diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 50278e5..c20f358 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -479,7 +479,7 @@ | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator + session | CLOSED 2026-07-23 (operator-ruled "Merge to main + full close"; commissioning 9/9 READY, merge commit on `main`, branch retired) -- [R] leg CLOSED 2026-07-21: addressing RATIFIED (D-124 amendment 2026-07-21, utterance quoted). [V] leg IN PROGRESS (branch `dc-dc-g12-dc1-substrate`): apex confirm-free DONE 2026-07-21 -- planes/uplink already assigned+consistent, transit 172.31.0.4/30 + rack 10.12.68.2 FREE (`docs/audit/dc1-apex-confirm-20260721.txt`); importer per-site dc1 support shipped (harness 117/117) with live dry-run preflight PASS (`docs/audit/dc1-rack-import-dryrun-20260721.txt`). vars + substrate root + lib-net dc1 arm COMMITTED 2026-07-22 (successor session landed the disconnected item 3 + the harness reconcile as changelog item 4): six harnesses reconciled to the ratified dc1 arm, phase-00 PLANES parity guard added, rbd-mirror/radosgw cross-DC reminder fixed; gauntlet **ALL GREEN (76)** (`docs/audit/gauntlet-20260722-g12-reconcile.txt`), repo-lint 0-fail. Apex `--commit` EXECUTED 2026-07-22 (operator-gated): 172.31.0.4/30 + 10.12.68.2/22 CREATED, post-commit read-back idempotent (`docs/audit/dc1-rack-import-commit-20260722.txt`). dc1 svc key minted (creds-audit CLEAN), tfvars authored (local), **outer step-A apply DONE 2026-07-22**: saved plan 5/0/0 exact, converged ZERO DIFF (section 5), vvr1-dc1 RUNNING, prior guests untouched (as-executed log dc1-deploy; changelog-20260722-g12-dc1-build.md). **Step B COMPLETE 2026-07-22**: cloudinit-vm interface_macs port + voffice1 dc1-transit NIC (0/2/0 exact, MACs pinned both domains, post-bounce battery ALL PASS, converged zero diff -- `docs/audit/outer-plan-20260722-voffice1-dc1nic.txt`), transit LIVE (voffice1 .5/30 <-> rack .6/30, dc1-key ssh proven), rack ENROLLED (region lists vvr1-dc1 `nmpcq4`), SEC-010 applied+verified BOTH ends, OPNsense 26.7 base staged via hash-verified copy of dc0's proven artifact; named gate EXIT 0 `docs/audit/dc1-stepB-check-20260722-final.txt` (changelog-20260722 items 5-8, three queued findings). **Step C COMPLETE 2026-07-22**: inner apply FROM voffice1 -- plan 28/0/0 exact (54 pinned MACs verified in-capture), one fix-forward (serial-log staging dir absent on dc1; queued to standup DoD), resume 10/0/0 exit 0; 28/28 in state, convergence ZERO DIFF (`docs/audit/inner-converge-20260722-dc1-stepC.txt`), **10/10 domains RUNNING inside vvr1-dc1**, edge at the 26.7 FreeBSD login prompt (D-112 datapoint #2); dc1 inner tfstate ON voffice1 (site backup set). **D-125 egress gate PASS 2026-07-22** (two identical runs, dc0 criteria exact, isolation confirmed -- `docs/audit/d125-egress-gate-20260722-dc1.txt`). **Edge bootstrap + v4 addressing COMPLETE 2026-07-23** (changelog-20260723-g12-dc1-edge.md): D-112(c) console bootstrap done (SSH + dc1 edge key materialized; payload needed `util.inc`/`shell_safe()` -- dc0 lesson iv the `.b64` artifact lacked), key-only SSH VERIFIED (`15.1-RELEASE-p1`); D-113(a2) API key MINTED via the vendor model + smoke test `GET core/firmware/status` exit 0 `product_abi 26.7` (second 26.7 datapoint); edge ADDRESSED -- WAN `172.30.3.2/24` gw `172.30.3.1` (egress 1.1.1.1 0% loss), LAN `192.168.1.1` -> `10.12.64.1/22` (ruled provider-public gw), API answers at the new LAN; interim reach leg removed, rack provider-public leg `10.12.64.2/22` LIVE on virbr4. Creds consolidated to `~/vr1-dc1-creds/opnsense-api.txt` (creds-audit CLEAN, 5 entries); rack edge-key copy shredded (**SEC-015** transient, remediated). Two queued findings: bootstrap `.b64` missing `util.inc`; `opnsense-bootstrap-apikey.sh` scp had a transient post-restart-sshd failure (readiness-wait/retry candidate). **Rack standup + region MAAS config DONE 2026-07-23** (changelog-20260723 items 7-11): dc-rack-net.sh dc1 arm shipped (harness 18/18, gauntlet 76 GREEN) + INSTALLED on the rack (check 10/10, forwarder answers authoritative maas-internal SOA -- D-131 fix; `docs/audit/dc1-rack-net-install-20260723.txt`); region MAAS on metal-admin subnet 11 -- D-120 range 10.12.68.100-.200, D-131 dns_servers=10.12.68.3 allow_dns=false, DHCP dhcp_on=true primary_rack=nmpcq4 (dhcpd verified RUNNING on virbr6, no Temporal incident); **dc1 enlistment PROVEN** via canary (machines 11->12 in ~2 min). **SEC-016 RULED + WIRED 2026-07-23** (operator: "Mint a dedicated dc1 power key" -- per-DC isolation; dedicated key authorized on the rack + installed in the region MAAS snap with per-host ssh config, dc0's SEC-012 key untouched). **COMMISSIONING 9/9 READY 2026-07-23** (`docs/audit/dc1-commissioning-verify-20260723.txt`): all 9 nodes PXE-enlisted by pinned 52:54:01:d1 MACs, `power_type=virsh` set + verified by real query-power-state (SEC-016 path proven), commissioned to **ALL 9 READY in ~3.5 min** (no timeout, no SERVFAIL), shapes EXACT to D-121 Option C (3x16cpu/64GiB + 2x12cpu/48GiB + 4x8cpu/24GiB). dc0's two stacked faults pre-empted by pinned MACs + the dc-rack-net forwarder. **G12 [V] leg (the dc1 build) is COMPLETE.** NEXT: G12 close-out only -- consolidate this session's changelogs (GA-R2), final gauntlet + repo-lint, GA-R7 memory review, skill sweep, **operator-gated merge of `dc-dc-g12-dc1-substrate` -> `main`** (merge commit), branch retirement; then G12 CLOSES. NOTE open SEC rows now include SEC-014/-015/-016 (G14 row count stale -- reconcile in the close). | | G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | OPEN (execution only; decision content complete) | -| G14 | 9 OPEN SEC rows (SEC-001, -003..-008, plus SEC-012 + SEC-013 opened 2026-07-20 for credentials this deploy created; SEC-010 CLOSED 2026-07-20, operator-ruled, applied+verified both transit ends) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012 also carries a SCOPE question (libvirt-group grant is broader than the power verbs MAAS needs), SEC-013 is tied to whether `opentofu/vr1-dc0-maas` is retired | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-20 | +| G14 | 12 OPEN SEC rows (SEC-001, -003..-008, SEC-012, -013, -014, plus SEC-015 + SEC-016 opened 2026-07-23 for dc1 credentials; SEC-010/-011 CLOSED) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012/-016 carry the same libvirt-group SCOPE hardening question; SEC-016 also a snap-refresh re-assert (queued to DC standup DoD) | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-23 (12 open) | | G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 remains PROPOSED/OPEN (items 2-3 + the item-1 re-scoped migration plan) | | G16 | office1 edge `channels = []` state reconcile (the D-129 module-schema residual) | [R] operator rules the mechanism; then [V] the converged re-plan capture | operator + session | CLOSED 2026-07-21: RULED "State surgery (Recommended)" (GA-R5, session changelog item 16); executed per G6 precedent -- channels null -> [] injected, serial 29 -> 30, backup kept, guests untouched (office1-opnsense Id 2 running throughout); convergence = ZERO DIFF (`docs/audit/outer-plan-20260721-postG16-converged.txt`); section 5 re-recorded | diff --git a/docs/session-ledger.md b/docs/session-ledger.md index 885062d..7442c12 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -30,7 +30,7 @@ ## Machine-derived (re-seed from `scripts/ledger-scan.sh`; do not hand-edit) -_Re-seeded from the 2026-07-21 evening scan (post-stage-3-close). Re-run `bash scripts/ledger-scan.sh` to refresh._ +_Re-seeded from the 2026-07-23 scan (post-G12-close/dc1-merge). Re-run `bash scripts/ledger-scan.sh` to refresh._ - **PROPOSED / OPEN decisions:** D-068 (Vault substrate hardening, Roosevelt), D-071 ADOPTED 2026-07-21 (all four points ruled -- drops off the scan), D-129 (RESOLVED as a decision 2026-07-21: all four subs ruled -- (i) COS scrapes edge per-DC, @@ -43,8 +43,10 @@ now surfaced by the scan itself after the PARTIAL fix), D-132 (Roosevelt per-DC MAAS topology -- PROPOSED 2026-07-21, operator-pinned to the next deployment). Status lines in `docs/design-decisions.md` are the only ruling authority. -- **OPEN security rows:** 10 open per `bash scripts/ledger-scan.sh` (re-verified at stage close; - SEC-013 surface NARROWED 2026-07-21, row still open for rotation). The SEC register of record +- **OPEN security rows:** 12 open per `bash scripts/ledger-scan.sh` (re-verified at G12 close + 2026-07-23; SEC-013 surface NARROWED 2026-07-21; SEC-015 (transient dc1 edge key on rack, + remediated) + SEC-016 (dedicated dc1 MAAS->libvirt power key, per-DC isolation) OPENED + 2026-07-23, both rotation obligations). The SEC register of record is `docs/security-ledger.md`; row-level dispositions live THERE only (GA-R4 amendment F3) -- this block carries pointer + count, never rows. - **Next-free numbers:** D = **133**, DOCFIX = **198**, BUNDLEFIX = 052. @@ -254,3 +256,22 @@ addressing -> rack standup DoD -> commissioning 9/9 -> G12 close-out; operator-gated merge to main is the hard new-session gate after that. - Details: docs/changelog-20260722-g12-dc1-build.md (items 1-10). Status lives ONLY in CURRENT-STATE.md. + +## SESSION CLOSE 2026-07-23 -- G12 dc1 edge->commission + CLOSE + MERGE (bounded, GA-R4) + +- Resumed from the 07-22 handoff (edge at login prompt); drove dc1 to a commissioned fleet, + every mutation operator-gated in `manual` permission mode (auto-mode classifier blocks + remote sudo shapes instead of prompting -- manual mode is the fix; noted). +- Edge: D-112(c) console bootstrap (payload needed util.inc/shell_safe -- dc0 lesson iv the + .b64 lacked) + key auth + D-113(a2) API mint (transient post-restart-sshd scp, ssh-pipe + workaround) + v4 addressing WAN 172.30.3.2 / LAN 10.12.64.1 (egress 0%). +- dc-rack-net dc1 arm (harness 18/18) + install (forwarder answers maas-internal); region MAAS + D-120 range + D-131 dns + DHCP primary_rack=nmpcq4 (dhcpd verified running). +- SEC-016 RULED "Mint a dedicated dc1 power key" (per-DC isolation) + wired (script=svc key, + MAAS snap=dedicated key). Commissioning ALL 9 READY ~3.5 min, shapes exact D-121 Option C -- + dc0's two stacked faults pre-empted by pinned MACs + forwarder. +- G12 CLOSED: gauntlet 76 GREEN, repo-lint 0-fail, consolidation + skill sweep (per-DC power + key invariant) + GA-R7 memory review; MERGED to main (merge commit a5c0a49), branch retired. +- Open after: SEC 12 rows (incl. SEC-015/-016); 3 findings (util.inc, scp readiness, snap-key + refresh fragility); D-068 item1, D-131 sub-4, D-132 pinned. Next stage branches off main. +- Full body: docs/archive/changelogs/changelog-20260723-g12-dc1-edge.md. Status ONLY in CURRENT-STATE.md.