# Pass 4 / W4.1 -- MASTER CHANGE INVENTORY (container-layer elimination)

**Author:** Worker W4.1 (Phase 4 -- change synthesis), multi-agent container-elim pass
(`SCOPE-AND-EXECUTION-PLAN.md` Section 4). **Date:** 2026-08-09. **Inputs:**
`pass0-admin-report.md` (baseline + confirmed target topology), `pass1-admin-report.md`
(planning change-set), `pass2-admin-report.md` (tools change-set), `pass3-admin-report.md`
(tests change-set) -- all four read in full. READ-ONLY synthesis; no mutation; nothing
here is executed. This document MERGES the planning + tools + tests change-sets into one
indexed table an execution session can work from directly.

**Baseline carried in (do not re-derive):** Option 1 CONFIRMED (flat node VMs on vcloud
libvirt + one small non-hypervisor `vr1-dcN-client` VM per DC); cross-DC handling (a)
CONFIRMED (new vcloud-level host isolation control); MAAS region stays on
`vr1-dcN-maas-01`; root topology (B) shared-outer + per-DC-flat RECOMMENDED (Phase-4
ratifies); THREE isolation controls confirmed distinct -- (i) the (a) cross-DC host
control, (ii) the SEC-010 transit-leg successor, (iii) the MAAS power-key blast-radius
mitigation; everything rides D-143 (10.12->10.13 re-IP); 13 owed artifacts (numbered #1-#13
below); tests change-set = 9 existing-change verdict-blocks / 5 existing-retire
verdict-blocks / 7 new-build harnesses / 3 rides.

**ID scheme:** `DEC-` decision (not a change; an open ruling) -- `TF-` tofu-module --
`LB-` lib (`lib-hosts.sh`/`lib-net.sh`) -- `SC-` script/procedure -- `DC-` doc
(deployment-workflow.md / CURRENT-STATE.md prose, non-gate) -- `RB-` runbook -- `GT-` gate
(preflight/cloud-assert/G-series) -- `HN-` harness (`A#`/`B#`/`C#` tags preserved from
`pass3-w3-new-tests.md` for cross-reference) -- `SEC-` security-ledger row.
**Axis:** `[CE]` container-elim only, `[D-143]` re-IP only, `[both]` dual-labeled (per
pass1 check 5's four confirmed dual items + this pass's extensions). **Owed-artifact#**
refers to the 13-item list in `pass2-admin-report.md` Section 5 (also restated below).

---

## 0. The 13 owed artifacts (for cross-reference; full spec in `pass2-admin-report.md` #5)

1. Teardown primitive (root-scoped `tofu destroy` + emergency lever) -- 6. rides as the
   emergency `virsh destroy` loop (distinct row, same fixture library)
2. The (a) cross-DC host isolation control (concern i)
3. SEC-010 transit-leg successor (concern ii)
4. R7 credential-revocation checklist
5. MAAS machine-record release/delete step (+ rack-controller decommission)
7. FIT-calculator extension + capacity measure (+ artifact-service sizing)
8. MAC re-measurement pass (post-apply)
9. NetBox DCIM migration
10. Post-build live asserts (geneve/jumbo)
11. Power-key blast-radius mitigation (concern iii) -- **critical path**
12. `modules/dc-site`
13. D-131 retirement-evidence step

