openstack-caracal-dc-dc / scripts /
..
checks DOCFIX-132/133: S-class cleanups -- S7 dead code + S4 trust_filter.py consolidation 23 days ago
prereqs Fold the AppArmor/libvirt rule into scripts/prereqs -- it gated every VR1 VM boot 18 days ago
sudoers.d Step-E netem sudo: scoped NOPASSWD fragment shipped (operator-ruled) 10 days ago
carve-host-interfaces.sh Delivery batch: lib-hosts VR1 arms, D-133 guards, appendix-A pf entry, DoD 8-9 (gauntlet 77 GREEN) 8 days ago
channel_assert.py Patches 28 days ago
cloud-assert.sh Four gate-integrity defects fixed, each demonstrated RED then GREEN 2 days ago
cloud-snapshot.sh addendum 28: operator-away batch integrated -- DOCFIX-098..105 (H4 drift detector, offboard orphan sweep + E0 guard, handover pack, cloud-snapshot, tenant-acceptance harness, lint L7 sweep rule, ledger-scan 099-boundary fix) 25 days ago
creds-audit.sh D-137 phase 2: fix the eight confirmed false-greens, regression-lock each 5 days ago
creds-matrix.py dc0 MAAS region LIVE; three creds minted, consolidated and REGISTERED (SEC-027) 1 day ago
creds-probe.sh D-137 tier 3 behavioural half: V2 declared-state + creds-probe.sh 4 days ago
d063-apply.sh test patched 27 days ago
dc-cache-proxy.sh Four gate-integrity defects fixed, each demonstrated RED then GREEN 2 days ago
dc-dc-ceph-disk-budget.sh D-119: region-qualify the VR1 DC namespace -- C3 / gap #19 CLOSED (Stage 3 unblocked) 17 days ago
dc-dc-dr-drill.sh D-119: region-qualify the VR1 DC namespace -- C3 / gap #19 CLOSED (Stage 3 unblocked) 17 days ago
dc-dc-mtu-geneve-budget.sh DOCFIX-162: MTU/geneve + Ceph disk-budget calculator scripts (gap #7) 21 days ago
dc-dc-radosgw-multisite.sh G12 dc1: item-3 substrate landed + harness reconcile (gauntlet 76 ALL GREEN) 9 days ago
dc-dc-rbd-mirror.sh G12 dc1: item-3 substrate landed + harness reconcile (gauntlet 76 ALL GREEN) 9 days ago
dc-dc-whole-host-budget.py Review sweep A+B + R-3 storage-04: coherent record, whole-host calculator, R-3-compliant Model A fallback 15 days ago
dc-mirror.sh Build the D-135 amendment: jammy-backports at source, T10 re-pointed 4 hours ago
dc-node-carve.sh dc-node-carve: unlink reason is a parameter, not a constant 22 hours ago
dc-node-v6-carve.py dc-node-v6-carve.py: honour MAAS_PROFILE; refuse instead of tracebacking 1 day ago
dc-plane-ipam.sh dc-plane-ipam: v6 bands are VERIFIED against MAAS's default reservation, not created 3 days ago
dc-rack-net.sh G12 dc1: dc-rack-net.sh dc1 site-table arm + harness (D-131 sub-1) 8 days ago
dc-region-topology.sh dc-region-topology: RENAME the auto fabric instead of moving the subnet 1 day ago
deploy-watch.sh scripts: add deploy-watch.sh (Window-2 settle monitor; fixes phase-01 line-148 dangling ref) 1 month ago
extract_admin_password.py New Phase Scripts 1 month ago
juju-spaces-check.sh DOCFIX-173: full-project sweep -- script logic bugs + security hardening 21 days ago
keystone-policy-drift.sh addendum 28: operator-away batch integrated -- DOCFIX-098..105 (H4 drift detector, offboard orphan sweep + E0 guard, handover pack, cloud-snapshot, tenant-acceptance harness, lint L7 sweep rule, ledger-scan 099-boundary fix) 25 days ago
keystone_policy_compare.py addendum 28: operator-away batch integrated -- DOCFIX-098..105 (H4 drift detector, offboard orphan sweep + E0 guard, handover pack, cloud-snapshot, tenant-acceptance harness, lint L7 sweep rule, ledger-scan 099-boundary fix) 25 days ago
ledger-scan.sh Session bookend: queue-pass CLOSED (ledger summary, changelog archived, scan fix) 8 days ago
