diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index a274e27..6786936 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -2470,6 +2470,16 @@ line, D-119's selector-only discharge, annotation coverage measured 0/4 -> 4/4, the phase-6 expansion old-vs-new run in a real shell, live A12 on the headend, and both hosts' gates (gauntlet ALL GREEN 89 on vcloud AND voffice1; repo-lint 0 fail; ledger-scan unchanged). + - **THE ARTIFACT THAT FILED Q1 IS CORRECTED TOO**, or the loop just closed would reopen: + `docs/audit/queued-findings-20260730.txt` still presented Q1 as an open ruling that "blocks + any FQDN cert" with "A12 REFUSES (exit 3)" -- both now false. An APPENDED correction (not a + rewrite; the `stage4-mirror-gate-20260727.txt` precedent) records the withdrawal and names + the two wrong claims. **Q2 (D-137 fork 1) is unaffected and still stands.** + - One stale residue swept: `docs/dc-dc-deployment-workflow.md:257` still described phase-6 as + proposing `overlays/dc1-hostnames.yaml`/`dc2-hostnames.yaml`. The RUNBOOK had already been + corrected to the region-qualified `vr1-dc0`/`vr1-dc1` form by an earlier session; only the + workflow doc's description of it lagged. Under D-119 `${DC}` IS `vr1-dc0`, so the + `${DC}-hostnames.yaml` interpolation used elsewhere is correct as written. **A PRECEDENCE BUG THE HARNESS CAUGHT:** REFUSE was checked before FAIL, so once A12 armed, a CONFIRMED wrong-region SAN reported as "could not evaluate". A known defect outranks an unevaluated one; the verdict now reports FAIL first and still names the refusal. diff --git a/docs/audit/docfix205-d117-annotation-20260730.txt b/docs/audit/docfix205-d117-annotation-20260730.txt index 52eb8fe..abc0fe5 100644 --- a/docs/audit/docfix205-d117-annotation-20260730.txt +++ b/docs/audit/docfix205-d117-annotation-20260730.txt @@ -1,12 +1,12 @@ DOCFIX-205 CAPTURE -- 2026-07-30 -- Q1 withdrawal + the D-117 annotation half ============================================================================== -1. THE SUPERSESSION, quoted from D-117's own Status line: - and is NOT bent to fit the repo. Supersedes the `docs/dc-dc-netbox-buildout-scope.md` G5 - recommendation (which proposed the opposite, Option A) and the D-106 `dc1`/`dc2` zone labels. - Closes G5. +1. THE SUPERSESSION, quoted from D-117's Status line (docs/design-decisions.md): + "Supersedes the `docs/dc-dc-netbox-buildout-scope.md` G5 recommendation (which + proposed the opposite, Option A) and the D-106 `dc1`/`dc2` zone labels. Closes G5." -rules the replacement: "The repo's `dc1`/`dc2` labels are retired in favour of `dc0`/`dc1`." + And D-117's amendment rules the replacement: + "The repo's `dc1`/`dc2` labels are retired in favour of `dc0`/`dc1`." 2. D-119 scopes its discharge to the SELECTOR half only: it executes D-117's own amendment (region-qualify the shell selectors) across the three surfaces diff --git a/docs/audit/queued-findings-20260730.txt b/docs/audit/queued-findings-20260730.txt index c2f910a..4899921 100644 --- a/docs/audit/queued-findings-20260730.txt +++ b/docs/audit/queued-findings-20260730.txt @@ -112,3 +112,36 @@ - All 31 commits are pushed to origin. Nothing in the repo lives only on this jumphost. - The workstation ProxyJump config is operator-side and intentionally NOT in the repo; F11 records the reasoning it depends on. + +-------------------------------------------------------------------------- +APPENDED CORRECTION 2026-07-30 (DOCFIX-205) -- Q1 ABOVE IS WITHDRAWN +-------------------------------------------------------------------------- +Appended, not rewritten, per the precedent set by stage4-mirror-gate-20260727.txt (a wrong +causal claim superseded by an appended correction). The Q1 entry above stands as the record of +what was believed; this block records what was MEASURED when it was put to the operator. + +Q1 IS NOT A RULING QUESTION. It was ruled on 2026-07-13 by D-117, whose Status line names the +supersession directly -- "Supersedes ... and the D-106 `dc1`/`dc2` zone labels" -- and whose +amendment rules the replacement: "The repo's `dc1`/`dc2` labels are retired in favour of +`dc0`/`dc1`." So substrate `vr1-dc0` -> `dc0`, `vr1-dc1` -> `dc1`, and the VR1 zones are +`omega.dc0.vr1.cloud.neumatrix.local` / `omega.dc1.vr1.cloud.neumatrix.local`. D-008's +four-label shape is unchanged; D-119's single `vr1-dc0` token is NOT adopted for DNS. + +TWO CLAIMS IN THE Q1 ENTRY ABOVE ARE WRONG AND WOULD MISLEAD A READER: + - "it now blocks any FQDN cert" -- it did