QUEUED FINDINGS -- session 2026-08-08 (dc0 activation checkpoint: F3 fix, provider net, G18 ruling, Octavia core, retrofit incident) Sweep method: model read the session, grepped each candidate. FIRST SURFACE items lead. Status authority is docs/CURRENT-STATE.md; this file is a sweep record, not status. Session body (what/why/revert per item): docs/changelog-20260808-dc0-activation.md (Items 1-7). ================================================================================ FIRST SURFACE (existed ONLY in transcript / gitignored -- would be lost on a clear) ================================================================================ F1. GITIGNORED PERMISSION RULES added to .claude/settings.local.json (allow[]) -- VERBATIM (always-sweep #1; lost on any rebuild of that gitignored file). Eight rules, all tightly scoped to the dc0 rack (172.31.0.2) staged phase-04/05 scripts + the octavia configure-resources action (the auto-mode classifier walls these despite a broad Bash(ssh *); targeted rules clear the wall -- the project's known pattern): Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-04-*) Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-04-*) Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-05-*) Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region bash ~/repo-stage/scripts/phase-05-*) Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region MODEL=vr1-dc0 bash ~/repo-stage/scripts/phase-05-*) Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'source ~/admin-openrc && MAAS_PROFILE=vr1-dc0-region MODEL=vr1-dc0 bash ~/repo-stage/scripts/phase-05-*) Bash(ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'juju run octavia/leader configure-resources -m vr1-dc0 *) Bash(timeout * ssh -o BatchMode=yes voffice1 "ssh -o BatchMode=yes 172.31.0.2 'juju run octavia/leader configure-resources -m vr1-dc0 *) F2. AMPHORA RETROFIT BUILD INCIDENT (rebuild-relevant; blocks the F6 "1 test LB"). Body: changelog Item 7. octavia-diskimage-retrofit action 72 exit 1 at the `-O raw` dib step; base uploaded ok (glance id 04c982c2-8906-48b9-8ddc-2febce82c9ef) but NO octavia-amphora image. Unit itself active/idle. Hypothesis (UNCONFIRMED, needs sudo on the unit): dib-in-LXD-container privilege/loop-device. appendix-A has NO matching symptom -> a new appendix-A entry is owed once diagnosed. OWED diagnosis: capture dib stderr via sudo on octavia-diskimage-retrofit/0; check loop devices + disk space in the snap common dir. F3. AMPHORA SCRIPT MODEL DEFAULT = openstack (VR0) -- rebuild-tooling defect. scripts/ phase-05-amphora-pipeline.sh defaults MODEL=openstack; VR1 needs MODEL=vr1-dc0 (first run failed "model ...openstack not found"). Not flagged prominently in the runbook. Rebuild tooling should derive/ default the model per-site. Body: changelog Item 7. F4. CLIENT PACKAGES absent on the dc0 rack but AVAILABLE from the dc0 mirror (D-135): python3-octaviaclient (Candidate 3.7.0-0ubuntu1), python3-designateclient (6.0.1-0ubuntu1). Both the Octavia LB smoke test and the Designate zone test need their client installed on the rack (a gated apt install; exercises D-135). Not yet installed. (Octavia/Designate activation itself does NOT need them -- only the smoke tests do.) F5. G18 OWED#3 (o-hm0 MTU, LP#2018998) NOT yet checked -- an adjacent Stage-5 Octavia obligation, independent of the G18 ruling. OWED read-only: verify o-hm0 MTU matches lb-mgmt-net's, measured. (G18 OWED#1 prefix + #2 router-isolation ARE done -- changelog Item 6.) ================================================================================ ALREADY ON SURFACE (verified present -- recorded for completeness) ================================================================================ - F3/D-138 co-location gap RESOLVED: phase-04 scripts MAAS_PROFILE-aware (DOCFIX-213), rack vr1-dc0-region profile registered (-> hot-kid 10.12.8.6:5240 in-DC regional), provider network created + EXIT GATE PASS -> changelog Items 1,3; committed f85daa7. - G18 RULED (GA-R5 option b) -> CURRENT-STATE G18 row CLOSED + D-101/R8 + D-139 annotations; changelog