diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index b3f5a33..05e8f45 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -28,13 +28,14 @@ `dc-dc-stage3-phase2-dc-substrate`; runbook `runbooks/dc-dc-phase2-tofu-dc-substrate.md`). Stages 0-2 precede it; stages 4-7 are authored, not executed (workflow doc:873). -- Position inside Stage 3: the DC0 outer `tofu apply` (deploy step A) is - OPEN at its gate (G9) -- the audit exit criteria are MET (2026-07-19); - what remains is the operator-gated, logged apply session itself, opening - with G8's same-session plane re-verify. Historical stop: `43b29d7` - (2026-07-18, post-reboot bounce risk -- since FIXED, D-130/G6). Nothing - DC0-scoped has been applied (`tofu -chdir=opentofu state list` shows no - `vvr1_dc0` or `vr1_dc0_uplink` resources; output quoted in section 2). +- Position inside Stage 3: deploy step A (the DC0 outer apply) EXECUTED + 2026-07-19 in the logged dc0-deploy window: 6 added / 0 changed / 6 + destroyed, exactly the saved plan; `vvr1-dc0` RUNNING (108 vCPU, 416 + GiB, autostart disable per D-127), `vr1-dc0-uplink` active, the six + vcloud planes destroyed (Model B relocation), both prior guests + untouched (ids 1/2). Convergence re-plan: no differences + (`docs/audit/outer-plan-20260719-postA-converged.txt`). ACTIVE gate: + G10 (steps B-E). - The grounding audit is COMPLETE and EXITED (2026-07-19): Phases 1-6 all closed (charter `148dcef`; rulings `docs/audit/ga-rulings.md`; the Phase-5 sweep ran as six operator-gated batches in one session; exit @@ -180,17 +181,15 @@ - pre-reboot gate was 5/0/6 (recorded at `docs/dc0-deploy-readiness.md:59`, `docs/session-ledger.md:278`). -The EXPECTED outer plan triple is **6 add / 0 change / 6 destroy**, -recorded 2026-07-19 with its evidencing capture -(`docs/audit/outer-plan-20260719-postG6.txt`, "Plan: 6 to add, 0 to -change, 6 to destroy."). WHY: 6 add = the 5 committed DC0 creates -(vvr1_dc0 domain/disk/seed/cloudinit + vr1_dc0_uplink) + voffice1's -benign staging-ISO re-create; 6 destroy = exactly the 6 empty relocated -planes; 0 change = D-130's guard suppressed the seed replace (v8) AND -the G6 state surgery recorded the already-true autostart. History: 7/2/7 -was the post-reboot symptom (decomposition at -`docs/audit/env-snapshot-20260718.md:33-46`); 6/2/6 was post-D-130 -pre-reconcile (v8 capture). A future plan differing from 6/0/6 is a STOP. +The EXPECTED outer plan is **ZERO DIFF** ("no changes needed"), recorded +2026-07-19 post-step-A with its evidencing capture +(`docs/audit/outer-plan-20260719-postA-converged.txt`). WHY: step A +applied the saved 6/0/6 plan exactly (pre-apply capture +`outer-plan-20260719-preapply.txt` matched the recorded triple; G8 +same-session planes check passed first). History: 7/2/7 post-reboot +symptom -> 6/2/6 post-D-130 -> 6/0/6 post-G6-reconcile -> applied. +A future outer plan showing ANY diff is a STOP (investigate drift +before touching anything). ## 6. Open gates @@ -208,8 +207,8 @@ | G5 | D-130 mechanism ruling (seed-volume durable fix) | [R] operator rules in Phase 5, quoting G4's captured output | operator | CLOSED 2026-07-19: D-130 ADOPTED (a) ignore_changes (`docs/design-decisions.md` D-130, GA-R5 utterance quoted); implemented in `modules/cloudinit-vm` + `tests/cloudinit-vm` | | G6 | State reconcile of autostart + seed WITHOUT bouncing guests | [R] gated mechanism, operator-ruled (S3) | operator | CLOSED 2026-07-19: ruled (ii) state surgery (GA-R5); pull -> inject autostart:true on both domains -> push (serial 22->23, backup `terraform.tfstate.pre-G6-20260719`); guests never touched (ids 1/2 unchanged, running) | | G7 | New captured plan == the expected triple recorded in section 5 | [V] re-plan to a capture file after G5+G6 | session | CLOSED 2026-07-19: capture `docs/audit/outer-plan-20260719-postG6.txt` = 6/0/6, equals section 5 exactly | -| G8 | Same-session pre-apply re-verify: 6 planes still empty (0 leases / 0 attached domains) | [V] run in the SAME session as the apply | session | Last verified in a prior session only (finding doc:259-265) | -| G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | OPEN: audit exit criteria MET 2026-07-19 (G1-G7, G11 closed; exit runs pass); closes on the operator-gated logged