Files
management/analysis/data/claims_verification.tsv
T
Thore Cimbal e68b295249 analysis: complete the systematic claim verification; add F-017 and ADR-0010 draft
verify_claims.py gives all 813 claim rows a mechanical disposition;
the 28 flags were adjudicated by hand (REPORT.md appendix). Two survived
as genuine drift (F-017): a closed issue still described as open in
shared/lab-netzwerk.md, and a 'pending' decision block in hosts/cfgmon.md
whose premise the same file records as executed.

Also: narrow the vendored-path filter (it silently dropped 7 tracked
icon files and produced false path-miss flags), record the confirmed
canonical author identity in F-003, verify the Gitea#48->GitLab#46
numbering shift by title in F-005, and add the ADR-0010 draft under
analysis/drafts/ for the human to git-mv into decisions/.

Branch renamed to Neckbeard-v0.1.1-analyse-1 per the human.
2026-08-10 12:00:00 +00:00

124 KiB

1pathlinestatuschecksflagshintclaim_text
2.gitlab/issue_templates/Deploy-Übergabe.md14prose-or-runtimeBeispiel: axion1337.chat/threadnet-operating @ main, b6007c5 -->
3.gitlab/issue_templates/Deploy-Übergabe.md67prose-or-runtimehistorical-wordingDatensammlung und Zustellung getrennt scharf zu schalten ist fast immer
4.gitlab/issue_templates/Deploy-Übergabe.md75prose-or-runtime## Bewusst offen gelassen
5CLAUDE.md1prose-or-runtime# CLAUDE.md — übergreifende Arbeitskonventionen (kanonisch)
6CLAUDE.md4prose-or-runtimeGruppe (axion1337.chat-Stack, ThreadNet-Repos, CFGMON/threadnet-operating,
7CLAUDE.md10informationalruntime-path:https://rohana.axion1337.de/sorb/management> Push-Mirror unter `https://rohana.axion1337.de/sorb/management` von überall
8CLAUDE.md11prose-or-runtime> **lesbar** — dort diese Datei und die ADRs nachschlagen. Nur pushen ist tabu.
9CLAUDE.md18prose-or-runtime## Projektrealitäten (Stand 2026-08-01)
10CLAUDE.md20prose-or-runtime**Das Lab ist die Quelle der Wahrheit** ([ADR-0002](decisions/0002-issues-und-management-ins-lab.md)):
11CLAUDE.md22informationalruntime-path:git.lab/axion1337.chat/*- Kanonische Repos liegen auf `git.lab/axion1337.chat/*` (nur im Lab/VPN
12CLAUDE.md23prose-or-runtimeauflösbar). Gitea/rohana wird per **Push-Mirror** beliefert und bleibt
13CLAUDE.md24prose-or-runtimeFlux-Source, Container-/npm-Registry und Release-Download
14CLAUDE.md25prose-or-runtime([ADR-0001](decisions/0001-gitlab-kanonisch-push-mirror.md)).
15CLAUDE.md27prose-or-runtimeliegen die *Baupläne*, auf Gitea eine Kopie, die der Cluster **ohne verfügbares
16CLAUDE.md34prose-or-runtime- **Nie direkt zu Gitea pushen** (gespiegelte Repos) — der Mirror überschreibt
17CLAUDE.md36prose-or-runtime- **Gespiegelt wird nur die Gruppe `axion1337.chat`** (die fünf Produkt-Repos und
18CLAUDE.md37prose-or-runtime`management`). Die Gruppe **`homelab`** (`docs`, `wiki`, `wiki-bookstack`) hat
19CLAUDE.md43checked-okpath-ok:verfahren/aar/@management(dir)`verfahren/aar/` (dieses Repo ist gespiegelt), nicht nur in die READMEs der
20CLAUDE.md45prose-or-runtime- Landet doch ein Commit auf Gitea (z. B. aus einer Host-Session ohne Lab-Route):
21CLAUDE.md48prose-or-runtimevon Gitea ziehen, `git am` (erhält Autorschaft), Push über git.lab.
22CLAUDE.md49prose-or-runtimehistorical-wording- **Issues leben auf git.lab.** Die alten Gitea-Issues sind geschlossen und
23CLAUDE.md52prose-or-runtimemeinen die Gitea-Nummer; verbindlich ist der Migrations-Fußtext im Issue.
24CLAUDE.md54prose-or-runtimeTURN-Rotations-CronJob schreibt weiter nach Gitea, weil er im Cluster läuft und
25CLAUDE.md56prose-or-runtime**Die Rotation nicht von Hand nachziehen und den PR nie auf Gitea mergen** —
26CLAUDE.md57prose-or-runtimedas erledigt seit 2026-08-02 der geplante CI-Job `canonize_rotation` im
27CLAUDE.md58prose-or-runtimegitops-Repo täglich von git.lab aus. Scheitert er, bleibt die Pipeline rot;
28CLAUDE.md62prose-or-runtimeDas gitops-Wiki liegt seit 2026-08-02 auf git.lab (*Wiki*-Reiter im Projekt);
29CLAUDE.md63checked-okpath-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir)⚠️ der `wiki`-**Branch** im gitops-Repo ist ein überholter Mai-Abzug von `docs/`
30CLAUDE.md65informationalforge-repo:homelab/wiki**axionwiki.lab** ([`homelab/wiki`](https://git.lab/homelab/wiki), Docusaurus) —
31CLAUDE.md72prose-or-runtime- **Alles Offene ist ein Issue** — host-/infra-Scope hier im management-Projekt
32CLAUDE.md73informationalimage-ref:host:;id-ok:CFGMON-01historical-wording(`host:`-Labels, alte IDs wie `CFGMON-01` bleiben im Titel), Projekt-Scope im
33CLAUDE.md74checked-okpath-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir)jeweiligen Projekt. Kein neues Backlog-Markdown anlegen; `hosts/`/`shared/`
34CLAUDE.md90prose-or-runtime- **Der Titel trägt keine Priorität.** Präfixe wie `[HIGH]`/`[MEDIUM]`/`[LOW]`
35CLAUDE.md92informationalid-ok:CFGMON-01historical-wordingAlte Kennungen wie `CFGMON-01` bleiben, die benennen den Gegenstand, nicht die
36CLAUDE.md94prose-or-runtime⚠️ Der Grund ist keine Ästhetik: Aus der Gitea-Migration trugen 34 Issues ein
37CLAUDE.md97prose-or-runtimeüber dieselbe Sache sind schlimmer als eine unvollständige. Bereinigt 2026-08-06.
