diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 5c73c3a..e600253 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2409,10 +2409,18 @@ per-UNIT is what avoided a false "override missing"). The probe is grounded in the real policy (`domain-manager-policy.yaml:103` create_grant managed-role guard); reusable for dc1's Step 7. (c) REMAINING phase-03 exit-gate item, NOT among the original 2: the exit gate's "Horizon - reachable AND login works" requirement -- F-CV3 fixed the VIP TLS, but D-044 cookie override + - D-075 root-redirect are PER-REBUILD (not applied this rebuild) and the VR0 external-nginx-repoint - model needs reconciling against the VR1 metal-admin-VIP-over-tailnet access model (Decision C). - To be MEASURED + RULED next before phase-03 closes. + reachable AND login works" requirement. RECONCILED 2026-08-07 (Decision C): measured that both + dashboard VIPs serve HTTPS login 200 + csrftoken from on-segment, and that D-044 (Secure-cookie + override) + the VR0 external-nginx-repoint are VR0-plain-HTTP-leg artifacts that would only + WEAKEN the cookie under the VR1 direct-HTTPS-over-tailnet access model. **Operator directive: + close Horizon PROPERLY by pulling the tailnet-access build forward -- "We need to pull the + tailscale steps forward so we can close out horizon properly."** So Step 3.3 (Horizon) SPLITS + into its own gate row (GA-R6/E3, no conditional close) gated on: the per-DC Tailscale + subnet-router build (D-129(iii) amendment 2026-08-07, rulings a-d, BOTH DCs) + the vault root + CA imported on the operator workstation (NOT done -- operator confirmed) + a browser login to + `https://10.12.8.58` over the tailnet. **phase-03 does NOT close this session; Step 3.3 travels + forward as its own gate.** The cert's IP-SAN already covers 10.12.8.58 (F-CV3), so CA-trust is + the only cert residual. D-044/D-075/nginx-repoint are NOT applied (VR0-specific; would regress). F-CV1: designate _admin backend DOWN -- **RESOLVED 2026-08-06 (BUNDLEFIX-056, operator-approved fix EXECUTED + VERIFIED).** Root cause (governing = D-052 + generic binding rule + the D-020 amendment's ruled .62 triple, NOT D-141): designate's bundle bindings OMITTED public + internal, diff --git a/docs/changelog-20260806-step34-g3-probe.md b/docs/changelog-20260806-step34-g3-probe.md index d4259c9..72f77f8 100644 --- a/docs/changelog-20260806-step34-g3-probe.md +++ b/docs/changelog-20260806-step34-g3-probe.md @@ -78,3 +78,40 @@ - gauntlet ALL GREEN (100 harnesses); g3 confirmed EXECUTED in-gauntlet (12 pass / 0 fail). - repo-lint 0 fail / 1 legacy warn (D-001..018 ASCII carve-out). - ledger-scan: decisions + SEC unchanged; no D/DOCFIX/BUNDLEFIX number consumed (new tooling). + +## Item 5 -- Decision C: phase-03 Horizon reconciled to VR1; Step 3.3 splits to its own gate + +WHAT: measured (read-only, dc0 rack) that BOTH dashboard VIPs serve Horizon login over HTTPS +200 + csrftoken (metal-admin 10.12.8.58 AND provider 10.12.4.58), that D-044/D-075 are NOT +applied this rebuild, and that the cert SAN on 10.12.8.58 already includes IP:10.12.8.58 (F-CV3). +Concluded (operator-directed reframing): D-044 (Secure-cookie override) + the VR0 external-nginx +repoint are artifacts of the VR0 plain-HTTP proxy leg and would only WEAKEN the cookie under the +VR1 direct-HTTPS-over-tailnet access model. Operator: "We need to pull the tailscale steps +forward so we can close out horizon properly." -> phase-03 does NOT close this session; Step 3.3 +(Horizon) splits into its own gate row (GA-R6/E3), gated on the per-DC Tailscale build + the +vault root CA on the operator workstation (NOT done) + a browser login over the tailnet. +REVERT: revert the CURRENT-STATE phase-03 (c)-clause hunk. + +## Item 6 -- D-129(iii) amendment: per-DC Tailscale operator-access rulings (a)-(d), BOTH DCs + +WHAT: recorded four GA-R5 rulings (2026-08-07) as a D-129(iii) amendment (advisor-corrected: +these are D-129 implementation sub-decisions, NOT a new D-143 -- D-129(iii) already says ACL/ +key-custody/SEC-row land at implementation): (a) dedicated VM at utility .7 (10.12.8.7 / +10.12.68.7); (b) STAR operator->DC only (the Headscale ACL / security boundary); (c) SINGLE +router, HA scale-up PINNED; (d) SNAT ON now, source-IP preservation PINNED. Operator directive +"Lets plan and push to both DC0 and DC1 in this step" -> both DCs. Also: corrected the D-107 +citation defect (D-107 is airgap/mirror/NTP, rules