Skip to content

Register ID Mapping — provisional to real, 2026-08-13

Classification: CONFIDENTIAL — Internal Use Only Document: governance/register-id-mapping-2026-08-13.md · v1.1 · 2026-08-17 · GPUS-IT


Purpose

The three GPUS-IT registers were opened on 2026-08-13 from a candidate list that used provisional identifiers S-1S-10, G-1G-9 and P-1P-16. This document records what each provisional identifier became, so any note, message or draft still using the provisional form resolves.

The provisional identifiers are retired. They were never published and should not be used again; P-3 in particular must not be confused with PRG-003, whose scope was corrected (see below).

Register ID prefix Document
Security findings VLN- security/vuln/tracker.md
Governance / tracking gaps GOV- governance/gap-register.md
Program work items PRG- priorities/gpus-it-priorities.md
Host-level blockers HB- same document, separate series

Security findings — S-VLN-

Continues the existing tracker series, which ran to VLN-012 after the chronyd reassignment. No existing id was reused.

Provisional Real Title
S-1 VLN-013 ESXi 6.7 EOL on fire and flower — VLN-004 misattributes it to water
S-2 VLN-014 rain serves a stale DNSSEC signing; RRSIGs expire 2026-08-28
S-3 VLN-015 NOPASSWD sudo on emu and ostrich — VLN-009 scope beyond WDC
S-4 VLN-016 Three identity strings for one person, with inverted access
S-5 VLN-017 gcloud list verbs exit 0 on permission denial
S-6 VLN-018 All 10 Cloud Run services in gpus-infra are ingress: all
S-7 VLN-019 duck.cloud.us.gl3 resolves to an address that is not duck's
S-8 VLN-020 Five Puppet node definitions can never match a certname
S-9 VLN-021 3 of 4 Meraki org admins hold orgAccess: full
S-10 VLN-022 Published forms go-live record asserts a claim VLN-011 disproves

Governance / tracking gaps — G-GOV-

New series. GAP- was not used: GAP-1 already denotes the forms renderer fix in the T1 workstream and reusing the prefix would collide. No GOV- identifier existed anywhere under docs/ before this date (checked 2026-08-13, zero matches).

Provisional Real Title
G-1 GOV-001 Two artifacts each claim single-source-of-truth
G-2 GOV-002 validate_portal_presence() checks two portals against a standard of three
G-3 GOV-003 cloud-services-render sentinel satisfies presence unconditionally, no expiry
G-4 GOV-004 No declared-vs-actual reconciliation control; no GL5 liveness monitoring
G-5 GOV-005 ADC and gcloud CLI identities diverge; Terraform reads ADC
G-6 GOV-006 VLN-011 had a published page and nav entry but no tracker row
G-7 GOV-007 priorities/session-log.md stale since 2026-04-24
G-8 GOV-008 Pre-existing Done rows predate the status rule, un-re-adjudicated
G-9 GOV-009 Register changes cannot be verified as rendered

Program work items — P-PRG- and HB-

The P- series split into two. P-12P-15 were directed to attach to the host rows they block rather than to the program, so they carry a distinct HB- prefix and are not numbered in the PRG- sequence. P-16 therefore becomes PRG-012, not PRG-016 — the PRG- series is contiguous and the numbers do not line up with the provisional ones after P-11.

Program items

Provisional Real Title
P-1 PRG-001 Stage 1c — enumerate Meraki org 395909 and three Synology units
P-2 PRG-002 Stage 2 — diff enumerated.yaml vs inventory.yaml, then disposition
P-3 PRG-003 Document the previously unlisted Cloud Run services ⚠ scope corrected
P-4 PRG-004 Identify 2 undocumented Cloud SQL instances in gpusa
P-5 PRG-005 Scope 18 buckets in gpus-it against the retirement commitment
P-6 PRG-006 Unattached disks and 47 static IPs — billing impact
P-7 PRG-007 35 orphan DNS names + 18 orphan Puppet node definitions
P-8 PRG-008 phoenix into inventory.yaml and under a liveness check
P-9 PRG-009 desert, river, star — powered-off VMs on flower
P-10 PRG-010 water hosts zero VMs and is mis-documented as hosting ocean
P-11 PRG-011 ~111 workstation DHCP reservations against 15 active leases
P-16 PRG-012 Billing export — highest-value cost action, not yet pulled

P-3PRG-003 is not a clean rename. P-3 named four "previously unlisted" Cloud Run services including gpus-forms-clamav-worker. That service is listed in inventory.yaml, as cloud_services.gpus_forms_clamav_worker (confirmed 2026-08-13). PRG-003 covers three genuinely absent services — gpus-security-backend, gpus-soc-site, gpus-status-backend — and carries the discrepancy as a recorded correction. Anything citing "the 4 unlisted services" is citing a count that does not hold.

