diff --git a/docs/archive/session-ledger-rotated-20260727.md b/docs/archive/session-ledger-rotated-20260727.md index 8df1e13..56a43c8 100644 --- a/docs/archive/session-ledger-rotated-20260727.md +++ b/docs/archive/session-ledger-rotated-20260727.md @@ -154,3 +154,29 @@ [ARCH]; 3 /root secrets unmoved. **GA-R4 F1: ledger 370 lines at OPEN vs 300 cap -- rotation OWED.** (DISCHARGED 2026-07-26: rotated oldest-first to 280 lines; see the ROTATED block above.) - Gauntlet 79 GREEN, repo-lint 0-fail, b2b0c80 pushed. Bookend EARLY (07-21 precedent); further work appends a POST-CLOSE ADDENDUM. Details: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md. + + +## POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent) +- The 2026-07-25 close bookend landed early by design; this addendum records the work that + followed it rather than re-opening the entry. +- Operator asked for a better mint/save method + "a durable rule ... so credentials aren't + misplaced or lost". Committee review (5 lenses) run; the operator's own insight drove the + design: a discovery sweep can NEVER detect a credential that was never minted -- absence + is invisible to discovery -- so an expected-state credential MATRIX is the missing half. +- **D-137 ADOPTED 2026-07-26**, all five sub-rulings RULED individually (GA-R5, each pushed + before the next was asked): enforcement = blocking in preflight; manifests DERIVED from + the matrix; --remote bounded to declared locations; D-137 is the policy authority + (SEC-009 demotes to a pointer); identity conflation FOLDED IN as the one-identity-one- + principal invariant. (SUPERSEDED SAME-DAY: implementation was built, committee-audited and + remediated later on 2026-07-26 -- see CURRENT-STATE, which is the status authority. This + line is kept as the narrative record of where the session stood at the time.) +- Research: 3 read-only agents. Capture `docs/audit/creds-creation-points-20260725.md` -- + 55 MINT sites, and **12 declared secrets have NO mint command anywhere** (`ssh-keygen` + = ZERO hits repo-wide), plus three credential dirs outside the SEC-009 convention. +- **SEC-021/-022/-023 OPENED** (rows 16 -> 19): a consolidated dc0 credential ABSENT from + its recorded location; two UNAUDITED shadow *-creds/ stores on the headend; sprawl-glob + blind spots incl. a PREDICTED Stage-5 admin-openrc exposure. All logged-not-actioned. +- NEXT as recorded at the time: build per `docs/D-137-implementation-plan.md`. THAT HAPPENED + in the same-day successor session (tiers 1-3 built, six-lens committee audit, remediation, + preflight P5 wired, SEC-009 demoted). Current status: CURRENT-STATE only. +- Status ONLY in CURRENT-STATE.md. Detail: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 65cc7ef..d90db82 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -136,30 +136,10 @@ the 300-line cap; one pass left it at 3 work appends a POST-CLOSE ADDENDUM. Details: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md. -## POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent) -- The 2026-07-25 close bookend landed early by design; this addendum records the work that - followed it rather than re-opening the entry. -- Operator asked for a better mint/save method + "a durable rule ... so credentials aren't - misplaced or lost". Committee review (5 lenses) run; the operator's own insight drove the - design: a discovery sweep can NEVER detect a credential that was never minted -- absence - is invisible to discovery -- so an expected-state credential MATRIX is the missing half. -- **D-137 ADOPTED 2026-07-26**, all five sub-rulings RULED individually (GA-R5, each pushed - before the next was