Item 4; committed 0e8b659. Exact utterance recorded (ruling fidelity OK). - Octavia CORE activated (configure-resources op 67) -> changelog Item 6; committed 295185d. lb-mgmt-subnetv6 = fc00:5b7a:7bdc:bd86::/64 (charm ULA); mgmt router external_gateway_info=None. - Designate decision: REAL D-106/D-117 Stage-7 (operator choice) + scope flag (os-public-hostname flip) -> changelog Item 5. D-106 puts Designate CONFIG at Stage 7 (design-decisions.md:2924). - Re-IP ruling-prep package -> docs/audit/reip-1013-ga-r5-ruling-prep-20260808.md (committed f85daa7); CURRENT-STATE pivot pointer. STILL OWED: 3 live-free checks (Headscale routes, live office1-netbox, live vr0-dc0) before the operator can rule. - G18 ruling-prep package -> docs/audit/g18-lb-mgmt-ipam-ruling-prep-20260808.md (committed 0e8b659). - REBUILD finding: vvr1-dc0/vvr1-dc1 outer hosts are MAAS rack controllers under OFFICE1 admin, NOT their DC regionals -> changelog Item 1 (operator directive: racks register up to DC regional). - F3-original correction (F3 said phase-05 needs maas -- FALSE) -> changelog Item 3. ================================================================================ ALWAYS-SWEEP FIVE ================================================================================ 1. GITIGNORED STATE: see F1 (8 permission rules, verbatim). No other gitignored artifact created. Credential used read-only: ~/vr1-dc0-creds/maas-region-api-key.txt (piped to `maas login -` via stdin, never printed) -- it is the vr1-dc0-region admin API key (proven by the profile resolving to hot-kid + returning the provider subnet). 2. DANGLING REFS: commits f85daa7/0e8b659/295185d/a6340e6 cite reip-1013-..., g18-lb-mgmt-..., changelog-20260808-..., the two phase-04 scripts + harnesses -- all resolve. 3. RULING FIDELITY: G18 exact utterance recorded (CURRENT-STATE G18 row + D-101/R8 annotation). Re-IP ruling NOT yet made (owed, blocked on live-free checks). Designate + F3-fix decisions are operator AskUserQuestion selections, recorded in changelog Items 5/1. 4. AS-EXECUTED LOG GAP: run-logged.sh NOT opened (structurally unusable -- interactive `script -aqe` cannot wrap tool-driven Bash). Declared in changelog Item 3. The changelog + this sweep + the session transcript ARE the as-executed record for this session's mutations (profile login, network-create, configure-resources, amphora pipeline x2). 5. CONTRADICTION DETECTOR: G18 OWED#2 (charm mgmt router external_gateway_info=None) settles R8's explicitly-unasserted external-gateway question favourably (recorded, changelog Item 6). No measurement left contradicting a standing doc unrecorded. ================================================================================ OWNED (own-mistakes, all caught + corrected this session) ================================================================================ - grep -viE 'active.*idle' mis-filter on juju oneline (idle precedes active) returned everything; caught immediately, re-queried with an explicit blocked|error|waiting grep. - my own `echo` string contained the literal "maas list" -> tripped the DOCFIX-016 guard (regex matches string literals anywhere in the command, not just live invocations); rephrased. - first amphora run used the script's MODEL=openstack default (VR0) -> failed fast at the config gate (no partial state); fixed with MODEL=vr1-dc0 (now F3 above). - earlier framed firing configure-resources as "deciding G18 by execution" (advisor concern); the G18 prep showed R8 already ruled the substance, so G18 was only apex-recording -- corrected before the ruling was put to the operator. NEXT: (1) diagnose the retrofit incident (F2, sudo on octavia-diskimage-retrofit/0) -> unblocks the LB test; (2) Designate real D-106/D-117 Stage-7 (confirm os-public-hostname-flip depth); (3) wrap gates (cloud-assert --capture, controller backup, verify-live) + G18 OWED#3 MTU; (4) re-IP ruling live-free checks -> present the re-IP GA-R5 ruling (Task #6). Operator PUSH the 4 commits (f85daa7..a6340e6) -> then voffice1 git pull. Status ONLY in CURRENT-STATE.md.