Skip to content

Information Asset Registry

Classification: CONFIDENTIAL — Internal Use Only

The Information Asset Registry (IAR) is the authoritative inventory of all hardware, network, and cloud assets managed by GPUS-IT. It supports CIS Control 1 (Inventory of Enterprise Assets), CIS Control 2 (Inventory of Software Assets), and PCI-DSS asset management requirements.

Sources of truth: wdc-hostregistry.csv, gcp-hostregistry.csv, and meraki-hostregistry.csv under hostregistry/ — maintained by IT Administration. Last updated: 2026-09-08 · Total assets: 130 on-premises + 15 GCP cloud assets + 9 gpus-it-infrastructure data-team GCE instances + 32 Meraki network devices + 5 forms-portal data assets + 1 legacy database asset

Handling requirement

This registry contains MAC addresses, IP assignments, and system details. Handle as CONFIDENTIAL. Do not share outside of IT and Security teams.


Asset summary

Category Count Network
Gateway / Firewall 1 192.168.120.251–254
Servers 5 192.168.120.1–40
Appliances, SANs, Printers 8 192.168.120.41–64
Hypervisors 3 192.168.120.65–69 / 192.168.122.150–250
Workstations 113 192.168.120.70–230
GCP Cloud Assets 15 us-central1 / 172.16.0.0/24
Network Devices (Meraki) 32 Multi-site (cloud-managed)
Total 177

What Total counts, and what it does not

Total is the sum of the rows in the table above and nothing else — 130 on-premises + 15 GCP + 32 Meraki. Three categories registered further down this document have never been inside it: the 9 GCE instances in gpus-it-infrastructure, the 5 forms-portal data assets, and the 1 legacy database. Grand total registered: 192.

Stated because the figure has been read as a whole-estate count and is not one. Two corrections were made on 2026-09-01 and are recorded rather than absorbed: GCP Cloud Assets read 7 against a section holding 8 rows — wrong before anything was added, present since a02640a, and not attributable to a later edit — and the seven Pub/Sub entities below were added, taking the row to 15 and the total from 169 to 177.


Gateway / Firewall

Hostname FQDN IP Address Description OS / Platform Dept
fw fw.wdc.us.gl3 192.168.120.254 Cisco Meraki MX100 Meraki IT

Servers

Hostname FQDN IP Address MAC Address Description OS Dept
sky sky.wdc.us.gl3 192.168.120.1 00:0c:29:6a:a8:74 Primary DNS/DHCP Server Rocky Linux 8.10 IT
rain rain.wdc.us.gl3 192.168.120.2 00:0c:29:e1:6d:e8 Secondary DNS/DHCP Server Rocky Linux 8.10 IT
sun sun.wdc.us.gl3 192.168.120.3 00:0c:29:a0:a7:70 Prometheus/Grafana Monitoring Rocky Linux 8.10 IT
wind wind.wdc.us.gl3 192.168.120.4 00:0c:29:1d:80:0d ELK Stack Logging Rocky Linux 8.10 IT
ocean ocean.wdc.us.gl3 192.168.120.28 00:50:56:a0:f0:19 Imaging Server Fedora IT

Appliances, SANs & Printers

Type Hostname FQDN IP Address MAC Address Description Dept
SAN solstorage solstorage.wdc.us.gl3 192.168.120.43 90:09:d0:61:ad:7f Synology Storage — Solutions team IT
SAN vmstorage vmstorage.wdc.us.gl3 192.168.120.51 90:09:d0:1b:fe:80 Synology Storage — VMs IT
Printer mailroom mailroom.wdc.us.gl3 192.168.120.56 60:12:8b:f7:c0:75 Mailroom Canon Printer IT
Printer fireweed fireweed.wdc.us.gl3 192.168.120.57 34:9f:7b:58:9c:3f Fireweed Canon Printer IT
Printer woche woche.wdc.us.gl3 192.168.120.58 34:9f:7b:58:74:ba Woche Printer IT
Printer payroll-printer payroll-printer.wdc.us.gl3 192.168.120.59 c8:d9:d2:cb:b3:ea Payroll Printer Finance
SAN synstorage synstorage.wdc.us.gl3 192.168.120.60 1c:34:da:0c:06:a0 Synology Storage — Video Media
Desktop gpusresearchdesktop gpusresearchdesktop.wdc.us.gl3 192.168.120.64 20:88:10:e3:33:ee Windows 11 Research Desktop Research

Hypervisors

Hostname FQDN IP Address Description OS Dept
water water.wdc.us.gl3 192.168.120.65 Hosts Ocean VMware ESXi 6.7 IT
fire fire.wdc.us.gl3 192.168.122.160 Security ESXi VMware ESXi 6.7 IT
flower flower.wdc.us.gl3 192.168.122.240 General hypervisor VMware ESXi 6.8 IT

Workstations

113 workstations registered in the wdc.us.gl3 domain, IP range 192.168.120.70–230. All managed via DHCP reservations on SKY/RAIN.