apply, with G8's same-session plane re-verify as its first step; state shows nothing DC0 applied | +| G8 | Same-session pre-apply re-verify: 6 planes still empty | [V] run in the SAME session as the apply | session | CLOSED 2026-07-19: verified in the apply session itself (all six 0 leases; only office1 nets attached) immediately before step A | +| G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | CLOSED 2026-07-19: G8 same-session planes check passed (6x 0 leases, 0 attachments); saved plan == 6/0/6 applied in the logged dc0-deploy window; convergence re-plan = no differences; vvr1-dc0 running, prior guests untouched | | G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Not reached (`docs/dc0-deploy-readiness.md:67-84,170-179`) | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | | G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator | HELD (`docs/dc0-deploy-readiness.md:100-103`) | diff --git a/docs/audit/outer-plan-20260719-postA-converged.txt b/docs/audit/outer-plan-20260719-postA-converged.txt new file mode 100644 index 0000000..d1fab52 --- /dev/null +++ b/docs/audit/outer-plan-20260719-postA-converged.txt @@ -0,0 +1,24 @@ +module.vvr1_dc0.libvirt_cloudinit_disk.seed: Refreshing state... [id=4666ca51f035e4d8] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=775234004c2669d9] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.vr1_dc0_uplink.libvirt_network.site_wan: Refreshing state... [id=f3500153-e4de-45f1-8854-9c92974a6094] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.vvr1_dc0.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-cloudinit.iso] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.vvr1_dc0.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] +module.vvr1_dc0.libvirt_domain.vm: Refreshing state... [name=vvr1-dc0] + +No changes. Your infrastructure matches the configuration. + +OpenTofu has compared your real infrastructure against your configuration and +found no differences, so no changes are needed. diff --git a/docs/audit/outer-plan-20260719-preapply.txt b/docs/audit/outer-plan-20260719-preapply.txt new file mode 100644 index 0000000..a97b746 --- /dev/null +++ b/docs/audit/outer-plan-20260719-preapply.txt @@ -0,0 +1,390 @@ +module.vr1_dc0_planes.libvirt_network.plane["metal-internal"]: Refreshing state... [id=99768f9d-256a-4a89-90dd-38de04efea03] +module.vr1_dc0_planes.libvirt_network.plane["replication"]: Refreshing state... [id=295dca85-52de-4e78-9894-16e48d969654] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.vr1_dc0_planes.libvirt_network.plane["storage"]: Refreshing state... [id=e5558f0e-9601-48fc-8eff-6a0e6adad0d7] +module.vr1_dc0_planes.libvirt_network.plane["data-tenant"]: Refreshing state... [id=31782537-790a-4399-a3a9-64dce7232e7b] +module.vr1_dc0_planes.libvirt_network.plane["metal-admin"]: Refreshing state... [id=29eca094-9b40-4e8c-9750-d1c7857f0a3c] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.vr1_dc0_planes.libvirt_network.plane["provider-public"]: Refreshing state... [id=3bb1e17c-53ce-4c1a-a4af-c9d6ad1f1c1b] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=775234004c2669d9] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] + +Note: Objects have changed outside of OpenTofu + +OpenTofu detected the following changes made outside of OpenTofu since the +last "tofu apply" which may have affected this plan: + + # module.office1_opnsense.libvirt_domain.vm has changed + ~ resource "libvirt_domain" "vm" { + ~ id = 13 -> 2 + name = "office1-opnsense" + # (11 unchanged attributes hidden) + } + + # module.voffice1.libvirt_domain.vm has changed + ~ resource "libvirt_domain" "vm" { + ~ id = 14 -> 1 + name = "voffice1" + # (11 unchanged attributes hidden) + } + + +Unless you have made equivalent changes to your configuration, or ignored the +relevant attributes using ignore_changes, the following plan may include +actions to undo or respond to these changes. + +───────────────────────────────────────────────────────────────────────────── + +OpenTofu used the selected providers to generate the following execution +plan. Resource actions are indicated with the following symbols: + + create + - destroy + +OpenTofu will perform the following actions: + + # module.voffice1.libvirt_cloudinit_disk.seed will be