrets +- add relation barbican:ha - barbican-hacluster:ha +- add relation magnum-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation magnum:shared-db - magnum-mysql-router:shared-db +- add relation magnum:identity-service - keystone:identity-service +- add relation magnum:amqp - rabbitmq-server:amqp +- add relation magnum:certificates - vault:certificates +- add relation magnum-dashboard:dashboard - openstack-dashboard:dashboard-plugin +- add relation magnum:ha - magnum-hacluster:ha +- add relation designate-mysql-router:db-router - mysql-innodb-cluster:db-router +- add relation designate-mysql-router:shared-db - designate:shared-db +- add relation designate:identity-service - keystone:identity-service +- add relation designate:amqp - rabbitmq-server:amqp +- add relation designate:certificates - vault:certificates +- add relation designate:coordinator-memcached - memcached:cache +- add relation designate:dns-backend - designate-bind:dns-backend +- add relation designate:ha - designate-hacluster:ha +- add unit ceph-osd/0 to new machine 5 +- add unit ceph-osd/1 to new machine 6 +- add unit ceph-osd/2 to new machine 7 +- add unit ceph-osd/3 to new machine 8 +- add unit nova-compute/0 to new machine 3 +- add unit nova-compute/1 to new machine 4 +- add lxd container 0/lxd/0 on new machine 0 +- add lxd container 0/lxd/1 on new machine 0 +- add lxd container 1/lxd/0 on new machine 1 +- add lxd container 2/lxd/0 on new machine 2 +- add lxd container 0/lxd/2 on new machine 0 +- add lxd container 0/lxd/3 on new machine 0 +- add lxd container 0/lxd/4 on new machine 0 +- add lxd container 0/lxd/5 on new machine 0 +- add lxd container 2/lxd/1 on new machine 2 +- add lxd container 0/lxd/6 on new machine 0 +- add lxd container 1/lxd/1 on new machine 1 +- add lxd container 0/lxd/7 on new machine 0 +- add lxd container 0/lxd/8 on new machine 0 +- add lxd container 0/lxd/9 on new machine 0 +- add lxd container 0/lxd/10 on new machine 0 +- add lxd container 1/lxd/2 on new machine 1 +- add lxd container 2/lxd/2 on new machine 2 +- add lxd container 0/lxd/11 on new machine 0 +- add lxd container 0/lxd/12 on new machine 0 +- add lxd container 0/lxd/13 on new machine 0 +- add lxd container 0/lxd/14 on new machine 0 +- add lxd container 0/lxd/15 on new machine 0 +- add lxd container 1/lxd/3 on new machine 1 +- add lxd container 2/lxd/3 on new machine 2 +- add lxd container 0/lxd/16 on new machine 0 +- add lxd container 0/lxd/17 on new machine 0 +- add lxd container 0/lxd/18 on new machine 0 +- add unit barbican/0 to 0/lxd/0 +- add unit ceph-mon/0 to 0/lxd/1 +- add unit ceph-mon/1 to 1/lxd/0 +- add unit ceph-mon/2 to 2/lxd/0 +- add unit ceph-radosgw/0 to 0/lxd/2 +- add unit ceph-rbd-mirror/0 to 0/lxd/3 +- add unit cinder/0 to 0/lxd/4 +- add unit designate/0 to 0/lxd/5 +- add unit designate-bind/0 to 2/lxd/1 +- add unit glance/0 to 0/lxd/6 +- add unit glance-simplestreams-sync/0 to 1/lxd/1 +- add unit keystone/0 to 0/lxd/7 +- add unit magnum/0 to 0/lxd/8 +- add unit memcached/0 to 0/lxd/9 +- add unit mysql-innodb-cluster/0 to 0/lxd/10 +- add unit mysql-innodb-cluster/1 to 1/lxd/2 +- add unit mysql-innodb-cluster/2 to 2/lxd/2 +- add unit neutron-api/0 to 0/lxd/11 +- add unit nova-cloud-controller/0 to 0/lxd/12 +- add unit octavia/0 to 0/lxd/13 +- add unit openstack-dashboard/0 to 0/lxd/14 +- add unit ovn-central/0 to 0/lxd/15 +- add unit ovn-central/1 to 1/lxd/3 +- add unit ovn-central/2 to 2/lxd/3 +- add unit placement/0 to 0/lxd/16 +- add unit rabbitmq-server/0 to 0/lxd/17 +- add unit vault/0 to 0/lxd/18 diff --git a/docs/audit/stage5-dc0-deploy-attempt1-20260731.txt b/docs/audit/stage5-dc0-deploy-attempt1-20260731.txt new file mode 100644 index 0000000..1265f72 --- /dev/null +++ b/docs/audit/stage5-dc0-deploy-attempt1-20260731.txt @@ -0,0 +1,53 @@ +STAGE 5 -- dc0 bundle deploy ATTEMPT 1: FAILED on a bundle/overlay defect (2026-07-31) +====================================================================================== + +COMMAND (from the dc0 rack, D-138 client host): + juju deploy ./bundle.yaml --overlay ./overlays/vr1-dc0-vips.yaml \ + --overlay ./overlays/vr1-dc0-machines.yaml --overlay ./overlays/vr1-dc0-octavia-pki.yaml + +VERDICT: + ERROR cannot deploy bundle: cannot deploy application "barbican": unknown option "prefer-ipv6" + +STATE AFTER THE FAILURE -- NOTHING IS HALF-APPLIED (measured, not assumed): + juju status -m vr1-dc0 -> Model "vr1-dc0" is empty. applications: 0 machines: 0 + Juju validated the whole bundle and aborted atomically BEFORE creating anything. + +THE DRY-RUN PASSED AND THE DEPLOY DID NOT. This is the load-bearing lesson: + 'juju deploy --dry-run' resolved all 56 charms, planned 108 relations and exited 0. + It does NOT validate charm CONFIG OPTION NAMES against each charm's schema. + A green --dry-run is therefore NOT a gate on option validity. + +ROOT CAUSE -- overlays/vr1-dc0-vips.yaml applies 'prefer-ipv6: true' to ALL 13 VIP apps +(R2, RULED 2026-07-27). MEASURED against CHARMHUB's own config-yaml at each pinned +channel -- the vendor schema, not a repo comment: + + CHARM CHANNEL prefer-ipv6? + ------ ------- ------------ + barbican 2024.1/stable NO + ceph-radosgw squid/stable YES + cinder 2024.1/stable YES + designate 2024.1/stable NO + glance 2024.1/stable YES + keystone 2024.1/stable YES + magnum 2024.1/stable NO + neutron-api 2024.1/stable YES + nova-cloud-controller 2024.1/stable YES + octavia 2024.1/stable NO + openstack-dashboard 2024.1/stable YES + placement 2024.1/stable NO + vault 1.8/stable NO + + SUPPORTED (7): ceph-radosgw cinder glance keystone neutron-api nova-cloud-controller openstack-dashboard + NOT SUPPORTED (6): barbican designate magnum octavia placement vault + +IT WAS NEVER REMOVED -- IT WAS NEVER THERE. barbican at 2023.2/stable, 2023.1/stable and +ussuri/stable all return NO. So this is not an obsoleted option that newer charms dropped; +'prefer-ipv6' simply belongs to a SUBSET of the OpenStack charms. The R2 ruling's uniform +application was never valid for these six. + +WHY IT MATTERS BEYOND THE ERROR -- provider-bundle-check INVARIANT 9 COUPLES THEM: + 'prefer-ipv6 makes HAProxy bind :::port in ADDITION to *:port, so the two must travel + together.' (scripts/provider-bundle-check.py:30-33) + So for the six unsupported charms the open question is whether their v6 VIP legs can + function at all without the option, or whether HAProxy will never bind v6 for them. + That is a RULED-SURFACE question (R2) and is NOT decided here. diff --git a/docs/changelog-20260730-dc0-node-carve.md b/docs/changelog-20260730-dc0-node-carve.md index 64581e4..ff7b8fa 100644 --- a/docs/changelog-20260730-dc0-node-carve.md +++ b/docs/changelog-20260730-dc0-node-carve.md @@ -386,3 +386,47 @@ Same shape as the five instrument errors swept on 2026-07-30. **Revert.** `juju destroy-model vr1-dc0`; `juju model-config -m vr1-dc0 --reset apt-mirror`. + +## Item 11 -- bundle deploy ATTEMPT 1: failed on a real overlay defect, nothing half-applied + +**What.** `juju deploy ./bundle.yaml` with all three overlays, from the rack. Result: + + ERROR cannot deploy bundle: cannot deploy application "barbican": unknown option "prefer-ipv6" + +**State after the failure, MEASURED:** `juju status -m vr1-dc0` -> `Model "vr1-dc0" is empty`, +0 applications, 0 machines. Juju validated the whole bundle and aborted atomically before +creating anything. Steps 1 through 3.5 are untouched and still good. + +**THE DRY-RUN PASSED AND THE DEPLOY DID NOT.** `--dry-run` resolved all 56 charms, planned +108 relations and exited 0. It does NOT validate charm CONFIG OPTION NAMES against each +charm's schema. **A green `juju deploy --dry-run` is not a gate on option validity** -- worth +recording because the runbook treats Step 4.2's dry-run as the pre-deploy check. + +Also measured: the plan is **56 apps / 108 relations**, not the `50 apps / 97 relations` +preflight P6's reminder text still quotes. Stale reference; captured output wins (GA-R1 r2). + +**Root cause, measured against CHARMHUB's own `config-yaml` per pinned channel.** +`overlays/vr1-dc0-vips.yaml` sets `prefer-ipv6: true` on all 13 VIP apps (R2, RULED +2026-07-27). Only SEVEN charms declare it -- `ceph-radosgw`, `cinder`, `glance`, `keystone`, +`neutron-api`, `nova-cloud-controller`, `openstack-dashboard`. SIX do not -- `barbican`, +`designate`, `magnum`, `octavia`, `placement`, `vault`. + +**It was never removed; it was never there.** barbican returns NO at 2023.2, 2023.1 and +ussuri. So this is not an obsoleted option -- `prefer-ipv6` belongs to a SUBSET of the +OpenStack charms, and R2's uniform application was never valid for these six. Same class as +"RULED IS NOT BUILT -- CHECK THE ARTIFACT": no gate in this repo reads a charm config schema. + +**OWNED -- an instrument error on the way to this.** My first charmhub query used +`fields=default-release.revision.config` and returned `NO-CONFIG-RETURNED` for all 13 charms. +A uniform answer across 13 different charms is implausible, which is what flagged it; the API +rejects that field name and the correct one is `...config-yaml`. Had I reported the first +result it would have read as "no charm supports it", which is the opposite of the truth for +seven of them. + +**NOT FIXED (hard rule 1 + ruled surface).** `provider-bundle-check` invariant 9 couples +`prefer-ipv6` to the dual-family VIP legs ("makes HAProxy bind `:::port` in ADDITION to +`*:port`, so the two must travel together"). Deleting the option from the six would trip that +gate, and raises the real question: can those six charms' v6 VIP legs bind at all without it? +That is an R2/D-136 ruling-surface question for a GA-R5 exchange. + +**Revert.** None needed -- the model is empty.