38CLAUDE.md101prose-or-runtimeeinzahlt**. Ein Issue ohne Meilenstein taucht in keiner Roadmap-Ansicht auf und
39CLAUDE.md112informationalruntime-path:~/.config/gitlab-lab/token`~/.config/gitlab-lab/token`) oder maskierte CI-Variablen.
40CLAUDE.md116prose-or-runtime## Commit-Konventionen (seit 2026-08-07)
41CLAUDE.md136prose-or-runtimehistorical-wording📎 Die Umstellung der Alt-Historie am 2026-08-07 hat 251 Commits neue SHAs
42CLAUDE.md138checked-okpath-ok:shared/commit-zuordnung-2026-08-07.md@management[`shared/commit-zuordnung-2026-08-07.md`](shared/commit-zuordnung-2026-08-07.md)
43CLAUDE.md146prose-or-runtimeöffentlichen Gitea-Spiegel. Wer daraus wirklich keine Muster ableitbar haben
44CLAUDE.md151prose-or-runtime- **Aussagen mit Quelle:** Verifiziert (Messung/Konsole) klar von Vermutung
45README.md1prose-or-runtime# management
46README.md8prose-or-runtimehistorical-wording*(Bis 2026-08-01 hieß dieses Repo `Backlogs` und führte offene Punkte als
47README.md11prose-or-runtime## Repo-Topologie (seit 2026-08-01)
48README.md13informationalruntime-path:git.lab;forge-repo:axion1337.chat/management**Kanonisch lebt dieses Repo auf `git.lab`** (`axion1337.chat/management`, nur im
49README.md15prose-or-runtime[ADR-0002](decisions/0002-issues-und-management-ins-lab.md)).
50README.md16informationalruntime-path:rohana.axion1337.de/sorb/management`rohana.axion1337.de/sorb/management` ist ein **Push-Mirror**: git.lab
51README.md17prose-or-runtimeüberschreibt ihn bei jedem Push per Force. Deshalb **nie direkt zu Gitea
52README.md18prose-or-runtimepushen** — solche Commits gehen beim nächsten Mirror-Lauf verloren (Rettung:
53README.md19prose-or-runtime`.patch` von Gitea ziehen + `git am`, siehe
54README.md22prose-or-runtimehistorical-wording**Keine Ausnahmen mehr.** Die **Deploy-Übergabe-Issues** liefen bis 2026-08-02 auf
55README.md23informationalruntime-path:git.labdem Gitea-Tracker, weil Hosts außerhalb des Labs `git.lab` nicht erreichten. Mit dem
56README.md25prose-or-runtimeGrund entfallen — bei eingeschaltetem Tunnel erreicht CFGMON git.lab. Sie sind
57README.md26informationalid-ok:LABNET-03umgezogen (LABNET-03), der Gitea-Tracker ist leer, die Vorlage liegt als
58README.md33checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,management| [`CLAUDE.md`](CLAUDE.md) | **Kanonische Arbeitskonventionen für alle Agenten-Sessions** (Topologie, Framework, Secrets, Karpathy-Guidelines) |
59README.md34checked-okpath-ok:vision/@management(dir)| `vision/` | Eine Vision je Linie: Community (axion1337.chat), Tool (ThreadNet), Plattform (Homelab) |
60README.md35checked-okpath-ok:roadmap.md@managementhistorical-wording| `roadmap.md` | Linien, Meilenstein-Kandidaten, Kadenz — GitLab-Milestones halten den Stand |
61README.md36checked-okpath-ok:decisions/@management(dir)| `decisions/` | ADRs — Pflicht bei Architekturentscheidungen **und dauerhaften Ausnahmen** |
62README.md37checked-okpath-ok:verfahren/@management(dir)| `verfahren/` | Wie wir arbeiten: [Deploy-Übergabe/DoD](verfahren/deploy-uebergabe.md), [Refinement & Retro](verfahren/refinement.md), [AARs](verfahren/aar/), Werkzeuge |
63README.md38checked-okpath-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir)| `hosts/`, `shared/` | **Bestand + Historie** je Host/Thema — u. a. [Branding](shared/branding.md) (Marke, Paletten, wo welches Theme eingestellt ist); offene Punkte sind Issues |
64README.md43informationalforge-repo:homelab/wiki[`homelab/wiki`](https://git.lab/homelab/wiki)). **Geändert wird immer hier, nie dort.**
65README.md48informationalimage-ref:host:;id-ok:CFGMON-01historical-wording`host:`-Labels; die alten IDs wie `CFGMON-01` bleiben im Titel) bzw. in den
66README.md64informationalid-ok:CFGMON-01;id-ok:ZONE-01**IDs** (`CFGMON-01`, `ZONE-01`, …) werden **nie wiederverwendet**; sie leben in
67README.md72prose-or-runtime**Erledigtes und Verworfenes** bleibt sichtbar: Issues werden geschlossen (nicht
68README.md78prose-or-runtimeKonfiguration lebt in den Projekt-Repos (z. B. `threadnet-operating` für den
69decisions/0001-gitlab-kanonisch-push-mirror.md1prose-or-runtime# 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert
70decisions/0001-gitlab-kanonisch-push-mirror.md8prose-or-runtime3,7-GiB-Host) und Gitea Actions zeigte mehrere echte Bugs. Das Homelab-GitLab
71decisions/0001-gitlab-kanonisch-push-mirror.md14informationalruntime-path:git.lab/axion1337.chat/*`git.lab/axion1337.chat/*` ist die kanonische Heimat aller Repos; Gitea/rohana
72decisions/0001-gitlab-kanonisch-push-mirror.md15prose-or-runtimewird über Push-Mirrors beliefert und bleibt Flux-Source, Container-Registry,
73decisions/0001-gitlab-kanonisch-push-mirror.md16prose-or-runtimenpm-Registry und Release-Download. **Direkte Pushes zu Gitea sind für gespiegelte
74decisions/0001-gitlab-kanonisch-push-mirror.md17prose-or-runtimeRepos verboten** — der Mirror überschreibt divergenten Stand per Force.
