# support_keyset_golden.txt -- VD-E3-28: per-source TOP-LEVEL
# key sets of the console/FULL support bundle, regenerated ON
# THE LAB by run_phase10_e3_s3_smoke.py --keyset-regen and
# diffed by --keyset. One row per archive member:
#   <entry-name> <comma-joined sorted top-level keys>
# Key sets are asserted only for entries whose MANIFEST row is
# ok on the asserting run; wireguard/ fan-out entries are
# exempt by prefix (lab-state-shaped). A legitimate widening
# is a one-row diff here, reviewed like any golden.
alerts/alerts.json channels,drift,enabled,rules,version
alerts/remotelog.json ca_bundle,client_cert,client_key,drift,enabled,facilities,host,port,proto,targets_public,version
collection.json arm,boot_anchor_note,bundle_format_version,collected_at,core_dumps,identity_source,os_version,product_version,uptime_sec,wireguard_enumerated_from
control/config_integrity.json integrity
control/restore_status.json restore_status
control/revisions.json revisions
control/schema_state.json schema_state
control/supervision.json supervision
dhcp/dhcp.json adopted,drift,enabled,rendered,rendered_truncated,reservations,running,subnets
dns/dns.json access_control,adopted,block,dnssec,drift,enabled,expanded_forwarders,extra,fallback_recursion,forward_first,health,listen,local_zones,options,rendered,rendered_truncated,router_uses_self,running,tls,upstream_mode,upstreams,zones
ipsec/ipsec.json backend,drift,enabled,ikev1_enabled_count,manual_enabled_count,pf_suggestion,pki,policy_count,preview,preview_truncated,rc_enabled,running
logs/alertd.json bytes,data,source,total,truncated
logs/arpd.json bytes,data,source,total,truncated
logs/authd.json bytes,data,source,total,truncated
logs/authlog.json bytes,data,source,total,truncated
logs/dhcpd.json bytes,data,source,total,truncated
logs/diagd.json bytes,data,source,total,truncated
logs/dnsd.json bytes,data,source,total,truncated
logs/healthd.json bytes,data,source,total,truncated
logs/ipsecd.json bytes,data,source,total,truncated
logs/logd.json bytes,data,source,total,truncated
logs/netd.json bytes,data,source,total,truncated
logs/pfd.json bytes,data,source,total,truncated
logs/routed.json bytes,data,source,total,truncated
logs/rtd.json bytes,data,source,total,truncated
logs/sysd.json bytes,data,source,total,truncated
logs/timed.json bytes,data,source,total,truncated
net/arp.json arp,drift
net/gateways.json gateways
net/interfaces.json drift,interfaces,page
net/ndp.json ndp
net/routes.json configured,count_capped,counts,drift,live,live_total
pf/pf.json bruteforce_ban_table,bruteforce_ban_ttl_s,bruteforce_enabled,bruteforce_have,bruteforce_threshold,bruteforce_window_s,drift,enabled,live_enabled,mgmt_covers_peer,mgmt_iface,mgmt_net,mgmt_sources,pf_unadopted,rc_enabled,rules,structured
routing/bgp.json adopted,bgp
routing/ospf.json adopted,areas,config_drift,enabled,enabled_drift,fib_priority,fib_update,has_rdomain,rdomain,redistribute,rendered,rendered_truncated,rfc1583compat,router_id,rtlabel_tags,running,spf_delay,spf_holdtime,stub_router
routing/routing.json adopted,areas,bgp,drift,enabled,fib_priority,fib_update,has_rdomain,rdomain,redistribute,rendered,rendered_truncated,rfc1583compat,router_id,rtlabel_tags,running,spf_delay,spf_holdtime,stub_router
system/cert.json cert,drift
system/dmesg_boot.json dmesg_boot
system/health.json health
system/host_facts.json host_facts
system/identity.json drift,identity
system/time.json drift,enabled,log_timestamp_mode,ntp,rendered,rendered_truncated,server_mode,status,timezone
