# Queued findings -- session 2026-08-06/07: phase-03 Step 3.4 + Decision C + per-DC Tailscale # Survives-a-clear sweep (savegame Step 3). Status authority is CURRENT-STATE.md. # Body: docs/changelog-20260806-step34-g3-probe.md. Each item says where it already lives, # or that THIS file is its first surface. === FIRST SURFACE (transcript-only until this file) === O1 DOCFIX candidate -- octet-map surface LAGS. design-decisions.md:5954 (D-134 AMENDMENT 2026-08-07, this session) states the STANDING utility octet map as .4 artifact / .5 Juju / .6 region / .7 Tailscale. The OLDER D-132 addendum at design-decisions.md:7168 still reads ".4 ... .5 ... .6 MAAS region" with NO .7 -- correct as of 07-30, now lagging. Append-only register, so it is history; but a reader grepping the map at :7168 misses .7. DOCFIX: annotate :7168 -> "extended to .7 Tailscale 2026-08-07, see the D-134 amendment". LOGGED, not fixed. O2 ENV/EXECUTION TRAIT: an `ssh voffice1 ''` session's default cwd is NOT the repo clone (/home/jessea123/openstack-caracal-dc-dc); git/tofu commands fail "not a git repository" unless the remote command LEADS with `cd $REPO`. Cost ~6 retries during this savegame's Step-1b sync. Prepend the cd in every remote git/tofu invocation. First surface. O3 AS-EXECUTED LOG IS PARTIAL for this window (F6 class). `run-logged.sh` was NOT opened this session; the live mutations (G3 probe, four tofu applies, four MAC-pin applies) ran gated but unwrapped. Every action is in the changelog + CURRENT-STATE with read-backs, and the G3 probe has its own capture (docs/audit/g3-dc0-probe-20260806.txt), but the as-executed log must NOT be read as complete for this window. O4 TOFU STATE DOES NOT CARRY AUTO-GENERATED MACs. With `macs = []`, the libvirt provider does not read the generated MAC addresses back into tofu state (`tofu state show` shows none); they must be captured live via `virsh domiflist ` over the qemu+ssh provider URI, then pinned. The region-VM comments already say "pin from virsh domiflist"; the state-blindness nuance is recorded here so a future session does not look for them in state. === ALREADY ON SURFACE (recorded where noted) === R1 Decision C -- phase-03 Horizon reconciled to VR1; Step 3.3 splits to its own gate row. Operator: "We need to pull the tailscale steps forward so we can close out horizon properly." -> CURRENT-STATE.md (phase-03 (c) clause) + changelog Item 5. R2 Four Tailscale rulings (a-d), EXACT utterances, + the "both DCs" directive: (a) "Dedicated VM at utility .7 (Recommended)"; (b) "Star: operator->DC only (Recommended)"; (c) "We will not be creating HA for this now. Pin HA scale up for Headscale/Tailscale."; (d) "SNAT ON now; pin source-IP preservation (Recommended)"; "Lets plan and push to both DC0 and DC1 in this step." -> design-decisions.md D-129(iii) AMENDMENT 2026-08-07 + D-134 AMENDMENT + gap-21 register row + changelog Item 6. R3 Substrate apply scope ruling: "dc0 full + dc1 FULL (also the region VM)" -> changelog Item 9. Build-pace ruling: "Push, build tooling AND stand up the .7 VMs". G3 build: "Build g3-probe.sh + harness"; "Run G3 probe now". -> changelog Items 1/8/9. R4 Measurements: G3 PASS live (7 ok/0 fail, teardown clean); Step 3.4 stage-1 PO: at UNIT level (app-aggregate hid it); both dashboard VIPs HTTPS 200 + csrftoken Secure; D-044/D-075 NOT applied; cert IP-SAN covers 10.12.8.58; capacity FIT 874/1024=85%; dc1 plan 4-add (region VM bundled); 3 VMs applied + MACs pinned + tofu clean. -> CURRENT-STATE + changelog Items 3-9 + substrate main.tf comments. R5 Headscale facts: control plane tailscale.baldurkeep.com (Cloudflare-fronted, server version UNMEASURED, operator no access this session); Office1 node UNTAGGED (AdvertiseTags null, 180-day key-expiry defect to fix); star ACL / autoApprovers / tagged authkey are the control-plane prerequisites. -> D-129(iii) amendment notes 1+4 + site-tailscale.sh header. R6 Security note: the .7 tailscale VM attaches all six planes (node-vm module default) but ADVERTISES only metal-admin; the other five legs stay uncarved/unrouted. -> substrate main.tf comment (both DCs). === DELIBERATELY NOT DONE (owed, next sessions) === N1 Headscale-side build: tagged pre-auth key, autoApprovers (write BEFORE first advertise), star ACL, the join via site-tailscale.sh install, fix the Office1 untagged node. BLOCKED on Headscale control-plane access (operator lacks it this session). N2 Per VM (3): start -> MAAS enlist/commission/deploy Ubuntu -> carve legs (.7 metal-admin + provider-public gw) -> install tailscale. All VMs currently powered off (autostart=false). N3 dc1 MAAS-region SETUP workstream (vr1-dc1-maas-01 stood up but not configured): init / PostgreSQL / image sync / eventual dc1 node migration. N4 SEC row for per-DC Tailscale key custody -- opens at authkey-mint time in the Headscale build (D-129(iii) amendment note). N5 O10 (carried, pre-existing): dc0/dc1 rack ~/repo-stage/bundle.yaml STALE vs repo; re-stage before any redeploy. This session touched no bundle/overlay, so the staleness is unchanged. === GITIGNORED / THROWAWAY (Step 3d.1) === - Throwaway tofu saved plans on voffice1 (dc0-tailscale.tfplan, dc0-macpin.tfplan, dc1-full.tfplan, dc1-macpin.tfplan) -- gitignored, already applied, no durable value. - No permission-rule (.claude/settings.local.json) changes this session. === STAGE-CLOSE OWED (added 2026-08-07, operator-directed "make sure the v6 posture carries forward") === O5 Fold the IPv6-PRIMARY posture invariant into the openstack-cloud-ops SKILL Posture section at the next STAGE close (the skill is the invariant home; swept at stage close). Auto-memory `ipv6-primary-posture.md` is the always-loaded defense NOW (added this session, pointer to D-101/D-139/D-141); the skill Posture line is the second surface so a stage-close skill sweep also carries it. The v6 posture is IPv6-primary (v6 wherever possible, v4/dual-stack only where forced); D-141's v4-active is the NARROW container-VIP necessity case, not a cloud-wide lean.