Information Asset Registry¶
Classification: CONFIDENTIAL — Internal Use Only
The Information Asset Registry (IAR) is the authoritative inventory of all hardware, network, and cloud assets managed by GPUS-IT. It supports CIS Control 1 (Inventory of Enterprise Assets), CIS Control 2 (Inventory of Software Assets), and PCI-DSS asset management requirements.
Sources of truth: wdc-hostregistry.csv, gcp-hostregistry.csv, and meraki-hostregistry.csv under hostregistry/ — maintained by IT Administration.
Last updated: 2026-09-08 · Total assets: 130 on-premises + 15 GCP cloud assets + 9 gpus-it-infrastructure data-team GCE instances + 32 Meraki network devices + 5 forms-portal data assets + 1 legacy database asset
Handling requirement
This registry contains MAC addresses, IP assignments, and system details. Handle as CONFIDENTIAL. Do not share outside of IT and Security teams.
Asset summary¶
| Category | Count | Network |
|---|---|---|
| Gateway / Firewall | 1 | 192.168.120.251–254 |
| Servers | 5 | 192.168.120.1–40 |
| Appliances, SANs, Printers | 8 | 192.168.120.41–64 |
| Hypervisors | 3 | 192.168.120.65–69 / 192.168.122.150–250 |
| Workstations | 113 | 192.168.120.70–230 |
| GCP Cloud Assets | 15 | us-central1 / 172.16.0.0/24 |
| Network Devices (Meraki) | 32 | Multi-site (cloud-managed) |
| Total | 177 |
What Total counts, and what it does not
Total is the sum of the rows in the table above and nothing else —
130 on-premises + 15 GCP + 32 Meraki. Three categories registered further
down this document have never been inside it: the 9 GCE instances in
gpus-it-infrastructure, the 5 forms-portal data assets, and the 1
legacy database. Grand total registered: 192.
Stated because the figure has been read as a whole-estate count and is not
one. Two corrections were made on 2026-09-01 and are recorded rather than
absorbed: GCP Cloud Assets read 7 against a section holding 8 rows —
wrong before anything was added, present since a02640a, and not
attributable to a later edit — and the seven Pub/Sub entities below were
added, taking the row to 15 and the total from 169 to 177.
Gateway / Firewall¶
| Hostname | FQDN | IP Address | Description | OS / Platform | Dept |
|---|---|---|---|---|---|
| fw | fw.wdc.us.gl3 | 192.168.120.254 | Cisco Meraki MX100 | Meraki | IT |
Servers¶
| Hostname | FQDN | IP Address | MAC Address | Description | OS | Dept |
|---|---|---|---|---|---|---|
| sky | sky.wdc.us.gl3 | 192.168.120.1 | 00:0c:29:6a:a8:74 | Primary DNS/DHCP Server | Rocky Linux 8.10 | IT |
| rain | rain.wdc.us.gl3 | 192.168.120.2 | 00:0c:29:e1:6d:e8 | Secondary DNS/DHCP Server | Rocky Linux 8.10 | IT |
| sun | sun.wdc.us.gl3 | 192.168.120.3 | 00:0c:29:a0:a7:70 | Prometheus/Grafana Monitoring | Rocky Linux 8.10 | IT |
| wind | wind.wdc.us.gl3 | 192.168.120.4 | 00:0c:29:1d:80:0d | ELK Stack Logging | Rocky Linux 8.10 | IT |
| ocean | ocean.wdc.us.gl3 | 192.168.120.28 | 00:50:56:a0:f0:19 | Imaging Server | Fedora | IT |
Appliances, SANs & Printers¶
| Type | Hostname | FQDN | IP Address | MAC Address | Description | Dept |
|---|---|---|---|---|---|---|
| SAN | solstorage | solstorage.wdc.us.gl3 | 192.168.120.43 | 90:09:d0:61:ad:7f | Synology Storage — Solutions team | IT |
| SAN | vmstorage | vmstorage.wdc.us.gl3 | 192.168.120.51 | 90:09:d0:1b:fe:80 | Synology Storage — VMs | IT |
| Printer | mailroom | mailroom.wdc.us.gl3 | 192.168.120.56 | 60:12:8b:f7:c0:75 | Mailroom Canon Printer | IT |
| Printer | fireweed | fireweed.wdc.us.gl3 | 192.168.120.57 | 34:9f:7b:58:9c:3f | Fireweed Canon Printer | IT |
| Printer | woche | woche.wdc.us.gl3 | 192.168.120.58 | 34:9f:7b:58:74:ba | Woche Printer | IT |
| Printer | payroll-printer | payroll-printer.wdc.us.gl3 | 192.168.120.59 | c8:d9:d2:cb:b3:ea | Payroll Printer | Finance |
| SAN | synstorage | synstorage.wdc.us.gl3 | 192.168.120.60 | 1c:34:da:0c:06:a0 | Synology Storage — Video | Media |
| Desktop | gpusresearchdesktop | gpusresearchdesktop.wdc.us.gl3 | 192.168.120.64 | 20:88:10:e3:33:ee | Windows 11 Research Desktop | Research |
Hypervisors¶
| Hostname | FQDN | IP Address | Description | OS | Dept |
|---|---|---|---|---|---|
| water | water.wdc.us.gl3 | 192.168.120.65 | Hosts Ocean | VMware ESXi 6.7 | IT |
| fire | fire.wdc.us.gl3 | 192.168.122.160 | Security ESXi | VMware ESXi 6.7 | IT |
| flower | flower.wdc.us.gl3 | 192.168.122.240 | General hypervisor | VMware ESXi 6.8 | IT |
Workstations¶
113 workstations registered in the wdc.us.gl3 domain, IP range 192.168.120.70–230. All managed via DHCP reservations on SKY/RAIN.
| Hostname | FQDN | IP Address | MAC Address | OS | Dept | User |
|---|---|---|---|---|---|---|
| noconnor | noconnor.wdc.us.gl3 | 192.168.120.70 | 34:48:ed:9e:98:7a | Windows 11 | Data | noconnor |
| hbakar | hbakar.wdc.us.gl3 | 192.168.120.71 | 5c:80:b6:2f:f6:8e | — | — | — |
| kacamosy-mabookpro | kacamosy-mabookpro.wdc.us.gl3 | 192.168.120.72 | 3c:07:54:7d:16:78 | — | — | — |
| macarret | macarret.wdc.us.gl3 | 192.168.120.73 | 14:75:5b:ee:25:e1 | — | — | — |
| nbarnes | nbarnes.wdc.us.gl3 | 192.168.120.74 | ec:63:d7:98:8f:91 | — | — | — |
| rskar | rskar.wdc.us.gl3 | 192.168.120.75 | f0:20:ff:2c:0c:8b | — | — | — |
| eprice-airbook | eprice-airbook.wdc.us.gl3 | 192.168.120.76 | 70:ae:d5:44:98:59 | — | — | — |
| kfrancis-airbook | kfrancis-airbook.wdc.us.gl3 | 192.168.120.77 | 9c:58:84:15:26:a4 | — | — | — |
| ksindayi-airbook | ksindayi-airbook.wdc.us.gl3 | 192.168.120.78 | 84:94:37:cd:f7:a7 | — | — | — |
| kacamosy-airbook | kacamosy-airbook.wdc.us.gl3 | 192.168.120.79 | 9c:58:84:6e:31:6e | — | — | — |
| lharris | lharris.wdc.us.gl3 | 192.168.120.80 | b0:60:88:af:91:aa | — | — | — |
| rocampo | rocampo.wdc.us.gl3 | 192.168.120.81 | d4:d8:53:4c:aa:b3 | — | — | — |
| tdivico-airbook | tdivico-airbook.wdc.us.gl3 | 192.168.120.82 | d0:88:0c:7f:60:c9 | — | — | — |
| nsmith | nsmith.wdc.us.gl3 | 192.168.120.83 | 64:49:7d:92:92:12 | — | — | — |
| arizocen-airbook | arizocen-airbook.wdc.us.gl3 | 192.168.120.84 | 10:b5:88:72:a0:80 | — | — | — |
| jharris-airbook | jharris-airbook.wdc.us.gl3 | 192.168.120.85 | d0:88:0c:65:14:6d | — | — | — |
| cpatters-airbook | cpatters-airbook.wdc.us.gl3 | 192.168.120.86 | 9c:58:84:17:7f:9d | — | — | — |
| gforbes-airbook | gforbes-airbook.wdc.us.gl3 | 192.168.120.87 | c0:95:6d:34:b9:7d | — | — | — |
| jsundius-airbook | jsundius-airbook.wdc.us.gl3 | 192.168.120.88 | 70:ae:d5:49:66:fa | — | — | — |
| folagbaj | folagbaj.wdc.us.gl3 | 192.168.120.89 | 8c:c6:81:1f:8e:0c | — | — | — |
| bloatwaretest | bloatwaretest.wdc.us.gl3 | 192.168.120.90 | 00:e0:4c:01:01:1d | — | — | — |
| asmith-airbook | asmith-airbook.wdc.us.gl3 | 192.168.120.91 | d0:88:0c:64:e1:cb | — | — | — |
| tgarg | tgarg.wdc.us.gl3 | 192.168.120.92 | b4:6b:fc:78:34:80 | — | — | — |
| lbigda-airbook | lbigda-airbook.wdc.us.gl3 | 192.168.120.93 | 84:94:37:c9:8e:fa | — | — | — |
| psindha-airbook | psindha-airbook.wdc.us.gl3 | 192.168.120.94 | 70:ae:d5:48:b3:d9 | — | — | — |
| kstores | kstores.wdc.us.gl3 | 192.168.120.95 | 98:59:7a:5b:1a:ee | — | — | — |
| taubry | taubry.wdc.us.gl3 | 192.168.120.96 | c0:47:0e:0d:6a:d4 | — | — | — |
| jfornber | jfornber.wdc.us.gl3 | 192.168.120.97 | 98:59:7a:5b:99:74 | — | — | — |
| aarminio-airbook | aarminio-airbook.wdc.us.gl3 | 192.168.120.98 | 70:ae:d5:43:fe:63 | — | — | — |
| ccray | ccray.wdc.us.gl3 | 192.168.120.99 | 14:75:5b:f5:a7:0d | — | — | — |
| tavila | tavila.wdc.us.gl3 | 192.168.120.100 | 98:59:7a:5b:d5:fb | — | — | — |
| bphelan | bphelan.wdc.us.gl3 | 192.168.120.101 | 68:7a:64:77:5d:99 | — | — | — |
| bloatwaretest1 | bloatwaretest1.wdc.us.gl3 | 192.168.120.102 | — | — | — | — |
| iherod-airbook | iherod-airbook.wdc.us.gl3 | 192.168.120.103 | d0:88:0c:6c:63:59 | — | — | — |
| alwhite | alwhite.wdc.us.gl3 | 192.168.120.104 | 14:75:5b:f2:89:a1 | — | — | — |
| hbaar-airbook | hbaar-airbook.wdc.us.gl3 | 192.168.120.105 | a4:c6:f0:27:de:bc | — | — | — |
| kmelges-airbook | kmelges-airbook.wdc.us.gl3 | 192.168.120.106 | 9c:58:84:70:29:f5 | — | — | — |
| msedita-airbook | msedita-airbook.wdc.us.gl3 | 192.168.120.107 | 9c:58:84:72:49:f2 | — | — | — |
| tgregory-airbook | tgregory-airbook.wdc.us.gl3 | 192.168.120.108 | 70:ae:d5:43:0e:69 | — | — | — |
| mlopez-airbook | mlopez-airbook.wdc.us.gl3 | 192.168.120.109 | 9c:58:84:1c:2e:e4 | — | — | — |
| jclark | jclark.wdc.us.gl3 | 192.168.120.110 | 98:59:7a:5a:cb:f7 | — | — | — |
| scruz-airbook | scruz-airbook.wdc.us.gl3 | 192.168.120.111 | c0:95:6d:3d:b1:37 | — | — | — |
| snicolas-airbook | snicolas-airbook.wdc.us.gl3 | 192.168.120.112 | a4:c6:f0:2d:88:38 | — | — | — |
| dwinprogpii | dwinprogpii.wdc.us.gl3 | 192.168.120.113 | 00:15:5d:06:1e:01 | — | — | — |
| jturner | jturner.wdc.us.gl3 | 192.168.120.114 | 68:7a:64:74:5e:91 | — | — | — |
| mbringas-airbook | mbringas-airbook.wdc.us.gl3 | 192.168.120.115 | 70:ae:d5:48:56:3d | — | — | — |
| dwin11progpi | dwin11progpi.wdc.us.gl3 | 192.168.120.116 | 00:15:5d:06:1e:02 | — | — | — |
| mcarter-airbook | mcarter-airbook.wdc.us.gl3 | 192.168.120.117 | 9c:58:84:20:1c:e5 | — | — | — |
| dwin11progpiv | dwin11progpiv.wdc.us.gl3 | 192.168.120.118 | 00:15:5d:06:1e:04 | — | — | — |
| staylor-airbook | staylor-airbook.wdc.us.gl3 | 192.168.120.119 | d0:88:0c:6b:33:3c | — | — | — |
| jchristi-airbook | jchristi-airbook.wdc.us.gl3 | 192.168.120.120 | 3c:22:fb:db:4c:fa | — | — | — |
| taubry-probook | taubry-probook.wdc.us.gl3 | 192.168.120.121 | bc:d0:74:23:b0:af | — | — | — |
| ddellprec75201 | ddellprec75201.wdc.us.gl3 | 192.168.120.122 | 10:65:30:ff:da:44 | — | — | — |
| dwin11progplll | dwin11progplll.wdc.us.gl3 | 192.168.120.123 | 00:15:5d:06:1e:03 | — | — | — |
| tbekele | tbekele.wdc.us.gl3 | 192.168.120.124 | 00:09:0f:aa:00:01 | — | — | — |
| kflynnja-airbook | kflynnja-airbook.wdc.us.gl3 | 192.168.120.125 | 10:b5:88:79:89:af | — | — | — |
| brichard | brichard.wdc.us.gl3 | 192.168.120.126 | f0:20:ff:2b:fe:fd | — | — | — |
