diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index a9d53ab..9b7d408 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -716,7 +716,18 @@ works and would MASK a regression. **Incidental corroboration of R8 from this repo's own tooling: that VR0-era verifier expecting an `fc00::/` ULA on o-hm0 independently confirms the charm's default lb-mgmt-subnet is an IPv6 ULA.** - Remaining: R9-R10 blocking, R12-R15 standing. + **G18 OPENED 2026-07-27 by operator direction (BLOCKING, ruling-type).** The follow-on + question from R8 -- does the charm-created `lb-mgmt-net` prefix get back-filled into the + NetBox apex, or is that plane recorded as deliberately charm-owned and out of apex scope + -- is NOT answerable from artifacts. Operator direction, verbatim: "leave this as an open + decision that will need a ruling once we have the cloud live and we have a better read on + the network and how everything is functioning with the addition of the new IPv6 + configurations. Make this a gated decision so we cannot close the project (or whatever + phase you think it best ruled in) without a ruling on this item." Placed as **gate G18** + (section 6): ANSWERABLE from Stage 5 onward once the prefix exists, **BLOCKING at the + FINAL stage close / project close**. Ruling it early would also pre-empt the UNRULED D-136 + render-pipeline decision, which covers the same apex-authority ground. + Remaining: R9-R10 blocking, R12-R15 standing; G18 deferred-and-gated. - Position inside Stage 3: deploy step A EXECUTED 2026-07-19 (6/0/6 exact; convergence zero -- `docs/audit/outer-plan-20260719-postA-converged.txt`). **Deploy step B @@ -1184,6 +1195,8 @@ | G16 | office1 edge `channels = []` state reconcile (the D-129 module-schema residual) | [R] operator rules the mechanism; then [V] the converged re-plan capture | operator + session | CLOSED 2026-07-21: RULED "State surgery (Recommended)" (GA-R5, session changelog item 16); executed per G6 precedent -- channels null -> [] injected, serial 29 -> 30, backup kept, guests untouched (office1-opnsense Id 2 running throughout); convergence = ZERO DIFF (`docs/audit/outer-plan-20260721-postG16-converged.txt`); section 5 re-recorded | | G17 | **Per-DC artifact source reachable FROM A NODE** -- the node-side half of Stage 4 DoD bullet 5, split out of Stage 4 by operator ruling rather than closed conditionally | [V] a NAMED executable check run from a node that has actually booted an OS on its real NICs, per DC, each capturing: dc0 -> `curl -sI http://10.12.8.4/` returns 200 from the node (the D-135 item-1 full mirror); dc1 -> the node resolves and fetches through the apt proxy at `10.12.68.4:3142` (the D-135-AMENDED ruled artifact path -- dc1 has NO node-facing mirror, so checking it as one would fail by design). The natural trigger is Stage 5 first boot, when Juju provisions the nodes and they run apt for real; a gated MAAS rescue-boot is the alternative if it must be answered sooner | session (each boot operator-approved) | **OPEN 2026-07-27.** WHY THIS EXISTS: the DoD bullet reads "per-DC mirror reachable from nodes", but the READY-handoff ruling (2026-07-23, DOCFIX-200) leaves all 18 nodes powered off in `Ready` -- MAAS-deploy is SKIPPED and Juju provisions at Stage 5 -- so no node-side probe can run inside Stage 4 at all. GA-R6 E3 forbids a conditional close, so the remainder splits here. RULING (GA-R5). Question as presented 2026-07-27: "The node-side half of bullet 5. Nodes are powered off by the READY-handoff ruling, so no node-side probe can run as things stand. Either a gated rescue-boot check on one node per DC now (closes it inside Stage 4), or split it into its own gate row targeted at Stage 5 first boot (GA-R6 E3 explicitly permits this; a conditional close is not permitted)." Operator answer, exact utterance: **"split it into its own gate row"**. SCOPE NOTE: what stays in Stage 4 is the RACK-side half -- the artifact source answers on its own address with an attested-current sync -- which is what `dc-mirror.sh check` / `dc-cache-proxy.sh check` verify (both fixed this session to stop false-greening; capture `docs/audit/stage4-mirror-gate-20260727.txt`). G17 is NOT a Stage-5 precondition and must not be conflated with one: Stage 5's own bootstrap needs OPEN edge egress for the juju agent stream + snaps (D-135 items 2-3 unbuilt), which is a different path from the apt artifact source this gate covers. | +| G18 | **IPAM apex completeness for the Octavia lb-mgmt plane** -- does the charm-created `lb-mgmt-net` prefix get BACK-FILLED into the NetBox apex, or is that plane recorded as deliberately charm-owned and out of apex scope? | [R] ruling-type gate (GA-R6 rule 6): closes ONLY on a GA-R5 recorded ruling with the operator's exact utterance, dated, committed and pushed. **DEFERRED BY OPERATOR DIRECTION 2026-07-27 until the cloud is LIVE and IPv6 behaviour has been observed** -- it is not answerable from artifacts alone. **BLOCKING: the deployment may NOT be declared complete while this is open.