---

## 1. MASTER CHANGE-INVENTORY TABLE

### 1.1 Decisions (open rulings -- not changes; gate the change rows below)

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| DEC-01 | decision | `docs/design-decisions.md` -- container-elim [ARCH] ruling (D-123 amendment vs new D-number) | new | none (root ruling; operator rules, GA-R5) | -- | [CE] |
| DEC-02 | decision | D-128 amendment ratification (Plane 2 shrinks to MAAS/NetBox; substrate build becomes wholly Plane 1) | new | DEC-01 | -- | [CE] |
| DEC-03 | decision | D-125 bridge-in retirement note (rides DEC-01) | new | DEC-01, TF-03 | -- | [CE] |
| DEC-04 | decision | D-138 concrete-host change (client VM replaces `vvr1-dcN` as the concrete host) | new | DEC-01 | -- | [CE] |
| DEC-05 | decision | D-122 site-down re-earn note (one-command site-down lost; re-earned via SC-09) | new | DEC-01 | -- | [CE] |
| DEC-06 | decision | D-124 sizing-void re-cause note (rack-addressing vars deleted with TF-01) | new | DEC-01 | -- | [CE] |
| DEC-07 | decision | D-132-addendum premises note (hypervisor-fate rationale moot under Option 1) | new | DEC-01, DEC-08 | -- | [CE] |
| DEC-08 | decision | Rack-controller retirement ratification (+ live re-measure of `primary_rack` both DCs) | new | live measurement (delivery-time, owed) | -- | [CE] |
| DEC-09 | decision | D-131 forwarder retire-with-evidence ratification (per-DC; dc1 asymmetry) | new | SC-15 (#13), DEC-08 | 13 | [CE] |
| DEC-10 | decision | Artifact-service (`.4`) placement + sizing decision | new | SC-16 (#7 FIT ext w/ mirror sizing) | 7 | [CE] |
| DEC-11 | decision | Root topology ratification: (B) shared-outer + per-DC-flat vs merged single root | new | none (Phase 4 ratifies recommendation) | -- | [CE] |
| DEC-12 | decision | Root naming (`vr1-dcN-flat` vs reserving `-substrate`) | new | DEC-11 | -- | [CE] |
| DEC-13 | decision | Client-VM octet `.8` + name `vr1-dcN-client` into D-134 standing map | new | none (recommended) | -- | [CE] |
| DEC-14 | decision | (a) control's concrete mechanism (nftables rule set / check shape / SEC-NNN) | new | none | 2 | [CE] |
| DEC-15 | decision | Concern-(iii) power-key mitigation mechanism choice (restricted key / wrapper / polkit ACL) + SEC-NNN -- **CRITICAL PATH** | new | none | 11 | [CE] |
| DEC-16 | decision | SEC-010 successor SEC-row disposition (new row vs amendment); endpoint ratification (client VM + voffice1, already recommended) | new | none | 3 | [CE] |
| DEC-17 | decision | `wan-bridge` module directory: delete vs leave-unreferenced (append-only bias) | new | DEC-01, TF-03 | -- | [CE] |
| DEC-18 | decision | SEC-013 `maas-vm-host` retire-or-keep (flagged to its owner, not this pass) | new | none | -- | [CE] |
| DEC-19 | decision | `maas-fabric-prune.sh`/`maas_fabric_classify.py` harness gap: build vs accept-as-named-exception (pre-existing, container-elim-adjacent only) | new | none | -- | [CE-adjacent] |
| DEC-20 | decision | A11's home: fold into `cloud-assert.sh` vs a dedicated `isolation-assert.sh` | new | DEC-14 | -- | [CE] |
| DEC-21 | decision | NetBox-migration design: rename-in-place vs concept retirement (for HN-A6/#9) | new | none | 9 | [CE] |
| DEC-22 | decision | D-127 client-VM autostart value (needed for HN-A1's new case) | new | none | -- | [CE] |
| DEC-23 | decision | State-blast-radius weighing (rides DEC-11) | new | DEC-11 | -- | [CE] |