nothing about Tailscale; D-129(iii) governs) +as a DOCFIX-in-amendment; extended D-134's standing octet map to .7 (D-134 AMENDMENT 2026-08-07); +updated the gap-21 register row (rulings made, build in progress) and CURRENT-STATE. +WHY: GA-R5 requires rulings committed before dependent work (the build). The four-rulings-before- +build precondition (gap-21) is now discharged. +REVERT: revert the D-129/D-134 amendment blocks + the gap-21 + CURRENT-STATE hunks (no code, no +cloud change -- records only). + +## Still owed (the build, next -- NOT done this commit) +- `scripts/site-tailscale.sh ` (install/check) + harness; the .7 VM per DC (inner-tofu + for_each); Tailscale tagged join + advertise + SNAT-on; Headscale star ACL + autoApprovers + (written BEFORE first advertise) + fix the Office1 untagged-node defect; SEC row (key custody); + browser login confirm over tailnet (needs the vault root CA on the workstation). +- Headscale server version remains UNMEASURED (operator has no access this session) -> tag + + autoApprovers support verified EMPIRICALLY at apply time. diff --git a/docs/dc-dc-deployment-workflow.md b/docs/dc-dc-deployment-workflow.md index 026db60..ea4f9f8 100644 --- a/docs/dc-dc-deployment-workflow.md +++ b/docs/dc-dc-deployment-workflow.md @@ -1123,6 +1123,16 @@ tailscale installation in DC0 and add it as a requirement for DC1 and any future installations."* + **>>> RULED + PULLED FORWARD 2026-08-07. <<<** All four sub-decisions (a)-(d) below are + RULED (GA-R5, D-129(iii) AMENDMENT 2026-08-07 in `docs/design-decisions.md`): (a) dedicated + VM at utility `.7`; (b) STAR (operator->DC only); (c) SINGLE router, HA scale-up PINNED; + (d) SNAT ON now, source-IP preservation PINNED. Operator directive "Lets plan and push to + both DC0 and DC1 in this step" -- so the build executes for BOTH DCs. Trigger to pull it + forward: closing phase-03 Horizon "properly" needs the real operator access path (browser + to the metal-admin dashboard VIP over the tailnet), not just the VIP serving TLS on-segment. + Build in progress; the four-rulings-before-build precondition is DISCHARGED. The text below + is retained as the requirement's origin + the vendor-research record. + **QUEUED, NOT EXECUTED** (hard rule 1 -- the current step is the Stage-5 deploy). This row is the requirement's home until it is built. diff --git a/docs/design-decisions.md b/docs/design-decisions.md index f4afac3..9ac140a 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -5508,6 +5508,62 @@ the governing copy; the text above stays as history (append-only register). The four OPEN sub-decisions (i)-(iv) are unaffected and remain OPEN on this entry. +### D-129(iii) -- AMENDMENT (2026-08-07): per-DC Tailscale subnet-router IMPLEMENTATION rulings (a)-(d) + +Sub-decision (iii) ruled the SHAPE (dedicated subnet-router node per site on metal-admin, edge +excluded). D-129(iii) itself states "per-site ACL scoping, key custody, and a SEC row land at +implementation" -- these are that implementation, ruled 2026-08-07 (GA-R5, one per exchange). +Operator directive framing them, verbatim: **"Lets plan and push to both DC0 and DC1 in this +step."** So the four rulings apply to BOTH DCs symmetrically and the build executes for both. +Standing per-DC-standup requirement (gap-register item 21; queued 2026-07-31 operator directive +"install tailscale in DC0, DC1, and any future DCs ... add it as a requirement"). + +- **(a) PLACEMENT + OCTET.** Question: dedicated VM vs co-locate; octet. Operator exact + utterance: **"Dedicated VM at utility .7 (Recommended)"**. A DEDICATED subnet-router VM in the + D-134 utility band at **`.7`** -- `10.12.8.7` (dc0) / `10.12.68.7` (dc1). Fate-separated from + the artifact mirror (.4) and MAAS region (.6). **This EXTENDS D-134's standing octet map: + `.4` artifact / `.5` Juju controller / `.6` MAAS region / `.7` Tailscale subnet router**; + divergence between DCs at the same octet remains a DEFECT (see the D-134 amendment of this date). +- **(b) REACHABILITY MODEL = STAR.** Question: star (operator->DC only) vs mesh. Operator exact + utterance: **"Star: operator->DC only (Recommended)"**. Operators reach each DC's metal-admin; + NO DC-to-DC management paths. This IS the security boundary -- an unpoliced Headscale is + allow-all, so the star is enforced by the Headscale ACL policy (tag:operators -> each DC + router's metal-admin; router<->router DENY). Keeps a compromised DC's blast radius inside that + DC, consistent with SEC-010/D-125. Cross-DC REPLICATION (rbd-mirror/radosgw) rides the + replication plane, not metal-admin, so it is not an argument for a management mesh. **[ARCH- + standing: a Roosevelt build session greps this before wiring operator access at region-region- + with-N-DCs scale; mesh's O(N^2) ACL does not survive it.]