diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 9570eb3..0674185 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2471,9 +2471,16 @@ ran the credential one-shot (creds generated + stored `0600` `/root/dc1-maas-creds.txt` ON the `.6`, never in context): DB role+db, `maas init region+rack`, `createadmin`. **`http://10.12.68.6:5240/MAAS/` answers 301.** OWED: consolidate the `.6` creds to `~/vr1-dc1-creds/` + creds-matrix (SEC-020/D-137). - **NEXT: (a) register the `vr1-dc1-region` profile (via an SSH tunnel to `10.12.68.6:5240`, the dc0 - pattern); (b) config via the tested tools (topology/power-key/IPAM/DHCP/image-sync) + import the - `office1_svc` pubkey; (c) REBUILD the 9 nodes+juju+.7 FRESH into it (the `.6`/`.7` aux-carve exist).** + **`vr1-dc1-region` PROFILE REGISTERED + verified (changelog Item 10):** dc0-pattern SSH tunnel on + voffice1 (`-L 127.0.0.1:5243:10.12.68.6:5240` via the rack; profile URL = the tunnel endpoint, so + RE-OPEN the tunnel after any voffice1 reboot before `maas vr1-dc1-region ...`); apikey piped + `.6`->stdin `maas login -` (never exposed); rack = `vr1-dc1-maas-01` (qtw8pm), 0 machines (empty). + **NEXT (all `--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01`, tested tools): (a) + `dc-region-topology.sh apply` (6-plane fabrics/subnets/VLANs); (b) `maas-region-power-key.sh` + (SEC-016 dc1 key into the `.6` snap) + `dc-plane-ipam.sh` + DHCP + jammy image sync; (c) import the + `office1_svc` pubkey; (d) REBUILD the 9 nodes+juju+.7 FRESH into it -- delete each from Office1 + `admin`, then power/enlist/commission/deploy/carve into `vr1-dc1-region`, naming each `vr1-dc1--NN` + (D-134 amdt); the aux-carve + lib-hosts octet/MAC map already cover every host.** F-CV1: designate _admin backend DOWN -- **RESOLVED 2026-08-06 (BUNDLEFIX-056, operator-approved fix EXECUTED + VERIFIED).** Root cause (governing = D-052 + generic binding rule + the D-020 amendment's ruled .62 triple, NOT D-141): designate's bundle bindings OMITTED public + internal, diff --git a/docs/changelog-20260807-dc0-tailscale-provisioning.md b/docs/changelog-20260807-dc0-tailscale-provisioning.md index 370b636..96f8751 100644 --- a/docs/changelog-20260807-dc0-tailscale-provisioning.md +++ b/docs/changelog-20260807-dc0-tailscale-provisioning.md @@ -264,3 +264,32 @@ REVERT: `sudo maas init --skip-... ` teardown or re-image the `.6` (release+deploy); the DB is local to the `.6`. No other host depends on it yet (profile not registered). + +## Item 10 -- vr1-dc1-region profile registered + verified (LIVE) + +WHAT: opened the dc0-pattern SSH tunnel on voffice1 -- `ssh -f -N -L 127.0.0.1:5243:10.12.68.6:5240 +jessea123@172.31.0.6` (voffice1 has NO L3 to the dc1 metal-admin; the tunnel goes voffice1->rack->.6; +dc0 uses 5241 for its region, PID still up). Region answers 301 via the tunnel. Registered the profile +WITHOUT exposing the API key: piped `maas apikey --username admin` from the `.6` (via the vcloud +office1_svc key) STRAIGHT into `maas login vr1-dc1-region http://127.0.0.1:5243/MAAS/ -` (stdin `-`), +so the key flowed .6->pipe->voffice1 and never entered a variable or my context. VERIFIED: +`maas vr1-dc1-region rack-controllers read` -> rack `vr1-dc1-maas-01` (qtw8pm, the .6 = region+rack); +`machines read` -> 0 (empty, correct -- the 9 nodes + juju + .7 are still in Office1, to be rebuilt in). + +NOTE: the profile URL is the TUNNEL endpoint (`127.0.0.1:5243`); if voffice1 reboots or the tunnel +dies, re-open it before any `maas vr1-dc1-region` command (dc0 has the same dependency, changelog +20260730 Item 3). Expected-rack for dc1 config/carve tooling = `vr1-dc1-maas-01`. + +REVERT: `maas logout vr1-dc1-region` (drops the profile); kill the tunnel PID on voffice1. + +## Where the dc1-region workstream stands (handoff) + +DONE: region VM bootstrapped (Items 7-8) + MAAS LIVE (Item 9) + profile registered (Item 10). REMAINING, +all against `--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01` (tested