### 1.2 OpenTofu roots/modules

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| TF-01 | tofu-module | `opentofu/main.tf` `module vvr1_dc0/_dc1` + sizing/rack-addressing/pubkey vars (`variables.tf:137-156,175-194,196-244`) | retire | DEC-01, DEC-11 | -- | [CE] |
| TF-02 | tofu-module | `opentofu/vr1-dc0-substrate/`, `vr1-dc1-substrate/` (whole inner roots + states) | retire (as roots; module bodies re-home) | DEC-11, TF-12, TF-13 | -- | [CE] |
| TF-03 | tofu-module | `modules/wan-bridge` (+ `vr1_dcN_wan` calls, IP-less uplink NIC, `br-vr1-dcN-wan` netplan) | retire | DEC-01, DEC-17 | -- | [CE] |
| TF-04 | tofu-module | `modules/site-wan` output rewire (feeds DC edge directly, no bridge-in) | change | TF-03 | -- | [CE] |
| TF-05 | tofu-module | `modules/cloudinit-vm` (loses 2 containment calls, gains the client-VM call) | re-home | TF-12, DEC-13 | -- | [CE] |
| TF-06 | tofu-module | `modules/dc-planes` (6 planes re-homed to vcloud level; same CIDRs/families/MTU) | re-home | TF-12 | -- | [CE] (shape only; values D-139/D-143-owned) |
| TF-07 | tofu-module | `modules/dc-storage-pool` (2-per-DC collapses to 1) | re-home | TF-12 | -- | [CE] |
| TF-08 | tofu-module | `modules/node-vm` x12/DC (unchanged body, re-homed call site) | re-home | TF-12 | -- | [CE] |
| TF-09 | tofu-module | `modules/opnsense-edge` (one input re-pointed to TF-04's direct NAT) | change | TF-04 | -- | [CE] |
| TF-10 | tofu-module | `modules/base-image` (re-homed call site, no logic change) | re-home | TF-12 | -- | [CE] |
| TF-12 | tofu-module | **NEW** `modules/dc-site` (composes pool + 6 planes + edge + 12 node VMs + client VM; replaces the ~230-266-line copy-pasted per-DC inner-root bodies) | new | DEC-11, DEC-13 | 12 | [CE] |
| TF-13 | tofu-module | **NEW** per-DC flat root files (shared-outer + per-DC-flat, 3 roots total) invoking `modules/dc-site` | new | DEC-11, DEC-12, TF-12 | -- | [CE] |
| TF-14 | tofu-module | D-124 transit-leg re-point (Office1-leg consumer: `vvr1-dcN` NIC1 -> client-VM transit NIC; `mesh-link`/`netem-link` bodies unchanged) | change | TF-12/TF-13, DEC-13 | -- | [both] (octet math D-143, bearer host CE) |

Note: `modules/office1-network`, `mesh-link` (x3), `netem-link` are CONFIRMED UNCHANGED
(pass2 check 3/4.5) -- not itemized as rows. `modules/maas-vm-host` is dead/orthogonal,
never instantiated -- see DEC-18, not itemized as a change row.

### 1.3 `lib-hosts.sh` / `lib-net.sh`

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| LB-01 | lib | `scripts/lib-hosts.sh` `VIRSH_POWER_ADDRESS_FROM_OFFICE1`/`_FROM_DCREGION` (`:212-213,246-251`) | change | DEC-15 -- **BLOCKED** | feeds 11 | [CE] |
| LB-02 | lib | `scripts/lib-hosts.sh` `REGION_HOST_SUFFIX` comment (`:95-100`) | change | none | -- | [CE] (comment-currency, low priority) |
| LB-03 | lib | `scripts/lib-net.sh` (whole file) | change | D-143 ruling (separate axis) | -- | [D-143] (ZERO container-elim edits, grep-verified; noted here only so the axis is not conflated) |

Note: `CARVE_AUX_HOSTS`, `NIC_PLANE_ORDER`, `BREX_PARENT_NIC`, `HOST_OCTET` maps/suffixes,
`HOST_TAG`, resolver fns -- UNCHANGED under container-elim (octet maps change under D-143
only). The client VM does NOT get a `lib-hosts.sh` row (resolved: it is L1 `cloudinit-vm`,
not MAAS/virsh-power-managed; identity lives in tofu + NetBox).