Hostname FQDN IP Address MAC Address OS Dept User
noconnor noconnor.wdc.us.gl3 192.168.120.70 34:48:ed:9e:98:7a Windows 11 Data noconnor
hbakar hbakar.wdc.us.gl3 192.168.120.71 5c:80:b6:2f:f6:8e
kacamosy-mabookpro kacamosy-mabookpro.wdc.us.gl3 192.168.120.72 3c:07:54:7d:16:78
macarret macarret.wdc.us.gl3 192.168.120.73 14:75:5b:ee:25:e1
nbarnes nbarnes.wdc.us.gl3 192.168.120.74 ec:63:d7:98:8f:91
rskar rskar.wdc.us.gl3 192.168.120.75 f0:20:ff:2c:0c:8b
eprice-airbook eprice-airbook.wdc.us.gl3 192.168.120.76 70:ae:d5:44:98:59
kfrancis-airbook kfrancis-airbook.wdc.us.gl3 192.168.120.77 9c:58:84:15:26:a4
ksindayi-airbook ksindayi-airbook.wdc.us.gl3 192.168.120.78 84:94:37:cd:f7:a7
kacamosy-airbook kacamosy-airbook.wdc.us.gl3 192.168.120.79 9c:58:84:6e:31:6e
lharris lharris.wdc.us.gl3 192.168.120.80 b0:60:88:af:91:aa
rocampo rocampo.wdc.us.gl3 192.168.120.81 d4:d8:53:4c:aa:b3
tdivico-airbook tdivico-airbook.wdc.us.gl3 192.168.120.82 d0:88:0c:7f:60:c9
nsmith nsmith.wdc.us.gl3 192.168.120.83 64:49:7d:92:92:12
arizocen-airbook arizocen-airbook.wdc.us.gl3 192.168.120.84 10:b5:88:72:a0:80
jharris-airbook jharris-airbook.wdc.us.gl3 192.168.120.85 d0:88:0c:65:14:6d
cpatters-airbook cpatters-airbook.wdc.us.gl3 192.168.120.86 9c:58:84:17:7f:9d
gforbes-airbook gforbes-airbook.wdc.us.gl3 192.168.120.87 c0:95:6d:34:b9:7d
jsundius-airbook jsundius-airbook.wdc.us.gl3 192.168.120.88 70:ae:d5:49:66:fa
folagbaj folagbaj.wdc.us.gl3 192.168.120.89 8c:c6:81:1f:8e:0c
bloatwaretest bloatwaretest.wdc.us.gl3 192.168.120.90 00:e0:4c:01:01:1d
asmith-airbook asmith-airbook.wdc.us.gl3 192.168.120.91 d0:88:0c:64:e1:cb
tgarg tgarg.wdc.us.gl3 192.168.120.92 b4:6b:fc:78:34:80
lbigda-airbook lbigda-airbook.wdc.us.gl3 192.168.120.93 84:94:37:c9:8e:fa
psindha-airbook psindha-airbook.wdc.us.gl3 192.168.120.94 70:ae:d5:48:b3:d9
kstores kstores.wdc.us.gl3 192.168.120.95 98:59:7a:5b:1a:ee
taubry taubry.wdc.us.gl3 192.168.120.96 c0:47:0e:0d:6a:d4
jfornber jfornber.wdc.us.gl3 192.168.120.97 98:59:7a:5b:99:74
aarminio-airbook aarminio-airbook.wdc.us.gl3 192.168.120.98 70:ae:d5:43:fe:63
ccray ccray.wdc.us.gl3 192.168.120.99 14:75:5b:f5:a7:0d
tavila tavila.wdc.us.gl3 192.168.120.100 98:59:7a:5b:d5:fb
bphelan bphelan.wdc.us.gl3 192.168.120.101 68:7a:64:77:5d:99
bloatwaretest1 bloatwaretest1.wdc.us.gl3 192.168.120.102
iherod-airbook iherod-airbook.wdc.us.gl3 192.168.120.103 d0:88:0c:6c:63:59
alwhite alwhite.wdc.us.gl3 192.168.120.104 14:75:5b:f2:89:a1
hbaar-airbook hbaar-airbook.wdc.us.gl3 192.168.120.105 a4:c6:f0:27:de:bc
kmelges-airbook kmelges-airbook.wdc.us.gl3 192.168.120.106 9c:58:84:70:29:f5
msedita-airbook msedita-airbook.wdc.us.gl3 192.168.120.107 9c:58:84:72:49:f2
tgregory-airbook tgregory-airbook.wdc.us.gl3 192.168.120.108 70:ae:d5:43:0e:69
mlopez-airbook mlopez-airbook.wdc.us.gl3 192.168.120.109 9c:58:84:1c:2e:e4
jclark jclark.wdc.us.gl3 192.168.120.110 98:59:7a:5a:cb:f7
scruz-airbook scruz-airbook.wdc.us.gl3 192.168.120.111 c0:95:6d:3d:b1:37
snicolas-airbook snicolas-airbook.wdc.us.gl3 192.168.120.112 a4:c6:f0:2d:88:38
dwinprogpii dwinprogpii.wdc.us.gl3 192.168.120.113 00:15:5d:06:1e:01
jturner jturner.wdc.us.gl3 192.168.120.114 68:7a:64:74:5e:91
mbringas-airbook mbringas-airbook.wdc.us.gl3 192.168.120.115 70:ae:d5:48:56:3d
dwin11progpi dwin11progpi.wdc.us.gl3 192.168.120.116 00:15:5d:06:1e:02
mcarter-airbook mcarter-airbook.wdc.us.gl3 192.168.120.117 9c:58:84:20:1c:e5
dwin11progpiv dwin11progpiv.wdc.us.gl3 192.168.120.118 00:15:5d:06:1e:04
staylor-airbook staylor-airbook.wdc.us.gl3 192.168.120.119 d0:88:0c:6b:33:3c
jchristi-airbook jchristi-airbook.wdc.us.gl3 192.168.120.120 3c:22:fb:db:4c:fa
taubry-probook taubry-probook.wdc.us.gl3 192.168.120.121 bc:d0:74:23:b0:af
ddellprec75201 ddellprec75201.wdc.us.gl3 192.168.120.122 10:65:30:ff:da:44
dwin11progplll dwin11progplll.wdc.us.gl3 192.168.120.123 00:15:5d:06:1e:03
tbekele tbekele.wdc.us.gl3 192.168.120.124 00:09:0f:aa:00:01
kflynnja-airbook kflynnja-airbook.wdc.us.gl3 192.168.120.125 10:b5:88:79:89:af
brichard brichard.wdc.us.gl3 192.168.120.126 f0:20:ff:2b:fe:fd