** +- **(c) HA COUNT = SINGLE, HA PINNED.** Question: one router vs two (HA). Operator exact + utterance: **"We will not be creating HA for this now. Pin HA scale up for Headscale/Tailscale."** + ONE subnet router per DC now; two-router HA is PINNED (deferred), alongside the D-121-class HA + scale-ups. This also discharges the Headscale-version dependency for the ruling: the >=0.18.0 + failover / >=0.29.0 HA-probing version gates only bind for two-router HA, which is not built. +- **(d) SNAT = ON now, source-IP preservation PINNED.** Question: `--snat-subnet-routes` on/off. + Operator exact utterance: **"SNAT ON now; pin source-IP preservation (Recommended)"**. The + router masquerades operator traffic (default on), so served metal-admin hosts need NO + route changes and access works immediately. Per-operator source-IP attribution in DC-side audit + logs (SNAT off + a `100.64.0.0/10` return route on the served hosts) is PINNED as a later + hardening with the HA scale-up. + +**CITATION CORRECTION (DOCFIX, gap-21 finding 2026-07-31, recorded here per append-only +discipline).** Earlier text in THIS entry cites "D-107 (Tailscale subnet-router VM)" and "D-107 +remains the governing decision for the Office1 installation". **D-107 is titled "Airgap posture, +per-DC artifact mirror, and NTP (VR1)" and rules NOTHING about Tailscale** (read in full +2026-07-31). D-129(iii) is ITSELF the governing per-site Tailscale-shape decision; the Office1 +installation and these per-DC installs are governed by D-129(iii), not D-107. + +**IMPLEMENTATION NOTES (vendor-researched 2026-07-31, not new rulings -- verified at build).** +(1) TAGGED identity, not user identity (Headscale tag removes user-auth + key-expiry); the +EXISTING Office1 node is UNTAGGED (`AdvertiseTags: null`, measured 2026-08-07) -> a 180-day +key-expiry outage risk, a DEFECT to fix in the same pass. (2) `autoApprovers` MUST be written to +the Headscale policy BEFORE a router first advertises (does not apply retroactively). (3) +Non-overlapping metal-admin CIDRs per DC permanently (`10.12.8.0/22` dc0 / `10.12.68.0/22` dc1; +Office1 `10.10.0.0/22`) -- a HARD addressing constraint (Headscale has no 4via6). (4) Headscale +server version is DEFERRED/unmeasured (Cloudflare-fronted; operator has no access this session); +tag support (>=0.28.0) + autoApprovers (>=0.17.0) are VERIFIED EMPIRICALLY at apply time, not +assumed. **SEC row for key custody opens at key-mint time in the build.** Roosevelt analog: +per-DC operator-access VPN, dedicated router, star ACL, per-DC key custody. + ## D-130: cloudinit seed-volume durable fix -- ignore_changes on the staging-derived create [ARCH] **Status:** ADOPTED 2026-07-19 (operator; GA-R5 -- question + utterance below; sweep Batch 1 item 3). @@ -5891,6 +5947,18 @@ work, and the controller VM cannot be commissioned until it has a `power_type` (measured EMPTY at enlistment -- the same state that blocked all nine role nodes on 2026-07-20). +## D-134 -- AMENDMENT (2026-08-07): the per-DC Tailscale subnet router takes utility-band .7 + +Extends the standing utility-band octet map by one slot, per the D-129(iii) implementation +ruling (a) of the same date (operator utterance "Dedicated VM at utility .7 (Recommended)"). +**The STANDING cross-DC utility-band octet map is now: `.4` artifact service (mirror or proxy) +/ `.5` Juju controller / `.6` MAAS region / `.7` Tailscale subnet router.** Addresses: +`10.12.8.7` (dc0) / `10.12.68.7` (dc1). Divergence between DCs at the same octet remains a +DEFECT (the standing rule this map encodes). Same scope note as the `.5` amendment: this +assigns the octet and the standing rule only; the MAAS record, tag, tofu pin, VM build, and +Tailscale join are separate gated work (the per-DC Tailscale build, both DCs). A future DC +standup carves `.7` for its subnet router by this standard. + ## D-134 -- AMENDMENT (2026-07-27): the bands become ENFORCED in MAAS, via a DC-aware tool; and v6 gains band discipline **Status:** RULED 2026-07-27 (operator, GA-R5). Question as presented, verbatim: "R4 --