75decisions/0001-gitlab-kanonisch-push-mirror.md22prose-or-runtime- Commits, die doch auf Gitea landen (z. B. Cluster-CronJobs ohne Lab-Route),
76decisions/0001-gitlab-kanonisch-push-mirror.md23checked-okpath-ok:verfahren/deploy-uebergabe.md@managementbrauchen das Kanonisierungs-Verfahren (`verfahren/deploy-uebergabe.md`):
77decisions/0001-gitlab-kanonisch-push-mirror.md24prose-or-runtime`.patch` ziehen, `git am`, Push über git.lab. Zweimal live gebraucht.
78decisions/0001-gitlab-kanonisch-push-mirror.md29informationalid-no-issue:CFGMON-10- CFGMON-CI aufrüsten (Swap/Limits): strukturell zu klein, verworfen mit CFGMON-10.
79decisions/0002-issues-und-management-ins-lab.md8prose-or-runtimeweiter auf Gitea — zwei Wahrheiten, driftgefährdet. Erreichbarkeits-Blocker
80decisions/0002-issues-und-management-ins-lab.md9informationalid-ok:LABNET-01LABNET-01 (WireGuard-Roadwarrior) wurde am 2026-08-01 gelöst.
81decisions/0002-issues-und-management-ins-lab.md13prose-or-runtimeAlle Projekt-Issues leben auf git.lab (62 migriert, Gitea-Issues geschlossen mit
82decisions/0002-issues-und-management-ins-lab.md14informationalforge-repo:axion1337.chat/managementVerweis); das Backlogs-Repo zieht als `axion1337.chat/management` ins Lab
83decisions/0002-issues-und-management-ins-lab.md15informationalforge-repo:sorb/management(Push-Mirror → `sorb/management` auf Gitea). Das Lab ist die Quelle der Wahrheit.
84decisions/0002-issues-und-management-ins-lab.md19prose-or-runtime- ⚠️ gitops-Issue-Nummern haben sich verschoben (Gitea zählte PRs mit); die
85decisions/0002-issues-und-management-ins-lab.md21prose-or-runtime- ~~**Befristete Ausnahme:** Deploy-Übergabe-Issues laufen auf dem Gitea-Tracker
86decisions/0002-issues-und-management-ins-lab.md22informationalforge-repo:sorb/managementvon `sorb/management`, weil CFGMON git.lab (noch) nicht erreicht.~~
87decisions/0002-issues-und-management-ins-lab.md23checked-okissue-ok:management#13(closed);id-ok:LABNET-03✅ **Zurückgebaut am 2026-08-02** (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)):
88decisions/0002-issues-und-management-ins-lab.md25checked-okissue-ok:management#25(opened)sind nach git.lab gewandert ([#25](https://git.lab/axion1337.chat/management/-/issues/25),
89decisions/0002-issues-und-management-ins-lab.md26checked-okissue-ok:management#26(closed)[#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist
90decisions/0002-issues-und-management-ins-lab.md27checked-okpath-ok:.gitlab/issue_templates/@management(dir)leer, die Vorlage liegt als `.gitlab/issue_templates/`. **Damit gilt diese ADR
91decisions/0002-issues-und-management-ins-lab.md29checked-okpath-ok:README.md@ThreadNet-Web,axion1337.chat-gitops,managementhistorical-wordingAusnahmen (siehe `README.md`) — dass sie befristet war und die Frist gehalten hat,
92decisions/0002-issues-und-management-ins-lab.md31prose-or-runtime- Releases bleiben auf Gitea (öffentlicher Download-Pfad), ebenso das gitops-Wiki.
93decisions/0002-issues-und-management-ins-lab.md35prose-or-runtime- Issues auf Gitea belassen: dauerhafte Doppelführung, Roadmap/Boards unmöglich.
94decisions/0003-cve-meldeweg-aggregiert.md8checked-okpath-ok:verfahren/aar/@management(dir);issue-ok:axion1337.chat-gitops#51(opened)Nachrichten und musste stummgeschaltet werden (gitops#51, AAR in `verfahren/aar/`).
95decisions/0003-cve-meldeweg-aggregiert.md9informationalid-no-issue:CFGMON-13historical-wordingGleichzeitig war entschieden (CFGMON-13), Release-/Security-Meldungen von
96decisions/0004-site-to-site-vpn-hetzner-lab.md3checked-okissue-ok:management#12(closed);issue-ok:management#12(closed)**Status:** akzeptiert (umgesetzt und abgenommen 2026-08-01, Testreihe 1–7 in [management#12](https://git.lab/axion1337.chat/management/-/issues/12)) · **Datum:** 2026-08-01 · **Entscheider:** sorb
97decisions/0004-site-to-site-vpn-hetzner-lab.md14informationalnet-ref:10.0.0.0/24;net-ref:10.58.73.0/24historical-wordingHetzner-Projektnetz `10.0.0.0/24` mit dem Lab-VLAN `10.58.73.0/24`. Der An/Aus-Schalter
98decisions/0004-site-to-site-vpn-hetzner-lab.md29informationalruntime-path:~lab;net-ref:10.58.73.1| **CFGMON** | WG-**Client/Initiator**, dauerhaft aktiv (`enable`) + `PersistentKeepalive 25`; AllowedIPs nur `10.58.73.0/24, 10.58.75.1/32`; Split-DNS nur `~lab` → `10.58.73.1`; `ip_forward` + iptabl
99decisions/0004-site-to-site-vpn-hetzner-lab.md30informationalnet-ref:192.168.178.20| **Fritzbox** | Portfreigabe UDP **51841** → `192.168.178.20` |
100decisions/0004-site-to-site-vpn-hetzner-lab.md31informationalnet-ref:10.0.0.0/8| **Hetzner** | Netz-Range auf **`10.0.0.0/8`** erweitert, Route `10.58.73.0/24 → 10.0.0.3` — damit erreichen alle Server im Netz das Lab **ohne eigene Konfiguration** |
101decisions/0004-site-to-site-vpn-hetzner-lab.md32informationalnet-ref:10.58.75.0/24;net-ref:10.0.0.0/24;image-ref:10.58.73.17:443;image-ref:10.58.73.1:53| **UniFi-Firewall** | Trennung vom Roadwarrior über **Quell-/Ziel-IP** (`10.58.75.0/24` + `10.0.0.0/24`), nicht über eine eigene Zone: erlaubt sind nur `10.58.73.17:443` (git.lab/Registry) und `10.58
102decisions/0004-site-to-site-vpn-hetzner-lab.md36checked-okissue-ok:management#13(closed);id-ok:LABNET-03- ✅ **Eingelöst am 2026-08-02 (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)):**
103decisions/0004-site-to-site-vpn-hetzner-lab.md37prose-or-runtimeÜbergabe-Issues können nicht nur umziehen — sie sind umgezogen
104decisions/0004-site-to-site-vpn-hetzner-lab.md38checked-okissue-ok:management#25(opened)([#25](https://git.lab/axion1337.chat/management/-/issues/25),
105decisions/0004-site-to-site-vpn-hetzner-lab.md39checked-okissue-ok:management#26(closed)[#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist
106decisions/0004-site-to-site-vpn-hetzner-lab.md40prose-or-runtimeleer, die Vorlage liegt als GitLab-Issue-Template, und die Ausnahme aus ADR-0002 ist
107decisions/0004-site-to-site-vpn-hetzner-lab.md50prose-or-runtimeGitea-PR-Ausnahme bleibt bewusst bestehen.