testmacmini testmacmini.wdc.us.gl3 192.168.120.127 4c:20:b8:e9:a3:6c
ngreen-airbook ngreen-airbook.wdc.us.gl3 192.168.120.128 a4:c6:f0:25:c4:0b
mridenho mridenho.wdc.us.gl3 192.168.120.129 a0:80:69:ff:32:32
msimons msimons.wdc.us.gl3 192.168.120.130 ec:63:d7:98:8e:fb
ggirgis ggirgis.wdc.us.gl3 192.168.120.131 68:7a:64:75:61:42
dpadmana-airbook dpadmana-airbook.wdc.us.gl3 192.168.120.132 70:ae:d5:4b:e6:2e
testwin2 testwin2.wdc.us.gl3 192.168.120.133 00:e0:4c:01:01:0c
ljurca-airbook ljurca-airbook.wdc.us.gl3 192.168.120.134 a4:c6:f0:2c:8e:91
smckenna-airbook smckenna-airbook.wdc.us.gl3 192.168.120.135 c0:95:6d:3c:fc:42
hharmon-airbook hharmon-airbook.wdc.us.gl3 192.168.120.136 2c:76:00:ec:c7:ab
tbrooks tbrooks.wdc.us.gl3 192.168.120.137 5c:80:b6:2f:01:cf
btaylor-airbook btaylor-airbook.wdc.us.gl3 192.168.120.138 a4:c6:f0:2a:f0:6e
hlambert-airbook hlambert-airbook.wdc.us.gl3 192.168.120.139 9c:58:84:12:f0:d6
loaner-e loaner-e.wdc.us.gl3 192.168.120.140 a4:b1:c1:4b:19:23
ewhisena-airbook ewhisena-airbook.wdc.us.gl3 192.168.120.141 00:e0:4c:00:09:0c
visuals-macpro visuals-macpro.wdc.us.gl3 192.168.120.142 e4:50:eb:b8:37:9d
sheidenr-airbook sheidenr-airbook.wdc.us.gl3 192.168.120.143 c0:95:6d:37:41:52
loaner-f loaner-f.wdc.us.gl3 192.168.120.144 a4:b1:c1:4a:93:22
carring-airbook carring-airbook.wdc.us.gl3 192.168.120.145 d0:88:0c:6e:10:a0
bavila-airbook bavila-airbook.wdc.us.gl3 192.168.120.146 70:ae:d5:45:31:dc
sraman-airbook sraman-airbook.wdc.us.gl3 192.168.120.147 84:94:37:ce:42:c0
mailroompc mailroompc.wdc.us.gl3 192.168.120.148 04:ed:33:c0:94:af
jdragon-airbook jdragon-airbook.wdc.us.gl3 192.168.120.149 10:b5:88:77:26:92
sseipelt sseipelt.wdc.us.gl3 192.168.120.150 14:75:5b:d4:13:81
btrewin btrewin.wdc.us.gl3 192.168.120.151 04:ed:33:c0:33:93
jmeisel-airbook jmeisel-airbook.wdc.us.gl3 192.168.120.152 fc:e2:6c:1a:01:dd
loaner-d loaner-d.wdc.us.gl3 192.168.120.153 8c:c6:81:1f:67:8d
chull chull.wdc.us.gl3 192.168.120.154 ec:63:d7:98:39:6a
sherrado-airbook sherrado-airbook.wdc.us.gl3 192.168.120.155 a4:c6:f0:25:69:d2
dkhoury-airbook dkhoury-airbook.wdc.us.gl3 192.168.120.156 9c:58:84:79:dd:16
sbullock-airbook sbullock-airbook.wdc.us.gl3 192.168.120.157 9c:58:84:14:61:4b
ktoruno ktoruno.wdc.us.gl3 192.168.120.158 5c:80:b6:30:41:07
amoas-airbook amoas-airbook.wdc.us.gl3 192.168.120.159 70:ae:d5:43:60:4b
jumoss jumoss.wdc.us.gl3 192.168.120.160 04:ed:33:2d:cf:e9
ahemphil-airbook ahemphil-airbook.wdc.us.gl3 192.168.120.161 d0:88:0c:66:10:59
dwatford-airbook dwatford-airbook.wdc.us.gl3 192.168.120.162 a4:c6:f0:25:0c:45
knelson-airbook knelson-airbook.wdc.us.gl3 192.168.120.163 c0:95:6d:3c:d1:6b
cprieto-airbook cprieto-airbook.wdc.us.gl3 192.168.120.164 d0:88:0c:63:0a:28
fortitest-airbook fortitest-airbook.wdc.us.gl3 192.168.120.165 c0:95:6d:36:c6:3d
kreyes-airbook kreyes-airbook.wdc.us.gl3 192.168.120.166 48:e1:5c:da:d1:ab
kchungya kchungya.wdc.us.gl3 192.168.120.167 30:89:4a:ae:1b:8b
sk-airbook sk-airbook.wdc.us.gl3 192.168.120.168 fc:e2:6c:15:eb:9f
d-macbook-air d-macbook-air.wdc.us.gl3 192.168.120.169 d0:81:7a:ab:ee:02
lpratt lpratt.wdc.us.gl3 192.168.120.170 5c:80:b6:2f:e7:d4
fvonsuck-airbook fvonsuck-airbook.wdc.us.gl3 192.168.120.171 9c:58:84:1a:ff:a9
jstuckey-airbook jstuckey-airbook.wdc.us.gl3 192.168.120.172 c0:95:6d:35:86:4e
sladwig sladwig.wdc.us.gl3 192.168.120.173 14:75:5b:ee:27:08
hbasioun-airbook hbasioun-airbook.wdc.us.gl3 192.168.120.174 84:94:37:d2:58:21
asterlin-airbook asterlin-airbook.wdc.us.gl3 192.168.120.175 9c:58:84:74:d4:ff
jhocevar jhocevar.wdc.us.gl3 192.168.120.176 a4:c3:f0:56:53:f6
gsmalley-airbook gsmalley-airbook.wdc.us.gl3 192.168.120.177 10:b5:88:74:ad:be
tdonaghy-airbook tdonaghy-airbook.wdc.us.gl3 192.168.120.178 70:ae:d5:4d:aa:81
jejohnso-airbook jejohnso-airbook.wdc.us.gl3 192.168.120.179 9c:58:84:7a:ac:b3
amorales-airbook amorales-airbook.wdc.us.gl3 192.168.120.180 10:b5:88:72:da:01
arincon-airbook arincon-airbook.wdc.us.gl3 192.168.120.181 9c:58:84:13:04:ba
mailroompc-eth mailroompc-eth.wdc.us.gl3 192.168.120.182 00:e0:4c:00:08:be Windows Mailroom