created + + resource "libvirt_cloudinit_disk" "seed" { + + id = (known after apply) + + meta_data = <<-EOT + instance-id: voffice1-d114 + local-hostname: voffice1 + EOT + + name = "voffice1-cloudinit" + + network_config = <<-EOT + version: 2 + ethernets: + lan: + match: + name: "en*" + dhcp4: true + EOT + + path = (known after apply) + + size = (known after apply) + + user_data = <<-EOT + #cloud-config + hostname: voffice1 + fqdn: voffice1.cloud.neumatrix.local + manage_etc_hosts: true + users: + - name: jessea123 + groups: [adm, sudo] + shell: /bin/bash + sudo: "ALL=(ALL) NOPASSWD:ALL" + ssh_authorized_keys: + - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINOgHIEyfMecOJ/G2Tbw5kKMd4ofUfxdyhVb00cjcpUX vr1-office1-svc + package_update: true + packages: + - qemu-guest-agent + runcmd: + - [systemctl, enable, --now, qemu-guest-agent] + EOT + } + + # module.vr1_dc0_planes.libvirt_network.plane["data-tenant"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "data-tenant.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "31782537-790a-4399-a3a9-64dce7232e7b" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-data-tenant" -> null + - uuid = "31782537-790a-4399-a3a9-64dce7232e7b" -> null + } + + # module.vr1_dc0_planes.libvirt_network.plane["metal-admin"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "metal-admin.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "29eca094-9b40-4e8c-9750-d1c7857f0a3c" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-metal-admin" -> null + - uuid = "29eca094-9b40-4e8c-9750-d1c7857f0a3c" -> null + } + + # module.vr1_dc0_planes.libvirt_network.plane["metal-internal"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "metal-internal.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "99768f9d-256a-4a89-90dd-38de04efea03" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-metal-internal" -> null + - uuid = "99768f9d-256a-4a89-90dd-38de04efea03" -> null + } + + # module.vr1_dc0_planes.libvirt_network.plane["provider-public"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "provider-public.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "3bb1e17c-53ce-4c1a-a4af-c9d6ad1f1c1b" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-provider-public" -> null + - uuid = "3bb1e17c-53ce-4c1a-a4af-c9d6ad1f1c1b" -> null + } + + # module.vr1_dc0_planes.libvirt_network.plane["replication"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "replication.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "295dca85-52de-4e78-9894-16e48d969654" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-replication" -> null + - uuid = "295dca85-52de-4e78-9894-16e48d969654" -> null + } + + # module.vr1_dc0_planes.libvirt_network.plane["storage"] will be destroyed + # (because libvirt_network.plane is not in configuration) + - resource "libvirt_network" "plane" { + - autostart = true -> null + - domain = { + - name = "storage.vr1-dc0.cloud.neumatrix.local" -> null + } -> null + - id = "e5558f0e-9601-48fc-8eff-6a0e6adad0d7" -> null + - mtu = { + - size = 9000 -> null + } -> null + - name = "vr1-dc0-storage" -> null + - uuid = "e5558f0e-9601-48fc-8eff-6a0e6adad0d7" -> null + } + + # module.vr1_dc0_uplink.libvirt_network.site_wan will be created + + resource "libvirt_network" "site_wan" { + + autostart = true + + domain = { + + name = "vr1-dc0-uplink" + } + + forward = { + + mode = "nat" + } + + id = (known after apply) + + ips = [ + + { + + address = "172.30.2.1" + + prefix = 24 + }, + ] + + mtu = { + + size = 1500 + } + + name = "vr1-dc0-uplink" + + uuid = (known after apply) + } + + # module.vvr1_dc0.libvirt_cloudinit_disk.seed will be created + + resource "libvirt_cloudinit_disk" "seed" { + + id = (known after apply) + + meta_data = <<-EOT + instance-id: vvr1-dc0-d123 + local-hostname: vvr1-dc0 + EOT + + name = "vvr1-dc0-cloudinit" + + network_config = <<-EOT + version: 2 + ethernets: + mgmt: + match: + name: "enp1s0" + set-name: mgmt + addresses: ["172.31.0.2/30"] + routes: + - to: "10.10.0.0/22" + via: "172.31.0.1" + uplink: + match: + name: "enp2s0" + set-name: uplink + dhcp4: false + dhcp6: false + bridges: + br-vr1-dc0-wan: + interfaces: [uplink] + dhcp4: false + dhcp6: false + parameters: + stp: false + forward-delay: 0 + EOT + + path = (known