Host-level blockers

Provisional Real Blocks
P-12 HB-001 gannet
P-13 HB-002 emu / ostrich rebuild
P-14 HB-003 catbird delete
P-15 HB-004 phoebe disposition

None of these four is attached to an actual host row. gannet, emu, ostrich, catbird and phoebe have zero matches in inventory.yaml (checked 2026-08-13); only catbird and phoebe appear anywhere under docs/, as /32 allowlist entries at compliance/iar.md:381-382. Each HB- row names its host in blocks and is parked until PRG-002 creates the host rows. This is the one instruction from the 2026-08-13 register build that could not be carried out as written.


Cross-register references created

Relations recorded during the build. Only PRG-002 blocked_by PRG-001 was stated in the source list; the rest were derived and are labelled as such in the rows themselves so they can be rejected on review.

From Relation To Source
PRG-002 blocked_by PRG-001 stated
HB-001…HB-004 blocked_by (anchor) PRG-002 derived — PRG-002 creates the host rows
GOV-009 blocks GOV-006, GOV-007, VLN-022 derived from the status rule
PRG-008 blocked_by GOV-004 derived — no liveness control exists to place phoenix under
VLN-004 scope disputed by VLN-013 stated in S-1's acceptance test
VLN-009 scope expanded by VLN-015 stated in S-3
VLN-011 evidences VLN-022, GOV-008 stated in S-10 / G-8

Prior reassignment, same date

Not part of the S/G/P mapping, recorded here for completeness because it moved an existing published identifier:

Was Now Note
VLN-009 (chronyd / NTP, CVSS 2.6, remediated 2026-03-10) VLN-012 Reassigned 2026-08-13 to resolve a duplicate id. VLN-009 is retained by the passwordless-sudo finding. A dated redirect is kept in tracker.md so stale references resolve.

Change log

Version Date Author Change
v1.0 2026-08-13 R. Chhetry / Claude Initial mapping. 10 S-VLN-013VLN-022; 9 G-GOV-001GOV-009; 12 P-PRG-001PRG-012; 4 P-HB-001HB-004. Two discontinuities recorded: P-16PRG-012 (not PRG-016), and P-3PRG-003 with a corrected scope of 3 services rather than 4.

Addendum — 2026-08-17 load: B- / M- to real IDs

Source: priorities/backlog-2026-08-17.md v1.0 (commit 6f045bc), read from disk 2026-08-17. 38 backlog items and 10 method learnings.

The provisional B- and M- identifiers are retired on load. They exist in the backlog document and nowhere else. Note the B- series does not map onto one register — it is routed in three blocks, so B-15 is a governance row while B-14 is a security one.

Security findings — B-01B-14VLN-023VLN-036

Continues the tracker series from its then-maximum, VLN-022.

Prov. Real Severity (as stated) Title
B-01 VLN-023 CRITICAL vmstorage degraded RAID 6, no spare — NFS datastore for every WDC VM
B-02 VLN-024 CRITICAL Plaintext vendor credentials in pushtab
B-03 VLN-025 HIGH puppetCrypt exists and pushtab bypasses it
B-04 VLN-026 HIGH vmstorage has no backup or replication task
B-05 VLN-027 HIGH Meraki IPsec PSKs returned in plaintext
B-06 VLN-028 HIGH SMBv1 with signing off on all three Synology units
B-07 VLN-029 HIGH Key material in a control repo scheduled for deletion
B-08 VLN-030 MEDIUM Undocumented second VPN peer Target, IKEv1
B-09 VLN-031 MEDIUM Zero 2FA across all three Synology units
B-10 VLN-032 MEDIUM Meraki org 395909 has no SSO and no IdP
B-11 VLN-033 MEDIUM synstorage volumes at 93.1% / 82.3%, status attention
B-12 VLN-034 MEDIUM rooster cannot compile in production
B-13 VLN-035 MEDIUM dataflow.us.gl3 resolves to a host that does not exist
B-14 VLN-036 LOW wdc-wap-5 status alerting

Governance / tracking gaps — B-15B-24GOV-010GOV-019

Prov. Real Title
B-15 GOV-010 inventory.yaml covers ~a fifth of the estate — 82 vs 481 ⚠ also rewrites GOV-001
B-16 GOV-011 PuppetDB enforcement gap — DERIVED is not enforced
B-17 GOV-012 Five nodes applying against a dead Puppet master
B-18 GOV-013 Control repo does not reproduce the running configuration
B-19 GOV-014 Three repos on deprecated CSR, one unassessed at 39 GB
B-20 GOV-015 Twelve power devices never enumerated
B-21 GOV-016 Hostname is not a reliable join key ⚠ also attached to GOV-004
B-22 GOV-017 Property disagreements between inventory.yaml and live state ⚠ justifies the VLN-013 widening
B-23 GOV-018 Orphan count superseded twice — record 50
B-24 GOV-019 Snapshot configuration unknown on all three Synology units

B-15 produced two entries, deliberately. It rewrote GOV-001 and was filed as GOV-010 in this load's batch. They are not merged: GOV-001 is the identifier already cited elsewhere and keeps its history plus its superseded 2026-08-13 wording; GOV-010 is the 2026-08-17 batch entry. Treat GOV-001 as canonical.

Program work items — B-25B-38PRG-013PRG-026

Prov. Real Title
B-25 PRG-013 Consolidate fire and flower onto water
B-26 PRG-014 WS2025 golden image family is a dependency, not a future item
B-27 PRG-015 magpie contradiction ⚠ owner: R. Chhetry and Rob MacMillan**
B-28 PRG-016 Seven unmanaged gpus-it hosts unexplained
B-29 PRG-017 Two undocumented Meraki networks plus three unassigned APs
B-30 PRG-018 Meraki WDC edge is an MX95 HA pair; registry says MX100
B-31 PRG-019 Vendor transfer stack — DECOMMISSION ⚠ a decision, not a verification
B-32 PRG-020 24 of 25 gpusa VMs moved UNKNOWN → DERIVED
B-33 PRG-021 The estate spans two GCP projects for Puppet purposes
B-34 PRG-022 gpusa UNKNOWN count is 154, not 146
B-35 PRG-023 gpus-dist staleness profile — 95% over three years old
B-36 PRG-024 duck IP contradiction from a second source ⚠ corroborates VLN-019
B-37 PRG-025 Enumeration surfaces missing from Stage 1
B-38 PRG-026 Seven entities declared with no identifying data

Unlike the 2026-08-13 load, this block is a clean contiguous shift: B-25 + (−12) = PRG-013 throughout. No HB- rows were created; HB-001HB-004 remain the only host-level blockers.

Method learnings — M-01M-10no IDs

Loaded into a new ## Method learnings section of governance/gap-register.md, unnumbered, status-less and unowned, per routing. They keep their M- labels as section headings only — those are not register identifiers and carry no acceptance test, no owner and no date_verified, because there is nothing in them to close. They are constraints on future controls.

Label Constraint
M-01 LOADED ≠ REACHABLE
M-02 Permission-denied is not unreachability
M-03 Exit codes carry no information for gcloud list verbs
M-04 --quiet required on read-only gcloud calls, forbidden on mutating ones
M-05 API_DISABLED is not an IAM denial
M-06 Recorded absence, never silent absence
M-07 Confidence and enforcement are different axes
M-08 Counts supplied from memory are provisional
M-09 Enumerate fully before classifying
M-10 UNKNOWN must be the default and must survive to the end

Cross-register relations recorded in this load

Only three were stated in the source; the rest are derived and are labelled as derived in the rows themselves so they can be rejected on review.

From Relation To Source
VLN-026 blocked_by GOV-019 derived — snapshot config unknown blocks severity assessment
VLN-023 related_to VLN-026 derived — no replication compounds the degraded array
VLN-024 related_to VLN-025 derived — puppetCrypt exists and pushtab bypasses it
GOV-011 gates PRG-020 derived — DERIVED is not enforced
VLN-035 evidences PRG-019 stated in B-13
PRG-024 corroborates VLN-019 stated in B-36
GOV-017 justifies the VLN-013 widening stated in B-22
GOV-016 attached to GOV-004 as a design constraint stated in B-21

Change log

Version Date Author Change
v1.1 2026-08-17 R. Chhetry / Claude Addendum for the 2026-08-17 load: B-01B-38VLN-023VLN-036, GOV-010GOV-019, PRG-013PRG-026; M-01M-10 loaded unnumbered. Records that B-15 produced both a GOV-001 rewrite and GOV-010, and that eight cross-register relations were recorded, five of them derived.
v1.0 2026-08-13 R. Chhetry / Claude Initial mapping. 10 S-VLN-013VLN-022; 9 G-GOV-001GOV-009; 12 P-PRG-001PRG-012; 4 P-HB-001HB-004.