not. Measured live on the headend, A12 was in its + INERT branch and PASSED on BOTH DCs, because `os-public-hostname` is set in no deploy + artifact (B5 IP-only). It would have armed only at D-106's Stage-7 work. + - "ENFORCED, NOT FILED: A12 REFUSES (exit 3)" -- that refusal NO LONGER EXISTS. A12 now + ASSERTS the full expected zone, derived from the site token (`${SITE%%-*}` region, + `${SITE#*-}` DC label). Harness 21/21 -> 23/23. + +WHY IT RESURFACED (the reusable half): D-117 ruled that the ADOPTED decision texts +D-101/D-106/D-111/D-115 be ANNOTATED in place. ZERO of the four carried the annotation, so +D-106 read as though its retired labels were live. It stayed invisible because D-117's OWN +Status line claimed "FULLY EXECUTED BY D-119", while D-119 scopes its discharge to the +SELECTOR half only. All four are annotated and D-117's Status is corrected. + +Q2 (D-137 open fork 1) IS UNAFFECTED and still stands as written. + +Evidence: docs/audit/docfix205-d117-annotation-20260730.txt; changelog +docs/changelog-20260730-docfix205-d117-annotation.md. Status ONLY in CURRENT-STATE.md. diff --git a/docs/dc-dc-deployment-workflow.md b/docs/dc-dc-deployment-workflow.md index abd5f0a..42cb042 100644 --- a/docs/dc-dc-deployment-workflow.md +++ b/docs/dc-dc-deployment-workflow.md @@ -254,7 +254,7 @@ | **Gate** | Designate resolving A + AAAA; FQDN-SAN certs valid (D-019/D-021 root cause closed); COS scraping; a CAPI workload cluster comes up per DC. | | **Owns** | D-106 (Designate), D-105 (CAPI/COS). | | **Reuse vs new** | HIGH REUSE for CAPI/Magnum: `runbooks/phase-06-incloud-mgmt-cluster.md` + `phase-07-conductor-graft.md` + `phase-08-workload-cluster-acceptance.md` are direct precedent, per-DC. Designate is a REVERSAL, not new build: VR0 DC0 deferred it (D-019, "DNS scope reduction"); D-106 reactivates it (supersedes D-019, reactivates the original D-008 bootstrap order) -- read D-008 and D-019 together before writing this stage's runbook, the static-`/etc/hosts` workaround they document goes away. | -| **Authoring status** | **Runbook WRITTEN 2026-07-09: `runbooks/dc-dc-phase6-designate-cos-magnum.md`.** Quotes `bundle.yaml`'s and `phase-01-bundle-deploy.md`'s actual current "NO designate (D-019)" text verbatim rather than paraphrasing, then the D-106 reversal against it. Flags that the reversal is bigger than "add designate" -- D-106's bootstrap order also reactivates `os-public-hostname` per API charm, reversing the bundle's separate B5 IP-only posture; proposes (not silently adopts) pushing per-DC hostname literals into new `overlays/dc1-hostnames.yaml`/`dc2-hostnames.yaml` files to keep `bundle.yaml` itself DC-agnostic, mirroring the existing octavia-pki overlay pattern. D-046's domain-setup trap quoted verbatim in a top callout and again inline. COS deployment mechanism explicitly left as an operator decision point (D-105 rules only the scope) rather than invented. Reuses `phase-06/07/08` by filename with concrete DC-parameterization notes (confirmed via tracing which scripts source `lib-net.sh`). NOT YET EXECUTED. | +| **Authoring status** | **Runbook WRITTEN 2026-07-09: `runbooks/dc-dc-phase6-designate-cos-magnum.md`.** Quotes `bundle.yaml`'s and `phase-01-bundle-deploy.md`'s actual current "NO designate (D-019)" text verbatim rather than paraphrasing, then the D-106 reversal against it. Flags that the reversal is bigger than "add designate" -- D-106's bootstrap order also reactivates `os-public-hostname` per API charm, reversing the bundle's separate B5 IP-only posture; proposes (not silently adopts) pushing per-DC hostname literals into new `overlays/vr1-dc0-hostnames.yaml`/`vr1-dc1-hostnames.yaml` files to keep `bundle.yaml` itself DC-agnostic, mirroring the existing octavia-pki overlay pattern (this cell said `dc1-hostnames.yaml`/`dc2-hostnames.yaml` until DOCFIX-205, 2026-07-30 -- the retired pre-D-117 spelling, which the runbook itself had already been corrected to the region-qualified form; under D-119 `${DC}` IS `vr1-dc0`, so `${DC}-hostnames.yaml` is now the correct interpolation). D-046's domain-setup trap quoted verbatim in a top callout and again inline. COS deployment mechanism explicitly left as an operator decision point (D-105 rules only the scope) rather than invented. Reuses `phase-06/07/08` by filename with concrete DC-parameterization notes (confirmed via tracing which scripts source `lib-net.sh`). NOT YET EXECUTED. | **State:** runbook written, not yet executed (status authority: docs/CURRENT-STATE.md).