| testmacmini | testmacmini.wdc.us.gl3 | 192.168.120.127 | 4c:20:b8:e9:a3:6c | — | — | — |
| ngreen-airbook | ngreen-airbook.wdc.us.gl3 | 192.168.120.128 | a4:c6:f0:25:c4:0b | — | — | — |
| mridenho | mridenho.wdc.us.gl3 | 192.168.120.129 | a0:80:69:ff:32:32 | — | — | — |
| msimons | msimons.wdc.us.gl3 | 192.168.120.130 | ec:63:d7:98:8e:fb | — | — | — |
| ggirgis | ggirgis.wdc.us.gl3 | 192.168.120.131 | 68:7a:64:75:61:42 | — | — | — |
| dpadmana-airbook | dpadmana-airbook.wdc.us.gl3 | 192.168.120.132 | 70:ae:d5:4b:e6:2e | — | — | — |
| testwin2 | testwin2.wdc.us.gl3 | 192.168.120.133 | 00:e0:4c:01:01:0c | — | — | — |
| ljurca-airbook | ljurca-airbook.wdc.us.gl3 | 192.168.120.134 | a4:c6:f0:2c:8e:91 | — | — | — |
| smckenna-airbook | smckenna-airbook.wdc.us.gl3 | 192.168.120.135 | c0:95:6d:3c:fc:42 | — | — | — |
| hharmon-airbook | hharmon-airbook.wdc.us.gl3 | 192.168.120.136 | 2c:76:00:ec:c7:ab | — | — | — |
| tbrooks | tbrooks.wdc.us.gl3 | 192.168.120.137 | 5c:80:b6:2f:01:cf | — | — | — |
| btaylor-airbook | btaylor-airbook.wdc.us.gl3 | 192.168.120.138 | a4:c6:f0:2a:f0:6e | — | — | — |
| hlambert-airbook | hlambert-airbook.wdc.us.gl3 | 192.168.120.139 | 9c:58:84:12:f0:d6 | — | — | — |
| loaner-e | loaner-e.wdc.us.gl3 | 192.168.120.140 | a4:b1:c1:4b:19:23 | — | — | — |
| ewhisena-airbook | ewhisena-airbook.wdc.us.gl3 | 192.168.120.141 | 00:e0:4c:00:09:0c | — | — | — |
| visuals-macpro | visuals-macpro.wdc.us.gl3 | 192.168.120.142 | e4:50:eb:b8:37:9d | — | — | — |
| sheidenr-airbook | sheidenr-airbook.wdc.us.gl3 | 192.168.120.143 | c0:95:6d:37:41:52 | — | — | — |
| loaner-f | loaner-f.wdc.us.gl3 | 192.168.120.144 | a4:b1:c1:4a:93:22 | — | — | — |
| carring-airbook | carring-airbook.wdc.us.gl3 | 192.168.120.145 | d0:88:0c:6e:10:a0 | — | — | — |
| bavila-airbook | bavila-airbook.wdc.us.gl3 | 192.168.120.146 | 70:ae:d5:45:31:dc | — | — | — |
| sraman-airbook | sraman-airbook.wdc.us.gl3 | 192.168.120.147 | 84:94:37:ce:42:c0 | — | — | — |
| mailroompc | mailroompc.wdc.us.gl3 | 192.168.120.148 | 04:ed:33:c0:94:af | — | — | — |
| jdragon-airbook | jdragon-airbook.wdc.us.gl3 | 192.168.120.149 | 10:b5:88:77:26:92 | — | — | — |
| sseipelt | sseipelt.wdc.us.gl3 | 192.168.120.150 | 14:75:5b:d4:13:81 | — | — | — |
| btrewin | btrewin.wdc.us.gl3 | 192.168.120.151 | 04:ed:33:c0:33:93 | — | — | — |
| jmeisel-airbook | jmeisel-airbook.wdc.us.gl3 | 192.168.120.152 | fc:e2:6c:1a:01:dd | — | — | — |
| loaner-d | loaner-d.wdc.us.gl3 | 192.168.120.153 | 8c:c6:81:1f:67:8d | — | — | — |
| chull | chull.wdc.us.gl3 | 192.168.120.154 | ec:63:d7:98:39:6a | — | — | — |
| sherrado-airbook | sherrado-airbook.wdc.us.gl3 | 192.168.120.155 | a4:c6:f0:25:69:d2 | — | — | — |
| dkhoury-airbook | dkhoury-airbook.wdc.us.gl3 | 192.168.120.156 | 9c:58:84:79:dd:16 | — | — | — |
| sbullock-airbook | sbullock-airbook.wdc.us.gl3 | 192.168.120.157 | 9c:58:84:14:61:4b | — | — | — |
| ktoruno | ktoruno.wdc.us.gl3 | 192.168.120.158 | 5c:80:b6:30:41:07 | — | — | — |
| amoas-airbook | amoas-airbook.wdc.us.gl3 | 192.168.120.159 | 70:ae:d5:43:60:4b | — | — | — |
| jumoss | jumoss.wdc.us.gl3 | 192.168.120.160 | 04:ed:33:2d:cf:e9 | — | — | — |
| ahemphil-airbook | ahemphil-airbook.wdc.us.gl3 | 192.168.120.161 | d0:88:0c:66:10:59 | — | — | — |
| dwatford-airbook | dwatford-airbook.wdc.us.gl3 | 192.168.120.162 | a4:c6:f0:25:0c:45 | — | — | — |
| knelson-airbook | knelson-airbook.wdc.us.gl3 | 192.168.120.163 | c0:95:6d:3c:d1:6b | — | — | — |
| cprieto-airbook | cprieto-airbook.wdc.us.gl3 | 192.168.120.164 | d0:88:0c:63:0a:28 | — | — | — |
| fortitest-airbook | fortitest-airbook.wdc.us.gl3 | 192.168.120.165 | c0:95:6d:36:c6:3d | — | — | — |
| kreyes-airbook | kreyes-airbook.wdc.us.gl3 | 192.168.120.166 | 48:e1:5c:da:d1:ab | — | — | — |
| kchungya | kchungya.wdc.us.gl3 | 192.168.120.167 | 30:89:4a:ae:1b:8b | — | — | — |
| sk-airbook | sk-airbook.wdc.us.gl3 | 192.168.120.168 | fc:e2:6c:15:eb:9f | — | — | — |
| d-macbook-air | d-macbook-air.wdc.us.gl3 | 192.168.120.169 | d0:81:7a:ab:ee:02 | — | — | — |
| lpratt | lpratt.wdc.us.gl3 | 192.168.120.170 | 5c:80:b6:2f:e7:d4 | — | — | — |
| fvonsuck-airbook | fvonsuck-airbook.wdc.us.gl3 | 192.168.120.171 | 9c:58:84:1a:ff:a9 | — | — | — |
| jstuckey-airbook | jstuckey-airbook.wdc.us.gl3 | 192.168.120.172 | c0:95:6d:35:86:4e | — | — | — |
| sladwig | sladwig.wdc.us.gl3 | 192.168.120.173 | 14:75:5b:ee:27:08 | — | — | — |
| hbasioun-airbook | hbasioun-airbook.wdc.us.gl3 | 192.168.120.174 | 84:94:37:d2:58:21 | — | — | — |
| asterlin-airbook | asterlin-airbook.wdc.us.gl3 | 192.168.120.175 | 9c:58:84:74:d4:ff | — | — | — |
| jhocevar | jhocevar.wdc.us.gl3 | 192.168.120.176 | a4:c3:f0:56:53:f6 | — | — | — |
| gsmalley-airbook | gsmalley-airbook.wdc.us.gl3 | 192.168.120.177 | 10:b5:88:74:ad:be | — | — | — |
| tdonaghy-airbook | tdonaghy-airbook.wdc.us.gl3 | 192.168.120.178 | 70:ae:d5:4d:aa:81 | — | — | — |
| jejohnso-airbook | jejohnso-airbook.wdc.us.gl3 | 192.168.120.179 | 9c:58:84:7a:ac:b3 | — | — | — |
| amorales-airbook | amorales-airbook.wdc.us.gl3 | 192.168.120.180 | 10:b5:88:72:da:01 | — | — | — |
| arincon-airbook | arincon-airbook.wdc.us.gl3 | 192.168.120.181 | 9c:58:84:13:04:ba | — | — | — |
| mailroompc-eth | mailroompc-eth.wdc.us.gl3 | 192.168.120.182 | 00:e0:4c:00:08:be | Windows | Mailroom | — |
GCP cloud assets¶
