Register ID Mapping — provisional to real, 2026-08-13¶
Classification: CONFIDENTIAL — Internal Use Only Document:
governance/register-id-mapping-2026-08-13.md· v1.1 · 2026-08-17 · GPUS-IT
Purpose¶
The three GPUS-IT registers were opened on 2026-08-13 from a candidate list that
used provisional identifiers S-1–S-10, G-1–G-9 and P-1–P-16. This
document records what each provisional identifier became, so any note, message
or draft still using the provisional form resolves.
The provisional identifiers are retired. They were never published and
should not be used again; P-3 in particular must not be confused with
PRG-003, whose scope was corrected (see below).
| Register | ID prefix | Document |
|---|---|---|
| Security findings | VLN- |
security/vuln/tracker.md |
| Governance / tracking gaps | GOV- |
governance/gap-register.md |
| Program work items | PRG- |
priorities/gpus-it-priorities.md |
| Host-level blockers | HB- |
same document, separate series |
Security findings — S- → VLN-¶
Continues the existing tracker series, which ran to VLN-012 after the
chronyd reassignment. No existing id was reused.
| Provisional | Real | Title |
|---|---|---|
| S-1 | VLN-013 | ESXi 6.7 EOL on fire and flower — VLN-004 misattributes it to water |
| S-2 | VLN-014 | rain serves a stale DNSSEC signing; RRSIGs expire 2026-08-28 |
| S-3 | VLN-015 | NOPASSWD sudo on emu and ostrich — VLN-009 scope beyond WDC |
| S-4 | VLN-016 | Three identity strings for one person, with inverted access |
| S-5 | VLN-017 | gcloud list verbs exit 0 on permission denial |
| S-6 | VLN-018 | All 10 Cloud Run services in gpus-infra are ingress: all |
| S-7 | VLN-019 | duck.cloud.us.gl3 resolves to an address that is not duck's |
| S-8 | VLN-020 | Five Puppet node definitions can never match a certname |
| S-9 | VLN-021 | 3 of 4 Meraki org admins hold orgAccess: full |
| S-10 | VLN-022 | Published forms go-live record asserts a claim VLN-011 disproves |
Governance / tracking gaps — G- → GOV-¶
New series. GAP- was not used: GAP-1 already denotes the forms renderer
fix in the T1 workstream and reusing the prefix would collide. No GOV-
identifier existed anywhere under docs/ before this date (checked 2026-08-13,
zero matches).
| Provisional | Real | Title |
|---|---|---|
| G-1 | GOV-001 | Two artifacts each claim single-source-of-truth |
| G-2 | GOV-002 | validate_portal_presence() checks two portals against a standard of three |
| G-3 | GOV-003 | cloud-services-render sentinel satisfies presence unconditionally, no expiry |
| G-4 | GOV-004 | No declared-vs-actual reconciliation control; no GL5 liveness monitoring |
| G-5 | GOV-005 | ADC and gcloud CLI identities diverge; Terraform reads ADC |
| G-6 | GOV-006 | VLN-011 had a published page and nav entry but no tracker row |
| G-7 | GOV-007 | priorities/session-log.md stale since 2026-04-24 |
| G-8 | GOV-008 | Pre-existing Done rows predate the status rule, un-re-adjudicated |
| G-9 | GOV-009 | Register changes cannot be verified as rendered |
Program work items — P- → PRG- and HB-¶
The P- series split into two. P-12–P-15 were directed to attach to the
host rows they block rather than to the program, so they carry a distinct HB-
prefix and are not numbered in the PRG- sequence. P-16 therefore becomes
PRG-012, not PRG-016 — the PRG- series is contiguous and the numbers do
not line up with the provisional ones after P-11.