### 1.4 Scripts

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| SC-01 | script | `scripts/maas-node-power.sh` invocation-site/runbook literals (no code change to the script itself -- address is `$1`) | change | LB-01, DEC-15 -- **BLOCKED** | feeds 11 | [CE] |
| SC-02 | script | `scripts/dc-rack-net.sh` -- LEGS/`br_of()` half retires; DNS-forwarder half depends on D-131 | change/retire (split) | DEC-09, TF-01 | -- | [CE] |
| SC-03 | script | `scripts/site-headend-install.sh` `node_host_setup()`/`node_host_check()` `--host-nodes` (~134 lines) | retire | DEC-01 | -- | [CE] |
| SC-04 | script | `scripts/site-headend-install.sh` SEC-010 writer extraction (`:273-320`) into a role-agnostic subcommand installing BOTH ends | change | DEC-16 | 3 | [CE] |
| SC-05 | script | `scripts/site-headend-install.sh` `--role rack` (Section 6) | retire (contingent) | DEC-08 | -- | [CE] |
| SC-06 | script | `scripts/dc-mirror.sh` / `dc-cache-proxy.sh` / `dc-snap-proxy.sh` -- new host + explicit disk sizing | change | SC-16 (#7), DEC-10 | rides 7 | [CE] |
| SC-07 | script | `scripts/maas-region-power-key.sh` (body unchanged; URI/key shape it installs re-derives) | change | DEC-15 -- **BLOCKED** | feeds 11 | [CE] |
| SC-08 | script | `scripts/site-baseleg.sh` comment block (re-cite D-138 + the (a) control, not the retired qemu+ssh premise) | change | none | -- | [CE] (doc-currency; stays a no-op) |
| SC-09 | script | **NEW** teardown primitive (module/root-scoped `tofu destroy` procedure) | new | DEC-11 | 1 | [CE] |
| SC-10 | script | **NEW** (a) cross-DC host isolation control (nftables artifact) | new | DEC-14 | 2 | [CE] |
| SC-11 | script | **NEW** power-key blast-radius mitigation (restricted key / wrapper / polkit ACL) -- **CRITICAL PATH** | new | DEC-15 | 11 | [CE] |
| SC-12 | script | **NEW** R7 credential-revocation checklist (enumerate every `vm-secret-locations` row keyed to the rack host class) | new | none (ready) | 4 | [both] |
| SC-13 | script | **NEW** MAAS machine-record release/delete step (+ `maas rack-controller delete` decommission + region+rack runbook note) | new | DEC-08 (decommission half) | 5 | [D-143 primary, CE ride] |
| SC-14 | script | **NEW** emergency site-down lever (`virsh destroy` loop over the DC root's domain set, roster from `lib-hosts.sh`) | new | DEC-11, SC-09 | 6 | [CE] |
| SC-15 | script | **NEW** D-131 retirement-evidence checker (dig test against each fresh region's own BIND) | new | DEC-09 | 13 | [CE] |
| SC-16 | script | `scripts/dc-dc-whole-host-budget.py` FIT-calculator extension (3 utility-node classes + artifact-service disk-sizing branch) + fresh vcloud capacity measurement | change | none (ready) | 7 | [both] |
| SC-17 | script | MAC re-measurement pass (post-apply, before B.6 trusts any MAC -- likely force-replace) | change (procedure) | TF-13 | 8 | [CE] |
| SC-18 | script | `netbox/dc-rack-mgmt-import.py` (decommission `vvr1-dcN` DCIM records; register client VM + flat roster) | change | DEC-21 | 9 | [CE] |
| SC-19 | script | `scripts/geneve-encap-assert.sh` -- new invocation point post-build (no code change; verbatim re-run) | change (new invocation only) | TF-13 | 10 | [both] (MTU budget analytically unchanged, live assert still owed) |

Note: `dc-node-carve.sh`, `dc-node-v6-carve.py`, `carve-host-interfaces.sh`,
`maas-role-tags.sh`, `maas-profile-assert.sh`, `maas-role-tags.sh`, `dc-egress-check.sh`
logic bodies -- NO CODE CHANGE (grep-verified zero containment hits; pure MAAS-API,
`<site>`-parameterized); only invocation-host currency (D-128-amendment territory) and doc
comments naming `vvr1-dcN` need updating -- LOW priority, not itemized as separate rows.

