diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index 67ef3ce..8ac4a68 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -93,8 +93,10 @@ > (iii) neutron `overlay_ip_version=6` (MTU). Test scaffold + the owed `lb-smoke` LB TORN DOWN (dc0 clean). > Delivered: `scripts/geneve-encap-assert.sh` (+ harness 16/16) asserts encap family consistency AND tunnel > `ofport>=0`; phase-04 Step 12.2 + Step 6 corrected to use it. Evidence + tested sequence in the root-cause -> record above (LIVE-CONFIRMED 2026-08-09 section). D-number for the containerized-chassis-v6 + bracket -> finding still OWED (amendment vs new-number is the operator's call). Changelog: +> record above (LIVE-CONFIRMED 2026-08-09 section). D-number RULED 2026-08-09 (GA-R5, operator: +> "D-139 amendment") -> `docs/design-decisions.md` D-139 AMENDMENT 2026-08-09. Still OWED for the +> rebuild: confirm the fixed ovn-chassis revision (bracket bug) or wire a persistent unbracket +> override; the container v6 carve; D-139's metal-admin-leg-IPv4 gate. Changelog: > `docs/changelog-20260809-geneve-v6-rootcause-gate.md`. > ## >>> STANDING OPERATOR DIRECTIVE, 2026-07-30: THE NEXT SESSION PROCEEDS TO THE JUJU DEPLOYMENT (STAGE 5). NO MATTER WHAT. <<< diff --git a/docs/design-decisions.md b/docs/design-decisions.md index 681006a..1a03a0c 100644 --- a/docs/design-decisions.md +++ b/docs/design-decisions.md @@ -7930,6 +7930,49 @@ handing out an in-use GUA address comes from step 1 above -- the 26 GUA records EXISTING -- not from the deprecation. +### AMENDMENT 2026-08-09 -- geneve-over-v6 CONFIRMED viable; containerized OVN chassis need CARVED v6 + an UNBRACKETED ovn-encap-ip + +**GA-R5.** Question put to the operator: "How should the geneve-over-v6 finding +(containerized-chassis v6 requirement + the ovn-chassis bracket bug + v6-only data-tenant +confirmed viable) be recorded in design-decisions.md -- as a D-139 amendment or a new D-number?" +**Operator answer: "D-139 amendment".** Recorded 2026-08-09. Amends D-139 ruling A/B; mints no +new number (the finding extends D-139's own family matrix + v6-only execution, and this project's +mint-a-number trap argues against a fresh D for an extension). + +**WHAT WAS MEASURED (live, vr1-dc0, D-138; full record + tested sequence: +`docs/audit/geneve-over-v6-rootcause-20260808.md`).** D-139 ruling A intends a v6-only data-tenant +geneve underlay but never proved geneve-over-v6 FORWARDS on this stack. Proved 2026-08-09: a real +VM-to-VM cross-compute ping over a v6 geneve tunnel = 8/8, 0% loss on OVS 3.3.0 / OVN 24.03.2 / +kernel 5.15.0-186. **geneve-over-IPv6 WORKS here; v4-forced is OFF the table.** (A first same-day +test wrongly read "v6 broken" from an OVN `localport` source that never tunnels by design -- +retracted; instrument-currency #23 sibling.) + +**TWO conditions, both necessary, neither guaranteed by "make the plane v6-only":** +1. **The containerized OVN chassis (octavia / ovn-chassis-octavia LXD) must take a CARVED v6 + data-tenant address.** They auto-pick v4 (D-134), producing the 2026-08-08 family split + (control v4 encap, metal v6 encap -> no cross-family tunnel). Carve/assign, do not auto-pick. +2. **`ovn-encap-ip` must reach OVS UNBRACKETED.** ovn-chassis 24.03 sets it bracketed + (`"[2602:...]"`); OVS geneve rejects that (`bad geneve 'remote_ip'`, tunnel `ofport -1`), so + every v6 tunnel is dead while a family-only check still reads PASS. Fix: a fixed ovn-chassis + revision, or a persistent post-deploy override + (`ovs-vsctl set open_vswitch . external_ids:ovn-encap-ip=`). Kernel/OVS support + v6 geneve fine once unbracketed (measured: unbracketed port instantiates, bracketed does not). + +Plus **neutron `overlay_ip_version=6`** for correct tenant MTU (~1422; v6 geneve is 20 bytes +heavier), else a later large-packet failure. + +**GATE (built 2026-08-09; replaces the ruled-not-built "geneve-over-v6 verified" item).** +`scripts/geneve-encap-assert.sh` (harness `tests/geneve-encap-assert/`, 16/16) asserts encap family +consistency (`--expect-family v6`) AND every geneve tunnel `ofport>=0` -- the tunnel-health half +catches the bracket bug a family-only check misses. Wired into +`runbooks/dc-dc-phase4-juju-bundle-per-dc.md` Step 12.2. + +**ROOSEVELT-DELTA.** A v6 build with LXD-hosted ovn-chassis (the norm on MAAS metal) must carve v6 +for those containers AND ensure an unbracketed encap-ip, and must PROVE geneve-over-v6 forwards +before committing a plane's overlay to v6 -- the gate above is that proof, run at Stage-5 close +before any workload smoke. Fixed-ovn-chassis-revision confirmation (charm-ovn-chassis IPv6 bracket +bug family) remains OWED for the rebuild. + ## D-141: IPAM allocations are DUAL-STACK, status-distinguished -- v4 active, v6 reserved-until-capable [ARCH] **Status: ADOPTED 2026-08-03 (operator ruling, GA-R5).** Question as presented: with the