| Type | Name | FQDN / Endpoint | Description | Region | Dept |
|---|---|---|---|---|---|
| Cloud Run | gpus-status-site | gpus-status-site-1056766133984.us-central1.run.app | Infrastructure status dashboard | us-central1 | IT |
| Cloud Run | gpus-status-backend | gpus-status-backend-1056766133984.us-central1.run.app | Live data API — SSH/Prometheus/ES polling | us-central1 | IT |
| Cloud Run | gpus-mkdocs-portal | gpus-mkdocs-portal-1056766133984.us-central1.run.app | IT Infrastructure Portal — https://infra.greenpeace.us | us-central1 | IT |
| DNS CNAME | infra.greenpeace.us | infra.greenpeace.us | Custom domain → gpus-mkdocs-portal; SSL: Cloud Run managed | — | IT |
| GCS Bucket | gpus-infra-backups-wdc | — | On-premises backup target | us-central1 | IT |
| GCS Bucket | gpus-infra-tf-state | — | Terraform state bucket | us-central1 | IT |
| VPN Gateway | gpus-vpn-gateway | — | Cloud VPN — peer: WDC Meraki MX100 (38.140.146.68); tunnel: ESTABLISHED | us-central1 | IT |
| Artifact Registry | gpus-images | us-central1-docker.pkg.dev/gpus-infra/gpus-images | Container image registry for all Cloud Run services | us-central1 | IT |
| Pub/Sub topic | gpus-forms-attachment-uploaded | projects/gpus-infra/topics/gpus-forms-attachment-uploaded | GCS OBJECT_FINALIZE notifications on gpus-forms-attachments fan in here; push subscription delivers to the ClamAV scan worker. Carries object pointers, no file content |
us-central1 | IT |
| Pub/Sub topic | gpus-forms-attachment-uploaded-dlq | projects/gpus-infra/topics/gpus-forms-attachment-uploaded-dlq | Dead-letter topic (5-attempt cap). Push sub gpus-forms-clamav-worker-dlq-alert-sub → worker /dlq-alert → Slack |
us-central1 | IT |
| Pub/Sub subscription | gpus-forms-clamav-worker-sub | push → gpus-forms-clamav-worker (Cloud Run) | Push subscription on gpus-forms-attachment-uploaded; dead-letters to …-dlq after 5 attempts |
us-central1 | IT |
| Pub/Sub topic | gpus-forms-approval-notify | projects/gpus-infra/topics/gpus-forms-approval-notify | Travel approval notifications, both kinds, discriminated on a kind message attribute (step / outcome). Published by gpus-forms-backend after the durable write commits; consumed on MAPLE. Payload is a pointer only — {kind, submission_id, version, step_index} — never a rendered body, address, comment or field value, because Pub/Sub messages are durable and retained and a rendered body would be stored plaintext travel data outside the database with none of its access control. A stall here means no approver is ever told their step is waiting |
us-central1 | IT |
| Pub/Sub subscription | gpus-forms-approval-notify-sub | pull ← gpus-forms-routing-worker (MAPLE) | Pull subscription consumed in the routing worker's main loop. Ack deadline 120s, retention 7d, retry 10s→600s, dead-letters after 5 attempts. Pull rather than push because Postfix on MAPLE is loopback-only | us-central1 | IT |
| Pub/Sub topic | gpus-forms-approval-notify-dlq | projects/gpus-infra/topics/gpus-forms-approval-notify-dlq | Dead-letter topic. A message here is an approval notification that was never rendered or sent; the submission row shows notification_published_at SET and notification_sent_at NULL |
us-central1 | IT |
| Pub/Sub subscription | gpus-forms-approval-notify-dlq-sub | pull ← gpus-forms-routing-worker (MAPLE) | Drained in-process by the routing worker's sweep, posting each exhausted notification to Slack. Ack deadline 60s, retention 7d. No push endpoint by design — so it drains only while the routing subscription is also healthy | us-central1 | IT |
Provenance of the seven Pub/Sub rows, and what is still missing
Sourced from inventory.yaml (inventory.cloud_services, seven
type: pub_sub entries) and from the code that names them, not from a
live gcloud pubsub topics list. That enumeration was attempted on
2026-09-01 and failed for both reachable identities: the workstation's
gcloud requires an interactive re-login, and MAPLE's maple-agent SA is
IAM_PERMISSION_DENIED on pubsub.topics.list — it holds subscriber
rights on named subscriptions, not project-wide list. Recorded as an
absence rather than passed over (M-06). The configuration details above
were verified live in GCP on 2026-08-26 and are carried forward from
inventory.yaml, which states that.
inventory.yaml itself does not declare the whole Pub/Sub estate. Four
resources named in running code have no inventory entry and are therefore
not registered here either: the topic gpus-forms-submission-ready
(forms-backend/config.py:45, routing_worker.py:108) and the
subscriptions gpus-forms-routing-worker-sub (routing_worker.py:103),
gpus-forms-routing-dlq-alert-sub (:106) and
gpus-forms-clamav-worker-dlq-alert-sub (named only inside another
entry's description). These are the 2.5(c) attachment-routing path —
the one the worker's own inventory entry calls its first job. They are
named here so the omission is on the record; adding them belongs in
inventory.yaml first, per the Adding Infrastructure workflow, not
directly in this page.
GPUS-IT-Infrastructure data-team GCE fleet (2026-06-26)¶
Nine Compute Engine instances in the gpus-it-infrastructure GCP
project (distinct from gpus-infra) on the shared gl5-shared
network domain, owned by the Data team. Tracked in inventory.yaml
under compute_instances and documented in
infrastructure/gpus-it-infrastructure.md.