GCP cloud assets

Type Name FQDN / Endpoint Description Region Dept
Cloud Run gpus-status-site gpus-status-site-1056766133984.us-central1.run.app Infrastructure status dashboard us-central1 IT
Cloud Run gpus-status-backend gpus-status-backend-1056766133984.us-central1.run.app Live data API — SSH/Prometheus/ES polling us-central1 IT
Cloud Run gpus-mkdocs-portal gpus-mkdocs-portal-1056766133984.us-central1.run.app IT Infrastructure Portal — https://infra.greenpeace.us us-central1 IT
DNS CNAME infra.greenpeace.us infra.greenpeace.us Custom domain → gpus-mkdocs-portal; SSL: Cloud Run managed IT
GCS Bucket gpus-infra-backups-wdc On-premises backup target us-central1 IT
GCS Bucket gpus-infra-tf-state Terraform state bucket us-central1 IT
VPN Gateway gpus-vpn-gateway Cloud VPN — peer: WDC Meraki MX100 (38.140.146.68); tunnel: ESTABLISHED us-central1 IT
Artifact Registry gpus-images us-central1-docker.pkg.dev/gpus-infra/gpus-images Container image registry for all Cloud Run services us-central1 IT
Pub/Sub topic gpus-forms-attachment-uploaded projects/gpus-infra/topics/gpus-forms-attachment-uploaded GCS OBJECT_FINALIZE notifications on gpus-forms-attachments fan in here; push subscription delivers to the ClamAV scan worker. Carries object pointers, no file content us-central1 IT
Pub/Sub topic gpus-forms-attachment-uploaded-dlq projects/gpus-infra/topics/gpus-forms-attachment-uploaded-dlq Dead-letter topic (5-attempt cap). Push sub gpus-forms-clamav-worker-dlq-alert-sub → worker /dlq-alert → Slack us-central1 IT
Pub/Sub subscription gpus-forms-clamav-worker-sub push → gpus-forms-clamav-worker (Cloud Run) Push subscription on gpus-forms-attachment-uploaded; dead-letters to …-dlq after 5 attempts us-central1 IT
Pub/Sub topic gpus-forms-approval-notify projects/gpus-infra/topics/gpus-forms-approval-notify Travel approval notifications, both kinds, discriminated on a kind message attribute (step / outcome). Published by gpus-forms-backend after the durable write commits; consumed on MAPLE. Payload is a pointer only{kind, submission_id, version, step_index} — never a rendered body, address, comment or field value, because Pub/Sub messages are durable and retained and a rendered body would be stored plaintext travel data outside the database with none of its access control. A stall here means no approver is ever told their step is waiting us-central1 IT
Pub/Sub subscription gpus-forms-approval-notify-sub pull ← gpus-forms-routing-worker (MAPLE) Pull subscription consumed in the routing worker's main loop. Ack deadline 120s, retention 7d, retry 10s→600s, dead-letters after 5 attempts. Pull rather than push because Postfix on MAPLE is loopback-only us-central1 IT
Pub/Sub topic gpus-forms-approval-notify-dlq projects/gpus-infra/topics/gpus-forms-approval-notify-dlq Dead-letter topic. A message here is an approval notification that was never rendered or sent; the submission row shows notification_published_at SET and notification_sent_at NULL us-central1 IT
Pub/Sub subscription gpus-forms-approval-notify-dlq-sub pull ← gpus-forms-routing-worker (MAPLE) Drained in-process by the routing worker's sweep, posting each exhausted notification to Slack. Ack deadline 60s, retention 7d. No push endpoint by design — so it drains only while the routing subscription is also healthy us-central1 IT

Provenance of the seven Pub/Sub rows, and what is still missing

Sourced from inventory.yaml (inventory.cloud_services, seven type: pub_sub entries) and from the code that names them, not from a live gcloud pubsub topics list. That enumeration was attempted on 2026-09-01 and failed for both reachable identities: the workstation's gcloud requires an interactive re-login, and MAPLE's maple-agent SA is IAM_PERMISSION_DENIED on pubsub.topics.list — it holds subscriber rights on named subscriptions, not project-wide list. Recorded as an absence rather than passed over (M-06). The configuration details above were verified live in GCP on 2026-08-26 and are carried forward from inventory.yaml, which states that.

inventory.yaml itself does not declare the whole Pub/Sub estate. Four resources named in running code have no inventory entry and are therefore not registered here either: the topic gpus-forms-submission-ready (forms-backend/config.py:45, routing_worker.py:108) and the subscriptions gpus-forms-routing-worker-sub (routing_worker.py:103), gpus-forms-routing-dlq-alert-sub (:106) and gpus-forms-clamav-worker-dlq-alert-sub (named only inside another entry's description). These are the 2.5(c) attachment-routing path — the one the worker's own inventory entry calls its first job. They are named here so the omission is on the record; adding them belongs in inventory.yaml first, per the Adding Infrastructure workflow, not directly in this page.


GPUS-IT-Infrastructure data-team GCE fleet (2026-06-26)

Nine Compute Engine instances in the gpus-it-infrastructure GCP project (distinct from gpus-infra) on the shared gl5-shared network domain, owned by the Data team. Tracked in inventory.yaml under compute_instances and documented in infrastructure/gpus-it-infrastructure.md.

These are monitoring-pending assets — Windows hosts intended for the WDC Wazuh agent, Linux hosts for Prometheus node_exporter — with no telemetry flowing yet. Registered here for CIS Control 1 (Inventory of Enterprise Assets) coverage; the coverage check requires an IAR entry for every gpus-it-infrastructure asset.

Instance Platform Private IP Public IP OS (EOL) Role Disposition Monitoring State
duck Windows 10.1.96.46 Windows Server 2016-DC (2027-01-12) Analyst terminal server + Redshift/SQL migrate (→WS2025, rebuild-cutover) wazuh-agent → WDC · pending-path running
grebe Windows 10.1.96.51 Windows Server 2016 (2027-01-12) Terminal/app server + 500 GB data disk migrate (→WS2025, rebuild-cutover) wazuh-agent → WDC · pending-path running
falcon Windows 10.1.96.12 35.223.86.92 Windows Server 2016 (2027-01-12) Talend ETL node (prod) migrate (→WS2025, rolling-cutover) wazuh-agent → WDC · pending-path running
gull Windows 10.1.96.42 104.154.21.30 Windows Server 2016 (2027-01-12) Talend ETL node (prod) migrate (→WS2025, rolling-cutover) wazuh-agent → WDC · pending-path running
kestrel Windows 10.1.96.15 35.239.221.226 Windows Server 2016 (2027-01-12) Talend ETL node (prod) migrate (→WS2025, rolling-cutover) wazuh-agent → WDC · pending-path running
woodpecker Windows 10.1.96.48 Windows Server 2022-DC Unknown — role unconfirmed investigate none · not-monitored terminated
kingfisher Linux 10.1.96.14 35.192.36.47 CentOS 7 (EOL 2024-06-30) Tamr data-mastering (legacy) decommission (gated: pending Tamr disposition) none · not-monitored terminated
magpie Linux 10.1.96.50 34.72.120.159 RHEL 8 (2029-05-31) SQL/Linux data service keep node-exporter → WDC · pending-path running
nfs-gw Linux 10.128.0.11 Debian 10 (EOL 2024-06-30) Filestore/NFS gateway (dual-homed) rebuild (supported OS) node-exporter → WDC · pending-path running

Roles are confirmed with the Data team except woodpecker (unconfirmed).