### 1.5 Doc (workflow doc + gate-table prose, non-runbook)

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| DC-01 | doc | `docs/dc-dc-deployment-workflow.md` Stage 3 (Build/Gate/Owns/Reuse-vs-new lines) | change | DEC-01, DEC-11 | -- | [CE] |
| DC-02 | doc | `docs/dc-dc-deployment-workflow.md` Stage 4 gate-line + G17 literal | change | DEC-08 (rack placement), D-143 address | -- | [both] |
| DC-03 | doc | `docs/dc-dc-deployment-workflow.md` Stage 5 literals (transit-IP re-point, e.g. `docs/CURRENT-STATE.md:7829` "openstackclient ... ON THE dc0 RACK (172.31.0.2)") | change | DEC-13 | -- | [CE] |
| DC-04 | doc | `docs/dc-dc-deployment-workflow.md` gap register: NEW entry for the (a) control | new | SC-10 | 2 | [CE] |
| DC-05 | doc | `docs/dc-dc-deployment-workflow.md` gap register: #2 reshapes, #17 closing-mechanism note goes historical, #20 verdict re-verify (its own expiry clause triggers) | change | TF-13 | -- | [both] |
| DC-06 | doc | `docs/dc-dc-deployment-workflow.md` Stage 2 -- explicit two-containment-patterns-distinction note (D-114 KEPT vs D-123 RETIRED, so name-similarity does not sweep Stage 2 in) | new | none | -- | [CE] |

Note: Stages 1, 6, 7 and the `dc-dc-office1-service-reip.md` / `dc-dc-phase0-vcloud-prep.md`
/ `dc-dc-phase1-office1-standup.md` runbooks are CONFIRMED NO CHANGE / OUT OF SCOPE (D-114,
zero containment hits) -- not itemized.

### 1.6 Runbooks

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| RB-01 | runbook | `runbooks/dc-dc-teardown-rollback.md` | change (rewrite) | DEC-11, SC-09, SC-13 | rides 1,5 | [both] |
| RB-02 | runbook | `runbooks/dc-dc-phase2-tofu-dc-substrate.md` | change (heaviest rewrite) | TF-12, TF-13, SC-10 | rides 2,12 | [CE] |
| RB-03 | runbook | `runbooks/dc-dc-phase3-maas-enlist-deploy.md` (SSH-jump-target lines `:424,430`) | change (low delta) | DEC-08 (rack/placement ruling) | -- | [CE] |
| RB-04 | runbook | `runbooks/dc-dc-phase4-juju-bundle-per-dc.md` (RUN-LOCATION table 3rd correction) | change | DEC-13 | -- | [both] (overlay literals D-143, execution-host CE) |
| RB-05 | runbook | `runbooks/dc-dc-phase6-designate-cos-magnum.md` (`:437-444` pre-existing stale-D-138 defect) | change (ride-along fix, not a container-elim delta) | none | -- | [pre-existing; rides RB-04's sweep] |

Note: `dc-dc-phase5-dr-failover-drill.md` has NO DIRECT CHANGE -- it inherits RB-04's table;
not itemized as its own row.