lib-hosts.sh lib-hosts: the node carve is ROLE-DEPENDENT, not uniform 1 day ago
lib-identity.sh lib-identity.sh: the estate's name and DNS base in ONE place 1 day ago
lib-net.sh P4 is DC-aware, 3.7 closed, and lib-net's dc1 arm populated 2 days ago
lib-validate.sh test patches 27 days ago
maas-fabric-prune.sh MAAS scripts 1 month ago
maas-node-power.sh NEW: maas-node-power.sh (+harness 24/24) -- per-machine virsh power, MAC-matched 11 days ago
maas-profile-assert.sh Region-resolution gate: maas-profile-assert.sh + named dc0 region profile 1 day ago
maas-region-power-key.sh Per-region power address, region power-key tool, and two red gates fixed 1 day ago
maas-role-tags.sh maas-role-tags owns the D-104 controller tag too; harness 11 -> 12 2 days ago
maas_fabric_classify.py MAAS scripts 1 month ago
net_overlap.py addendum 29: D-074 ADOPTED+EXECUTED -- overlap-allowed tenant CIDRs (Phase 0 gates proven live: exact-overlap subnet + Magnum cluster via API-LB), stage-4 guard rewritten with real overlap math (DOCFIX-106), repo_lint L5 numbering print removed (DOCFIX-107), D-016 amended, contract/runbook/intake aligned 24 days ago
octavia-pki.sh lib-identity.sh: the estate's name and DNS base in ONE place 1 day ago
opentofu-validate.sh voffice1 reconcile: a gate that was RED on the only host that deploys 1 day ago
opnsense-api.sh D-113(a2) step 1: thin OPNsense REST API client + harness 18 days ago
opnsense-bootstrap-apikey.sh Queue pass: post-G12 queued findings delivered (5 script/harness fixes + DOCFIX-198/-199) 8 days ago
opnsense-mint-apikey.php D-113(a2): API-key bootstrap -- no GUI click, no re-implemented crypto 18 days ago
opnsense-plugins.sh FIX false-success: opnsense-plugins.sh apply ALWAYS dry-ran (DRY_RUN:+ expands on 0) 11 days ago
opnsense-prep-image.sh Queue pass: post-G12 queued findings delivered (5 script/harness fixes + DOCFIX-198/-199) 8 days ago
opnsense-set-iface-v4.php NEW: opnsense-set-interface-v4 pair (+harness 53/53) -- IPv4 + WAN gateway via the vendor config model 11 days ago
opnsense-set-iface-v6.php opnsense-set-interface-v6: script the LAN IPv6 the REST API cannot set (D-113 amendment) 17 days ago
opnsense-set-interface-v4.sh set-interface-v4: reload the pf filter on --commit (RULED); appendix-A rewritten 4 days ago
opnsense-set-interface-v6.sh opnsense-set-interface-v6: script the LAN IPv6 the REST API cannot set (D-113 amendment) 17 days ago
osd-blank-check.sh DOCFIX-173: full-project sweep -- script logic bugs + security hardening 21 days ago
phase-00-maas-standup.sh G12 dc1: item-3 substrate landed + harness reconcile (gauntlet 76 ALL GREEN) 9 days ago
phase-00-teardown-destroy.sh Phase handoff updates 1 month ago
phase-00-teardown-release.sh Phase handoff updates 1 month ago
phase-02-vault-preflight.sh Patches 28 days ago
phase-03-admin-openrc.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
phase-03-core-verify.sh Patches 28 days ago
phase-04-internal-cert-san-verify.sh Patches 28 days ago
phase-04-network-create.sh DOCFIX-134: S8a -- FIP pool literals to lib-net.sh (single source of truth) 23 days ago
phase-04-network-verify.sh DOCFIX-134: S8a -- FIP pool literals to lib-net.sh (single source of truth) 23 days ago
phase-05-amphora-pipeline.sh New Phase Scripts 1 month ago
phase-05-octavia-verify.sh Octavia: R8a BUILT (record was false), two stale surfaces, R7 generator de-frozen 2 days ago
phase-06-bootstrap.sh Patches 28 days ago
phase-06-capi-stack.sh DOCFIX-173: full-project sweep -- script logic bugs + security hardening 21 days ago