Orphaned-resource cleanup (recorded in inventory.yaml cleanup_notes, not managed assets): loonnew orphaned persistent disk (unattached) and dead GKE PVCs from a since-deleted cluster — both queued for deletion to reclaim storage.

Change log:

  • 2026-06-26 — gpus-it-infrastructure integration: 9 data-team GCE instances registered as compute_instances; all monitoring-pending (WDC collector path not yet wired). loonnew disk + dead GKE PVCs logged for cleanup.

Finding — gpusa-it-infrastructure-306400 is absent from the inventory (2026-09-04)

Status: OPEN. Recorded, not remediated in this pass.

The GCP project gpusa-it-infrastructure-306400 has zero entries in inventory.yaml and, before this note, zero entries in this register. As of 2026-09-04 it contains 25 Compute Engine instances (23 running, 2 terminated) and 2 Cloud SQL instances — none of them registered:

  • Running: albatross, astrapia, babbler, blackbird, catbird, cormorant, emu, gannet, grouse, moa, mockingbird, ostrich, phoebe, phoenix, pintail, puffin, rail, rallidae, robin, sparrow, thrasher, thrush, whistler
  • Terminated: cromber, quail
  • Cloud SQL: pitta, bulbul

This is a CIS Control 1 / ID.AM-1 coverage gap, and a material one: emu and ostrich are the authoritative DNS servers for us.gl3 and cloud.us.gl3, and phoenix is the Puppet master for the estate. The Component Coverage Standard is satisfied for gpus-infra and gpus-it-infrastructure while an entire third project sits outside it.

The list above is a snapshot as of 2026-09-04 and is already out of date by design. phoebe and pitta were deleted 2026-09-04 and bulbul 2026-09-08, so both Cloud SQL instances and one of the running GCE instances are gone. The snapshot is kept as written rather than edited down, because the size of the gap on the day it was found is the finding; silently shrinking the list as assets are retired would make a coverage gap look like it was being closed by inventory work when it was being closed by deletion.

Deliberate decision, 2026-09-04, extended 2026-09-08: phoebe, pitta and bulbul were not added to inventory.yaml as part of their retirement. Creating inventory entries for three assets purely in order to delete them would record a compliance posture that never existed and would leave the other 24 unregistered. The savings ledger (savings-ledger.yaml) is the retirement record for those three; this register carries the narrative.

Owner action: populating gpusa-it-infrastructure-306400 in inventory.yaml is an enterprise-architecture decision — it needs a monitoring_intent per host and a documented_in target that does not yet exist — and is tracked in that workstream, not here.


Meraki network fabric (Wave 1, 2026-04-28)

Cisco Meraki cloud-managed network infrastructure — security appliances (MX), switches (MS), and wireless access points (MR) — distributed across five networks at three physical sites (Washington DC HQ, MDEC, OAKEC) plus residential APs (DC Apartments) and an MDM-only network (Major Gifts). Managed via Meraki Dashboard organization 395909 (license expires 2027-11-28). Full per-device inventory with serials, MACs, EOL dates, and lifecycle actions: meraki-hostregistry.csv.

For network architecture, uplink topology, GCP VPN integration, and phased roadmap, see meraki-infrastructure.md.

Security appliances (MX) — 4 devices:

Hostname Serial Site Network Role Criticality Notes
wdc-fw-primary Q2XN-V4XE-UQKX WDC WDC-Eye Street firewall-primary critical HA primary; VRRP master; GCP VPN terminator
wdc-fw-secondary Q2XN-LXCR-EJEW WDC WDC-Eye Street firewall-secondary critical HA secondary
MDEC MX Q2KN-AFKR-5EES MDEC MDEC firewall-primary high Single uplink, no HA
oakec-fw-primary Q2KN-86TU-N6CP OAKEC OAKEC firewall-primary high Renamed from Justin-Bieber 2026-04-23

Switches (MS) — 11 devices:

Hostname Serial Site Network Model Criticality EOL Status
WDC-STACK-0-NOPOE Q2HW-F8RK-KULW WDC WDC-Eye Street MS225-48 critical EoSale 2026-04-30
WDC-STACK-1-NOPOE Q2HW-HMCF-4LJ5 WDC WDC-Eye Street MS225-48 critical EoSale 2026-04-30
WDC-STACK-2-NOPOE Q2HW-HKLA-DPXW WDC WDC-Eye Street MS225-48 critical EoSale 2026-04-30
WDC-STACK-3-NOPOE Q2HW-FN64-HZWA WDC WDC-Eye Street MS225-48 critical EoSale 2026-04-30
WDC-STACK-4-POE Q2KW-3VQQ-DE9H WDC WDC-Eye Street MS225-48FP critical EoSale 2026-04-30
WDC-STACK-5-POE Q2KW-TJTU-B2ET WDC WDC-Eye Street MS225-48FP critical EoSale 2026-04-30
WDC-STACK-6-POE Q2KW-VRUK-9LS6 WDC WDC-Eye Street MS225-48FP critical EoSale 2026-04-30
wdc-edge-1 Q4AA-B9B4-HLZQ WDC WDC-Eye Street MS120-8 high EoS 2030-03-28
wdc-edge-2 Q4AA-VRAQ-2GSF WDC WDC-Eye Street MS120-8 high EoS 2030-03-28
MDEC-access-2 Q2SX-HDV2-2UTV MDEC MDEC MS210-24P medium EoSale 2026-04-30
Oakland Warehouse Switch1 Q2SX-29PM-F7KP OAKEC OAKEC MS210-24P medium EoSale 2026-04-30

Wireless access points (MR) — 17 devices:

