diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index f3c3dd1..31c2bda 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -441,19 +441,19 @@ `docs/session-ledger.md:278`). The EXPECTED outer plan is **ZERO DIFF** ("no differences"), -re-recorded 2026-07-21 with its evidencing capture -(`docs/audit/outer-plan-20260721-postG16-converged.txt`) after the -operator-ruled G16 state surgery (channels null -> [] injected on the -office1 edge's state entry, serial 29 -> 30, backup -`terraform.tfstate.pre-G16-20260721`; guests never touched -- G6 -precedent). A future outer plan showing ANY diff is a STOP -(investigate drift before touching anything). History: 7/2/7 +re-recorded 2026-07-22 with its evidencing capture +(`docs/audit/outer-plan-20260722-postdc1-converged.txt`) after the +G12 dc1 substrate step-A apply (saved plan 5/0/0 exact -- vvr1-dc1 + +vr1-dc1-uplink adds only, zero touches to live resources). A future +outer plan showing ANY diff is a STOP (investigate drift before +touching anything). History: 7/2/7 post-reboot symptom -> 6/2/6 post-D-130 -> 6/0/6 post-G6-reconcile -> applied exact -> zero diff -> 1/1/1 (voffice1 transit, ruled+applied) -> 2/0/2 (rack netplan fix, applied) -> zero diff converged 2026-07-20 -> 1/1/0 netem-wire STOP -> targeted netem apply 1/0/0 exact -> 0/1/0 -office1 residual -> G16 state surgery -> zero diff converged (this -entry). +office1 residual -> G16 state surgery -> zero diff converged 2026-07-21 +-> 5/0/0 dc1 substrate adds (G12 step A, saved-plan applied exact +2026-07-22) -> zero diff converged (this entry). ## 6. Open gates @@ -475,7 +475,7 @@ | G9 | DC0 outer apply (deploy step A) | [V] operator-gated, logged (`run-logged.sh`), after G1-G8; audit exit criteria met (charter Phase 6). SEC pre-apply dependency (S2): SEC-010's transit FORWARD-drop is applied+verified at deploy step B via `site-headend-install.sh --host-nodes --check` on vvr1-dc0 (gate G10) -- the ONLY SEC row gated on this apply (register of record: security-ledger). CANONICAL ENTRY DOC (probe hole H1): `runbooks/dc-dc-phase2-tofu-dc-substrate.md`, with `docs/dc0-deploy-readiness.md` section E as the step table | operator | CLOSED 2026-07-19: G8 same-session planes check passed (6x 0 leases, 0 attachments); saved plan == 6/0/6 applied in the logged dc0-deploy window; convergence re-plan = no differences; vvr1-dc0 running, prior guests untouched | | G10 | Deploy steps B-E in-sequence gates: SEC-010 `--host-nodes --check` on vvr1-dc0; depth-4 nested boot; D-125 foreign-MAC egress test; MAAS reachability + `TF_VAR_maas_api_key` before step D; netem placeholder step E | [V] exercised during the gated deploy | session (each mutation operator-approved) | Step B DONE 2026-07-20 (`--check` EXIT 0 incl. SEC-010, `docs/audit/stepB-check-20260720-final.txt`; interfaces enp1s0/enp2s0). Depth-4 nested boot DONE (10 domains running inside vvr1-dc0). D-125 egress isolation test PASS 2026-07-20 (`docs/audit/d125-egress-gate-20260720-matrix.txt`), and the edge itself now egresses 0% loss after the v4 addressing. Step D COMPLETE incl. commissioning: ALL 9 NODES READY 2026-07-21 (two stacked faults diagnosed + fixed -- `docs/audit/commissioning-diag-20260721.txt`; section 1). Step E (netem) DONE 2026-07-21: sudo fragment installed+verified, module local-mode amendment, targeted apply 1/0/0 exact (operator-ruled at the 1/1/0 STOP), placeholder profile live on virbr5, virbr7/virbr3 untouched (`docs/audit/stepE-netem-20260721.txt` + `outer-{plan,apply}-20260721-netem*.txt`). **G10 CLOSED 2026-07-21** | | G11 | Operator signs THIS document | [R] read top-to-bottom; discrepancies resolved in the document | operator | CLOSED: RE-SIGNED 2026-07-19 at audit exit, section 11 (replaces the 2026-07-18 signature) | -| G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator + session | OPEN -- [R] leg CLOSED 2026-07-21: addressing RATIFIED (D-124 amendment 2026-07-21, utterance quoted). [V] leg IN PROGRESS (branch `dc-dc-g12-dc1-substrate`): apex confirm-free DONE 2026-07-21 -- planes/uplink already assigned+consistent, transit 172.31.0.4/30 + rack 10.12.68.2 FREE (`docs/audit/dc1-apex-confirm-20260721.txt`); importer per-site dc1 support shipped (harness 117/117) with live dry-run preflight PASS (`docs/audit/dc1-rack-import-dryrun-20260721.txt`). vars + substrate root + lib-net dc1 arm COMMITTED 2026-07-22 (successor session landed the disconnected item 3 + the harness reconcile as changelog item 4): six harnesses reconciled to the ratified dc1 arm, phase-00 PLANES parity guard added, rbd-mirror/radosgw cross-DC reminder fixed; gauntlet **ALL GREEN (76)** (`docs/audit/gauntlet-20260722-g12-reconcile.txt`), repo-lint 0-fail. PENDING: operator-gated apex `--commit` (transit /30 + rack IP -- the only owed apex write), then tfvars + gated build | +| G12 | `vr1-dc1` build | [R] operator rules dc1 transit/rack addressing; then vars + substrate authored | operator + session | OPEN -- [R] leg CLOSED 2026-07-21: addressing RATIFIED (D-124 amendment 2026-07-21, utterance quoted). [V] leg IN PROGRESS (branch `dc-dc-g12-dc1-substrate`): apex confirm-free DONE 2026-07-21 -- planes/uplink already assigned+consistent, transit 172.31.0.4/30 + rack 10.12.68.2 FREE (`docs/audit/dc1-apex-confirm-20260721.txt`); importer per-site dc1 support shipped (harness 117/117) with live dry-run preflight PASS (`docs/audit/dc1-rack-import-dryrun-20260721.txt`). vars + substrate root + lib-net dc1 arm COMMITTED 2026-07-22 (successor session landed the disconnected item 3 + the harness reconcile as changelog item 4): six harnesses reconciled to the ratified dc1 arm, phase-00 PLANES parity guard added, rbd-mirror/radosgw cross-DC reminder fixed; gauntlet **ALL GREEN (76)** (`docs/audit/gauntlet-20260722-g12-reconcile.txt`), repo-lint 0-fail. Apex `--commit` EXECUTED 2026-07-22 (operator-gated): 172.31.0.4/30 + 10.12.68.2/22 CREATED, post-commit read-back idempotent (`docs/audit/dc1-rack-import-commit-20260722.txt`). dc1 svc key minted (creds-audit CLEAN), tfvars authored (local), **outer step-A apply DONE 2026-07-22**: saved plan 5/0/0 exact, converged ZERO DIFF (section 5), vvr1-dc1 RUNNING, prior guests untouched (as-executed log dc1-deploy; changelog-20260722-g12-dc1-build.md). NEXT (gated): dc1 step B analog -- transit leg 172.31.0.5/30 on voffice1, vvr1-dc1 bootstrap (site-headend rack role + SEC-010 both ends), OPNsense 26.7 staging; then inner apply FROM voffice1 (D-128) with first-apply MAC pins + D-131 standup DoD (dc-rack-net install, forwarder 10.12.68.3, maas-node-power) | | G13 | D-129 residuals | [R] operator-gated live plugin install on office1-opnsense; qga channel retrofit at that edge's next scheduled restart. All 4 sub-decisions RULED 2026-07-21 (D-129 Status line) -- only the two execution items remain | operator | OPEN (execution only; decision content complete) | | G14 | 9 OPEN SEC rows (SEC-001, -003..