diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 83f9145..b8bf159 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -55,20 +55,15 @@ on its FACTORY LAN `192.168.1.1/24`. Rack legs `10.12.4.2/22` + `10.12.8.2/22` added INTERIM (non-persistent `ip addr`; script support is a queued finding), plus a temporary `192.168.1.2/22` to reach the - factory LAN. **D-125 egress gate EXECUTED 2026-07-20 (as written, - throwaway VM) -- PARTIAL, gate OPEN**: bridge-in PROVEN (foreign MAC in - vvr1-dc0 -> vcloud ISP NAT gateway, ping 3/3) but the guest's upstream - egress FAILS (ICMP; a TCP datapoint from the GUEST is still missing -- - the rack-sourced follow-up was confounded by the rack having no default - route, corrected in the changelog per C2). Controls pass (vcloud egress - OK; office1 edge egresses via the same-shape office1-wan NAT). - Config/design ruled out by - `net-dumpxml` equivalence, so the suspect is vcloud's live firewall - rules for virbr4; the double-NAT fallback is NOT invoked (it remedies a - design failure, not a host rule gap). Blocked on one read-only - operator-sudo measurement (`nft list ruleset` virbr4 vs virbr11). - Capture: `docs/audit/d125-egress-gate-20260720.txt`. - REMAINING: close D-125, edge re-address over REST + factory LAN. **D-125 egress isolation gate: PASS / CLOSED 2026-07-20** + (executed as written -- throwaway VM on `br-vr1-dc0-wan`; two identical + consecutive runs: gateway ping 0, internet ping 0, `curl 1.1.1.1` 301, + `curl archive.ubuntu.com` 200). Bridge-in is PROVEN end to end and the + double-NAT fallback is NOT needed. Captures: + `docs/audit/d125-egress-gate-20260720{,-matrix}.txt`. One earlier run + failed ICMP-to-internet on the same path and is recorded UNEXPLAINED in + the session changelog (start there if a DC edge shows first-boot egress + failure). REMAINING: edge re-address over REST (LAN 10.12.4.1/22, WAN static on 172.30.2.0/24) + D-129 plugins, MAAS reach + `TF_VAR_maas_api_key` + region-side metal-admin DHCP naming this rack primary_rack (step D), netem (E). @@ -258,7 +253,7 @@ | G7 | New captured plan == the expected triple recorded in section 5 | [V] re-plan to a capture file after G5+G6 | session | CLOSED 2026-07-19: capture `docs/audit/outer-plan-20260719-postG6.txt` = 6/0/6, equals section 5 exactly | | G8 | Same-session pre-apply re-verify: 6 planes still empty | [V] run in the SAME session as the apply | session | CLOSED 2026-07-19: verified in the apply session itself (all six 0 leases; only office1 nets attached) immediately before step A | | G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | CLOSED 2026-07-19: G8 same-session planes check passed (6x 0 leases, 0 attachments); saved plan == 6/0/6 applied in the logged dc0-deploy window; convergence re-plan = no differences; vvr1-dc0 running, prior guests untouched | -| G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B item DONE 2026-07-20: `--check` EXIT 0 incl. SEC-010 (`docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). REMAINING: depth-4 boot + D-125 egress test (step C), MAAS reach + key (step D), netem (step E) | +| G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`). REMAINING: edge REST config + D-129 plugins, MAAS reach + key + region-side metal-admin DHCP (step D), netem (step E) | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator | HELD (`docs/dc0-deploy-readiness.md:100-103`) | | G13 | D-129 residuals | [R] operator-gated live plugin install on the edge; qga channel retrofit at next scheduled edge restart; 4 sub-decisions (section 8) | operator | OPEN / PARTIALLY RULED (`docs/design-decisions.md:4017`) | diff --git a/docs/audit/d125-egress-gate-20260720-matrix.txt b/docs/audit/d125-egress-gate-20260720-matrix.txt new file mode 100644 index 0000000..10a4d50 --- /dev/null +++ b/docs/audit/d125-egress-gate-20260720-matrix.txt Binary files differ diff --git a/docs/changelog-20260719-dc0-deploy-stepB.md b/docs/changelog-20260719-dc0-deploy-stepB.md index 294fd98..69203cc 100644 --- a/docs/changelog-20260719-dc0-deploy-stepB.md +++ b/docs/changelog-20260719-dc0-deploy-stepB.md @@ -306,7 +306,37 @@ both `forward mode=nat` + ``; only netmask-vs- prefix notation differs) -- so the delta is in vcloud's LIVE firewall rules for virbr4, NOT in the design or the config. -- **Gate status: OPEN (not FAIL).** The runbook's FAIL remedy (revert to +- **GATE STATUS: PASS / CLOSED 2026-07-20** (runs 3+4, capture + `docs/audit/d125-egress-gate-20260720-matrix.txt`). The "missing rule" + hypothesis was DISPROVED by measurement first: the operator-run dumps + show virbr4's rule set is structurally IDENTICAL to the WORKING virbr11 + (only counters differ; virbr11's one extra rule is a DHCP checksum + fixup it has because it carries a DHCP range). All three masquerade + rules exist for 172.30.2.0/24 INCLUDING the generic (non-tcp/udp) one, + and it had FIRED (1 packet/84 bytes = one ICMP conntrack entry), with + FORWARD accept counting 136 packets. So `net-destroy/net-start` would + have fixed nothing -- the pre-staged fix was correctly NOT run. +- Decisive re-probe used a protocol/destination MATRIX instead of counter + archaeology. Result, IDENTICAL on two consecutive runs: gateway ping 0, + **internet ping 0**, `curl http://1.1.1.1` -> 301, `curl + archive.ubuntu.com` -> 200. Egress works for ICMP AND TCP to real + hosts, so the D-125 bridge-in chain is PROVEN end to end and the + double-NAT fallback is NOT needed. +- **Run-2 anomaly, recorded UNEXPLAINED (not swept):** the same path + failed ICMP-to-internet once while its gateway ping passed 3/3. Runs 3+4 + passed identically with no intervening change to the uplink or its + rules. Most likely a first-use conntrack/ARP transient on vcloud. It is + not reproducible now; if a DC edge ever shows first-boot egress failure, + START HERE rather than re-deriving. +- **Security-positive side observation** (extra probe, outside the gate): + the guest could NOT reach the Office1 management LAN through the ISP NAT + (`10.10.0.20:8000` -> 000) on all runs, while internet egress worked. + That is the D-122/SEC-010 intent holding: the DC's WAN segment is an ISP + uplink, not a path into Office1. Worth an explicit assertion in the + hardening tests rather than leaving it an incidental observation. +- Prior status line (superseded, kept for the audit trail): gate was held + OPEN pending measurement rather than FAILED. The runbook's FAIL remedy + (revert to double-NAT) is for a DESIGN failure; invoking it against what is very likely a host firewall-rule gap would be the wrong remedy and would add Roosevelt delta. Next step is a read-only measurement needing operator