Hostname Serial Site Network Model Criticality EOL Status
wdc-wap-1 Q3AP-D6NB-GY3G WDC WDC-Eye Street MR57 high OK
wdc-wap-2 Q3AP-VVT6-7Q7T WDC WDC-Eye Street MR57 high OK
wdc-wap-3 Q3AP-6SSC-Z2L7 WDC WDC-Eye Street MR57 high OK
wdc-wap-4 Q3AP-2YDY-XZQZ WDC WDC-Eye Street MR57 high OK
wdc-wap-5 Q3AP-T34T-45AG WDC WDC-Eye Street MR57 high OK
First Floor AP Q2LD-2P6D-FQ9Q MDEC MDEC MR52 medium EoS 2026-07-21 ⚠
Garage AP Q2LD-K2TR-N97R MDEC MDEC MR52 medium EoS 2026-07-21 ⚠
Second Floor AP Q2LD-SCPN-R4KY MDEC MDEC MR52 medium EoS 2026-07-21 ⚠
OAKEC-AP1 Q2LD-4DN3-3BT9 OAKEC OAKEC MR52 medium EoS 2026-07-21 ⚠
OAKEC-AP2 Q2LD-L3GL-NG4Z OAKEC OAKEC MR52 medium EoS 2026-07-21 ⚠
APT 707 Q2LD-5XJZ-2SZC DC Apartments DC Apartments MR52 low EoS 2026-07-21 ⚠
APT 709 Q2PD-KDPN-SBFR DC Apartments DC Apartments MR33 low EoS 2026-07-21 ⚠
APT 611 Q2PD-PN66-3P86 DC Apartments DC Apartments MR33 low EoS 2026-07-21 ⚠
APT211 Q2PD-GKDC-PVLG DC Apartments DC Apartments MR33 low EoS 2026-07-21 ⚠
mdec garage Q2JD-29US-5JXK unassigned MR32 decommission PAST EoS 2024-07-31 ⚠⚠
mdec 1st floor work room Q2JD-2MFW-39AG unassigned MR32 decommission PAST EoS 2024-07-31 ⚠⚠
mdec 2nd floor by the bunk room Q2PD-L4QQ-9G54 unassigned MR33 decommission EoS 2026-07-21

Network breakdown:

Network Network ID Devices Site Notes
WDC-Eye Street L_630503947831890190 13 Washington DC HQ HA firewall pair, GCP VPN terminator
MDEC L_630503947831873852 5 Mid-Atlantic Direct Engagement Center Single uplink
OAKEC L_630503947831873855 4 Oakland Engagement Center Single uplink
DC Apartments N_630503947831910695 4 Residential staff housing Wireless-only
Major Gifts N_630503947831998386 0 (SM only) Donor team endpoints MDM-only, no hardware in this registry
Unassigned 3 Decommission queue (see lifecycle_action in CSV)

Compliance: This Meraki section satisfies CIS Control 1 (Inventory of Enterprise Assets) and ID.AM-1 (Hardware inventory) for the network fabric domain. Per-control mapping detail is documented in meraki-infrastructure.md under "Compliance Mappings" — covers MITRE ATT&CK, PCI-DSS v4.0, NIST CSF 2.0, NIST 800-53 Rev. 5, ISO 27001:2022, and CIS Controls v8.

Audit findings (2026-04-27/28): 10 findings logged through Meraki discovery (MERAKI-2026-04-001 through 010) — see meraki-infrastructure.md § Audit Findings. Critical-severity: MERAKI-2026-04-003 (2× MR32 past EoS, decommission immediately). High-severity: MERAKI-2026-04-001 (Sedita stale full admin), MERAKI-2026-04-002 (no SAML SSO), MERAKI-2026-04-004 (12× APs hitting EoS 2026-07-21), MERAKI-2026-04-007 (no syslog → CEDAR).


Forms portal data assets (Phase 1, 2026-04-18)

The Forms Portal (forms.greenpeace.us) introduces five data assets that are not hosts — they are Cloud SQL schemas, GCS buckets, and KMS keys. They are tracked here rather than in wdc-hostregistry.csv because they do not have an IP or MAC. The fifth — the travel approval workflow tables — was added 2026-09-01, four and a half months after the other four; the section heading still reads Phase 1, 2026-04-18 because that is when the section was opened, not when its contents were last complete.

Asset Classification Type Encryption / Key Retention Owner
Forms Portal Database CONFIDENTIAL Cloud SQL PostgreSQL 15 (gpus-forms-db, private IP) CMEK via gpus-forms-cmek + per-submission AES-256-GCM DEK wrapped by gpus-forms-dek-wrapper 7 years (submissions + audit log); automated daily backups + PITR Director of Cyber Security
Forms Portal Attachments CONFIDENTIAL GCS bucket (gpus-forms-attachments), signed-URL-only, ClamAV scanned CMEK via gpus-forms-cmek 7 years = 2555 days; retention policy set 2026-06-15, currently UNLOCKEDlock scheduled pending bucket cleanup + versioning/lifecycle decision (see forms-portal-controls.md retention audit log, 2026-06-15) Director of Cyber Security
Forms Portal KMS Keys RESTRICTED Cloud KMS keys (gpus-forms-cmek, gpus-forms-dek-wrapper) in us-central1 Software-protected, automatic 90-day rotation. IAM grants: gpus-forms-backend@gpus-infra.iam.gserviceaccount.com = cryptoKeyEncrypterDecrypter (wrap + unwrap); maple-agent@gpus-infra.iam.gserviceaccount.com = cryptoKeyDecrypter (decrypt-only, on gpus-forms-dek-wrapper only, for 2.5(d) send-time render — the only non-backend identity able to recover submission plaintext; see change log 2026-06-17) Key material retained per KMS defaults; rotation verified quarterly Director of Cyber Security
Forms Portal Backups CONFIDENTIAL GCS bucket (gpus-infra-backups-wdc/forms-db/), pg_dump weekly + Cloud SQL automated daily CMEK via gpus-forms-cmek 7 years Backup Admin
Travel Approval Workflow Tables CONFIDENTIAL Cloud SQL PostgreSQL tables inside gpus-forms-dbsubmission_approvals, approval_steps, approval_role_members, the SMT approver map and submissions.parent_submission_id (migrations 014022) Inherits the database's CMEK (gpus-forms-cmek). Approver comments, decision timestamps and resolved_okta_email are stored in plaintext columns, NOT under the per-submission AES-256-GCM DEK — the field-level encryption covers submission_fields, and these are approval-chain columns beside it 7 years, inherited from the database row (retention_expires_at); note PRG-028 — no retention purge executor exists, so nothing acts on the expiry Director of Cyber Security

The IAR gate does not cover these assets — a passing coverage check is not evidence of registration

scripts/check-component-coverage.py does enforce an IAR entry, and that enforcement is narrower than it looks. Read validate_portal_presence(): the mandatory-IAR loop runs over gpit_assets only — inventory.compute_instances, plus any entity in any other category carrying project: gpus-it-infrastructure. For each of those it hard-errors with [iar] … no IAR entry.