These are monitoring-pending assets — Windows hosts intended for the
WDC Wazuh agent, Linux hosts for Prometheus node_exporter — with no
telemetry flowing yet. Registered here for CIS Control 1 (Inventory of
Enterprise Assets) coverage; the coverage check requires an IAR entry for
every gpus-it-infrastructure asset.
| Instance | Platform | Private IP | Public IP | OS (EOL) | Role | Disposition | Monitoring | State |
|---|---|---|---|---|---|---|---|---|
| duck | Windows | 10.1.96.46 | — | Windows Server 2016-DC (2027-01-12) | Analyst terminal server + Redshift/SQL | migrate (→WS2025, rebuild-cutover) | wazuh-agent → WDC · pending-path | running |
| grebe | Windows | 10.1.96.51 | — | Windows Server 2016 (2027-01-12) | Terminal/app server + 500 GB data disk | migrate (→WS2025, rebuild-cutover) | wazuh-agent → WDC · pending-path | running |
| falcon | Windows | 10.1.96.12 | 35.223.86.92 | Windows Server 2016 (2027-01-12) | Talend ETL node (prod) | migrate (→WS2025, rolling-cutover) | wazuh-agent → WDC · pending-path | running |
| gull | Windows | 10.1.96.42 | 104.154.21.30 | Windows Server 2016 (2027-01-12) | Talend ETL node (prod) | migrate (→WS2025, rolling-cutover) | wazuh-agent → WDC · pending-path | running |
| kestrel | Windows | 10.1.96.15 | 35.239.221.226 | Windows Server 2016 (2027-01-12) | Talend ETL node (prod) | migrate (→WS2025, rolling-cutover) | wazuh-agent → WDC · pending-path | running |
| woodpecker | Windows | 10.1.96.48 | — | Windows Server 2022-DC | Unknown — role unconfirmed | investigate | none · not-monitored | terminated |
| kingfisher | Linux | 10.1.96.14 | 35.192.36.47 | CentOS 7 (EOL 2024-06-30) | Tamr data-mastering (legacy) | decommission (gated: pending Tamr disposition) | none · not-monitored | terminated |
| magpie | Linux | 10.1.96.50 | 34.72.120.159 | RHEL 8 (2029-05-31) | SQL/Linux data service | keep | node-exporter → WDC · pending-path | running |
| nfs-gw | Linux | 10.128.0.11 | — | Debian 10 (EOL 2024-06-30) | Filestore/NFS gateway (dual-homed) | rebuild (supported OS) | node-exporter → WDC · pending-path | running |
Roles are confirmed with the Data team except woodpecker (unconfirmed).
Orphaned-resource cleanup (recorded in inventory.yaml cleanup_notes,
not managed assets): loonnew orphaned persistent disk (unattached) and
dead GKE PVCs from a since-deleted cluster — both queued for deletion to
reclaim storage.
Change log:
- 2026-06-26 — gpus-it-infrastructure integration: 9 data-team GCE
instances registered as
compute_instances; all monitoring-pending (WDC collector path not yet wired). loonnew disk + dead GKE PVCs logged for cleanup.
Finding — gpusa-it-infrastructure-306400 is absent from the inventory (2026-09-04)¶
Status: OPEN. Recorded, not remediated in this pass.
The GCP project gpusa-it-infrastructure-306400 has zero entries
in inventory.yaml and, before this note, zero entries in this register.
As of 2026-09-04 it contains 25 Compute Engine instances (23 running,
2 terminated) and 2 Cloud SQL instances — none of them registered:
- Running:
albatross,astrapia,babbler,blackbird,catbird,cormorant,emu,gannet,grouse,moa,mockingbird,ostrich,phoebe,phoenix,pintail,puffin,rail,rallidae,robin,sparrow,thrasher,thrush,whistler - Terminated:
cromber,quail - Cloud SQL:
pitta,bulbul
This is a CIS Control 1 / ID.AM-1 coverage gap, and a material one:
emu and ostrich are the authoritative DNS servers for us.gl3 and
cloud.us.gl3, and phoenix is the Puppet master for the estate. The
Component Coverage Standard is satisfied for gpus-infra and
gpus-it-infrastructure while an entire third project sits outside it.
The list above is a snapshot as of 2026-09-04 and is already out of
date by design. phoebe and pitta were deleted 2026-09-04 and
bulbul 2026-09-08, so both Cloud SQL instances and one of the running
GCE instances are gone. The snapshot is kept as written rather than
edited down, because the size of the gap on the day it was found is the
finding; silently shrinking the list as assets are retired would make a
coverage gap look like it was being closed by inventory work when it was
being closed by deletion.
Deliberate decision, 2026-09-04, extended 2026-09-08: phoebe,
pitta and bulbul were not added to inventory.yaml as part of
their retirement. Creating inventory entries for three assets purely in
order to delete them would record a compliance posture that never
existed and would leave the other 24 unregistered. The savings
ledger (savings-ledger.yaml) is the retirement record for those
three; this register carries the narrative.
Owner action: populating gpusa-it-infrastructure-306400 in
inventory.yaml is an enterprise-architecture decision — it needs a
monitoring_intent per host and a documented_in target that does not
yet exist — and is tracked in that workstream, not here.
Meraki network fabric (Wave 1, 2026-04-28)¶
Cisco Meraki cloud-managed network infrastructure — security appliances
(MX), switches (MS), and wireless access points (MR) — distributed
across five networks at three physical sites (Washington DC HQ, MDEC,
OAKEC) plus residential APs (DC Apartments) and an MDM-only network
(Major Gifts). Managed via Meraki Dashboard organization 395909
(license expires 2027-11-28). Full per-device inventory with serials,
MACs, EOL dates, and lifecycle actions: meraki-hostregistry.csv.
For network architecture, uplink topology, GCP VPN integration, and
phased roadmap, see meraki-infrastructure.md.