** ANSWERABLE from Stage 5 onward (the prefix exists once Octavia deploys); BLOCKS the FINAL stage close / project close. | operator | **OPEN 2026-07-27.** WHY IT EXISTS: R8 ruled that Octavia creates and owns its own IPv6 lb-mgmt network. Measured consequence -- the octavia charm exposes NO CIDR, address-family or router configuration option (`create-mgmt-network`, default True, is the only related option), so the prefix is CHARM-GENERATED and cannot come from the D-111 carve. NetBox is therefore knowingly INCOMPLETE for exactly one plane. That is the authority-inversion concern the Stage-5 grounding audit's lens 7 raised (the apex being back-filled to match a deploy rather than driving it), and it is adjacent to the UNRULED D-136 NetBox-coupled render pipeline -- so ruling it early would pre-empt D-136. OPERATOR DIRECTION, verbatim: "leave this as an open decision that will need a ruling once we have the cloud live and we have a better read on the network and how everything is functioning with the addition of the new IPv6 configurations. Make this a gated decision so we cannot close the project (or whatever phase you think it best ruled in) without a ruling on this item." RELATED AND ALSO RECORDED: the absence of an lb-mgmt `:x80` prefix in the VR1 ULA carve is CORRECT under R8, not a gap -- see the D-101 R8 ruling note; a future session must not "fix" it. Options to present at ruling time: (a) back-fill the charm-created prefix into NetBox post-deploy as a documented record; (b) record the plane as charm-owned and explicitly out of apex scope; (c) fold the decision into D-136's render-pipeline ruling if that is taken first. | + ## 7. Version pins (measured; the authority for every pin) | Component | Measured value | Command (run 2026-07-18) | Where measured | diff --git a/docs/audit/queued-rulings-20260727.md b/docs/audit/queued-rulings-20260727.md index 80adccd..417c7b9 100644 --- a/docs/audit/queued-rulings-20260727.md +++ b/docs/audit/queued-rulings-20260727.md @@ -517,6 +517,32 @@ --- +## R16 (GATED, DEFERRED) -- IPAM apex completeness for the Octavia lb-mgmt plane + +**Tracked as gate G18 in `docs/CURRENT-STATE.md` section 6, which is the authority.** +Not answerable from artifacts: it needs the cloud LIVE and a read on how IPv6 is +actually behaving. **BLOCKING -- the deployment may not be declared complete while it +is open.** Answerable from Stage 5 onward (the prefix exists once Octavia deploys). + +Arises from R8: the octavia charm exposes no CIDR/family/router option, so the +`lb-mgmt-net` prefix is charm-generated and NetBox is knowingly incomplete for that one +plane. Adjacent to the UNRULED D-136, so ruling it early would pre-empt that decision. + +Operator direction, verbatim (2026-07-27): "leave this as an open decision that will +need a ruling once we have the cloud live and we have a better read on the network and +how everything is functioning with the addition of the new IPv6 configurations. Make +this a gated decision so we cannot close the project (or whatever phase you think it +best ruled in) without a ruling on this item." + +**Options to present at ruling time:** (a) back-fill the charm-created prefix into +NetBox post-deploy as a documented record; (b) record the plane as charm-owned and +explicitly out of apex scope; (c) fold it into D-136's render-pipeline ruling if that +is taken first. + +OPERATOR UTTERANCE: *(deferred by direction -- do NOT rule from artifacts)* + +--- + ## R12. G17's scope: does it carry the node time-source check? **Finding:** L1-8. `docs/CURRENT-STATE.md:852` lists only the artifact-reachability diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 87381fa..7c8b5be 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -2251,6 +2251,14 @@ than a gap -- the prefix is charm-generated and cannot come from the apex. That absence should be recorded as DELIBERATE so a later reader does not "fix" it. +**APEX COMPLETENESS IS GATED, NOT SETTLED -- see gate G18.** Because the prefix is +charm-generated, NetBox is knowingly INCOMPLETE for this one plane. Whether it gets +back-filled post-deploy or is recorded as deliberately out of apex scope was DEFERRED BY +OPERATOR DIRECTION 2026-07-27 until the cloud is live and IPv6 behaviour has been observed, +and made a BLOCKING ruling-type gate: **the deployment may not be declared complete while +G18 is open.** Ruling it early would also pre-empt the unruled D-136 render-pipeline +decision, which covers the same apex-authority ground. + **STANDING OBLIGATION, carried by the operator's own reasoning:** LP #2018998 ("MTU mismatch between o-hm0 and lb-mgmt-net", charm-octavia, High) is Fix Released across our lineage but **recurred 2025-12-31 against octavia 14.0.0 / 2024.1 stable -- our exact pin**. A jumbo