Every forms-portal asset on this page is in gpus-infra. Read live from inventory.yaml on 2026-09-01: all thirteen cloud_services entries — the database, the Cloud Run services, the routing worker and all seven Pub/Sub entities — carry no project: key at all, so none of them ever enters that loop. Only the 9 compute_instances do.

The consequence, stated plainly: the approval workflow tables went unregistered here from migration 014 (2026-08-18) until 2026-09-01 while check-component-coverage.py returned PASS on every run in between. It was still returning PASS immediately before this row was added. The gate could not have caught it and did not fail. An absent IAR row for a gpus-infra asset is a compliance gap the pre-build check does not detect — do not read a green coverage check as evidence that this registry is complete.

inventory.yaml had recorded the gap in prose the whole time: the gpus_forms_db entry's own description ends "…not separately registered there yet." A description is not a check.

Why the approval tables are CONFIDENTIAL, precisely

The tables themselves hold the chain — states, step indexes, role keys, resolved approver addresses, decision timestamps and free-text approver comments. They do not store traveller names or destinations; those live in submission_fields under the per-submission DEK.

The classification follows from what the tables authorize, not only from what they store. approval_steps.resolved_okta_email + status is the whole authorization test (approval_access.resolve_access_core), and a party holding a DISPATCHED step can decrypt and read the full submission — audit_log records exactly that on 2026-08-31 for c84bfb45: decrypt_success … endpoint: approval_view, field_count: 15. A row in approval_steps is therefore a grant of access to CONFIDENTIAL travel data, and is classified as such.

Two properties worth carrying into any assessment. (1) The grant is frozen at dispatch and there is no way to revoke it — see GOV-030, which records that the ASVS scope statement's stated mitigation for this was never built. (2) comment, decided_by_email and resolved_okta_email are TEXT columns in 014_approval_workflow.sql (:234, :240, :241) — the field-level AES-256-GCM covers submission_fields, not these. Approver comments are protected by CMEK at rest and by database access control, and by nothing else.

Change log:

  • 2026-04-18 — Phase 1 cutover: four forms-portal data assets registered; database and attachments marked CONFIDENTIAL, KMS keys marked RESTRICTED. See forms-backend/RUNBOOK-CLAUDE-CODE.md (provisioning) and forms-backend/RUNBOOK-COWORK.md Task 10 for the addition rationale.
  • 2026-09-01 — Travel approval workflow tables registered as the fifth forms-portal data asset, CONFIDENTIAL: submission_approvals, approval_steps, approval_role_members, the SMT approver map and submissions.parent_submission_id (migrations 014022). Unregistered since 014 shipped on 2026-08-18. Classified on what the rows authorize — a DISPATCHED step is a grant of decrypt access to the full submission, evidenced in audit_log for c84bfb45 on 2026-08-31 (decrypt_success … field_count: 15) — and recorded with the fact that comment, decided_by_email and resolved_okta_email are plain TEXT, outside the per-submission DEK. Also recorded: check-component-coverage.py could not have caught this omission. validate_portal_presence() enforces a mandatory IAR entry only for compute_instances and for assets tagged project: gpus-it-infrastructure; all thirteen cloud_services entries carry no project key, and the check returned PASS throughout. See GOV-030 for the related assurance gap on revocation, and PRG-028 — the 7-year retention this row inherits has no purge executor acting on it. Section preamble corrected four → five data assets.
  • 2026-09-01 — Seven Pub/Sub entities added to GCP cloud assets — the topics gpus-forms-attachment-uploaded, …-dlq, gpus-forms-approval-notify, …-dlq and the subscriptions gpus-forms-clamav-worker-sub, gpus-forms-approval-notify-sub, …-dlq-sub. Sourced from inventory.yaml and the code that names them; a live gcloud pubsub topics list was attempted and failed for both reachable identities (workstation gcloud needs re-login; maple-agent is IAM_PERMISSION_DENIED on pubsub.topics.list) and that is recorded rather than passed over. Four further Pub/Sub resources named in running code — gpus-forms-submission-ready, gpus-forms-routing-worker-sub, gpus-forms-routing-dlq-alert-sub, gpus-forms-clamav-worker-dlq-alert-sub — have no inventory.yaml entry and are therefore still unregistered; named on the page so the omission is visible, and left for inventory.yaml to declare first per the Adding Infrastructure workflow. Counts: GCP Cloud Assets 7 → 15 — of which one is a correction, not an addition: the row read 7 against a section holding 8 data rows, wrong since a02640a and before anything was added. Total 169 → 177, and a note now states what Total covers (this table only) against the grand total of 192 the document actually registers.
  • 2026-06-17 — Forms 2.5(d) send-time render: granted maple-agent@gpus-infra.iam.gserviceaccount.com roles/cloudkms.cryptoKeyDecrypter (DECRYPT-ONLY, key-level) on gpus-forms-dek-wrapper. Third standing IAM binding on maple-agent (after storage.objectViewer on gpus-forms-attachments + self-tokenCreator for signBlob, 2.5(c) Gate 4) and the only one able to recover submission plaintext — flagged for the recurring admin-review scope. Decrypt-only by design: the role grants useToDecrypt but not useToEncrypt, so the worker can unwrap existing per-submission DEKs but cannot wrap new ones (encrypt-denied probe confirms the asymmetry). Boundary = option 3: the routing worker decrypts at send-time, renders, sends, and never persists plaintext. See forms-backend/crypto.py (unwrap_dek) and gpus-forms-routing-worker/routing_worker.py.

Legacy Forms Database (in_formfeed)

Tracked here as part of the Phase 1.5 migration from the legacy PHP forms system. See Phase 1.5 addendum Task A and Task B for verification and right-sizing work.

