diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index fb73967..3d2483e 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2341,10 +2341,13 @@ apt-cacher-ng proxy hangs ~2 of 6 containers provisioned at once (today's CLOSE-WAIT class) -- remediated per appendix-A + switched to ONE app / 2 containers at a time (clean thereafter); (ii) hacluster scale-up briefly STOPS the leader VIP until cluster_count=3 reforms the cluster (~1-2 min) - -- harmless for stateless API apps, sequence keystone/vault deliberately. **REMAINING: Wave 2 - keystone (cloud-wide auth VIP blip) + nova-cloud-controller; Wave 3 rabbitmq; Wave 4 VAULT LAST -- - operator unseals each new unit (SEC-003, guard-hook-blocked for the agent) + cert-SAN check before - the VIP flip.** OWED: D-121 execution runbook (dc1 reuse); post-wave bundle/overlay review vs the + -- harmless for stateless API apps, sequence keystone/vault deliberately. **12 of 14 HA apps DONE at 3-unit HA (2026-08-05):** the 8 Wave-1 apps + + placement (pilot) + nova-cloud-controller + rabbitmq-server (native erlang 3-node cluster, no + hacluster) + barbican. New units on nova-cc/barbican settle DB/messaging relations transiently. + **REMAINING 2, BOTH OPERATOR-GATED: keystone** (cloud-wide auth VIP blip -- do when ready) **and + VAULT LAST** -- operator unseals each new unit (SEC-003, guard-hook-blocked for the agent) + + cert-SAN check before the VIP flip; vault HA also RESOLVES the barbican-vault `secrets-storage` + dependency. OWED: D-121 execution runbook (dc1 reuse); post-wave bundle/overlay review vs the live HA installs (pinned task). Body: `docs/changelog-20260805-d121-ha-scaleup.md`. **NAMED-GATE DEFECT found by measurement -- `phase-03-core-verify.md` Step 3.1 asserts expected non-active/idle = 1 (octavia only); the VR1 roster yields 4 deferred-by-design + gss.** That gate