{
  "phase": "L6-runner-pivot-feasibility",
  "date": "2026-08-17",
  "operator_go": "C -> 2 (2026-08-17, runner pivot assessment -> connectivity probe)",
  "gitlab_access": "truonglt/1qaz@123 OAuth Bearer VALID, is_admin=True, id=4 (revalidated 2026-08-17). .token glpat EXPIRED (401).",
  "runners": "0 instance / 0 group (poms/parking/merchantx) - clean, would need to create+register own",
  "internal_targets": {
    "172.31.2.15": "mail/parking/poms DB (67 refs in L2/L4) - PRIMARY vdss internal hub",
    "10.215.102.41": "secondary internal (7 refs)",
    "10.1.27.43": "keycloak ms-core (1 ref)"
  },
  "connectivity_probe": {
    "method": "PowerShell TCP connect (Test-NetConnection + raw TcpClient 3s timeout) via COPY FROM PROGRAM",
    "from_14.225.11.57": {"172.31.2.15:5432": false, "172.31.2.15:3306": false, "10.215.102.41:5432": false},
    "from_14.225.11.8": {"172.31.2.15:5432": false, "172.31.2.15:3306": false, "10.215.102.41": false},
    "verdict": "NO ROUTE from CGIS network (14.225.11.0/24) to vdss internal DB network"
  },
  "conclusion": {
    "runner_pivot": "INFEASIBLE for vdss core. GitLab CI runner executes jobs on the host where registered. Our only runner-hosts (PG .57/.8) sit in CGIS network with NO route to 172.31.2.15/10.215.102.41. Registering a runner there yields a runner that cannot reach the internal targets.",
    "only_path_to_internal": "a runner-host INSIDE the vdss internal network (172.31.x) - we have no such host/access",
    "external_allowlist_targets": "14.225.5.225 cms_vdss_live + 211.188.52.92 chondb remain allowlist-filtered; runner pivot does not help (same egress problem in reverse)"
  },
  "confidence": "CONFIRMED (direct TCP probe from both PG hosts)",
  "sysmod": "none - read-only TCP connect probes",
  "artifacts": "L6_connectivity_probe.txt, this file"
}