-008, plus SEC-012 + SEC-013 opened 2026-07-20 for credentials this deploy created; SEC-010 CLOSED 2026-07-20, operator-ruled, applied+verified both transit ends) | [R] per-row: rotations/flips at v1 close (external to VR1 track); SEC-012 also carries a SCOPE question (libvirt-group grant is broader than the power verbs MAAS needs), SEC-013 is tied to whether `opentofu/vr1-dc0-maas` is retired | operator / external | `docs/security-ledger.md` (register of record, GA-R4/F3); count re-verified vs `bash scripts/ledger-scan.sh` 2026-07-20 | | G15 | D-068 / D-071 rulings | [R] operator rules (section 8); neither blocks the VR1 substrate | operator | D-071 ADOPTED 2026-07-21 (all four points); D-068 remains PROPOSED/OPEN (items 2-3 + the item-1 re-scoped migration plan) | diff --git a/docs/audit/dc1-rack-import-commit-20260722.txt b/docs/audit/dc1-rack-import-commit-20260722.txt new file mode 100644 index 0000000..0cbe340 --- /dev/null +++ b/docs/audit/dc1-rack-import-commit-20260722.txt @@ -0,0 +1,29 @@ +# dc1 rack/transit importer COMMIT -- 2026-07-22T20:12:52Z -- piped to office1-netbox, token on-host (never printed) +Target : http://localhost:8000 (SANDBOX) + +*** COMMITTING. *** + +Transit prefix (office1<->vr1-dc1 mesh leg): + CREATED 172.31.0.4/30 (id=139) role=transit scope=vr1-dc1 + +Rack metal-admin static IP: + CREATED 10.12.68.2/22 (id=4) dns=vvr1-dc1 + +================================================================== +created: 2 already present: 0 +exit=0 +# dc1 rack/transit importer POST-COMMIT idempotency read-back -- 2026-07-22T20:13:54Z +Target : http://localhost:8000 (SANDBOX) + +*** DRY RUN -- nothing will be written. Re-run with --commit. *** + +Transit prefix (office1<->vr1-dc1 mesh leg): + EXISTS 172.31.0.4/30 + +Rack metal-admin static IP: + EXISTS 10.12.68.2/22 + +================================================================== +would create: 0 already present: 2 +DRY RUN -- nothing was written. Re-run with --commit. +exit=0 diff --git a/docs/audit/dc1-rack-import-dryrun-20260722.txt b/docs/audit/dc1-rack-import-dryrun-20260722.txt new file mode 100644 index 0000000..66f4a7d --- /dev/null +++ b/docs/audit/dc1-rack-import-dryrun-20260722.txt @@ -0,0 +1,15 @@ +# dc1 rack/transit importer DRY-RUN re-verify -- 2026-07-22T19:33:47Z -- piped to office1-netbox, token on-host (/root/netbox-secrets/api.token, never printed) +Target : http://localhost:8000 (SANDBOX) + +*** DRY RUN -- nothing will be written. Re-run with --commit. *** + +Transit prefix (office1<->vr1-dc1 mesh leg): + [dry-run] would CREATE 172.31.0.4/30 role=transit scope=dcim.site:vr1-dc1 + +Rack metal-admin static IP: + [dry-run] would CREATE 10.12.68.2/22 dns=vvr1-dc1 (metal-admin static band) + +================================================================== +would create: 2 already present: 0 +DRY RUN -- nothing was written. Re-run with --commit. +exit=0 diff --git a/docs/audit/outer-plan-20260722-dc1-substrate.txt b/docs/audit/outer-plan-20260722-dc1-substrate.txt new file mode 100644 index 0000000..631243d --- /dev/null +++ b/docs/audit/outer-plan-20260722-dc1-substrate.txt @@ -0,0 +1,252 @@ +module.netem_vr1_dc0_vr1_dc1.terraform_data.netem: Refreshing state... [id=1ea36d3f-e7af-984c-8157-152724a0b85a] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=a4694210c663c9ce] +module.vvr1_dc0.libvirt_cloudinit_disk.seed: Refreshing state... [id=ff281478c6083cc3] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.vr1_dc0_uplink.libvirt_network.site_wan: Refreshing state... [id=f3500153-e4de-45f1-8854-9c92974a6094] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.vvr1_dc0.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-cloudinit.iso] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.vvr1_dc0.