Field Value
Asset Cloud SQL MySQL instance, public IP 34.171.123.238
Project [confirm during migration runbook Step 1]
Data 260 KB, 5 tables (category, form, field, pulldown, template) — 772 rows combined
Classification INTERNAL (no PII; metadata and form definitions only, no submissions stored)
Purpose Legacy reference after Phase 1.5 migration to gpus-forms-db
Status Read-only reference, no writes since cutover — cutover date TBD (Phase 4 go-live)
Retention Decision pending (see addendum Task B — oversized instance / retirement decision)
Access formfeed@34.171.123.238 — credentials in Secret Manager (gpus-formfeed-mysql-password)
Network exposure Public IP (34.171.123.238); authorized networks restricted to three /32 CIDRs (no 0.0.0.0/0 present — good)

Authorized networks (confirmed 2026-04-18):

CIDR Description Disposition
113.199.192.121/32 rchhetry — admin access Removed with the instance 2026-09-04 (label lost in the ACL edit — see change log)
34.121.207.171/32 phoebe — legacy GCP VM REMOVED 2026-09-04, ahead of instance deletion
34.45.99.114/32 catbird — legacy GCP VM Removed with the instance 2026-09-04 (label lost in the ACL edit; entry never matched catbird's real egress — see change log)

This instance no longer exists

pitta was deleted 2026-09-04 at 18:59:30 UTC. The table above is retained as the historical record of its network exposure, not as a description of anything live.

Security finding status: No 0.0.0.0/0 entry — instance is already restricted to three /32 sources. No immediate remediation required; phoebe and catbird entries are scheduled for removal after Phase 4 cutover to retire unused legacy paths. Record removal dates in the change log below when they happen.

Change log:

  • 2026-04-18 — Legacy database registered ahead of Phase 1.5 migration cutover. Authorized-networks audit completed (3 /32 CIDRs, no 0.0.0.0/0). phoebe + catbird entries queued for removal after Phase 4 cutover.
  • 2026-09-03 — phoebe retirement began. Ten DNS records referencing phoebe removed at the canonical source across two zones (cloud.us.gl3: phoebe A, plus redirects, forms, lam CNAMEs; us.gl3: sharperlight, redirects, lam, forms, dhcp, budget CNAMEs). Both zone serials set to 2026090400 and distributed to emu and ostrich. The eleven user databases on this instance were exported to gs://gpusa-it-infrastructure-database-archive/retirement-2026-09-03/pitta/ (11 objects, 1.61 GiB).
  • 2026-09-04 — Verification, ahead of removal. All ten DNS names confirmed NXDOMAIN from two independent client vantages (catbird, phoenix), each paired with controls that returned NOERROR from the same vantage so an empty answer could not be mistaken for a REFUSED or a timeout. Export re-verified independently of the 2026-09-03 record: 11/11 objects present, byte sizes matching, every dump carrying a valid gzip CRC over the full stream, a mysqldump header, and a -- Dump completed trailer. Finding — phoebe was already not serving. The instance reports RUNNING, but from catbird on the same subnet it answers no ICMP and has no open port (22, 80, 443, 3306, 8080), while controls emu, ostrich and thrush answer ping and accept :22 from that same vantage. lastStartTimestamp is 2024-06-28 with no restart since. The 34.121.207.171/32 grant has therefore been dormant, not merely unused. Finding — the catbird row overstates a live path. 34.45.99.114/32 is catbird's assigned NAT address, but its observed egress is 35.192.34.26. The ACL entry does not match the address catbird actually presents, so it grants no working access. The row is accurate as a record of intent and inaccurate as a record of exposure; it is retained here rather than corrected silently, and should be reconciled when the catbird disposition is settled. Instance deletion and the removal of the phoebe /32 are gated on the 86,400 s DNS TTL, which expires 2026-09-04 18:51 UTC. Removal date to be appended here when it happens.
  • 2026-09-04 — RETIREMENT EXECUTED. All times UTC; note that the operator's local clock (+05:45) had already rolled to 09-05, and the UTC date is the one of record.
    • 18:52 — DNS re-verified from both client vantages (catbird, phoenix). All four controls NOERROR with answers at each vantage; all ten removed names NXDOMAIN with zero answers; serial 2026090400 live on both emu and ostrich. A failed control was treated as a stop condition, on the reasoning that a lying vantage invalidates the ten negatives rather than sitting beside them.
    • 18:55:09 — phoebe stopped (TERMINATED). The stop took ~3 minutes, consistent with a guest that could not respond to a graceful shutdown.
    • 18:56 — phoebe deleted. Its 100 GB pd-standard boot disk carried autoDelete: true and went with it; both instance and disk confirmed absent.
    • 18:58 — pitta authorized networks replaced with the two survivors. 34.121.207.171/32 confirmed absent.
    • 18:58 — pitta deletion protection patched to False and confirmed before proceeding. It had been True; the deletion would otherwise have failed outright.
    • 18:59:30 — pitta deleted and confirmed absent.
    • All ten retained artifacts enumerated by name and confirmed present after deletion — the seven gcs-phoebe-8728708703581121380-* dailies, phoebe-evidence-live-20260812, and both evidence images — each READY with unchanged storageBytes. Verified rather than assumed: snapshots are independent objects and do not follow an autoDelete disk.
    • pitta's automated backups were destroyed with the instance, as expected. The GCS export at gs://gpusa-it-infrastructure-database-archive/retirement-2026-09-03/pitta/ is now the only copy of those eleven databases; re-confirmed intact immediately after deletion at 11 objects / 1,724,337,246 bytes. ACL NAME LABELS LOST — recorded rather than passed over. gcloud sql instances patch --authorized-networks replaces the entire list and accepts CIDRs only; there is no flag that carries the name field. The two surviving entries therefore came back as name: ''. Access is unaffected and the CIDR-to-identity mapping is preserved in the table above, but the labels themselves did not survive the edit. Noted because a compliance record should say when it lost a field, not quietly present a thinner one. Moot in this instance's case — it was deleted ninety seconds later — but the same operation on a surviving instance would silently strip its documentation.

Maintenance

The IAR is updated whenever:

  • A new device is assigned a DHCP reservation on SKY/RAIN
  • A new server, appliance, or cloud asset is provisioned
  • An asset is decommissioned or reassigned

Update procedure:

  1. Edit the appropriate registry under hostregistry/wdc-hostregistry.csv on SKY for WDC hosts; gcp-hostregistry.csv via repo for GCP cloud assets; meraki-hostregistry.csv via repo for Meraki devices.
  2. Increment version header (vX.Y → vX.Y+1) and update date
  3. Update this page to match
  4. Log the change: echo "$(date -Is) IAR updated — [reason]" >> /var/log/asset-inventory.log
  5. Run AIDE baseline update per Post-Change Checklist

Information Asset Registry · v1.5 · 2026-09-01 · GPUS-IT · Classification: CONFIDENTIAL — Internal Use Only