108decisions/0004-site-to-site-vpn-hetzner-lab.md54prose-or-runtimehistorical-wordingJob läuft im Lab und erreicht Gitea öffentlich. Das war der eigentliche Grund für
109decisions/0004-site-to-site-vpn-hetzner-lab.md56informationalid-ok:GAME-01- game.axion1337.de profitiert erst nach Aufnahme in den vSwitch (GAME-01).
110decisions/0005-pm-framework-kanban.md1prose-or-runtime# 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen
111decisions/0005-pm-framework-kanban.md22checked-okpath-ok:vision/@management(dir)| Product Goal / Vision | `vision/` (eine Datei je Linie) |
112decisions/0005-pm-framework-kanban.md24checked-okpath-ok:verfahren/aar/@management(dir)| Review/Retro | AARs (`verfahren/aar/`) nach Deploys/Incidents |
113decisions/0005-pm-framework-kanban.md25checked-okpath-ok:verfahren/deploy-uebergabe.md@management| Definition of Done | Deploy-Übergabe-Verfahren (`verfahren/deploy-uebergabe.md`) |
114decisions/0005-pm-framework-kanban.md26checked-okpath-ok:roadmap.md@management| Roadmap/Meilensteine | Gruppen-Milestones + `roadmap.md` (CE: keine Epics/Roadmap-View) |
115decisions/0005-pm-framework-kanban.md27checked-okpath-ok:decisions/@management(dir)| Entscheidungen | ADRs in `decisions/` |
116decisions/0005-pm-framework-kanban.md32informationalforge-repo:axion1337.chat/management- Das Backlogs-Repo wird zum Management-Repo `axion1337.chat/management`;
117decisions/0005-pm-framework-kanban.md33checked-okpath-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir);image-ref:host:offene Punkte aus `hosts/`/`shared/` sind Issues mit `host:`-Labels,
118decisions/0006-wikis-konsolidieren-docusaurus.md9prose-or-runtimehistorical-wording1. **Gitea-Wiki-Repo** `…gitops.wiki.git` — 15 Seiten, gepflegt bis 2026-07-31.
119decisions/0006-wikis-konsolidieren-docusaurus.md10prose-or-runtimeVom Push-Mirror **nicht** erfasst: ein Wiki ist ein eigenes Repo, kein Branch.
120decisions/0006-wikis-konsolidieren-docusaurus.md11prose-or-runtime2. **`wiki`-Branch im gitops-Repo** — Stand 2026-05-14, mitgezogen, weil der Mirror
121decisions/0006-wikis-konsolidieren-docusaurus.md12checked-okpath-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir)historical-wordingalle Branches trägt. Inhalt: ein damaliger Abzug von `docs/`, kein gepflegtes Wiki.
122decisions/0006-wikis-konsolidieren-docusaurus.md13checked-okpath-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir)3. **`docs/` im main-Branch** — die eigentliche, laufend gepflegte Repo-Doku.
123decisions/0006-wikis-konsolidieren-docusaurus.md15prose-or-runtimehistorical-wordingDazu waren die GitLab-Wikis aller Projekte **leer**, und die Wiki-Inhalte enthielten
124decisions/0006-wikis-konsolidieren-docusaurus.md26informationalforge-repo:homelab/wiki[`homelab/wiki`](https://git.lab/homelab/wiki) baut mit Docusaurus eine Seite unter
125decisions/0006-wikis-konsolidieren-docusaurus.md28informationalforge-repo:homelab/docshistorical-wordingHomelab (`homelab/docs`), Arbeitsweise (`management`). Die Inhalte werden beim Bau
126decisions/0006-wikis-konsolidieren-docusaurus.md33FLAGpath-miss:content/path-miss:content/- **Änderungen gehören ins Quell-Repo**, nie ins Wiki-Repo — was dort in `content/`
127decisions/0006-wikis-konsolidieren-docusaurus.md43prose-or-runtime`.md` wird als CommonMark statt MDX geparst.
128decisions/0006-wikis-konsolidieren-docusaurus.md44prose-or-runtime- **Der `wiki`-Branch im gitops-Repo ist überholt.** Er bleibt vorerst als Historie
129decisions/0006-wikis-konsolidieren-docusaurus.md47checked-okissue-ok:management#19(opened)([Issue #19](https://git.lab/axion1337.chat/management/-/issues/19)).
130decisions/0006-wikis-konsolidieren-docusaurus.md51prose-or-runtime- **Alles in ein Repo verschmelzen:** Die Quellen haben unterschiedliche Leser und
131decisions/0006-wikis-konsolidieren-docusaurus.md53prose-or-runtime- **Wiki auf Gitea belassen:** widerspricht ADR-0002 und hielt eine Ausnahme am
132decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md3checked-okissue-ok:management#20(opened)**Status:** vorgeschlagen (Entscheidung offen → [Issue #20](https://git.lab/axion1337.chat/management/-/issues/20)) · **Datum:** 2026-08-02 · **Entscheider:** sorb
133decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md8informationalruntime-path:axionwiki.labDocusaurus als Lesefläche gebaut — läuft seit 2026-08-02 unter `axionwiki.lab`.
134decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md42prose-or-runtimeWahrheit neben git.lab — genau das, was [ADR-0002](0002-issues-und-management-ins-lab.md)
135decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md52informationalid-ok:CFGMON-09Datenbank ohne Sicherung ist eine Zeitbombe (vgl. CFGMON-09, wo genau das seit
136decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md53prose-or-runtime2026-07-30 offen ist).
137decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md54FLAGpath-miss:import/path-miss:import/- **Ein Einweg-Import zum Befüllen, aber keine Synchronisation** (`import/` im
138decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md56FLAGpath-miss:provision.pypath-miss:provision.pyvergleichen, deshalb legt `provision.py` dieselben drei Bereiche an wie das
139decisions/0008-agenten-sessions-root-aequivalent.md3checked-okissue-ok:management#17(closed)**Status:** akzeptiert · **Datum:** 2026-08-06 (Struktur-Workshop [#17](https://git.lab/axion1337.chat/management/-/issues/17)) · **Entscheider:** sorb
140decisions/0008-agenten-sessions-root-aequivalent.md9informationalid-ok:LABNET-02LABNET-02-Nacht lief deshalb über die **docker-Gruppenmitgliedschaft** des Kontos
141decisions/0008-agenten-sessions-root-aequivalent.md24checked-okissue-ok:management#14(opened)[#14](https://git.lab/axion1337.chat/management/-/issues/14).
142decisions/0008-agenten-sessions-root-aequivalent.md46informationalid-ok:LABNET-02ohne diese Entscheidung wäre LABNET-02 gar nicht durchführbar gewesen.
143decisions/0008-agenten-sessions-root-aequivalent.md55prose-or-runtimeKommt einer dazu, wird diese ADR abgelöst.
144decisions/0008-agenten-sessions-root-aequivalent.md57prose-or-runtime## Offen, bewusst nicht vor der Entscheidung geklärt
145decisions/0008-agenten-sessions-root-aequivalent.md66checked-okissue-ok:management#14(opened)historical-wordingnächsten Host-Session, festgehalten in #14.
146decisions/0008-agenten-sessions-root-aequivalent.md80checked-okpath-ok:hosts/cfgmon.md@managementund nicht bloß ein Absatz in `hosts/cfgmon.md`.
147decisions/0009-commit-konventionen-und-historien-anonymisierung.md5prose-or-runtime> Nachgetragen am 2026-08-09 in der [Retro](../verfahren/retro/2026-08-09.md). Die
148decisions/0009-commit-konventionen-und-historien-anonymisierung.md13prose-or-runtimeöffentlichem Gitea-Spiegel heißt das: Jeder, der die Repos liest, kann ablesen, an
149decisions/0009-commit-konventionen-und-historien-anonymisierung.md23prose-or-runtime**Regel ab 2026-08-07**, gültig für alle Repos der Gruppe `axion1337.chat` und die
150decisions/0009-commit-konventionen-und-historien-anonymisierung.md29prose-or-runtime**Rückwirkend angewandt am 2026-08-09** auf **251 Commits** — alles aus dieser
151decisions/0009-commit-konventionen-und-historien-anonymisierung.md34prose-or-runtime| gitops | 117 von 264 | ab 2026-07-27 |
152decisions/0009-commit-konventionen-und-historien-anonymisierung.md35prose-or-runtime| management | 78 von 78 | vollständig |
153decisions/0009-commit-konventionen-und-historien-anonymisierung.md36prose-or-runtime| ThreadNet-Web | 47 von 50 | ab 2026-07-28 |
154decisions/0009-commit-konventionen-und-historien-anonymisierung.md37prose-or-runtime| threadnet-call | 9 von 9 | vollständig |
155decisions/0009-commit-konventionen-und-historien-anonymisierung.md39prose-or-runtimeDabei wurden 17 Tags mit umgezogen und die Autoren-Identitäten vereinheitlicht —
156decisions/0009-commit-konventionen-und-historien-anonymisierung.md54checked-okpath-ok:shared/commit-zuordnung-2026-08-07.md@management[`shared/commit-zuordnung-2026-08-07.md`](../shared/commit-zuordnung-2026-08-07.md).
157decisions/0009-commit-konventionen-und-historien-anonymisierung.md61prose-or-runtimewieder aktiv.
158decisions/0009-commit-konventionen-und-historien-anonymisierung.md66prose-or-runtimeliegen im selben GitLab und teilweise auf dem öffentlichen Spiegel — und sind
159decisions/0009-commit-konventionen-und-historien-anonymisierung.md72prose-or-runtimeDas Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines
160decisions/0009-commit-konventionen-und-historien-anonymisierung.md74informationaltag-ok:v0.4.0`v0.4.0` aus altem Quellcode gegen heutige Basis-Images neu gebaut und
161decisions/0009-commit-konventionen-und-historien-anonymisierung.md77checked-okissue-ok:ThreadNet-Web#14(closed)ThreadNet-Web#14; die Sperre ist seit `3cb43f5` scharf.
162decisions/0009-commit-konventionen-und-historien-anonymisierung.md86prose-or-runtimeangefasst (`Scrublord@Mac.Bad`, 135 Commits aus der Zeit vor dieser
163decisions/README.md6prose-or-runtimeauf `abgelöst durch NNNN` gesetzt.
164decisions/template.md3prose-or-runtime**Status:** vorgeschlagen | akzeptiert | abgelöst durch NNNN · **Datum:** JJJJ-MM-TT · **Entscheider:** sorb
165hosts/cfgmon.md3prose-or-runtimeMonitoring-Stack, Gitea und der Reverse Proxy für alles Öffentliche.
