diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 6455735..e45e30e 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -476,7 +476,7 @@ | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator | HELD (`docs/dc0-deploy-readiness.md:100-103`) | | G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | OPEN (execution only; decision content complete) | | G14 | 9 OPEN SEC rows (SEC-001, -003..-008, plus SEC-012 + SEC-013 opened 2026-07-20 for credentials this deploy created; SEC-010 CLOSED 2026-07-20, operator-ruled, applied+verified both transit ends) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012 also carries a SCOPE question (libvirt-group grant is broader than the power verbs MAAS needs), SEC-013 is tied to whether `opentofu/vr1-dc0-maas` is retired | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-20 | -| G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | PROPOSED/OPEN (status lines, section 8) | +| G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 remains PROPOSED/OPEN (items 2-3 + the item-1 re-scoped migration plan) | | G16 | office1 edge `channels = []` state reconcile (the D-129 module-schema residual) | [R] operator rules the mechanism; then [V] the converged re-plan capture | operator + session | CLOSED 2026-07-21: RULED "State surgery (Recommended)" (GA-R5, session changelog item 16); executed per G6 precedent -- channels null -> [] injected, serial 29 -> 30, backup kept, guests untouched (office1-opnsense Id 2 running throughout); convergence = ZERO DIFF (`docs/audit/outer-plan-20260721-postG16-converged.txt`); section 5 re-recorded | ## 7. Version pins (measured; the authority for every pin) @@ -516,11 +516,11 @@ (Vault version) needs a re-scoped migration plan since the 1.16 forward-pin was proven NOT viable (amendment, :1650). Evidence in `docs/D-068-vault-1.8-vs-1.16-analysis.md`. -4. D-071 -- update cadence + controller patch policy (PROPOSED, - `docs/design-decisions.md:1605`). QUESTION: adopt policy points 1-4 - (monthly-review window trigger; patch-only controller jumps; order; - acceptable single-controller risk) as amended by the confirmed backup - posture (:1677). +4. D-071 -- ADOPTED 2026-07-21: all four policy points ruled (monthly + review trigger; patch-only controller jumps; standing order; + in-channel-only refreshes), each its own GA-R5 exchange -- status + line in design-decisions.md is the authority. No open question + remains; ops-update-procedure is the policy vehicle. 5. D-129 -- ALL FOUR sub-decisions RULED 2026-07-21 ((i) COS scrapes the edge in-scope per-DC; (ii) os-frr pinned to Roosevelt design; (iii) per-site Tailscale = dedicated node on metal-admin, edge diff --git a/docs/changelog-20260721-tenant-review-pin.md b/docs/changelog-20260721-tenant-review-pin.md index 9010cab..35ad9c2 100644 --- a/docs/changelog-20260721-tenant-review-pin.md +++ b/docs/changelog-20260721-tenant-review-pin.md @@ -127,3 +127,17 @@ machine block updated same-commit; D-129 drops off ledger-scan's open-decisions list by design. - **Revert:** git revert this commit (records only). + +## 10. D-071 ADOPTED: all four update-policy points ruled (four GA-R5 exchanges) + +- Points 1-4 presented and ruled individually, all "Adopt as proposed + (Recommended)": (1) monthly review trigger, security pulls forward; + (2) patch-only controller jumps in routine windows; (3) standing order + controller -> agents -> charms, keystone first / nova-compute last, + never interleave; (4) in-channel-only refreshes, channel moves always + per-decision. Status ADOPTED; ops-update-procedure is the policy + vehicle. Commits: points 1-3 individually (35952b1, bdbbce4, 9121e6c), + point 4 + closure couplings in this commit. G15 row updated (D-068 + remainder only); CURRENT-STATE item 4 + ledger machine block coupled. +- **Revert:** git revert the four commits (records only; no live surface + touched). diff --git a/docs/design-decisions.md b/docs/design-decisions.md index f7f48d9..507a191 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -1610,11 +1610,14 @@ ## D-071: Routine update cadence and Juju controller patch policy -**Status:** PARTIALLY RULED (point 1 of 4 RULED 2026-07-21; points 2-4 open). Filed -PROPOSED 2026-07-04 (by the jumphost controller-update workstream; number relinquished by -the main stream per the 2026-07-03 addendum-10 contention note). Mechanism: -`runbooks/ops-update-procedure.md` (DOCFIX-086); usable per-window under individual gating -meanwhile. Point 1 RULED 2026-07-21 (GA-R5): question as presented = "adopt the proposed +**Status:** ADOPTED -- all four policy points RULED 2026-07-21, each its own GA-R5 exchange +(utterances quoted below). Filed PROPOSED 2026-07-04 (by the jumphost controller-update +workstream; number relinquished by the main stream per the 2026-07-03 addendum-10 contention +note). Mechanism: `runbooks/ops-update-procedure.md` (DOCFIX-086), now the POLICY vehicle. +Point 4 RULED 2026-07-21 (GA-R5): question as presented = "adopt in-channel-only refreshes +for routine windows (channel moves always per-decision)?"; operator selection, exact +utterance: "Adopt as proposed (Recommended)". Routine windows refresh revisions only inside +D-002-pinned channels; every channel move is its own decision. Point 1 RULED 2026-07-21 (GA-R5): question as presented = "adopt the proposed cadence trigger (monthly review window; security pulls forward)?"; operator selection, exact utterance: "Adopt as proposed (Recommended)". Cadence = monthly review of `can-upgrade-to` + controller patch delta; non-empty review opens a maintenance window run via diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 295c6a5..76ff207 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -32,8 +32,8 @@ _Re-seeded from the 2026-07-21 evening scan (post-stage-3-close). Re-run `bash scripts/ledger-scan.sh` to refresh._ -- **PROPOSED / OPEN decisions:** D-068 (Vault substrate hardening, Roosevelt), D-071 (routine - update cadence + Juju controller patch policy), D-129 (RESOLVED as a decision 2026-07-21: all four subs ruled -- (i) COS scrapes edge per-DC, +- **PROPOSED / OPEN decisions:** D-068 (Vault substrate hardening, Roosevelt), D-071 ADOPTED + 2026-07-21 (all four points ruled -- drops off the scan), D-129 (RESOLVED as a decision 2026-07-21: all four subs ruled -- (i) COS scrapes edge per-DC, (ii) os-frr to Roosevelt design, (iii) per-site Tailscale = dedicated node not edge, (iv) MAAS NTP hierarchy stays; office1 live install + qga retrofit remain as G13 execution items; entry drops off the scan's open list), D-131 (node-facing DNS strategy for