diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index c7afab8..c91d6c7 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -1166,8 +1166,20 @@ credential, the matrix was extended to expect the same at BOTH DCs, and dc1's half does not exist because dc1's region VM is authored but NOT applied. The finding is "dc1 has not been built", stated by a register that can see an absence. **Deleting the rows to go green is the - one thing the standing rules forbid.** The diff is appended to the capture. **THIS NEEDS ITS - OWN GA-R5 EXCHANGE BEFORE THE DEPLOY** and is the only thing left. + one thing the standing rules forbid.** The diff is appended to the capture. + **^ RULED 2026-07-31 (GA-R5). Question as presented: preflight is RED on P5 only; the + 2026-07-30 acceptance covered six ENUMERATED findings and says it covers "these six, + enumerated, and nothing else"; all six are still present and FIVE are new, all vr1-dc1, all + the D-137 forward register reporting that dc1's MAAS region is authored but not applied. + Accept the five and proceed, or stop and remediate first? Operator answer, exact utterance: + "Accept the five and proceed to the dc0 deploy".** CONSEQUENCE: the five are accepted as + known, by-design absences carried on their existing SEC-027 / SEC-028 rows. They describe + dc1, which is not built; nothing about them affects the dc0 deploy. `preflight.sh` will + continue to exit FAIL on P5 for the rest of this stage and that RED is ruled-accepted -- it + is NOT a reason to re-run the audit, and it must NOT be made green by deleting or weakening + a matrix row. **Like its 2026-07-30 predecessor this acceptance covers these FIVE, + enumerated, and nothing else** -- a future session must not read it as covering any newer + P5 finding. Total accepted at P5 is now ELEVEN, enumerated across the two rulings. **(d) STEP 4.2 `--dry-run` RUN AGAINST THE FIXED INPUT: EXIT 0, 56 applications / 108 relations / 33 unit placements.** Its green is NOT evidence on option names -- that is the whole lesson of attempt 1 -- but it does confirm the re-rendered overlay resolves and plans. diff --git a/docs/changelog-20260731-prefer-ipv6-research.md b/docs/changelog-20260731-prefer-ipv6-research.md index cfd4acc..76b3dcc 100644 --- a/docs/changelog-20260731-prefer-ipv6-research.md +++ b/docs/changelog-20260731-prefer-ipv6-research.md @@ -6,8 +6,15 @@ Context: bundle deploy attempt 1 failed 2026-07-31 with `unknown option "prefer-ipv6"` on barbican, and the operator ruled *"Research what those 6 charms do with v6 VIPs first (Recommended)"*. Stage 5 is blocked on that -research. This session executes it. **Read-only throughout: no cloud mutation, no -overlay edit, no ruling adopted.** +research. This session executes it, the operator RULES on the result, and the ruling is +then BUILT and verified. + +**Scope correction to this header, made when it stopped being true.** It first read +"Read-only throughout: no cloud mutation, no overlay edit, no ruling adopted", which was +accurate for items 1-5. After the ruling landed the session edited the renderer, the +gate, both overlays and both values files, and refreshed the deploy input staged on the +dc0 rack. **No cloud state changed at any point** -- the `vr1-dc0` model is still empty +and no `juju deploy` was run. --- @@ -270,3 +277,26 @@ **Revert.** Nothing to revert in the repo beyond the capture. The rack-side file copy is reversed by copying the previous overlay back; its pre-change hash was `3ae79e82`. + +## Item 9 -- SECOND RULING: the five new P5 findings accepted + +**Question as presented.** Preflight for dc0 is RED on P5 only. It reports 11 findings; +the 2026-07-30 acceptance covered SIX, enumerated, and says it covers "these six, +enumerated, and nothing else". All six are still present. Five are NEW, all vr1-dc1, all +opened after that ruling -- `maas-region-db-password`, `maas-region-admin-password`, +`maas-region-api-key.txt` (SEC-027) and `maas-juju-api-key.txt`, +`maas-juju-user-password` (SEC-028) -- and every one is the D-137 forward register +correctly reporting that dc1's MAAS region is authored but not applied. Accept and +proceed, or stop and remediate? + +**Operator answer, exact utterance: "Accept the five and proceed to the dc0 deploy".** + +**Consequence.** The five are carried as known, by-design absences on their existing +SEC-027 / SEC-028 rows. They describe dc1, which is not built; nothing about them +affects the dc0 deploy. `preflight.sh` keeps exiting FAIL on P5 for the rest of this +stage, that RED is ruled-accepted, and it must NOT be made green by deleting or +weakening a matrix row. **Like its predecessor this covers these FIVE, enumerated, and +nothing else.** Total accepted at P5 is now ELEVEN across the two rulings. + +**Revert.** A ruling is a record, not a change; there is nothing to revert. Withdrawing +it would require a new GA-R5 exchange.