166hosts/cfgmon.md8prose-or-runtime| **OS** | Ubuntu 24.04.4 LTS |
167hosts/cfgmon.md9informationalnet-ref:188.245.193.243| **IPv4** | `188.245.193.243` |
168hosts/cfgmon.md11informationalnet-ref:10.0.0.3;net-ref:10.0.0.2| **Privat** | `10.0.0.3` (`enp7s0`, Hetzner-Netz — dort liegt auch k3s auf `10.0.0.2`) |
169hosts/cfgmon.md12informationalruntime-path:rohana.axion1337.de| **DNS** | `rohana.axion1337.de` → Gitea, `selendis.axion1337.de` → Grafana |
170hosts/cfgmon.md19checked-okimage-ref:prom/prometheus:v3.3.1;forge-repo:sorb/threadnet-operating;path-ok:monitoring/@axion1337.chat-gitops(dir),threadnet-operating(dir)| prometheus | `prom/prometheus:v3.3.1` | `monitoring` | `sorb/threadnet-operating`, `monitoring/` |
171hosts/cfgmon.md20informationalimage-ref:grafana/loki:3.7.1| loki | `grafana/loki:3.7.1` | `monitoring` | dito |
172hosts/cfgmon.md21informationalimage-ref:grafana/grafana:12.0.0| grafana | `grafana/grafana:12.0.0` | `monitoring` | dito |
173hosts/cfgmon.md22informationalimage-ref:grafana/alloy:v1.16.0| alloy | `grafana/alloy:v1.16.0` | `monitoring` | dito |
174hosts/cfgmon.md23informationalimage-ref:prom/node-exporter:v1.9.1| node-exporter | `prom/node-exporter:v1.9.1` | `monitoring` | dito |
175hosts/cfgmon.md24informationalimage-ref:traefik:v3.7.9;forge-repo:sorb/thread-net-git;id-no-issue:CFGMON-02| traefik | `traefik:v3.7.9` | `thread-net-git` | `sorb/thread-net-git`, seit 2026-07-30 in `main` (siehe [CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07
176hosts/cfgmon.md25informationalimage-ref:gitea/gitea:1.27.0;image-ref::latesthistorical-wording| gitea | `gitea/gitea:1.27.0` | `thread-net-git` | dito, gepinnt (war `:latest`) |
177hosts/cfgmon.md26informationalruntime-path:gcr.io/cadvisor/cadvisor:v0.49.1;image-ref::latesthistorical-wording| cadvisor | `gcr.io/cadvisor/cadvisor:v0.49.1` | `thread-net-git` | dito, gepinnt (war `:latest`) |
178hosts/cfgmon.md27informationalimage-ref:gitea/act_runner:0.6.1;id-no-issue:CFGMON-02| runner | `gitea/act_runner:0.6.1` | `thread-net-git` | dito, Container `gitea-runner`, siehe CFGMON-02 |
179hosts/cfgmon.md28informationalimage-ref:portainer/agent:2.27.5| portainer_agent | `portainer/agent:2.27.5` | — | standalone, kein Compose |
180hosts/cfgmon.md32informationalimage-ref:10.0.0.2:9100(`10.0.0.2:9100`), `pterodactyl_host_node` und `gameserver_cadvisor`
181hosts/cfgmon.md33informationalnet-ref:157.90.155.206(beide `157.90.155.206`, siehe [game](game.md)).
182hosts/cfgmon.md38prose-or-runtimehistorical-wording[management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten.
183hosts/cfgmon.md41checked-okissue-ok:management#7(opened);id-ok:CFGMON-01- [CFGMON-01 — Zertifikatserneuerung braucht offene Ports (zeitkritisch ab 2026-09-28)](https://git.lab/axion1337.chat/management/-/issues/7)
184hosts/cfgmon.md42checked-okissue-ok:management#8(opened);id-ok:CFGMON-03- [CFGMON-03 — Prometheus-Remote-Write/Loki öffentlich ohne Auth (Weg A, nachgelagerte Prüfung)](https://git.lab/axion1337.chat/management/-/issues/8)
185hosts/cfgmon.md43checked-okissue-ok:management#9(opened);id-ok:CFGMON-04- [CFGMON-04 — Grafana-Admin-Credentials aus `.env` gelten nicht für die API](https://git.lab/axion1337.chat/management/-/issues/9)
186hosts/cfgmon.md44checked-okissue-ok:management#10(opened);id-ok:CFGMON-09- [CFGMON-09 — Gitea-Backups off-host (⚠️ Backup-Cron deaktiviert)](https://git.lab/axion1337.chat/management/-/issues/10)
187hosts/cfgmon.md46informationalid-no-issue:CFGMON-11## CFGMON-11 — Gitea-CI-Rückbau nach GitLab-Umzug
188hosts/cfgmon.md48prose-or-runtime**Status:** erledigt (2026-07-31 spätabends) — bis auf einen kosmetischen Handgriff:
189hosts/cfgmon.md49prose-or-runtimeauf CFGMON `cd /opt/thread-net-git && git checkout main && git pull` (Checkout parkt
190hosts/cfgmon.md52informationalruntime-path:/opt/threadnet-operating**Dazu neu (2026-08-01 ~05:00):** Auch `/opt/threadnet-operating` braucht einmal
191hosts/cfgmon.md53prose-or-runtime`git fetch && git reset --hard origin/main` — der State-Persistenz-Commit wurde
192hosts/cfgmon.md54prose-or-runtimedort direkt nach Gitea gepusht (dfe04c4a), vom Mirror überschrieben, vom Mac aus
193hosts/cfgmon.md55prose-or-runtimeper Patch gerettet und kanonisch als `6ffab68` neu aufgelegt (inhaltsgleich,
194hosts/cfgmon.md58prose-or-runtime**Erledigt (2026-08-01, autonom):**
195hosts/cfgmon.md59prose-or-runtime- Actions-Toggles deaktiviert: `ThreadNet-Web`, `threadnet-call`, `axion1337.chat-gitops`
196hosts/cfgmon.md60checked-okpath-ok:.github/workflows/@threadnet-call(dir)historical-wording- `ThreadNet-Web`: alle `.github/workflows/`-Dateien entfernt (Commit `a876758`)
197hosts/cfgmon.md61FLAGpath-miss:.gitea/workflows/path-miss:.gitea/workflows/historical-wording- gitops: Verifikations-Job nach GitLab portiert + `.gitea/workflows/` entfernt
198hosts/cfgmon.md62FLAGpath-miss:milestone-release.ymlpath-miss:milestone-release.yml(Commit `5e46a24`, Pipeline grün, Mirror→Gitea verifiziert; `milestone-release.yml`
199hosts/cfgmon.md63FLAGissue-miss:management#33issue-miss:management#33historical-wordingwar toter Code, siehe #33). Flux unberührt.
200hosts/cfgmon.md64checked-okpath-ok:.env.example@threadnet-call,threadnet-operatinghistorical-wording- `thread-net-git`: Runner-Service/Config/`.env.example` per Commit `d904734` entfernt
201hosts/cfgmon.md65prose-or-runtime(auf git.lab; Mirror trägt nach Gitea) — **noch nicht deployt**, siehe unten.
