# Session changelog 2026-07-24 -- Stage-5 bundle-render committee + Fork-1 ruling

Branch `dc-dc-stage4-phase3-maas-deploy`. Session resumed the DC1 Stage-5
bundle-rework blocker under a committee review (operator-requested). Status lives
ONLY in `docs/CURRENT-STATE.md` (GA-R1); this changelog is the review surface --
each item states what / why / revert. No cloud state was mutated this session.

## Item 1 -- Committee record (Track 2 bundle render)

**What:** new `docs/audit/committee-20260724-track2-bundle-render.md` -- a 4-lens
(Roosevelt-delta / HA-DR / operational-risk / Juju-MAAS-mechanism) read-only
committee review of the vr1-dc1 deploy-artifact render, with the adjudication and
open operator decisions. Advisory/audit record; adopts nothing (GA-R5).
**Why:** operator: "Deploy a committee to review Track 2 and provide
recommendations based on overall end project goals and decisions already
researched." Durable, citable authority (commissioning-committee precedent).
**Revert:** `git rm docs/audit/committee-20260724-track2-bundle-render.md`.

## Item 2 -- Capacity gate capture (Fork-1 option a)

**What:** new `docs/audit/stage5-controller-capacity-20260724.txt` -- captured
`scripts/dc-dc-whole-host-budget.py` runs: baseline built layout 3+2+4 x2 DC =
838/1024 GiB (82%, FIT); +controller (+8 GiB/+4 vCPU per-DC containment overhead)
= 854/1024 GiB (83%, FIT, 170 GiB headroom). Read-only calculator; nothing
queried live.
**Why:** GA-R1 -- the Fork-1 (a) capacity claim must be MEASURED, not inferred
(the signed doc's 790/77% is the OLD 8-node layout). Gate = PASS.
**Revert:** `git rm docs/audit/stage5-controller-capacity-20260724.txt`.

## Item 3 -- D-104 amendment (Fork-1 ruling: dedicated 10th controller VM)

**What:** appended a D-104 amendment (2026-07-24) in `docs/design-decisions.md`
recording the operator's GA-R5 ruling -- the per-DC Juju controller is a DEDICATED
10th node VM (distinct tag `juju-controller-vr1-dc1`, no role tag), separate from
the 9 Option C role nodes; additive (`for_each`-keyed); capacity gate PASS
(cites item 2); the 9-node D-121 layout is unchanged.
**Why:** Fork 1 was the blocking architectural decision; operator selected
"Dedicated 10th VM (Recommended)" over shrink-a-role and co-locate. Controller
placement is D-104's subject; recorded as its amendment (not a new D-number).
**Revert:** delete the "### D-104 -- AMENDMENT (2026-07-24)" block in
`docs/design-decisions.md` (git range-diff of this commit).

## Item 4 -- CURRENT-STATE Stage-4 bullet update (GA-R1 / C1)

**What:** rewrote the Stage-4 bullet's render sub-bullets: committee-adjudicated;
Fork 1 RULED (a) + capacity gate; Fork 2/3 as OPS committee-unanimous
recommendations (gated at execution); BUNDLEFIX-052 fixed; a corrected NEXT list.
Also corrected an earlier inaccurate characterization (dc-ha-scaleup is not "stale
ceph-osd 3" -- it deliberately excludes ceph-osd) and the "consumes 1 of 9"
arithmetic (now a dedicated 10th VM).
**Why:** GA-R1/C1 -- a status-changing commit updates CURRENT-STATE in the SAME
commit (repo-lint L10). Status authority stays single-sourced.
**Revert:** restore the prior Stage-4 bullet text (git range-diff of this commit).

## Item 5 -- BUNDLEFIX-052: ceph-rbd-mirror duplicate `bindings:`

**What:** removed an orphaned 4-space-indented `bindings:` block in `bundle.yaml`
(old line ~907) that `yaml.safe_load` take-last had absorbed into `ceph-rbd-mirror`,
clobbering its real `ceph-local`/`ceph-remote` (replication) + `nrpe-external-master`
bindings (D-108/D-052) and injecting a phantom `dashboard` binding (a charm with no
such endpoint) -> `juju deploy` validation reject.
**Why:** confirmed pre-existing latent defect (committee mechanism lens; verified
via `yaml.safe_load`). Fork-independent; fix now so the dc1 render starts clean.
**Validation:** `yaml.safe_load` confirms `ceph-rbd-mirror.bindings` restored to
`{'': metal-admin, ceph-local: replication, ceph-remote: replication,
nrpe-external-master: metal-internal}`; `provider-bundle-check.py bundle.yaml` PASS.
**Revert:** re-insert the orphan block after the vault-hacluster comment (not
advised -- it is the bug).

## Next (not done this session; gated)

Commit+push this batch (GA-R5: rulings land before dependent work). Then, each
operator-gated: per-role MAAS tags; author + apply the 10th controller VM
(egress OPEN); render the 9-node `bundle.yaml` (re-home base placements, re-scope
tokens) + extend `provider-bundle-check.py` with placement assertions + wire
overlays + de-stale phase-4 Step 4; gated `juju bootstrap` (by controller tag,
egress OPEN) -> deploy. Deploy-time VERIFY-LIVE gates: vault-3-unit HA-on-MySQL,
hacluster cluster_count:3, dc1 VIPs, CRUSH failure-domain=host.
