diff --git a/docs/audit/uca-origin-asbuilt-comparison-20260802.txt b/docs/audit/uca-origin-asbuilt-comparison-20260802.txt index 38b16a1..205c6b9 100644 --- a/docs/audit/uca-origin-asbuilt-comparison-20260802.txt +++ b/docs/audit/uca-origin-asbuilt-comparison-20260802.txt @@ -78,3 +78,20 @@ anchor convention so the armored key appears ONCE, then apply via the Step-7 pattern. Fastest path to an unblocked deploy. COST: keeps dc0 diverged from the only proven configuration, and keeps per-DC key rotation as standing surface. + +-------------------------------------------------------------------------------------- +RULED 2026-08-02 -- OPTION (A). D-135 AMENDMENT 2026-08-02 (b). +-------------------------------------------------------------------------------------- +Operator, exact utterance: "Option A, converge. We have gathered the information we need +on the mirror buildout. It will be a future implementation but will not be used in +Roosevelt but much later so keep the information as informational only with no pin or +expectation on a future deployment date." + +dc0 converges on the apt caching proxy. The per-DC origin override is DELETED, not +repaired -- the proxy forwards whatever URL it is handed, so `cloud:jammy-caracal` (the +as-built value in FINDING 1, defined once behind bundle.yaml's anchors) works unmodified +and the signing-key problem ceases to exist. + +>>> THE MIRROR MATERIAL IN THIS FILE IS INFORMATIONAL ONLY. NO PIN, NO EXPECTED DATE, + NOT A ROOSEVELT ITEM. Do not convert it into a pinned item, a gap-register row, a + trigger, or a forward commitment. <<< diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 5f4b8e0..3d21ed0 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -7317,6 +7317,60 @@ **UNCHANGED:** dc1 is unaffected (it was already the proxy arm). Nothing here touches the currently-running dc0 mirror, which is verified intact (236/236 + 2/2 indices, 2026-08-02). +### AMENDMENT 2026-08-02 (b) -- D-135: dc0 CONVERGES NOW; THE EXPERIMENT IS COMPLETE AND ITS RESULT IS INFORMATIONAL ONLY + +**Operator ruling, exact utterance: "Option A, converge. We have gathered the information we +need on the mirror buildout. It will be a future implementation but will not be used in +Roosevelt but much later so keep the information as informational only with no pin or +expectation on a future deployment date."** + +**QUESTION AS PRESENTED.** The dc0 Stage-5 bundle deploy failed with nine units at +`hook failed: "install"`, root cause `NO_PUBKEY 5EDB1B62EC4926EA` -- the mirrored UCA is +reachable and its signatures intact, but no cloud-archive keyring reaches a freshly deployed +node, because the 2026-07-31 repoint replaced `cloud:jammy-caracal` with a raw `deb` line and +the `cloud:` path is what installs `ubuntu-cloud-keyring`. The as-built comparison +(`docs/audit/uca-origin-asbuilt-comparison-20260802.txt`) showed the only configuration this +project has ever deployed successfully is `cloud:jammy-caracal` on six apps, with ZERO raw +`deb` lines and ZERO `key:` options in any capture, and that the PROXY arm needs no override +at all. Options put: **(A)** converge dc0 on the proxy now and DELETE the origin block, +returning to the as-built configuration; **(B)** keep the mirror and restructure the armored +signing key behind a single YAML anchor. + +**RULED (A).** dc0's artifact strategy becomes the apt caching proxy +(`scripts/dc-cache-proxy.sh`, apt-cacher-ng on the D-134 utility `.4:3142`, consumed via +`juju model-config apt-http-proxy`), on the dc1 pattern. **Both DCs now run ONE strategy.** +The per-DC origin override is DELETED rather than repaired: the proxy forwards whatever URL it +is handed, so `cloud:jammy-caracal` -- the as-built-proven value, defined once behind +`bundle.yaml`'s `&openstack-origin` / `&ceph-source` anchors -- works unmodified, and the +signing-key problem does not exist to be solved. + +**THIS SUPERSEDES THE TRIGGER CLAUSE OF THE AMENDMENT ABOVE.** That amendment made convergence +conditional on a REBUILD of dc0's artifact service. This one converges on the ruling itself, +without waiting for a rebuild. + +**THE EXPERIMENT IS COMPLETE -- "we have gathered the information we need on the mirror +buildout".** The comparison the amendment above lists as "owed at the rebuild" is therefore +owed NOW, and it is the experiment's deliverable. It is recorded as EVIDENCE, and its status +is set by this ruling: + +**>>> INFORMATIONAL ONLY. NO PIN. NO EXPECTED DEPLOYMENT DATE. NOT A ROOSEVELT ITEM. <<<** +The operator's words are explicit: the mirror "will be a future implementation but will not be +used in Roosevelt but much later". So this material carries **no trigger, no owed work, no +review date, and no forward commitment.** It is retained because the comparison is worth +having, not because anything is scheduled on it. **A later session must NOT convert this into +a pinned item, a gap-register row, a deferred-forward item with a trigger, or a Roosevelt +delta** -- doing so would manufacture an expectation the operator explicitly declined to +create. `ledger-scan` and the forward-items register must stay clean of it. + +**WHAT `dc-mirror.sh` IS NOW.** Retained for the historical arm and for the currency lesson its +`check` encodes (assert on CONTENT, never on existence; an unrecognised state REFUSES). It is +NOT deleted. `dc-mirror.sh install ` is a deliberate strategy REVERSAL, never a repair. + +**NOT RULED HERE, and deliberately left alone:** whether the running dc0 mirror is torn down, +and when its 953 GB is reclaimed. Convergence is about which strategy the DEPLOY consumes; +dismantling the mirror is a separate destructive action needing its own approval. The mirror +may stand indefinitely without affecting this ruling. + ## D-140: PINNED -- OpenTofu management of the Juju layer, after a hardened and tested dc0 deployment [ARCH] **Status: PINNED 2026-08-02 to the end-of-deployment review.** Operator ruling, exact