asked): enforcement = blocking in preflight; manifests DERIVED from - the matrix; --remote bounded to declared locations; D-137 is the policy authority - (SEC-009 demotes to a pointer); identity conflation FOLDED IN as the one-identity-one- - principal invariant. (SUPERSEDED SAME-DAY: implementation was built, committee-audited and - remediated later on 2026-07-26 -- see CURRENT-STATE, which is the status authority. This - line is kept as the narrative record of where the session stood at the time.) -- Research: 3 read-only agents. Capture `docs/audit/creds-creation-points-20260725.md` -- - 55 MINT sites, and **12 declared secrets have NO mint command anywhere** (`ssh-keygen` - = ZERO hits repo-wide), plus three credential dirs outside the SEC-009 convention. -- **SEC-021/-022/-023 OPENED** (rows 16 -> 19): a consolidated dc0 credential ABSENT from - its recorded location; two UNAUDITED shadow *-creds/ stores on the headend; sprawl-glob - blind spots incl. a PREDICTED Stage-5 admin-openrc exposure. All logged-not-actioned. -- NEXT as recorded at the time: build per `docs/D-137-implementation-plan.md`. THAT HAPPENED - in the same-day successor session (tiers 1-3 built, six-lens committee audit, remediation, - preflight P5 wired, SEC-009 demoted). Current status: CURRENT-STATE only. -- Status ONLY in CURRENT-STATE.md. Detail: docs/archive/changelogs/changelog-20260725-maas-admin-recovery.md. +## ROTATED 2026-07-27 (fourth pass, GA-R4 rule 3 / F1 -- cap restored at this close) + +The oldest remaining live summary ("POST-CLOSE ADDENDUM 2026-07-26 -- D-137 ADOPTED (GA-R4; 07-18/07-21 addendum precedent)") moved VERBATIM to +`docs/archive/session-ledger-rotated-20260727.md`. The live ledger was 316 lines against the 300-line cap. ## SESSION CLOSE 2026-07-26 -- D-137 build + committee audit + remediation (bounded, GA-R4) @@ -291,3 +271,24 @@ - **Session-scoped permission block REMOVED at close.** Full body: `docs/archive/changelogs/changelog-20260727-stage5-grounding-audit.md`. Status ONLY in CURRENT-STATE.md. + + + +## SESSION CLOSE 2026-07-27 -- Phase 0, R15 gates, D-136, step 3 executed (bounded, GA-R4) + +- Merged the grounding-audit branch to `main` (`607813b`, recorded `6495cfb`), retired it; 29 + commits on `dc-dc-stage5-preconditions`. NO stage opened/closed. SEC 21; D 138/DOCFIX 205. +- PHASE 0: voffice1 off a 105-commit-stale retired branch (both DCs' inner tfstate lives there -- + proven gitignored, sha256 identical after); `openstack` 6.6.0 (snap REFUTED, no Caracal channel). +- ALL THREE R15 GATES FIXED, each reproduced first: repo-lint PASSED over ZERO files on a typo'd + flag; preflight left "clear to deploy" on exits 127/126/130/3; the gauntlet pinned no names. +- RULINGS (GA-R5, quoted): no DC ordering + NOC deferred (F1); **D-136 ADOPTED option (D)**; v6 + host part mirrors the v4 octet (F4); dc1 FIP pool; node v6 = MAAS static. **D-101 GOVERNING + RATIONALE recorded** -- IPv6 unless IPv4 necessary, v4-first deliberate, NAT64 REJECTED. +- STEP 3 EXECUTED both DCs: 12 v6 subnets, 24 bands + 2 FIP pools, apex 3->27 ranges / 4->160 + addresses (156 VIPs), node carve 108 links. D-134 bands + D-020/R11 VIPs were RULED-BUT-NEVER- + BUILT, now artifacts. 18 Ready unchanged. Found: gauntlet HOST-DEPENDENT, preflight P5 HOST-BLIND. +- OWNED: called step 3 "complete" twice while the node layer was unbuilt; mis-filed P0-5; built + the apex tool against a dump so it matched zero live. All corrected on-surface. +- NEXT: gate host-authority; `provider-bundle-check` ARITY gap (imminent); **voffice1 back to + `main` at merge**; then the renderer. Body: `docs/changelog-20260727-stage5-phase0.md`.