diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 1dc4a5e..32424c2 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -102,6 +102,62 @@ later unplaced `juju add-unit ceph-osd`, which would match no machine. The real impact is measurable at Step 4.2's `--dry-run` and not before, so it is recorded here and decided there -- it is not folded into the P5 ruling above. + **STEP-1/2.0 GATES PASSED 2026-07-30, all read-only, ON voffice1.** Selectors: both + `lib_net_select_dc vr1-dc0` and `lib_hosts_select_dc vr1-dc0` exit 0; six planes + (`10.12.4/8/12/16/32/36.0/22`); ten hosts, the tenth being `vr1-dc0-juju-01`, the + D-104 dedicated controller VM. Step 2.0 credential gate = outcome 1 of 3 (LISTED + + user exists): `juju credentials --client` shows `vr1-dc0-cred, vr1-dc1-cred` on cloud + `vr1-maas` (`credential-count: 2`), MAAS user `juju-vr1-dc0` present -- so the mint is + SKIPPED, correctly: re-minting would be SEC-018 credential sprawl on an already-red + register. Controller-tag gate: `maas-role-tags.sh check vr1-dc0` PASS (0 missing, + 0 needing a tag, 0 not in MAAS) and EXACTLY ONE machine carries + `juju-controller-vr1-dc0` -- system_id `7n87bt`, `Ready`. + **ARTIFACT SOURCES AND EGRESS RE-MEASURED 2026-07-30, both DCs.** dc0 mirror PASS + (`last-sync: OK 2026-07-30T00:20:20Z ubuntu=0 uca=0`, answers 200 on 10.12.8.4); + dc1 proxy PASS (apt-cacher-ng active on 10.12.68.4:3142, serves archive AND UCA 200). + Egress re-probed from BOTH rack hosts with `--noproxy '*'` so a cache hit could not + fake it: juju agent stream `streams.canonical.com/juju/tools/` 200, snap store + `api.snapcraft.io` answering, `archive.ubuntu.com` jammy Release 200, 1.1.1.1 0% loss, + default routes via 10.12.4.1 / 10.12.64.1. **The bootstrap window is OPEN on both DCs + as of this date** -- the shelf-life clause on the 2026-07-27 measurement is discharged + for this session and no further. **INSTRUMENT NOTE, recorded because it cost a + measurement:** run from voffice1, `dc-mirror.sh check dc0` and `dc-cache-proxy.sh check + dc1` both report EVERY item MISS and FAIL. That is the scripts measuring voffice1's own + filesystem -- they RUN ON THE RACK HOST and must be piped there + (`ssh voffice1 "ssh 'sudo -n bash -s -- check '" < scripts/