202hosts/cfgmon.md66informationalpackage-ref:@sorb/threadnet-call-embedded- Registry-Entscheidung npm final (Evidenz: `@sorb/threadnet-call-embedded` ist
203hosts/cfgmon.md67checked-okpath-ok:apps/web@ThreadNet-Web(dir)pnpm-Dependency von `apps/web`, Lockfile pinnt Tarball-URL auf rohana): **bleibt Gitea**.
204hosts/cfgmon.md70prose-or-runtime1. ~~`thread-net-git`-Stand deployen~~ **erledigt (2026-07-31 spätabends, via
205hosts/cfgmon.md71FLAGpath-miss:runner-data/path-miss:runner-data/historical-wordingCFGMON-Session)**: Runner-Container/Netz/`runner-data/`/`.env`-Zeile entfernt,
206hosts/cfgmon.md72prose-or-runtimehistorical-wording`builder-1` aus der Gitea-Admin-UI gelöscht, Actions-Registrierungstoken rotiert.
207hosts/cfgmon.md75checked-okissue-ok:thread-net-git#1(closed)Mac→git.lab→Mirror (`15c8f2d`), Hergang in thread-net-git#1 (geschlossen).
208hosts/cfgmon.md77prose-or-runtimehistorical-wordinggetippte Token (`a89bfb…`) war der Gitea-**Actions-Runner-Registrierungstoken**
209hosts/cfgmon.md82prose-or-runtime3. ~~Token-Rotation b~~ **erledigt (2026-07-31 abends)**: Generalschlüssel
210hosts/cfgmon.md87informationalruntime-path:~/.config/gitea-rohana/token`~/.config/gitea-rohana/token` auf dem Mac), `claude-push` (write:repository,
211hosts/cfgmon.md88informationalruntime-path:~/.config/gitea-rohana/push-token`~/.config/gitea-rohana/push-token`). Erster CI-Publish `0.19.2-threadnet.6`
212hosts/cfgmon.md89checked-okissue-ok:threadnet-call#1(closed)historical-wordingverifiziert → threadnet-call#1 geschlossen. Alle Klartext-Reste entfernt
213hosts/cfgmon.md94informationalruntime-path:git.lab/axion1337.chat(`git.lab/axion1337.chat`, Gruppe mit importierten Projekten angelegt; die Domain ist
214hosts/cfgmon.md97prose-or-runtimepausieren). Der am 2026-07-30 auf Gitea-Seite aufgebaute CI-Unterbau wird damit teilweise
215hosts/cfgmon.md102prose-or-runtime- **Actions-Toggle** `has_actions` bei `ThreadNet-Web` (am 2026-07-30 per API aktiviert)
216hosts/cfgmon.md103prose-or-runtimewieder deaktivieren, ebenso bei `threadnet-call` (stoppt die fehlschlagende
217hosts/cfgmon.md105checked-okpath-ok:.github/workflows/@threadnet-call(dir)- **`.github/workflows/` in `ThreadNet-Web`** (der kuratierte 6-Dateien-Satz) — wird durch
218hosts/cfgmon.md106checked-okpath-ok:.gitlab-ci.yml@ThreadNet-Web,axion1337.chat-gitops,management`.gitlab-ci.yml` ersetzt. Die Erkenntnisse aus den Läufen vom 2026-07-30 mitnehmen:
219hosts/cfgmon.md110prose-or-runtime- **Geerbte Upstream-Workflows in `threadnet-call`** (build/publish/test/translations/
220hosts/cfgmon.md113FLAGpath-miss:runner-data/.runnerpath-miss:runner-data/.runnerder Gitea-Admin-UI deregistrieren und `runner-data/.runner` auf dem Host entfernen.
221hosts/cfgmon.md114FLAGpath-miss:embedded/web/.npmrcpath-miss:embedded/web/.npmrc- **Token: npm-Token in `threadnet-call`s untracked `embedded/web/.npmrc`** (Klartext im
222hosts/cfgmon.md121prose-or-runtime- **Runner-Service in `thread-net-git` ganz entfernen?** Hängt daran, ob das gitops-Repo
223hosts/cfgmon.md122FLAGpath-miss:deploy-on-push.ymlpath-miss:deploy-on-push.ymlseinen leichten `deploy-on-push.yml` (YAML-Validierung/Notification, läuft sauber)
224hosts/cfgmon.md124FLAGpath-miss:runner/config.yamlpath-miss:runner/config.yamlRevert-Commit in `thread-net-git`: Compose-Service `runner`, `runner/config.yaml`,
225hosts/cfgmon.md125FLAGpath-ok:.env.example@threadnet-call,threadnet-operating;path-miss:runner-data/path-miss:runner-data/`.env.example` (RUNNER_TOKEN), Cache-Port-Bindung 8088, `runner-data/`.
226hosts/cfgmon.md126informationalpackage-ref:@sorb/threadnet-call-embedded- **Registry-Ziel für `@sorb/threadnet-call-embedded`**: bleibt die Gitea-npm-Registry
227hosts/cfgmon.md128prose-or-runtimeGitLab-Package-Registry (dann läuft die Gitea-Package-Seite leer).
228hosts/cfgmon.md129prose-or-runtime- **Container-Images bleiben in der rohana-Registry** (Flux/k8s pullt von dort — spricht
229hosts/cfgmon.md131prose-or-runtime**neuen** Deploy-/Push-Token für die rohana-Registry (Neuanlage, kein Rückbau).
230hosts/cfgmon.md135prose-or-runtimeGitea selbst, gitops-Repo als Flux-Source, Issues/Wiki/dieses Repo, der
231hosts/cfgmon.md136informationalid-ok:CFGMON-09API-Token für Issue-Verwaltung, das Gitea-Backup-Script (CFGMON-09).
232hosts/cfgmon.md139prose-or-runtimeumgezogen — [ADR-0002](../decisions/0002-issues-und-management-ins-lab.md) —,
233hosts/cfgmon.md140prose-or-runtimedas Repo dabei von `Backlogs` zu `management` umgewidmet
234hosts/cfgmon.md142prose-or-runtimeden damaligen Rückbau der Gitea-CI, nicht auf Dauer.)*
235hosts/cfgmon.md145checked-okissue-ok:ThreadNet-Web#2(closed)[ThreadNet-Web#2](https://rohana.axion1337.de/sorb/ThreadNet-Web/issues/2),
236hosts/cfgmon.md146checked-okissue-ok:threadnet-call#1(closed)[threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1).