phase-06-k8s-bootstrap.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
phase-06-kubeconfig-gate.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
phase-06-mgmt-vm.sh Fix scripts 1 month ago
phase-06-net-setup.sh Patches 28 days ago
phase-07-conductor-graft.sh Patches 28 days ago
phase03_accept_walk.py Updated scripts 1 month ago
pre-flight-checks.sh P4 is DC-aware, 3.7 closed, and lib-net's dc1 arm populated 2 days ago
preflight.sh P7: the Octavia amphora PKI becomes an actual pre-deploy gate 1 day ago
provider-bundle-check.py Option D half 1: explicit base on all 56 apps, gated by new invariant 12 6 hours ago
record-audit.py Batch 6: exit runs 1/2/4/5 -- archive exclusion (operator-ruled), adjudication, plan==triple, S2 12 days ago
reenroll-hosts.sh Delivery batch: lib-hosts VR1 arms, D-133 guards, appendix-A pf entry, DoD 8-9 (gauntlet 77 GREEN) 8 days ago
render-dc-overlays.py Build the 2026-07-31 ruling: renderer + invariant 9 replaced, overlays re-rendered 13 hours ago
repo-lint.sh D-137 tier 2: local half blocking in P5; --pending-stage -> coupled projection 5 days ago
repo_lint.py R15(1): repo-lint can no longer report PASS over zero files 3 days ago
resolve_tenant_ip.py Phase 6 scripts 1 month ago
run-logged.sh Patches 28 days ago
run-tests-all.sh Four gate-integrity defects fixed, each demonstrated RED then GREEN 2 days ago
site-baseleg.sh D-126 base-leg oneshot (site-baseleg.sh) + D-128 operating model; post-restart sweep 14 days ago
site-forward.sh D-126: durable rootless agent access to VR1 site VMs (shell + forward) + DC creds prep 15 days ago
site-headend-install.sh Queue pass: post-G12 queued findings delivered (5 script/harness fixes + DOCFIX-198/-199) 8 days ago
site-ssh-config.sh D-126: durable rootless agent access to VR1 site VMs (shell + forward) + DC creds prep 15 days ago
snapshot_scrub.py addendum 28: operator-away batch integrated -- DOCFIX-098..105 (H4 drift detector, offboard orphan sweep + E0 guard, handover pack, cloud-snapshot, tenant-acceptance harness, lint L7 sweep rule, ledger-scan 099-boundary fix) 25 days ago
tenant-acceptance.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
tenant-assert.sh addendum 27: d011-batch3 window EXECUTED -- D-073 APPLIED, foil1 onboarded, d011-04/05 PASS, D-011 closed-except-item-6; DOCFIX-095/096/097 25 days ago
tenant-offboard.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
tenant-onboard.sh DOCFIX-138: S8b -- centralize KEYSTONE_VIP default into lib-net.sh (single source of truth) 22 days ago
trust_filter.py DOCFIX-132/133: S-class cleanups -- S7 dead code + S4 trust_filter.py consolidation 23 days ago
validate.sh addendum 33: script-quality fix batch DOCFIX-112..117 -- anti-escalation guard fail-closed (SECURITY), tenant-offboard hardening cluster, validate/juju-spaces fail-opens, pipefail sweep, guard-hook extension; deferred-findings register; ledger REMAINING-OPEN-WORK block 24 days ago
vault-kv-health.sh addendum 33: script-quality fix batch DOCFIX-112..117 -- anti-escalation guard fail-closed (SECURITY), tenant-offboard hardening cluster, validate/juju-spaces fail-opens, pipefail sweep, guard-hook extension; deferred-findings register; ledger REMAINING-OPEN-WORK block 24 days ago
vault-kv-inner-probe.sh addendum 33: script-quality fix batch DOCFIX-112..117 -- anti-escalation guard fail-closed (SECURITY), tenant-offboard hardening cluster, validate/juju-spaces fail-opens, pipefail sweep, guard-hook extension; deferred-findings register; ledger REMAINING-OPEN-WORK block 24 days ago