Program items¶
| Provisional | Real | Title |
|---|---|---|
| P-1 | PRG-001 | Stage 1c — enumerate Meraki org 395909 and three Synology units |
| P-2 | PRG-002 | Stage 2 — diff enumerated.yaml vs inventory.yaml, then disposition |
| P-3 | PRG-003 | Document the previously unlisted Cloud Run services ⚠ scope corrected |
| P-4 | PRG-004 | Identify 2 undocumented Cloud SQL instances in gpusa |
| P-5 | PRG-005 | Scope 18 buckets in gpus-it against the retirement commitment |
| P-6 | PRG-006 | Unattached disks and 47 static IPs — billing impact |
| P-7 | PRG-007 | 35 orphan DNS names + 18 orphan Puppet node definitions |
| P-8 | PRG-008 | phoenix into inventory.yaml and under a liveness check |
| P-9 | PRG-009 | desert, river, star — powered-off VMs on flower |
| P-10 | PRG-010 | water hosts zero VMs and is mis-documented as hosting ocean |
| P-11 | PRG-011 | ~111 workstation DHCP reservations against 15 active leases |
| P-16 | PRG-012 | Billing export — highest-value cost action, not yet pulled |
⚠
P-3→PRG-003is not a clean rename.P-3named four "previously unlisted" Cloud Run services includinggpus-forms-clamav-worker. That service is listed ininventory.yaml, ascloud_services.gpus_forms_clamav_worker(confirmed 2026-08-13).PRG-003covers three genuinely absent services —gpus-security-backend,gpus-soc-site,gpus-status-backend— and carries the discrepancy as a recorded correction. Anything citing "the 4 unlisted services" is citing a count that does not hold.
Host-level blockers¶
| Provisional | Real | Blocks |
|---|---|---|
| P-12 | HB-001 | gannet |
| P-13 | HB-002 | emu / ostrich rebuild |
| P-14 | HB-003 | catbird delete |
| P-15 | HB-004 | phoebe disposition |
⚠ None of these four is attached to an actual host row.
gannet,emu,ostrich,catbirdandphoebehave zero matches ininventory.yaml(checked 2026-08-13); onlycatbirdandphoebeappear anywhere underdocs/, as/32allowlist entries atcompliance/iar.md:381-382. EachHB-row names its host inblocksand is parked untilPRG-002creates the host rows. This is the one instruction from the 2026-08-13 register build that could not be carried out as written.
Cross-register references created¶
Relations recorded during the build. Only PRG-002 blocked_by PRG-001 was
stated in the source list; the rest were derived and are labelled as such in the
rows themselves so they can be rejected on review.
| From | Relation | To | Source |
|---|---|---|---|
| PRG-002 | blocked_by | PRG-001 | stated |
| HB-001…HB-004 | blocked_by (anchor) | PRG-002 | derived — PRG-002 creates the host rows |
| GOV-009 | blocks | GOV-006, GOV-007, VLN-022 | derived from the status rule |
| PRG-008 | blocked_by | GOV-004 | derived — no liveness control exists to place phoenix under |
| VLN-004 | scope disputed by | VLN-013 | stated in S-1's acceptance test |
| VLN-009 | scope expanded by | VLN-015 | stated in S-3 |
| VLN-011 | evidences | VLN-022, GOV-008 | stated in S-10 / G-8 |
Prior reassignment, same date¶
Not part of the S/G/P mapping, recorded here for completeness because it moved an existing published identifier:
| Was | Now | Note |
|---|---|---|
VLN-009 (chronyd / NTP, CVSS 2.6, remediated 2026-03-10) |
VLN-012 |
Reassigned 2026-08-13 to resolve a duplicate id. VLN-009 is retained by the passwordless-sudo finding. A dated redirect is kept in tracker.md so stale references resolve. |
Change log¶
| Version | Date | Author | Change |
|---|---|---|---|
| v1.0 | 2026-08-13 | R. Chhetry / Claude | Initial mapping. 10 S- → VLN-013–VLN-022; 9 G- → GOV-001–GOV-009; 12 P- → PRG-001–PRG-012; 4 P- → HB-001–HB-004. Two discontinuities recorded: P-16 → PRG-012 (not PRG-016), and P-3 → PRG-003 with a corrected scope of 3 services rather than 4. |
Addendum — 2026-08-17 load: B- / M- to real IDs¶
Source: priorities/backlog-2026-08-17.md v1.0 (commit 6f045bc), read from
disk 2026-08-17. 38 backlog items and 10 method learnings.