### 1.7 Gates (preflight / cloud-assert / G-series)

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| GT-01 | gate | **NEW** Stage-1 gate for the (a) control -- `--check` enumerates the live bridge set for both DCs' six planes, asserts FORWARD denial between every dc0-tagged/dc1-tagged bridge pair, REFUSES if fewer than the full plane count resolves | new | SC-10, DEC-14 | 2 | [CE] |
| GT-02 | gate | `cloud-assert.sh` A11a (periodic re-verify of the (a) control: post-deploy/restart/pre-change/post-incident) | new | GT-01 | -- | [CE] |
| GT-03 | gate | `preflight.sh` P10 (SEC-010 successor / concern ii, DC-scoped, host-bound on the P7 model; one installer/checker covers both ends) | new | SC-04, DEC-16 | 3 | [CE] |
| GT-04 | gate | `preflight.sh` P4 dependency + `cloud-assert.sh` A11b (power-key concern-iii verification -- negative test: a DC's region key cannot reach domains outside its own roster) -- **CRITICAL PATH** | new/change | SC-11, DEC-15 | 11 | [CE] |
| GT-05 | gate | `preflight.sh` P8 substrate-drift loop -- extend from one hardcoded path to a **DECLARED list** of every post-flatten root (never a glob -- administrator amendment, a glob cannot fail on a missing/renamed root) | change | DEC-12 | -- | [CE] |
| GT-06 | gate | `preflight.sh` P5 creds-matrix register rows re-point (`rack`-class -> `client`-class); NEW rows for SC-04(#3)/SC-11(#11) key material when minted | change (data) | SC-04, SC-11 | -- | [both] |
| GT-07 | gate | `preflight.sh` P9 (`dc-egress-check` invocation-host literal, re-points to the ruled B.5 host) | change | DEC-08 (B.5 placement ruling) | -- | [CE] |
| GT-08 | gate | `docs/CURRENT-STATE.md` G9/G10 successor -- single apply-and-verify gate (substrate apply + (a) `--check` + depth-2 boot proof + direct-NAT egress test), replacing the outer/inner pair | change | TF-13, GT-01 | -- | [CE] |
| GT-09 | gate | `docs/CURRENT-STATE.md` G17 -- the one dual-cause gate-literal edit (new address family D-143 + new host container-elim, in one edit) | change | DEC-08, D-143 ruling | -- | [both] |
| GT-10 | gate | `docs/CURRENT-STATE.md` G14 (indirect -- residency re-points + >=1 new SEC row are count-affecting; flag for the next `ledger-scan.sh` reader, instrument-currency lesson #25) | change (flag only) | SEC-01, SEC-02 | -- | [CE] |

Note: G12 is CLOSED/historical, read as "the shape being replaced," not touched further.
G18, G1-G8, G11, G13, G15, G16 and cloud-assert A0-A10 -- CONFIRMED no container-layer
dependency (verified per-gate by W1.2/W3.2); not itemized.

### 1.8 Harnesses (tests/) -- A/B/C tags preserved from `pass3-w3-new-tests.md`

**A: existing -- change (9 verdict-blocks)**

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-A1 | harness | `tests/opentofu-validate` T14/T15 (autostart pins) + new `vr1-dcN-client` case | change | DEC-12 (root-naming), DEC-22 (D-127 client-VM value) | -- | [CE] |
| HN-A2 | harness | `tests/node-vm` T8-T11 (hardcoded `INNER=` path) | change | DEC-12 | -- | [CE] |
| HN-A3 | harness | `tests/site-headend-install` Section-8 SEC-010 sub-case (= owed #3's harness half) | change | SC-04 | 3 | [CE] |
| HN-A4 | harness | `tests/dc-selector` power-address rows (`:204-247`) | change | DEC-15, SC-11 -- **BLOCKED** | feeds 11 | [CE] |
| HN-A5 | harness | `tests/maas-region-power-key` URI assertions (`:67,82,102,108`) -- edited TOGETHER with HN-A4, same session | change | DEC-15, SC-11, HN-A4 -- **BLOCKED** | feeds 11 | [CE] |
| HN-A6 | harness | `tests/dc-rack-mgmt-import` vvr1 pins (`:77-78`, = owed #9's harness half) | change | DEC-21, DEC-08 | 9 | [CE] |
| HN-A7 | harness | `tests/maas-profile-assert` office1-profile fixture (`:41,68,72,80`) | change | DEC-08 | -- | [CE] |
| HN-A8 | harness | `tests/dc-dc-whole-host-budget` (= owed #7's harness; the one universe-boundary crossing) | change | SC-16 | 7 | [both] |
| HN-A9 | harness | `tests/pre-flight-checks` -- NEW case post-#11 (live power-address must match the mitigation's issued shape) | new (case) | SC-11, GT-04 -- **BLOCKED** | 11 | [CE] |

**B: existing -- retire (5 verdict-blocks)**

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-B1 | harness | `tests/opentofu-validate` T13 (D-127 containment autostart pin) | retire | TF-01 | -- | [CE] |
| HN-B2 | harness | `tests/site-headend-install` `--host-nodes` block (~15 cases; excludes the SEC-010 sub-case = HN-A3) | retire | SC-03 | -- | [CE] |
| HN-B3 | harness | `tests/site-headend-install` Section 6 (`--role rack`) | retire (contingent) | DEC-08 | -- | [CE] |
| HN-B4 | harness | `tests/dc-rack-net` LEGS cases (T3,T5,T13,T15,T17) | retire | SC-02 | -- | [CE] |
| HN-B5 | harness | `tests/dc-rack-net` DNS-forwarder cases (T4,T9,T16) + 8 hygiene cases | retire (contingent) | DEC-09 | -- | [CE] |