Security appliances (MX) — 4 devices:
| Hostname | Serial | Site | Network | Role | Criticality | Notes |
|---|---|---|---|---|---|---|
| wdc-fw-primary | Q2XN-V4XE-UQKX | WDC | WDC-Eye Street | firewall-primary | critical | HA primary; VRRP master; GCP VPN terminator |
| wdc-fw-secondary | Q2XN-LXCR-EJEW | WDC | WDC-Eye Street | firewall-secondary | critical | HA secondary |
| MDEC MX | Q2KN-AFKR-5EES | MDEC | MDEC | firewall-primary | high | Single uplink, no HA |
| oakec-fw-primary | Q2KN-86TU-N6CP | OAKEC | OAKEC | firewall-primary | high | Renamed from Justin-Bieber 2026-04-23 |
Switches (MS) — 11 devices:
| Hostname | Serial | Site | Network | Model | Criticality | EOL Status |
|---|---|---|---|---|---|---|
| WDC-STACK-0-NOPOE | Q2HW-F8RK-KULW | WDC | WDC-Eye Street | MS225-48 | critical | EoSale 2026-04-30 |
| WDC-STACK-1-NOPOE | Q2HW-HMCF-4LJ5 | WDC | WDC-Eye Street | MS225-48 | critical | EoSale 2026-04-30 |
| WDC-STACK-2-NOPOE | Q2HW-HKLA-DPXW | WDC | WDC-Eye Street | MS225-48 | critical | EoSale 2026-04-30 |
| WDC-STACK-3-NOPOE | Q2HW-FN64-HZWA | WDC | WDC-Eye Street | MS225-48 | critical | EoSale 2026-04-30 |
| WDC-STACK-4-POE | Q2KW-3VQQ-DE9H | WDC | WDC-Eye Street | MS225-48FP | critical | EoSale 2026-04-30 |
| WDC-STACK-5-POE | Q2KW-TJTU-B2ET | WDC | WDC-Eye Street | MS225-48FP | critical | EoSale 2026-04-30 |
| WDC-STACK-6-POE | Q2KW-VRUK-9LS6 | WDC | WDC-Eye Street | MS225-48FP | critical | EoSale 2026-04-30 |
| wdc-edge-1 | Q4AA-B9B4-HLZQ | WDC | WDC-Eye Street | MS120-8 | high | EoS 2030-03-28 |
| wdc-edge-2 | Q4AA-VRAQ-2GSF | WDC | WDC-Eye Street | MS120-8 | high | EoS 2030-03-28 |
| MDEC-access-2 | Q2SX-HDV2-2UTV | MDEC | MDEC | MS210-24P | medium | EoSale 2026-04-30 |
| Oakland Warehouse Switch1 | Q2SX-29PM-F7KP | OAKEC | OAKEC | MS210-24P | medium | EoSale 2026-04-30 |
Wireless access points (MR) — 17 devices:
| Hostname | Serial | Site | Network | Model | Criticality | EOL Status |
|---|---|---|---|---|---|---|
| wdc-wap-1 | Q3AP-D6NB-GY3G | WDC | WDC-Eye Street | MR57 | high | OK |
| wdc-wap-2 | Q3AP-VVT6-7Q7T | WDC | WDC-Eye Street | MR57 | high | OK |
| wdc-wap-3 | Q3AP-6SSC-Z2L7 | WDC | WDC-Eye Street | MR57 | high | OK |
| wdc-wap-4 | Q3AP-2YDY-XZQZ | WDC | WDC-Eye Street | MR57 | high | OK |
| wdc-wap-5 | Q3AP-T34T-45AG | WDC | WDC-Eye Street | MR57 | high | OK |
| First Floor AP | Q2LD-2P6D-FQ9Q | MDEC | MDEC | MR52 | medium | EoS 2026-07-21 ⚠ |
| Garage AP | Q2LD-K2TR-N97R | MDEC | MDEC | MR52 | medium | EoS 2026-07-21 ⚠ |
| Second Floor AP | Q2LD-SCPN-R4KY | MDEC | MDEC | MR52 | medium | EoS 2026-07-21 ⚠ |
| OAKEC-AP1 | Q2LD-4DN3-3BT9 | OAKEC | OAKEC | MR52 | medium | EoS 2026-07-21 ⚠ |
| OAKEC-AP2 | Q2LD-L3GL-NG4Z | OAKEC | OAKEC | MR52 | medium | EoS 2026-07-21 ⚠ |
| APT 707 | Q2LD-5XJZ-2SZC | DC Apartments | DC Apartments | MR52 | low | EoS 2026-07-21 ⚠ |
| APT 709 | Q2PD-KDPN-SBFR | DC Apartments | DC Apartments | MR33 | low | EoS 2026-07-21 ⚠ |
| APT 611 | Q2PD-PN66-3P86 | DC Apartments | DC Apartments | MR33 | low | EoS 2026-07-21 ⚠ |
| APT211 | Q2PD-GKDC-PVLG | DC Apartments | DC Apartments | MR33 | low | EoS 2026-07-21 ⚠ |
| mdec garage | Q2JD-29US-5JXK | unassigned | — | MR32 | decommission | PAST EoS 2024-07-31 ⚠⚠ |
| mdec 1st floor work room | Q2JD-2MFW-39AG | unassigned | — | MR32 | decommission | PAST EoS 2024-07-31 ⚠⚠ |
| mdec 2nd floor by the bunk room | Q2PD-L4QQ-9G54 | unassigned | — | MR33 | decommission | EoS 2026-07-21 |
Network breakdown:
| Network | Network ID | Devices | Site | Notes |
|---|---|---|---|---|
| WDC-Eye Street | L_630503947831890190 |
13 | Washington DC HQ | HA firewall pair, GCP VPN terminator |
| MDEC | L_630503947831873852 |
5 | Mid-Atlantic Direct Engagement Center | Single uplink |
| OAKEC | L_630503947831873855 |
4 | Oakland Engagement Center | Single uplink |
| DC Apartments | N_630503947831910695 |
4 | Residential staff housing | Wireless-only |
| Major Gifts | N_630503947831998386 |
0 (SM only) | Donor team endpoints | MDM-only, no hardware in this registry |
| Unassigned | — | 3 | — | Decommission queue (see lifecycle_action in CSV) |
Compliance: This Meraki section satisfies CIS Control 1 (Inventory of
Enterprise Assets) and ID.AM-1 (Hardware inventory) for the network
fabric domain. Per-control mapping detail is documented in
meraki-infrastructure.md
under "Compliance Mappings" — covers MITRE ATT&CK, PCI-DSS v4.0,
NIST CSF 2.0, NIST 800-53 Rev. 5, ISO 27001:2022, and CIS Controls v8.
Audit findings (2026-04-27/28): 10 findings logged through Meraki
discovery (MERAKI-2026-04-001 through 010) — see
meraki-infrastructure.md § Audit Findings. Critical-severity:
MERAKI-2026-04-003 (2× MR32 past EoS, decommission immediately).
High-severity: MERAKI-2026-04-001 (Sedita stale full admin),
MERAKI-2026-04-002 (no SAML SSO), MERAKI-2026-04-004 (12× APs
hitting EoS 2026-07-21), MERAKI-2026-04-007 (no syslog → CEDAR).
Forms portal data assets (Phase 1, 2026-04-18)¶
The Forms Portal (forms.greenpeace.us) introduces five data assets that are not hosts — they are Cloud SQL schemas, GCS buckets, and KMS keys. They are tracked here rather than in wdc-hostregistry.csv because they do not have an IP or MAC. The fifth — the travel approval workflow tables — was added 2026-09-01, four and a half months after the other four; the section heading still reads Phase 1, 2026-04-18 because that is when the section was opened, not when its contents were last complete.
| Asset | Classification | Type | Encryption / Key | Retention | Owner |
|---|---|---|---|---|---|
| Forms Portal Database | CONFIDENTIAL | Cloud SQL PostgreSQL 15 (gpus-forms-db, private IP) |
CMEK via gpus-forms-cmek + per-submission AES-256-GCM DEK wrapped by gpus-forms-dek-wrapper |
7 years (submissions + audit log); automated daily backups + PITR | Director of Cyber Security |
| Forms Portal Attachments | CONFIDENTIAL | GCS bucket (gpus-forms-attachments), signed-URL-only, ClamAV scanned |
CMEK via gpus-forms-cmek |
7 years = 2555 days; retention policy set 2026-06-15, currently UNLOCKED — lock scheduled pending bucket cleanup + versioning/lifecycle decision (see forms-portal-controls.md retention audit log, 2026-06-15) |
Director of Cyber Security |
| Forms Portal KMS Keys | RESTRICTED | Cloud KMS keys (gpus-forms-cmek, gpus-forms-dek-wrapper) in us-central1 |
Software-protected, automatic 90-day rotation. IAM grants: gpus-forms-backend@gpus-infra.iam.gserviceaccount.com = cryptoKeyEncrypterDecrypter (wrap + unwrap); maple-agent@gpus-infra.iam.gserviceaccount.com = cryptoKeyDecrypter (decrypt-only, on gpus-forms-dek-wrapper only, for 2.5(d) send-time render — the only non-backend identity able to recover submission plaintext; see change log 2026-06-17) |
Key material retained per KMS defaults; rotation verified quarterly | Director of Cyber Security |
| Forms Portal Backups | CONFIDENTIAL | GCS bucket (gpus-infra-backups-wdc/forms-db/), pg_dump weekly + Cloud SQL automated daily |
CMEK via gpus-forms-cmek |
7 years | Backup Admin |
| Travel Approval Workflow Tables | CONFIDENTIAL | Cloud SQL PostgreSQL tables inside gpus-forms-db — submission_approvals, approval_steps, approval_role_members, the SMT approver map and submissions.parent_submission_id (migrations 014–022) |
Inherits the database's CMEK (gpus-forms-cmek). Approver comments, decision timestamps and resolved_okta_email are stored in plaintext columns, NOT under the per-submission AES-256-GCM DEK — the field-level encryption covers submission_fields, and these are approval-chain columns beside it |
7 years, inherited from the database row (retention_expires_at); note PRG-028 — no retention purge executor exists, so nothing acts on the expiry |
Director of Cyber Security |
The IAR gate does not cover these assets — a passing coverage check is not evidence of registration
scripts/check-component-coverage.py does enforce an IAR entry, and
that enforcement is narrower than it looks. Read
validate_portal_presence(): the mandatory-IAR loop runs over
gpit_assets only — inventory.compute_instances, plus any entity in any
other category carrying project: gpus-it-infrastructure. For each of
those it hard-errors with [iar] … no IAR entry.
Every forms-portal asset on this page is in gpus-infra. Read live
from inventory.yaml on 2026-09-01: all thirteen cloud_services entries
— the database, the Cloud Run services, the routing worker and all seven
Pub/Sub entities — carry no project: key at all, so none of them ever
enters that loop. Only the 9 compute_instances do.
The consequence, stated plainly: the approval workflow tables went
unregistered here from migration 014 (2026-08-18) until 2026-09-01 while
check-component-coverage.py returned PASS on every run in between.
It was still returning PASS immediately before this row was added. The
gate could not have caught it and did not fail. An absent IAR row for a
gpus-infra asset is a compliance gap the pre-build check does not
detect — do not read a green coverage check as evidence that this
registry is complete.
inventory.yaml had recorded the gap in prose the whole time: the
gpus_forms_db entry's own description ends "…not separately registered
there yet." A description is not a check.
Why the approval tables are CONFIDENTIAL, precisely
The tables themselves hold the chain — states, step indexes, role keys,
resolved approver addresses, decision timestamps and free-text approver
comments. They do not store traveller names or destinations; those
live in submission_fields under the per-submission DEK.
The classification follows from what the tables authorize, not only
from what they store. approval_steps.resolved_okta_email + status is
the whole authorization test (approval_access.resolve_access_core), and
a party holding a DISPATCHED step can decrypt and read the full
submission — audit_log records exactly that on 2026-08-31 for
c84bfb45: decrypt_success … endpoint: approval_view, field_count: 15.
A row in approval_steps is therefore a grant of access to CONFIDENTIAL
travel data, and is classified as such.
Two properties worth carrying into any assessment. (1) The grant is
frozen at dispatch and there is no way to revoke it — see GOV-030, which
records that the ASVS scope statement's stated mitigation for this was
never built. (2) comment, decided_by_email and
resolved_okta_email are TEXT columns in 014_approval_workflow.sql
(:234, :240, :241) — the field-level AES-256-GCM covers
submission_fields, not these. Approver comments are protected by CMEK at
rest and by database access control, and by nothing else.
Change log:
- 2026-04-18 — Phase 1 cutover: four forms-portal data assets registered; database and attachments marked CONFIDENTIAL, KMS keys marked RESTRICTED. See
forms-backend/RUNBOOK-CLAUDE-CODE.md(provisioning) andforms-backend/RUNBOOK-COWORK.mdTask 10 for the addition rationale. - 2026-09-01 — Travel approval workflow tables registered as the fifth forms-portal data asset, CONFIDENTIAL:
submission_approvals,approval_steps,approval_role_members, the SMT approver map andsubmissions.parent_submission_id(migrations014–022). Unregistered since014shipped on 2026-08-18. Classified on what the rows authorize — aDISPATCHEDstep is a grant of decrypt access to the full submission, evidenced inaudit_logforc84bfb45on 2026-08-31 (decrypt_success … field_count: 15) — and recorded with the fact thatcomment,decided_by_emailandresolved_okta_emailare plainTEXT, outside the per-submission DEK. Also recorded:check-component-coverage.pycould not have caught this omission.validate_portal_presence()enforces a mandatory IAR entry only forcompute_instancesand for assets taggedproject: gpus-it-infrastructure; all thirteencloud_servicesentries carry noprojectkey, and the check returnedPASSthroughout. SeeGOV-030for the related assurance gap on revocation, andPRG-028— the 7-year retention this row inherits has no purge executor acting on it. Section preamble corrected four → five data assets. - 2026-09-01 — Seven Pub/Sub entities added to GCP cloud assets — the topics
gpus-forms-attachment-uploaded,…-dlq,gpus-forms-approval-notify,…-dlqand the subscriptionsgpus-forms-clamav-worker-sub,gpus-forms-approval-notify-sub,…-dlq-sub. Sourced frominventory.yamland the code that names them; a livegcloud pubsub topics listwas attempted and failed for both reachable identities (workstationgcloudneeds re-login;maple-agentisIAM_PERMISSION_DENIEDonpubsub.topics.list) and that is recorded rather than passed over. Four further Pub/Sub resources named in running code —gpus-forms-submission-ready,gpus-forms-routing-worker-sub,gpus-forms-routing-dlq-alert-sub,gpus-forms-clamav-worker-dlq-alert-sub— have noinventory.yamlentry and are therefore still unregistered; named on the page so the omission is visible, and left forinventory.yamlto declare first per the Adding Infrastructure workflow. Counts: GCP Cloud Assets 7 → 15 — of which one is a correction, not an addition: the row read7against a section holding 8 data rows, wrong sincea02640aand before anything was added. Total 169 → 177, and a note now states whatTotalcovers (this table only) against the grand total of 192 the document actually registers. - 2026-06-17 — Forms 2.5(d) send-time render: granted
maple-agent@gpus-infra.iam.gserviceaccount.comroles/cloudkms.cryptoKeyDecrypter(DECRYPT-ONLY, key-level) ongpus-forms-dek-wrapper. Third standing IAM binding onmaple-agent(afterstorage.objectViewerongpus-forms-attachments+ self-tokenCreatorfor signBlob, 2.5(c) Gate 4) and the only one able to recover submission plaintext — flagged for the recurring admin-review scope. Decrypt-only by design: the role grantsuseToDecryptbut notuseToEncrypt, so the worker can unwrap existing per-submission DEKs but cannot wrap new ones (encrypt-denied probe confirms the asymmetry). Boundary = option 3: the routing worker decrypts at send-time, renders, sends, and never persists plaintext. Seeforms-backend/crypto.py(unwrap_dek) andgpus-forms-routing-worker/routing_worker.py.
Legacy Forms Database (in_formfeed)¶
Tracked here as part of the Phase 1.5 migration from the legacy PHP forms system. See Phase 1.5 addendum Task A and Task B for verification and right-sizing work.
| Field | Value |
|---|---|
| Asset | Cloud SQL MySQL instance, public IP 34.171.123.238 |
| Project | [confirm during migration runbook Step 1] |
| Data | 260 KB, 5 tables (category, form, field, pulldown, template) — 772 rows combined |
| Classification | INTERNAL (no PII; metadata and form definitions only, no submissions stored) |
| Purpose | Legacy reference after Phase 1.5 migration to gpus-forms-db |
| Status | Read-only reference, no writes since cutover — cutover date TBD (Phase 4 go-live) |
| Retention | Decision pending (see addendum Task B — oversized instance / retirement decision) |
| Access | formfeed@34.171.123.238 — credentials in Secret Manager (gpus-formfeed-mysql-password) |
| Network exposure | Public IP (34.171.123.238); authorized networks restricted to three /32 CIDRs (no 0.0.0.0/0 present — good) |
Authorized networks (confirmed 2026-04-18):
| CIDR | Description | Disposition |
|---|---|---|
113.199.192.121/32 |
rchhetry — admin access | Removed with the instance 2026-09-04 (label lost in the ACL edit — see change log) |
34.121.207.171/32 |
phoebe — legacy GCP VM | REMOVED 2026-09-04, ahead of instance deletion |
34.45.99.114/32 |
catbird — legacy GCP VM | Removed with the instance 2026-09-04 (label lost in the ACL edit; entry never matched catbird's real egress — see change log) |
This instance no longer exists
pitta was deleted 2026-09-04 at 18:59:30 UTC. The table above is
retained as the historical record of its network exposure, not as a
description of anything live.
Security finding status: No 0.0.0.0/0 entry — instance is already restricted to three /32 sources. No immediate remediation required; phoebe and catbird entries are scheduled for removal after Phase 4 cutover to retire unused legacy paths. Record removal dates in the change log below when they happen.
Change log:
- 2026-04-18 — Legacy database registered ahead of Phase 1.5 migration cutover. Authorized-networks audit completed (3
/32CIDRs, no0.0.0.0/0).phoebe+catbirdentries queued for removal after Phase 4 cutover. - 2026-09-03 — phoebe retirement began. Ten DNS records referencing
phoeberemoved at the canonical source across two zones (cloud.us.gl3:phoebeA, plusredirects,forms,lamCNAMEs;us.gl3:sharperlight,redirects,lam,forms,dhcp,budgetCNAMEs). Both zone serials set to2026090400and distributed toemuandostrich. The eleven user databases on this instance were exported togs://gpusa-it-infrastructure-database-archive/retirement-2026-09-03/pitta/(11 objects, 1.61 GiB). - 2026-09-04 — Verification, ahead of removal. All ten DNS names confirmed
NXDOMAINfrom two independent client vantages (catbird,phoenix), each paired with controls that returnedNOERRORfrom the same vantage so an empty answer could not be mistaken for aREFUSEDor a timeout. Export re-verified independently of the 2026-09-03 record: 11/11 objects present, byte sizes matching, every dump carrying a valid gzip CRC over the full stream, amysqldumpheader, and a-- Dump completedtrailer. Finding —phoebewas already not serving. The instance reportsRUNNING, but fromcatbirdon the same subnet it answers no ICMP and has no open port (22, 80, 443, 3306, 8080), while controlsemu,ostrichandthrushanswer ping and accept:22from that same vantage.lastStartTimestampis 2024-06-28 with no restart since. The34.121.207.171/32grant has therefore been dormant, not merely unused. Finding — thecatbirdrow overstates a live path.34.45.99.114/32iscatbird's assigned NAT address, but its observed egress is35.192.34.26. The ACL entry does not match the addresscatbirdactually presents, so it grants no working access. The row is accurate as a record of intent and inaccurate as a record of exposure; it is retained here rather than corrected silently, and should be reconciled when thecatbirddisposition is settled. Instance deletion and the removal of thephoebe/32are gated on the 86,400 s DNS TTL, which expires 2026-09-04 18:51 UTC. Removal date to be appended here when it happens. - 2026-09-04 — RETIREMENT EXECUTED. All times UTC; note that the operator's local clock (+05:45) had already rolled to 09-05, and the UTC date is the one of record.
- 18:52 — DNS re-verified from both client vantages (
catbird,phoenix). All four controlsNOERRORwith answers at each vantage; all ten removed namesNXDOMAINwith zero answers; serial2026090400live on bothemuandostrich. A failed control was treated as a stop condition, on the reasoning that a lying vantage invalidates the ten negatives rather than sitting beside them. - 18:55:09 —
phoebestopped (TERMINATED). The stop took ~3 minutes, consistent with a guest that could not respond to a graceful shutdown. - 18:56 —
phoebedeleted. Its 100 GBpd-standardboot disk carriedautoDelete: trueand went with it; both instance and disk confirmed absent. - 18:58 —
pittaauthorized networks replaced with the two survivors.34.121.207.171/32confirmed absent. - 18:58 —
pittadeletion protection patched toFalseand confirmed before proceeding. It had beenTrue; the deletion would otherwise have failed outright. - 18:59:30 —
pittadeleted and confirmed absent. - All ten retained artifacts enumerated by name and confirmed present after deletion — the seven
gcs-phoebe-8728708703581121380-*dailies,phoebe-evidence-live-20260812, and both evidence images — eachREADYwith unchangedstorageBytes. Verified rather than assumed: snapshots are independent objects and do not follow anautoDeletedisk. pitta's automated backups were destroyed with the instance, as expected. The GCS export atgs://gpusa-it-infrastructure-database-archive/retirement-2026-09-03/pitta/is now the only copy of those eleven databases; re-confirmed intact immediately after deletion at 11 objects / 1,724,337,246 bytes. ACL NAME LABELS LOST — recorded rather than passed over.gcloud sql instances patch --authorized-networksreplaces the entire list and accepts CIDRs only; there is no flag that carries thenamefield. The two surviving entries therefore came back asname: ''. Access is unaffected and the CIDR-to-identity mapping is preserved in the table above, but the labels themselves did not survive the edit. Noted because a compliance record should say when it lost a field, not quietly present a thinner one. Moot in this instance's case — it was deleted ninety seconds later — but the same operation on a surviving instance would silently strip its documentation.
- 18:52 — DNS re-verified from both client vantages (
Maintenance¶
The IAR is updated whenever:
- A new device is assigned a DHCP reservation on SKY/RAIN
- A new server, appliance, or cloud asset is provisioned
- An asset is decommissioned or reassigned
Update procedure:
- Edit the appropriate registry under
hostregistry/—wdc-hostregistry.csvon SKY for WDC hosts;gcp-hostregistry.csvvia repo for GCP cloud assets;meraki-hostregistry.csvvia repo for Meraki devices. - Increment version header (vX.Y → vX.Y+1) and update date
- Update this page to match
- Log the change:
echo "$(date -Is) IAR updated — [reason]" >> /var/log/asset-inventory.log - Run AIDE baseline update per Post-Change Checklist
Information Asset Registry · v1.5 · 2026-09-01 · GPUS-IT · Classification: CONFIDENTIAL — Internal Use Only