The provisional B- and M- identifiers are retired on load. They exist in
the backlog document and nowhere else. Note the B- series does not map
onto one register — it is routed in three blocks, so B-15 is a governance row
while B-14 is a security one.
Security findings — B-01 – B-14 → VLN-023 – VLN-036¶
Continues the tracker series from its then-maximum, VLN-022.
| Prov. | Real | Severity (as stated) | Title |
|---|---|---|---|
| B-01 | VLN-023 | CRITICAL | vmstorage degraded RAID 6, no spare — NFS datastore for every WDC VM |
| B-02 | VLN-024 | CRITICAL | Plaintext vendor credentials in pushtab |
| B-03 | VLN-025 | HIGH | puppetCrypt exists and pushtab bypasses it |
| B-04 | VLN-026 | HIGH | vmstorage has no backup or replication task |
| B-05 | VLN-027 | HIGH | Meraki IPsec PSKs returned in plaintext |
| B-06 | VLN-028 | HIGH | SMBv1 with signing off on all three Synology units |
| B-07 | VLN-029 | HIGH | Key material in a control repo scheduled for deletion |
| B-08 | VLN-030 | MEDIUM | Undocumented second VPN peer Target, IKEv1 |
| B-09 | VLN-031 | MEDIUM | Zero 2FA across all three Synology units |
| B-10 | VLN-032 | MEDIUM | Meraki org 395909 has no SSO and no IdP |
| B-11 | VLN-033 | MEDIUM | synstorage volumes at 93.1% / 82.3%, status attention |
| B-12 | VLN-034 | MEDIUM | rooster cannot compile in production |
| B-13 | VLN-035 | MEDIUM | dataflow.us.gl3 resolves to a host that does not exist |
| B-14 | VLN-036 | LOW | wdc-wap-5 status alerting |
Governance / tracking gaps — B-15 – B-24 → GOV-010 – GOV-019¶
| Prov. | Real | Title |
|---|---|---|
| B-15 | GOV-010 | inventory.yaml covers ~a fifth of the estate — 82 vs 481 ⚠ also rewrites GOV-001 |
| B-16 | GOV-011 | PuppetDB enforcement gap — DERIVED is not enforced |
| B-17 | GOV-012 | Five nodes applying against a dead Puppet master |
| B-18 | GOV-013 | Control repo does not reproduce the running configuration |
| B-19 | GOV-014 | Three repos on deprecated CSR, one unassessed at 39 GB |
| B-20 | GOV-015 | Twelve power devices never enumerated |
| B-21 | GOV-016 | Hostname is not a reliable join key ⚠ also attached to GOV-004 |
| B-22 | GOV-017 | Property disagreements between inventory.yaml and live state ⚠ justifies the VLN-013 widening |
| B-23 | GOV-018 | Orphan count superseded twice — record 50 |
| B-24 | GOV-019 | Snapshot configuration unknown on all three Synology units |
⚠
B-15produced two entries, deliberately. It rewroteGOV-001and was filed asGOV-010in this load's batch. They are not merged:GOV-001is the identifier already cited elsewhere and keeps its history plus its superseded 2026-08-13 wording;GOV-010is the 2026-08-17 batch entry. TreatGOV-001as canonical.
Program work items — B-25 – B-38 → PRG-013 – PRG-026¶
| Prov. | Real | Title |
|---|---|---|
| B-25 | PRG-013 | Consolidate fire and flower onto water |
| B-26 | PRG-014 | WS2025 golden image family is a dependency, not a future item |
| B-27 | PRG-015 | magpie contradiction ⚠ owner: R. Chhetry and Rob MacMillan** |
| B-28 | PRG-016 | Seven unmanaged gpus-it hosts unexplained |
| B-29 | PRG-017 | Two undocumented Meraki networks plus three unassigned APs |
| B-30 | PRG-018 | Meraki WDC edge is an MX95 HA pair; registry says MX100 |
| B-31 | PRG-019 | Vendor transfer stack — DECOMMISSION ⚠ a decision, not a verification |
| B-32 | PRG-020 | 24 of 25 gpusa VMs moved UNKNOWN → DERIVED |
| B-33 | PRG-021 | The estate spans two GCP projects for Puppet purposes |
| B-34 | PRG-022 | gpusa UNKNOWN count is 154, not 146 |
| B-35 | PRG-023 | gpus-dist staleness profile — 95% over three years old |
| B-36 | PRG-024 | duck IP contradiction from a second source ⚠ corroborates VLN-019 |
| B-37 | PRG-025 | Enumeration surfaces missing from Stage 1 |
| B-38 | PRG-026 | Seven entities declared with no identifying data |
Unlike the 2026-08-13 load, this block is a clean contiguous shift: B-25 +
(−12) = PRG-013 throughout. No HB- rows were created; HB-001–HB-004
remain the only host-level blockers.
Method learnings — M-01 – M-10 → no IDs¶
Loaded into a new ## Method learnings section of governance/gap-register.md,
unnumbered, status-less and unowned, per routing. They keep their M-
labels as section headings only — those are not register identifiers and
carry no acceptance test, no owner and no date_verified, because there is
nothing in them to close. They are constraints on future controls.
| Label | Constraint |
|---|---|
| M-01 | LOADED ≠ REACHABLE |
| M-02 | Permission-denied is not unreachability |
| M-03 | Exit codes carry no information for gcloud list verbs |
| M-04 | --quiet required on read-only gcloud calls, forbidden on mutating ones |
| M-05 | API_DISABLED is not an IAM denial |
| M-06 | Recorded absence, never silent absence |
| M-07 | Confidence and enforcement are different axes |
| M-08 | Counts supplied from memory are provisional |
| M-09 | Enumerate fully before classifying |
| M-10 | UNKNOWN must be the default and must survive to the end |
Cross-register relations recorded in this load¶
Only three were stated in the source; the rest are derived and are labelled as derived in the rows themselves so they can be rejected on review.
| From | Relation | To | Source |
|---|---|---|---|
| VLN-026 | blocked_by | GOV-019 | derived — snapshot config unknown blocks severity assessment |
| VLN-023 | related_to | VLN-026 | derived — no replication compounds the degraded array |
| VLN-024 | related_to | VLN-025 | derived — puppetCrypt exists and pushtab bypasses it |
| GOV-011 | gates | PRG-020 | derived — DERIVED is not enforced |
| VLN-035 | evidences | PRG-019 | stated in B-13 |
| PRG-024 | corroborates | VLN-019 | stated in B-36 |
| GOV-017 | justifies | the VLN-013 widening |
stated in B-22 |
| GOV-016 | attached to | GOV-004 as a design constraint | stated in B-21 |
Change log¶
| Version | Date | Author | Change |
|---|---|---|---|
| v1.1 | 2026-08-17 | R. Chhetry / Claude | Addendum for the 2026-08-17 load: B-01–B-38 → VLN-023–VLN-036, GOV-010–GOV-019, PRG-013–PRG-026; M-01–M-10 loaded unnumbered. Records that B-15 produced both a GOV-001 rewrite and GOV-010, and that eight cross-register relations were recorded, five of them derived. |
| v1.0 | 2026-08-13 | R. Chhetry / Claude | Initial mapping. 10 S- → VLN-013–VLN-022; 9 G- → GOV-001–GOV-009; 12 P- → PRG-001–PRG-012; 4 P- → HB-001–HB-004. |