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] +module.vvr1_dc0.libvirt_domain.vm: Refreshing state... [name=vvr1-dc0] + +Note: Objects have changed outside of OpenTofu + +OpenTofu detected the following changes made outside of OpenTofu since the +last "tofu apply" which may have affected this plan: + + # module.vvr1_dc0.libvirt_domain.vm has changed + ~ resource "libvirt_domain" "vm" { + ~ id = 4 -> 7 + name = "vvr1-dc0" + # (11 unchanged attributes hidden) + } + + +Unless you have made equivalent changes to your configuration, or ignored the +relevant attributes using ignore_changes, the following plan may include +actions to undo or respond to these changes. + +───────────────────────────────────────────────────────────────────────────── + +OpenTofu used the selected providers to generate the following execution +plan. Resource actions are indicated with the following symbols: + + create + +OpenTofu will perform the following actions: + + # module.vr1_dc1_uplink.libvirt_network.site_wan will be created + + resource "libvirt_network" "site_wan" { + + autostart = true + + domain = { + + name = "vr1-dc1-uplink" + } + + forward = { + + mode = "nat" + } + + id = (known after apply) + + ips = [ + + { + + address = "172.30.3.1" + + prefix = 24 + }, + ] + + mtu = { + + size = 1500 + } + + name = "vr1-dc1-uplink" + + uuid = (known after apply) + } + + # module.vvr1_dc1.libvirt_cloudinit_disk.seed will be created + + resource "libvirt_cloudinit_disk" "seed" { + + id = (known after apply) + + meta_data = <<-EOT + instance-id: vvr1-dc1-d124a + local-hostname: vvr1-dc1 + EOT + + name = "vvr1-dc1-cloudinit" + + network_config = <<-EOT + version: 2 + ethernets: + transit: + match: + name: "enp1s0" + addresses: ["172.31.0.6/30"] + routes: + - to: "10.10.0.0/22" + via: "172.31.0.5" + uplink: + match: + name: "enp2s0" + dhcp4: false + dhcp6: false + bridges: + br-vr1-dc1-wan: + interfaces: [uplink] + dhcp4: false + dhcp6: false + parameters: + stp: false + forward-delay: 0 + EOT + + path = (known after apply) + + size = (known after apply) + + user_data = <<-EOT + #cloud-config + hostname: vvr1-dc1 + fqdn: vvr1-dc1.cloud.neumatrix.local + manage_etc_hosts: true + users: + - name: jessea123 + groups: [adm, sudo] + shell: /bin/bash + sudo: "ALL=(ALL) NOPASSWD:ALL" + ssh_authorized_keys: + # D-126 per-env-key: vvr1-dc1 authorizes the DEDICATED dc1 key ONLY + # (~/vr1-dc1-creds/, D-124 amendment 2026-07-21). Inner root's qemu+ssh matches. + - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAWB2qmc9Qrb/iaWYy6aNioqARVM/H+VHaHPqBi+4g2t vr1-dc1_svc (D-126 per-env key) + package_update: true + packages: + - qemu-guest-agent + runcmd: + - [systemctl, enable, --now, qemu-guest-agent] + EOT + } + + # module.vvr1_dc1.libvirt_domain.vm will be created + + resource "libvirt_domain" "vm" { + + autostart = false + + cpu = { + + features = [] + + mode = "host-passthrough" + } + + devices = { + + disks = [ + + { + + driver = { + + type = "qcow2" + } + + source = { + + volume = { + + pool = "vr1-dc1-pool" + + volume = "vvr1-dc1-disk.qcow2" + } + } + + target = { + + bus = "virtio" + + dev = "vda" + } + }, + + { + + device = "cdrom" + + source = { + + volume = { + + pool = "vr1-dc1-pool" + + volume = "vvr1-dc1-cloudinit.iso" + } + } + + target = { + + bus = "sata" + + dev = "sda" + } + }, + ] + + interfaces = [ + + { + + model = { + + type = "virtio" + } + + source = { + + network = { + + network = "mesh-vr1-dc1-office1" + } + } + }, + + { + + model = { + + type = "virtio" + } + + source = { + + network = { + + network = "vr1-dc1-uplink" + } + } + }, + ] + } + + features = { + + acpi = true + + apic = {} + } + + id = (known after apply) + + memory = 425984 + + memory_unit = "MiB" + + name = "vvr1-dc1" + + os = { + + type = "hvm" + + type_arch = "x86_64" + + type_machine = "q35" + } + + running = true + + type = "kvm" + + uuid = (known after apply) + + vcpu = 108 + } + + # module.vvr1_dc1.libvirt_volume.disk will be created + + resource "libvirt_volume" "disk" { + + allocation = (known after apply) + + backing_store = { + + format = { + + type = "qcow2" + } + + path = "/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2" + } + + capacity = 3221225472000 + + id = (known after apply) + + key = (known after apply) + + name = "vvr1-dc1-disk.qcow2" + + path = (known after apply) + + physical = (known after apply) + + pool = "vr1-dc1-pool" + + target = { + + format = { + + type = "qcow2" + } + + path = (known after apply) + } + } + + # module.vvr1_dc1.libvirt_volume.seed will be created + + resource "libvirt_volume" "seed" { + + allocation = (known after apply) + + capacity = (known after apply) + + create = { + + content = { + + url = (known after apply) + } + } + + id = (known after apply) + + key = (known after apply) + + name = "vvr1-dc1-cloudinit.iso" + + path = (known after apply) + + physical = (known after apply) + + pool = "vr1-dc1-pool" + } + +Plan: 5 to add, 0 to change, 0 to destroy. + +───────────────────────────────────────────────────────────────────────────── + +Note: You didn't use the -out option to save this plan, so OpenTofu can't +guarantee to take exactly these actions if you run "tofu apply" now. diff --git a/docs/audit/outer-plan-20260722-postdc1-converged.txt b/docs/audit/outer-plan-20260722-postdc1-converged.txt new file mode 100644 index 0000000..d71168b --- /dev/null +++ b/docs/audit/outer-plan-20260722-postdc1-converged.txt @@ -0,0 +1,30 @@ +module.netem_vr1_dc0_vr1_dc1.terraform_data.netem: Refreshing state... [id=1ea36d3f-e7af-984c-8157-152724a0b85a] +module.voffice1.libvirt_cloudinit_disk.seed: Refreshing state... [id=a4694210c663c9ce] +module.mesh_vr1_dc0_office1.libvirt_network.link: Refreshing state... [id=8318548f-c3d6-4e06-bef4-fe3f11d68125] +module.vvr1_dc1.libvirt_cloudinit_disk.seed: Refreshing state... [id=41e9ec4b712038fc] +module.vvr1_dc0.libvirt_cloudinit_disk.seed: Refreshing state... [id=ff281478c6083cc3] +module.office1_storage.libvirt_pool.dc: Refreshing state... [id=5f94194c-69c1-4b04-a85f-c18d87303a03] +module.vr1_dc0_storage.libvirt_pool.dc: Refreshing state... [id=7ce1101c-a89e-40ca-9263-5f572bee40a9] +module.mesh_vr1_dc1_office1.libvirt_network.link: Refreshing state... [id=38a20d2d-cd91-4604-a5f4-8e2a6609633c] +module.office1_network.libvirt_network.office1_local: Refreshing state... [id=8fdd2a97-417c-44d4-89e4-ae8d65594135] +module.vr1_dc1_storage.libvirt_pool.dc: Refreshing state... [id=4a1df114-ee04-4c80-9233-cc0c140c8556] +module.vr1_dc0_uplink.libvirt_network.site_wan: Refreshing state... [id=f3500153-e4de-45f1-8854-9c92974a6094] +module.mesh_vr1_dc0_vr1_dc1.libvirt_network.link: Refreshing state... [id=9cbc8589-9f40-48e6-872e-ef3abfe29a93] +module.vr1_dc1_uplink.libvirt_network.site_wan: Refreshing state... [id=4aad75c2-924f-410c-96bb-fa9217f8b4ea] +module.voffice1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-cloudinit.iso] +module.office1_opnsense.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/office1-opnsense-disk.qcow2] +module.vvr1_dc0.