Skip to content

docs(ovn): document evidence-first log and trust recovery - #34

Merged
jmgilman merged 1 commit into
masterfrom
docs/desktop-phase6-ovn-recovery
Sep 16, 2026
Merged

jmgilman merged 1 commit into
masterfrom
docs/desktop-phase6-ovn-recovery

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Change

  • Document evidence-first ENOSPC recovery: off-VM log capture and full signature scan, immutable archive, exact-file truncation approval, and inode recheck after rotation.
  • Document explicit CA creation and pinned trust, selective PID-witnessed Incus daemon rolls, and source-managed OVN/syslog/journal retention controls.
  • Record the approved 2026-09-14 recovery and observed results, including unchanged central database/northd processes and reduced connection churn.
  • Link companion source prevention in GilmanLab/fleet#20. No design documents changed.

Verification

  • moon run docs:build passed (strict MkDocs build).
  • The documented incident commands were exercised against nas01:ovncentral01: selected Incus service roll, logging activation, rsyslog validation, logrotate debug, and unchanged central process witnesses.
  • The pre-recovery archive is immutable; later recovery evidence is explicitly distinguished from its contents.

@jmgilman
jmgilman merged commit 0ab6ac1 into master Sep 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant