diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 84f0bc8..287122f 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -411,10 +411,12 @@ `docs/design-decisions.md:3291,3474,3543,3635,3713`): the DC0 deploy sequence they rule (steps A-E, `docs/dc0-deploy-readiness.md:170-179`) exists only as config + runbook. Nothing DC0 is built. -- `vr1-dc1`: ruled at topology level (D-100/D-101 two-DC design) but HELD - -- no ruled dc1 transit/rack addressing, no `vr1_dc1_rack_*` variables, - no dc1 substrate root (`docs/dc0-deploy-readiness.md:100-103`). Only its - storage pool and mesh legs exist (state list, 2.1). +- `vr1-dc1`: topology ruled (D-100/D-101) and addressing RATIFIED + 2026-07-21 (D-124 amendment: planes contiguous in 10.12.64.0/19, + transit 172.31.0.4/30, uplink 172.30.3.0/24; apex confirm-free at + authoring). Still UNBUILT: no `vr1_dc1_rack_*` variables, no dc1 + substrate root; only its storage pool and mesh legs exist (state + list, 2.1). Gate row G12 carries the remaining [V] leg. - D-100 netem: mechanism authored (`opentofu/modules/netem-link`) but HELD as a comment in the root (`opentofu/main.tf:309-319`); placeholder parameters ruled for the rehearsal (readiness doc:73-75); final @@ -473,7 +475,7 @@ | G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | CLOSED 2026-07-19: G8 same-session planes check passed (6x 0 leases, 0 attachments); saved plan == 6/0/6 applied in the logged dc0-deploy window; convergence re-plan = no differences; vvr1-dc0 running, prior guests untouched | | G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`), and the edge itself now egresses 0% loss after the v4 addressing. Step D COMPLETE incl. commissioning: ALL 9 NODES READY 2026-07-21 (two stacked faults diagnosed + fixed -- `docs/audit/commissioning-diag-20260721.txt`; section 1). Step E (netem) DONE 2026-07-21: sudo fragment installed+verified, module local-mode amendment, targeted apply 1/0/0 exact (operator-ruled at the 1/1/0 STOP), placeholder profile live on virbr5, virbr7/virbr3 untouched (`docs/audit/stepE-netem-20260721.txt` + `outer-{plan,apply}-20260721-netem*.txt`). **G10 CLOSED 2026-07-21** | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | -| G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator | HELD (`docs/dc0-deploy-readiness.md:100-103`) | +| G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator + session | OPEN -- [R] leg CLOSED 2026-07-21: addressing RATIFIED (D-124 amendment 2026-07-21, utterance quoted). Remaining [V] leg: apex confirm-free, vr1_dc1_rack_* vars, dc1 substrate root, build | | G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | OPEN (execution only; decision content complete) | | G14 | 9 OPEN SEC rows (SEC-001, -003..-008, plus SEC-012 + SEC-013 opened 2026-07-20 for credentials this deploy created; SEC-010 CLOSED 2026-07-20, operator-ruled, applied+verified both transit ends) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012 also carries a SCOPE question (libvirt-group grant is broader than the power verbs MAAS needs), SEC-013 is tied to whether `opentofu/vr1-dc0-maas` is retired | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-20 | | G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 remains PROPOSED/OPEN (items 2-3 + the item-1 re-scoped migration plan) | diff --git a/docs/changelog-20260721-tenant-review-pin.md b/docs/changelog-20260721-tenant-review-pin.md index a669d8a..607c776 100644 --- a/docs/changelog-20260721-tenant-review-pin.md +++ b/docs/changelog-20260721-tenant-review-pin.md @@ -156,3 +156,19 @@ repo-lint 0-fail. No live execution (nothing to probe until Stage 5). - **Revert:** git revert this commit (restores cloud-assert.sh + harness to pre-A9; no live surface touched). + +## 12. G12 [R] leg CLOSED: vr1-dc1 addressing RATIFIED (D-124 amendment) + +- Prep derived every candidate from ruled patterns (D-115 supernet + 10.12.64.0/19, D-101 role order, D-124 transit supernet, D-120 bands, + D-131 forwarder, D-125/D-122 edge, D-126 creds); the one divergence + (contiguous /22 carve -- dc0's offsets cannot fit a /19) is documented + in the amendment. Operator selection, exact utterance: "Adopt scheme + as derived (Recommended)". +- Recorded as D-124 AMENDMENT (2026-07-21) with the full table + tfvar + fills; G12 row flipped HELD -> OPEN with the [V] remainder named + (apex confirm-free, vars, substrate root, build); CURRENT-STATE + section 4 bullet updated same-commit. lib-net.sh vr1-dc1 arm stays + FAIL until the apex assignment lands (its own rule). +- No live or config surface touched -- ruling + records only. +- **Revert:** git revert this commit (records only). diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 0fb884a..0371c8d 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -3792,6 +3792,39 @@ `--commit` runs ON office1-netbox (apex token local there; unreachable from the vcloud jumphost). See `docs/archive/changelogs/changelog-20260716-d124-addressing-pin.md`. +### D-124 -- AMENDMENT (2026-07-21): vr1-dc1 addressing RATIFIED (the G12 [R] leg) + +RULED 2026-07-21 (GA-R5): question as presented = "G12 addressing ruling: adopt the +pattern-mirror dc1 addressing scheme (table above, apex-confirm at authoring)?"; operator +selection, exact utterance: "Adopt scheme as derived (Recommended)". Every value below is +pattern-derived from ruled decisions (D-115 supernet, D-101 role set, this decision's transit +scheme, D-120 bands, D-131 forwarder, D-125/D-122 edge shape) and is CONFIRMED FREE against +the live apex (office1-netbox) at var-authoring time BEFORE any commit -- same discipline as +the dc0 block above. + +vr1-dc1 ratified addressing (supernet 10.12.64.0/19, D-115): +- planes, CONTIGUOUS first-six /22s keeping dc0's role ORDER (dc0's 4/8/12/16/32/36 offsets + cannot fit inside a /19 -- deliberate, documented divergence; 10.12.88+92.0/22 spare): + provider-public 10.12.64.0/22 (edge LAN gw 10.12.64.1), metal-admin 10.12.68.0/22, + metal-internal 10.12.72.0/22, data-tenant 10.12.76.0/22, storage 10.12.80.0/22, + replication 10.12.84.0/22. +- region<->rack transit: 172.31.0.4/30 (region .5, rack .6) -- next /30 in this decision's + 172.31.0.0/24 transit supernet. +- rack metal-admin IP 10.12.68.2 (first static, D-120 .2-.49 band); D-131 forwarder alias + 10.12.68.3; MAAS dynamic range 10.12.68.100-.200 (D-120 inheritance). +- simulated ISP uplink: 172.30.3.0/24 (WAN .2 on edge, gw .1) -- next per-DC /24 in the + D-115 Edge role (172.30.1 = office1, 172.30.2 = dc0). +- creds: ~/vr1-dc1-creds/vr1-dc1_svc_ed25519 (D-126 option a per-env key convention). +- standup definition-of-done carries the ruled invariants: scripts/dc-rack-net.sh site row + (legs MEASURED at standup) + install, D-131 forwarder, MAC pinning from the FIRST apply, + per-machine virsh power via maas-node-power.sh (pods refuted, D-103/D-123 amendments). + +These fill the four vr1_dc1_rack_* tfvars when authored: rack_transit_ip=172.31.0.6, +rack_transit_prefix=30, rack_transit_peer_ip=172.31.0.5, rack_metal_admin_ip=10.12.68.2. +G12's remaining [V] leg: apex confirm-free + vars + dc1 substrate authoring + build. +lib-net.sh's vr1-dc1 selector arm stays a FAIL until the apex assignment lands (the arm's +own rule: NetBox assigns, then the literals enter the lib in the same change). + ## D-125: VR1 Model B per-DC ISP egress -- bridge-in single-NAT (resolves OBS-3's design gap; egress efficacy is a deploy-time gate) [ARCH] **Status:** ADOPTED (operator ruling 2026-07-16 -- "DC0 and DC1 are supposed to have ISP connections",