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-cloudinit.iso] +module.ubuntu_noble_base.libvirt_volume.base: Refreshing state... [id=/var/lib/libvirt/vr1/office1/ubuntu-24.04-base.qcow2] +module.vvr1_dc1.libvirt_volume.seed: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-cloudinit.iso] +module.voffice1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/office1/voffice1-disk.qcow2] +module.vvr1_dc0.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc0/vvr1-dc0-disk.qcow2] +module.vvr1_dc1.libvirt_volume.disk: Refreshing state... [id=/var/lib/libvirt/vr1/vr1-dc1/vvr1-dc1-disk.qcow2] +module.office1_opnsense.libvirt_domain.vm: Refreshing state... [name=office1-opnsense] +module.vvr1_dc0.libvirt_domain.vm: Refreshing state... [name=vvr1-dc0] +module.vvr1_dc1.libvirt_domain.vm: Refreshing state... [name=vvr1-dc1] +module.voffice1.libvirt_domain.vm: Refreshing state... [name=voffice1] + +No changes. Your infrastructure matches the configuration. + +OpenTofu has compared your real infrastructure against your configuration and +found no differences, so no changes are needed. diff --git a/docs/changelog-20260722-g12-dc1-build.md b/docs/changelog-20260722-g12-dc1-build.md new file mode 100644 index 0000000..e100765 --- /dev/null +++ b/docs/changelog-20260722-g12-dc1-build.md @@ -0,0 +1,79 @@ +# 2026-07-22 -- G12 [V] leg: dc1 apex write + substrate build step A (session changelog) + +Session scope: continue the G12 [V] leg from the reconciled tree (predecessor +delivery landed as changelog-20260721-g12-dc1-authoring.md items 3-4, commit +`d2bf743`): the one owed apex write, tfvars, and the gated outer build. +Branch: `dc-dc-g12-dc1-substrate`. One changelog for the session (GA-R2/D1); +every item carries its revert. + +## Item 1 -- apex `--commit` EXECUTED (the one owed dc1 apex write; operator-gated) + +Same-session read-only preflight FIRST (verify-before-mutate): dry-run re-run +against the live apex = would-create exactly 2, already-present 0 -- +`docs/audit/dc1-rack-import-dryrun-20260722.txt`, identical to the 07-21 +preflight. Then the gated write (piped to office1-netbox over ssh; token +sourced on-host from `/root/netbox-secrets/api.token` per +`creds-manifests/vr1-office1.manifest`, value never printed or brought into +context): + +- CREATED `172.31.0.4/30` (prefix id=139) role=transit scope=dcim.site:vr1-dc1 +- CREATED `10.12.68.2/22` (ip id=4) dns=vvr1-dc1 + +Post-commit idempotency read-back: would-create 0 / already-present 2. Both +runs captured in `docs/audit/dc1-rack-import-commit-20260722.txt`. Values +verbatim from the D-124 amendment (ruled 2026-07-21); exactly the two objects +the dc0 precedent registered. + +Revert: delete the two apex objects by id (prefix 139, ip-address 4) via the +NetBox UI/API on office1-netbox; delete the capture files. + +## Item 2 -- vr1-dc1 service keypair MINTED (manifest-prescribed at-deploy step) + +`~/vr1-dc1-creds/vr1-dc1_svc_ed25519{,.pub}` generated on vcloud (ed25519, +modes 600/644) per `creds-manifests/vr1-dc1.manifest` ("MINTED AT DC DEPLOY"). +`bash scripts/creds-audit.sh vr1-dc1` = CLEAN. D-126 option (a) per-env key; +pubkey feeds vvr1-dc1 cloud-init (item 3), private half jumphost-local. + +Revert: remove both key files (couples to item 4 -- vvr1-dc1's cloud-init +authorizes this pubkey; re-mint requires a seed rebuild). + +## Item 3 -- dc1 tfvars authored (LOCAL, gitignored -- recorded here, not committed) + +`opentofu/d124-rack.auto.tfvars` gained the five vr1_dc1_* values, verbatim +from the D-124 