**C: new-build (7 harnesses, one per owed artifact)**

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| HN-C1 | harness | `tests/dc-site/run-tests.sh` (static fixture `.tf` trees) | new | TF-12 | 12 | [CE] |
| HN-C2 | harness | (a) control offline fixture harness | new | SC-10, DEC-14 | 2 | [CE] |
| HN-C3 | harness | Teardown-primitive fixture library (+ #6 emergency lever rides the same library) | new | SC-09, DEC-11 | 1, 6 | [CE] |
| HN-C4 | harness | Power-key mitigation harness -- **itself a precondition for HN-A4/HN-A5/HN-A9** | new | SC-11, DEC-15 | 11 | [CE] CRITICAL |
| HN-C5 | harness | D-131 retire-evidence checker harness (fixtures exist in the two cited changelogs) | new | SC-15 | 13 | [CE] (fixture-ready) |
| HN-C6 | harness | R7 credential-revocation checklist harness | new | SC-12 | 4 | [both] (ready) |
| HN-C7 | harness | MAAS record release/delete (+ rack decommission) harness | new | SC-13 | 5 | [D-143/CE] (ready) |

Rides (no separate build): #6 -> HN-C3's fixture library; #8 MAC re-measure -> HN-C1's MAC
invariant; #10 geneve/jumbo -> `geneve-encap-assert` verbatim, new invocation point only
(SC-19). `tests/opentofu-validate` T8-T10, `node-vm` T1-T7/T12-T15, `site-headend-install`
Sections 1-5/7, `maas-node-power` (opaque pass-through arg), `preflight` pending-change
fixture, `geneve-encap-assert` (all cases), `site-baseleg`, `cloudinit-vm`,
`d124-transit-seed`, `netem-link` (declared grep false-positive), and the 90 no-hit
harnesses are CONFIRMED STAY -- not itemized.

### 1.9 Security-ledger (SEC) rows

| ID | category | artifact | change | depends-on | owed-artifact# | axis |
|---|---|---|---|---|---|---|
| SEC-01 | SEC | NEW SEC-NNN row for the (a) cross-DC host isolation control (concern i); next-free confirmed **SEC-034** as of 2026-08-09, re-grep at mint time | new | DEC-14 | 2 | [CE] |
| SEC-02 | SEC | NEW SEC-NNN row for the power-key mitigation (concern iii) -- **CRITICAL PATH** | new | DEC-15 | 11 | [CE] |
| SEC-03 | SEC | SEC-010 disposition: new row vs amendment (concern ii) | new/change | DEC-16 | 3 | [CE] |
| SEC-04 | SEC | `vm-secret-locations` register rows (SEC-026/SEC-028/SEC-029) re-point rack-class -> client-class; rotation triggers ("if the rack is rebuilt") FIRE on this change | change | DEC-13, SC-12 | -- | [both] |

---

## 2. Critical-path dependency chains

### Chain A -- Power-key blast-radius mitigation (owed #11; the single largest blocker)
`DEC-15` (mechanism choice: restricted key / wrapper / polkit ACL) -> `SEC-02` (mint the
SEC row) -> `SC-11` (build the #11 artifact) -> `HN-C4` (harness -- itself a precondition,
not just coverage) -> `LB-01` (`lib-hosts.sh` power-address re-derivation) + `SC-07`
(`maas-region-power-key.sh` URI/key shape) -> `SC-01` (`maas-node-power.sh` call-site
literals) -> `HN-A4` + `HN-A5` (`dc-selector` / `maas-region-power-key` assertions,
**edited together, same session** -- H1 hazard: a plausible-looking URI swapped in before
the mechanism exists produces a false-green harness) -> `HN-A9` (`pre-flight-checks` P4
case) + `GT-04` (cloud-assert A11b) -> `GT-06` (P5 register row for the new key material).
Six downstream test/tool edits are frozen until `DEC-15` rules (pass3 Section 4); the
interim RED on `HN-A4`/`HN-A5` once `lib-hosts.sh` changes is the DESIRED fail-loud state,
never something to "fix" early.

