dc: vr1-dc1
output: overlays/vr1-dc1-vips.yaml
family: dual
legs:
- provider-public
- metal-admin
- metal-internal
prefixes_v4:
  provider-public: 10.12.64
  metal-admin: 10.12.68
  metal-internal: 10.12.72
source_v4: scripts/lib-net.sh lib_net_select_dc vr1-dc1
prefixes_v6:
  provider-public: 2602:f3e2:f03:11
  metal-admin: fd50:840e:74e2:320
  metal-internal: fd50:840e:74e2:321
apex_record: netbox/draft/vr1-office1-current-20260725.json
apps:
- name: keystone
  octet: 50
- name: barbican
  octet: 51
- name: cinder
  octet: 52
- name: glance
  octet: 53
- name: magnum
  octet: 54
- name: neutron-api
  octet: 55
- name: nova-cloud-controller
  octet: 56
- name: octavia
  octet: 57
- name: openstack-dashboard
  octet: 58
- name: placement
  octet: 59
- name: ceph-radosgw
  octet: 60
- name: vault
  octet: 61
- name: designate
  octet: 62
header: '# overlays/vr1-dc1-vips.yaml

  # Per-DC VIP overlay for vr1-dc1. GENERATED by scripts/render-dc-overlays.py from

  # render/values/vr1-dc1-vips.yaml -- edit the values file and re-render; do not

  # hand-edit this file.

  #   juju deploy ./bundle.yaml --overlay ./overlays/vr1-dc1-vips.yaml

  #

  # RULING 3 (2026-07-25) made bundle.yaml VIP-FREE, so this file is the ONLY source of

  # vr1-dc1''s VIPs and the bundle is not deployable without it.

  #

  # DUAL-FAMILY per R2 (RULED 2026-07-27): each vip carries the three v4 legs THEN the

  # three v6 legs. Column order is provider-public / metal-admin / metal-internal,

  # v4 then v6.

  #

  # `prefer-ipv6: true` IS EMITTED ONLY FOR THE SEVEN CHARMS THAT DECLARE IT (RULED

  # 2026-07-31, D-101 RULING NOTE: "Yes -- keep the v6 legs, remove only the option").

  # The six that do not -- barbican, designate, magnum, octavia, placement, vault --

  # keep every v6 leg and simply do not get the option; juju rejects the WHOLE bundle

  # on an unknown option, which killed deploy attempt 1 on 2026-07-31. The option is

  # NOT what makes HAProxy bind :::port: that is gated on the kernel disable_ipv6

  # sysctl, and pacemaker picks IPv6addr by address-family detection

  # (docs/audit/stage5-prefer-ipv6-charm-research-20260731.txt). Where it IS legal it

  # still travels with the v6 legs -- provider-bundle-check invariant 9b. The

  # charm list lives in provider-bundle-check.py PREFER_IPV6_CHARMS and the renderer

  # READS it; it is a PINNED MEASUREMENT, re-measure if a channel pin moves.

  #   v4 prefixes  MEASURED from scripts/lib-net.sh lib_net_select_dc vr1-dc1

  #   v6 prefixes  READ FROM THE NETBOX APEX (D-136 option (D)); the provider leg uses

  #                the DEDICATED GUA VIP /64, admin+internal their own plane /64s

  #   v6 host part MIRRORS the v4 octet textually (RULED 2026-07-27) -- .50 -> ::50

  #

  # vault .61 and designate .62 are R11 (a D-020 AMENDMENT, 2026-07-27). Per R6 these

  # land BEFORE overlays/dc-ha-scaleup.yaml, which is what gives vault a real HA target.

  # The B1 / B5 tokens below are DEFINED in bundle.yaml''s own header block.

  '