amendment's own tfvars line (rack_metal_admin_ip=10.12.68.2, +rack_transit_ip=172.31.0.6, rack_transit_prefix=30, +rack_transit_peer_ip=172.31.0.5) + `vr1_dc1_ssh_pubkey_path` to the item-2 +pubkey. Stale "dc1 DEFERRED" header comment replaced. `tofu fmt` applied; +`scripts/opentofu-validate.sh` PASS (all roots). + +Revert: remove the vr1_dc1_* block from the local file. + +## Item 4 -- outer apply: dc1 substrate step A (operator-gated, logged, saved-plan exact) + +Preconditions measured in-session: host RAM 1007 GiB with 450 GiB committed +(voffice1 32 + edge 2 + vvr1-dc0 416) -> +416 GiB fits with ~140 GiB headroom; +vCPU 234/256 post-apply; dc-dc-whole-host-budget 13/13 PASS. + +Saved plan `tfplan-dc1-20260722` = **5/0/0 exact** (vr1-dc1-uplink network + +vvr1-dc1 domain/disk/seed/cloudinit; ZERO touches to live resources) -- +capture `docs/audit/outer-plan-20260722-dc1-substrate.txt`. Applied via the +saved plan under a per-command as-executed wrap +(`~/as-executed/2026-07-22-dc1-deploy.log`; index row added): **5 added, 0 +changed, 0 destroyed**. Convergence re-plan = **zero diff** +(`docs/audit/outer-plan-20260722-postdc1-converged.txt`). Live verify: +vvr1-dc1 RUNNING (Id 8), voffice1/office1-opnsense/vvr1-dc0 untouched and +running; vr1-dc1-uplink + both dc1 mesh legs active. + +Revert: `runbooks/dc-dc-teardown-rollback.md` decision tree; the targeted +destroy set is the five applied resources (module.vvr1_dc1.* + +module.vr1_dc1_uplink.*); delete the plan/capture files and the tfplan. + +## Next (gated, not run here) + +Step B analog for dc1 per the dc0 sequence of record: transit leg +(region end 172.31.0.5/30 on voffice1), vvr1-dc1 bootstrap +(site-headend-install rack role + SEC-010 both ends), OPNsense 26.7 nano +staging; then the inner apply FROM voffice1 (D-128 Plane 2) with MAC pins +from the FIRST apply, and the D-131/D-124-amendment standup +definition-of-done items (dc-rack-net.sh install, forwarder 10.12.68.3, +maas-node-power per-machine virsh). Runbook + CURRENT-STATE govern. diff --git a/logs/as-executed-index.md b/logs/as-executed-index.md index ef011f3..7be6d69 100644 --- a/logs/as-executed-index.md +++ b/logs/as-executed-index.md @@ -14,3 +14,4 @@ | 2026-07-08 | ops-decommission | jesse.austin (Claude Code lane, per-command wrap) | decommission window: lbtest LB reclaim + beta-cluster teardown + foil1 offboard (first offboard v2 --apply; E0 always-403 defect logged) + magnum orphan-sweep audit (clean); open/close cloud-assert PASS | | 2026-07-08 | ops-devteam-template | jesse.austin (Claude Code lane, per-command wrap) | deliver devteam-k8s cluster template (stage5, calico, hidden=False) after stuck flannel TestCluster2 confirmed gone + RAM reclaimed; closes the addendum-39 no-delivered-template gap | | 2026-07-21 | ops-commissioning-diag | jesse.austin (Claude Code lane, per-command wrap) | G10 commissioning diagnosis: instrumented run per committee; MAC-drift fault (all 9) repaired in place (ruled); MAAS 3.7 rack-only agent resolver defect found, dc0-node-dns forwarder workaround (ruled); ALL 9 NODES READY; SEC-014 opened; D-131 proposed | +| 2026-07-22 | dc1-deploy | jesse.austin (Claude Code lane, per-command wrap) | G12 dc1 build: apex --commit (transit /30 + rack IP, 2 objects), dc1 svc key minted, outer apply 5/0/0 exact (vvr1-dc1 + uplink), converged zero diff | diff --git a/opentofu/tfplan-dc1-20260722 b/opentofu/tfplan-dc1-20260722 new file mode 100644 index 0000000..71809a7 --- /dev/null +++ b/opentofu/tfplan-dc1-20260722 Binary files differ