tools, tunnel must be up): +(1) `dc-region-topology.sh apply` -- build the 6-plane fabrics/spaces/subnets/VLANs in the empty region; +(2) `maas-region-power-key.sh` -- install the SEC-016 dc1 power key INTO the .6's snap (needs a .6 shell +via office1_svc); (3) `dc-plane-ipam.sh` reserved ranges + DHCP on metal-admin + jammy image sync; +(4) import the office1_svc pubkey into the region (so deployed nodes get it); (5) REBUILD the 9 role +nodes + juju + .7 FRESH into vr1-dc1-region -- delete each from the Office1 `admin` region, then +power/enlist/commission/deploy/carve into vr1-dc1-region (the .6/.7 aux-carve + the octet/MAC map in +lib-hosts already cover every host). Naming convention (D-134 amdt): set each to `vr1-dc1--NN`. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index d2aeb79..536a3dc 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -284,16 +284,13 @@ - Gates: repo-lint 0 fail (1 legacy warn); gauntlet ALL GREEN 101 AFTER the node-vm reconcile. Sweep: docs/audit/queued-findings-20260807-tailscale-substrate.txt (O1-O4 FIRST SURFACE). Body: docs/changelog-20260806-step34-g3-probe.md. - NEXT: when Headscale access -> the join + Office1-untagged fix; else MAAS commission/deploy/carve/install the 3 VMs + the dc1 region setup; then Horizon-over-tailnet confirm closes Step 3.3. Status ONLY in CURRENT-STATE.md. -## SESSION CLOSE 2026-08-07 (dc0 tailscale) -- dc0 Tailscale .7 driven to CARVED-AND-READY + aux-carve tooling (bounded, GA-R4) +## SESSION CLOSE 2026-08-07 (dc0 tailscale + dc1 region) -- dc0 .7 carved-and-ready; naming convention; vr1-dc1-region LIVE (bounded, GA-R4) -- Branch dc-dc-stage5-preconditions; pushed `d36d815..c8ddfb6` (2 commits) + this bookend. voffice1 synced. Scan: 4 open decisions, SEC 29, next-free D-143 / DOCFIX-213 / BUNDLEFIX-059 (NO new numbers -- implements the D-129(iii) amendment). -- dc0 .7 subnet-router DRIVEN TO CARVED-AND-READY (all gated, read back): power set (`10.12.8.2`) -> commissioned Ready -> carve pass=8/0 (metal-admin `10.12.8.7` + provider-public `10.12.4.7`, no br-ex) -> MAAS-deployed jammy; BOTH legs live (ping 0% from the rack). MEASURED correction: the .7 had ALREADY self-enlisted as `known-marten` (prior close's "powered off" omitted the enlisted part). -- NEW aux-carve tooling: `dc-node-carve.sh` `is_tailscale_host`/`is_two_plane_host` + lib-hosts `CARVE_AUX_HOSTS` (isolates the .7 from every HOSTS consumer); harness 58/0; gauntlet ALL GREEN 101. -- RULINGS (verbatim): dc1 = "No migration. Build region on DC1 correctly." (dc1 .7 GATED behind building `vr1-dc1-region` -- MEASURED not registered); the join key on hand is PLAIN (not tag-scoped) -> the Tailscale JOIN stays blocked. -- TWO JOIN PREREQS remain (off-session): a TAGGED pre-auth key + Headscale autoApprovers/ACL; SSH access via `vr1-office1-svc` (region injects only that key -- operator holds it). -- OWNED: nearly read the prior close's "powered off" as "not enlisted" (measured `known-marten` first); the advisor caught the unverified provider-public leg (then measured both legs live) and the missing bookend; `run-logged.sh` NOT opened (O3, 2nd consecutive -- a background agent cannot drive its interactive subshell). -- Gates: repo-lint 0 fail (1 legacy warn); gauntlet ALL GREEN 101 (docs-only edits since). Sweep: `docs/audit/queued-findings-20260807-dc0-tailscale-provisioning.txt` (F1-F4 FIRST SURFACE: no per-DC MAAS-region-build runbook; the vr1-office1-svc inject vs SEC-012/016; phase-3 aux-deploy DOCFIX). Body: `docs/changelog-20260807-dc0-tailscale-provisioning.md`. -- POST-BOOKEND (same session): operator naming correction -> renamed dc0 known-marten->vr1-dc0-tailscale-01 + subtle-grouse->vr1-dc0-juju-01 (all 11 dc0-region names now vr1-dc0-*); recorded the standing convention as **D-134 AMENDMENT 2026-08-07** ("Record that as the preferred naming convention going forward") + lib-hosts comment. dc1 node-handling RULED "Rebuild fresh into dc1-region" (build region, then