after apply) + + size = (known after apply) + + user_data = <<-EOT + #cloud-config + hostname: vvr1-dc0 + fqdn: vvr1-dc0.cloud.neumatrix.local + manage_etc_hosts: true + users: + - name: jessea123 + groups: [adm, sudo] + shell: /bin/bash + sudo: "ALL=(ALL) NOPASSWD:ALL" + ssh_authorized_keys: + # D-126 per-env-key (ruling 2026-07-16, option a): vvr1-dc0 authorizes the DEDICATED + # dc0 key, NOT office1's -- per-env blast-radius isolation. Inner root's qemu+ssh matches. + - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID54oMqwY4majxq4oWpBviXb6DlVyj99TUPxDkhszcZG vr1-dc0_svc (D-126 per-env key) + package_update: true + packages: + - qemu-guest-agent + runcmd: + - [systemctl, enable, --now, qemu-guest-agent] + EOT + } + + # module.vvr1_dc0.libvirt_domain.vm will be created + + resource "libvirt_domain" "vm" { + + autostart = false + + cpu = { + + features = [] + + mode = "host-passthrough" + } + + devices = { + + disks = [ + + { + + driver = { + + type = "qcow2" + } + + source = { + + volume = { + + pool = "vr1-dc0-pool" + + volume = "vvr1-dc0-disk.qcow2" + } + } + + target = { + + bus = "virtio" + + dev = "vda" + } + }, + + { + + device = "cdrom" + + source = { + + volume = { + + pool = "vr1-dc0-pool" + + volume = "vvr1-dc0-cloudinit.iso" + } + } + + target = { + + bus = "sata" + + dev = "sda" + } + }, + ] + + interfaces = [ + + { + + model = { + + type = "virtio" + } + + source = { + + network = { + + network = "mesh-vr1-dc0-office1" + } + } + }, + + { + + model = { + + type = "virtio" + } + + source = { + + network = { + + network = "vr1-dc0-uplink" + } + } + }, + ] + } + + features = { + + acpi = true + + apic = {} + } + + id = (known after apply) + + memory = 425984 + + memory_unit = "MiB" + + name = "vvr1-dc0" + + os = { + + type = "hvm" + + type_arch = "x86_64" + + type_machine = "q35" + } + + running = true + + type = "kvm" + + uuid = (known after apply) + + vcpu = 108 + } + + # module.vvr1_dc0.libvirt_volume.disk will be created + + resource "libvirt_volume" "disk" { + + allocation = (known after apply) + + backing_store = { + + format = { + + type = "qcow2" + } + + path = "/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2" + } + + capacity = 3221225472000 + + id = (known after apply) + + key = (known after apply) + + name = "vvr1-dc0-disk.qcow2" + + path = (known after apply) + + physical = (known after apply) + + pool = "vr1-dc0-pool" + + target = { + + format = { + + type = "qcow2" + } + + path = (known after apply) + } + } + + # module.vvr1_dc0.libvirt_volume.seed will be created + + resource "libvirt_volume" "seed" { + + allocation = (known after apply) + + capacity = (known after apply) + + create = { + + content = { + + url = (known after apply) + } + } + + id = (known after apply) + + key = (known after apply) + + name = "vvr1-dc0-cloudinit.iso" + + path = (known after apply) + + physical = (known after apply) + + pool = "vr1-dc0-pool" + } + +Plan: 6 to add, 0 to change, 6 to destroy. + +───────────────────────────────────────────────────────────────────────────── + +Note: You didn't use the -out option to save this plan, so OpenTofu can't +guarantee to take exactly these actions if you run "tofu apply" now. diff --git a/docs/session-ledger.md b/docs/session-ledger.md index e2aad16..adf5f31 100644 --- a/docs/session-ledger.md +++ b/docs/session-ledger.md @@ -116,3 +116,12 @@ fresh probe trio 21/21 (7/7 on all three); operator RE-SIGNED CURRENT-STATE 2026-07-19. - AUDIT EXITED: G3 + G11 CLOSED, FREEZE lifted, G9 OPEN (gated logged apply, G8 first). - Full body: docs/archive/session-20260719-phase5-sweep.md. Status lives ONLY in CURRENT-STATE.md. + +## SESSION 2026-07-19 (continued) -- DC0 deploy, step A (logged: dc0-deploy) + +- Same session continued past the audit close at operator direction (skill re-invoked; fresh-session + hygiene noted and waived by the operator's go). +- G8 passed in-session; validate PASS; pre-apply capture == 6/0/6; saved plan applied: 6/0/6 exact. +- vvr1-dc0 RUNNING (108 vCPU / 416 GiB / autostart off); guests untouched; convergence = no diff. +- Next: step B (bootstrap vvr1-dc0: site-headend-install --role rack --host-nodes + SEC-010 check, + OPNsense base prep ON the VM) -- needs transit reachability + the dc0 key (D-126 DC rows).