### Chain B -- The (a)-control-before-any-flat-apply invariant (owed #2)
`DEC-14` (mechanism) -> `SEC-01` (SEC row) -> `SC-10` (#2 artifact) -> `HN-C2` (harness) ->
`GT-01` (Stage-1 gate, installed + `--check`-verified) -> **MUST PRECEDE** -> `TF-13`
(first flat substrate apply of EITHER per-DC root, under whatever `DEC-11` root shape
lands -- fork-robust: a merged single root's FIRST apply can create both DCs' planes at
once, so "before the second DC's apply" is not sufficient, only "before ANY flat apply"
survives the fork) -> `GT-02` (A11a re-verify at each apply's close) -> `GT-08` (folds into
the G9/G10 successor gate) -> re-verified again at Stage-5 live traffic (the first point
the claim is actually tested).

### Chain C -- R7 + MAAS-release before destroy (Part A of the teardown sequence)
`SC-12` (#4 R7 credential-revocation checklist, enumerated from every `vm-secret-locations`
row keyed to the rack host class) + `HN-C6` (harness) -> **run BEFORE any substrate
destroy** (revoking after the hosts are gone degrades to "assume it's moot") -> `SC-13`
(#5 MAAS machine-record release/delete + rack-controller decommission + region-side
`primary_rack`/DHCP-reference cleanup) + `HN-C7` (harness) -> `TF-01`/`TF-02` destroy
applies (inner roots first from voffice1, then outer from vcloud) -> `RB-01` (teardown
runbook rewrite encodes this exact order). This chain governs the CURRENT 10.12 checkpoint
teardown and is largely independent of `DEC-11`'s root-shape ruling for the NEW build.

### Cross-cutting: the root-topology fork (`DEC-11`)
Gates `TF-02`, `TF-12`, `TF-13`, `SC-09`, `SC-14`, `HN-C3`, `RB-01`, `GT-05`, `HN-A1`,
`HN-A2`, `DEC-12`, `DEC-23` -- the sequence itself is invariant to the fork (per pass1
check 2), but the teardown primitive's exact wording, the state blast radius, and every
root-naming literal are NOT. Ratify `DEC-11` early; it unblocks the largest single cluster
of "ready once ratified" rows.

---

## 3. Count summary by category

| Category | Rows |
|---|---|
| decision (DEC) | 23 |
| tofu-module (TF) | 13 |
| lib (LB) | 3 |
| script (SC) | 19 |
| doc (DC) | 6 |
| runbook (RB) | 5 |
| gate (GT) | 10 |
| harness (HN) | 21 (9 change + 5 retire + 7 new-build) |
| SEC | 4 |
| **Total** | **104** |

Cross-check against source counts: harness total (21) matches pass3 Section 2's
9-existing-change + 5-existing-retire + 7-new-build decomposition exactly; owed-artifact
references (13 distinct #-tags) all appear at least once across TF/SC/GT/HN/SEC rows, with
no double-counting (rack decommission folds into SC-13/#5; artifact-service sizing rides
SC-16/#7; the SEC-010-writer extraction IS SC-04/#3's implementation shape -- all per
pass2 Section 5's explicit "not double-counted" note, carried forward here).

---

## 4. Verification note

Author = W4.1 (no model name asserted). This document is a MERGE of `pass1-admin-report.md`
Sections 2-6, `pass2-admin-report.md` Sections 3-6, and `pass3-admin-report.md` Sections
2-5 -- no new repo reads were performed beyond the four admin reports and their stated
verification notes; every row's artifact path/line traces to a citation already verified
in one of those four reports (see each report's own Section verifying "Verification note"
/ "Adversarial-check results" for the underlying grep/read evidence). READ-ONLY; nothing
executed; findings LOGGED only.