power/enlist/commission/deploy the 9 nodes+juju FRESH into it -- NOT delete+re-enlist). -- dc1-region STARTED + `.6` region VM DONE to Deployed: `normal-piglet`->`vr1-dc1-maas-01`, power set -> recommissioned -> aux-carve EXTENDED for `-maas-01` (commit 9fea7c1, gauntlet 101) -> carved 10.12.68.6 + 10.12.64.6 (--profile admin, all 3 Office1 racks) -> **Deployed jammy, both legs live** (ping 0%). MAAS 3.7 install/init researched (changelog Items 7-8; external DB, createadmin=SEC-020). -- **vr1-dc1-region MAAS is LIVE** (changelog Item 9): shared `vr1-office1-svc` key found ON VCLOUD (`~/vr1-office1-creds/office1_svc_ed25519`); reached the .6 from vcloud (key local, ProxyCommand via voffice1->rack); snap egress via the snapd proxy 10.12.68.2:8000; maas 3.7.2 + postgresql 16.14; operator-authorised credential one-shot (creds generated+stored 0600 on the .6, never in context) -> `http://10.12.68.6:5240/MAAS/` answers 301. OWED: consolidate .6 creds to ~/vr1-dc1-creds/ (SEC-020). -- NEXT (dc1): (a) register `vr1-dc1-region` profile (SSH tunnel to 10.12.68.6:5240, dc0 pattern); (b) config via tested tools (topology/power-key/IPAM/DHCP/image-sync) + import office1_svc pubkey; (c) REBUILD 9 nodes+juju+.7 fresh into it. Separately dc0 Step 3.3 closes on a TAGGED key + Headscale access -> `site-tailscale.sh install` -> browser login `https://10.12.8.58`. Status ONLY in CURRENT-STATE.md. +- Branch dc-dc-stage5-preconditions; commits `d36d815..9216bdf` (+ a final close) all pushed; voffice1 synced. Scan: 4 open decisions, SEC 29, next-free D-143 / DOCFIX-213 / BUNDLEFIX-059 (NO new numbers). Body: `docs/changelog-20260807-dc0-tailscale-provisioning.md` (Items 1-10). Sweep: `docs/audit/queued-findings-20260807-dc0-tailscale-provisioning.txt` (F1-F4). +- dc0 `.7` DRIVEN TO CARVED-AND-READY (gated): power->commission->carve pass=8/0 (metal-admin 10.12.8.7 + provider-public 10.12.4.7, no br-ex)->deploy jammy, both legs live. C2 correction: it had already self-enlisted (`known-marten`). Join still blocked (PLAIN key + no Headscale ACL; `.7` reachable only via vr1-office1-svc). +- NEW aux-carve tooling: `dc-node-carve.sh` is_tailscale/is_region/is_two_plane_host + lib-hosts CARVE_AUX_HOSTS (isolates aux VMs from HOSTS consumers); harness 63/0; gauntlet 101. +- NAMING convention corrected + RULED standing: renamed dc0 machines to `vr1-dc0-*`; **D-134 AMENDMENT** ("Record that as the preferred naming convention going forward") + lib-hosts comment + memory. +- dc1 RULED "No migration. Build region on DC1 correctly." + "Rebuild fresh into dc1-region"; then BUILT it: `.6` (`vr1-dc1-maas-01`) power->recommission->carve (10.12.68.6/10.12.64.6, `--profile admin`)->deploy jammy; **vr1-dc1-region MAAS LIVE** (maas 3.7.2 + postgresql 16.14; the shared vr1-office1-svc key is ON VCLOUD `~/vr1-office1-creds/office1_svc_ed25519`; reached the .6 from vcloud; snap egress via snapd proxy; operator-authorised credential one-shot, creds 0600 on the .6, never in context; `10.12.68.6:5240/MAAS/`->301). PROFILE registered+verified (voffice1 tunnel -L 5243; rack vr1-dc1-maas-01, 0 machines). +- OWNED: nearly read "powered off" as "not enlisted" (measured first); advisor caught the unverified provider-public leg + the missing bookend; a false-negative `curl -x` 400 vs snap-egress-works (tested definitively); `run-logged.sh` NOT opened (O3, 3rd consecutive). +- OWED: consolidate the .6 MAAS creds to `~/vr1-dc1-creds/` (SEC-020); RE-OPEN the voffice1:5243 tunnel after any reboot before `maas vr1-dc1-region ...`. +- NEXT (dc1, `--profile vr1-dc1-region --expect-rack vr1-dc1-maas-01`, tunnel up): `dc-region-topology.sh apply` (6-plane) -> `maas-region-power-key.sh` (.6 snap) + `dc-plane-ipam.sh` + DHCP + jammy image sync -> import office1_svc pubkey -> REBUILD 9 nodes+juju+.7 fresh in (delete from Office1 admin -> enlist/commission/deploy/carve, name vr1-dc1--NN). Separately dc0 Step 3.3 on a TAGGED key + Headscale. Status ONLY in CURRENT-STATE.md.