237hosts/cfgmon.md148prose-or-runtime**Nächster Schritt:** die drei manuellen Schritte oben, dann → erledigt.
238hosts/cfgmon.md150informationalid-no-issue:CFGMON-13## CFGMON-13 — Absender-Design für Release-/CVE-Meldungen: eigener Bot?
239hosts/cfgmon.md154checked-okissue-ok:axion1337.chat-gitops#47(opened)Alertmanager-Routing: [gitops#47](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/47).
240hosts/cfgmon.md160checked-okissue-ok:axion1337.chat-gitops#22(opened)1. **release-watch** (gitops#22, deploybereit): Upstream-Releases/Security-Releases
241hosts/cfgmon.md162checked-okissue-ok:axion1337.chat-gitops#31(opened)2. **Trivy-CVE-Scans** (gitops#31, läuft wöchentlich in der Lab-CI): Funde landen
242hosts/cfgmon.md168informationalpackage-ref:@alertsscharf/stumm schaltbar bleibt? Oder bewusst alles über `@alerts` bündeln?
243hosts/cfgmon.md174informationalid-no-issue:CFGMON-12## CFGMON-12 — Gitea-Projektmetadaten nach GitLab umziehen/integrieren
244hosts/cfgmon.md176checked-okissue-ok:axion1337.chat-gitops#48(opened)**Status:** abgelöst durch [gitops#48](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/48) (2026-08-01, sorb: HOHE Priorität — vollständige Issue-Migration + zentrale Gruppen-Roadmap; Pl
245hosts/cfgmon.md178prose-or-runtime✅ **Umgesetzt am 2026-08-01/02**: Die Migration ist durch — 62 Issues liegen auf
246hosts/cfgmon.md179prose-or-runtimegit.lab, die Gitea-Issues sind geschlossen und tragen einen Migrations-Fußtext.
247hosts/cfgmon.md182informationalid-ok:LABNET-03für Deploy-Übergabe-Issues ist am 2026-08-02 mit LABNET-03 ebenfalls zurückgebaut.
248hosts/cfgmon.md187prose-or-runtimeProjektmetadaten liegen weiterhin auf Gitea/rohana. Verifiziert per API am
249hosts/cfgmon.md190prose-or-runtimeNoch auf Gitea:
250hosts/cfgmon.md192checked-okissue-ok:management#2(opened);issue-ok:management#5(opened);issue-ok:management#1(opened)- **Issues** inkl. Kommentare/Labels: ThreadNet-Web (#2, #5, …), threadnet-call (#1),
251hosts/cfgmon.md193checked-okissue-ok:management#24(opened);issue-ok:management#25(opened);issue-ok:management#32(opened)gitops (#24, #25, #32, …)
252hosts/cfgmon.md195FLAGpath-miss:00-TASKS.mdpath-miss:00-TASKS.md- **Wiki** (gitops-Wiki mit `00-TASKS.md`-Log — bisher bewusst direkt-Gitea)
253hosts/cfgmon.md197informationalid-no-issue:CFGMON-11[CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug) auf rohana — bei
254hosts/cfgmon.md202prose-or-runtime1. **GitLab-Gitea-Importer vs. API-Skript** — der Importer verliert Autorenschaft
255hosts/cfgmon.md205prose-or-runtime2. **Erreichbarkeit**: rohana ist von überall erreichbar, git.lab nur im Homelab —
256hosts/cfgmon.md208prose-or-runtimedirekt-Gitea).
257hosts/cfgmon.md219informationalid-no-issue:CFGMON-10### CFGMON-10 — threadnet-call-CI schlägt am Artifact-Schritt fehl · verworfen 2026-07-30
258hosts/cfgmon.md221prose-or-runtimeAusgelöst durch einen Push nach `threadnet-call` am 2026-07-30: der Runner (`builder-1`)
259hosts/cfgmon.md226prose-or-runtime**Hypothese inzwischen im Kern bestätigt** — beim parallelen ThreadNet-Web-CI-Versuch
260hosts/cfgmon.md229prose-or-runtimeohne Swap, trägt daneben Gitea/Traefik/Monitoring) kann das strukturell nicht liefern.
261hosts/cfgmon.md233informationalid-no-issue:CFGMON-11[CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug)), CFGMON bleibt bei leichten
262hosts/cfgmon.md234checked-okissue-ok:threadnet-call#1(closed)Jobs. Issue-Seite: [threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1).
263hosts/cfgmon.md236informationalid-no-issue:CFGMON-02### CFGMON-02 — Traefik, Gitea, cAdvisor und Runner unter IaC gebracht · erledigt 2026-07-30
264hosts/cfgmon.md238informationalruntime-path:/data/compose/8Liefen ursprünglich im Compose-Projekt `thread-net-git` aus `/data/compose/8`, einem von
265hosts/cfgmon.md239informationalforge-repo:sorb/thread-net-git;image-ref::latestPortainer verwalteten Stack ohne Repo dazu. Jetzt in `sorb/thread-net-git`: `:latest`-Tags
266hosts/cfgmon.md240prose-or-runtimehistorical-wordinggepinnt (Gitea `1.27.0`, cAdvisor `v0.49.1`), Projektname `thread-net-git` beibehalten
267hosts/cfgmon.md242prose-or-runtimeVolume-Namen, Downgrade-Verbot für Gitea), nächtliches Backup-Script. Zusätzlich neu: ein
268hosts/cfgmon.md243informationalimage-ref:gitea/act_runner:0.6.1`runner`-Service (`gitea/act_runner:0.6.1`, Container `gitea-runner`, Labels
269hosts/cfgmon.md244prose-or-runtime`ubuntu-latest`/`linux-build`/`win-wine` — die letzten beiden gezielt für Electron-Builds)
270hosts/cfgmon.md245informationalid-no-issue:CFGMON-08— ursprünglich unter [CFGMON-08](#cfgmon-08) als offene Frage gelistet, siehe dort.
271hosts/cfgmon.md247informationalbranch-ok:rework/stackEntstanden auf Branch `rework/stack`, zunächst nicht gemergt (produktiv aber schon aktiv).
272hosts/cfgmon.md248informationalbranch-ok:origin/main;branch-ok:origin/rework/stack**2026-07-30 nach `main` gemergt** (`origin/main` == `origin/rework/stack` auf `02b3224`,
273hosts/cfgmon.md249prose-or-runtimeverifiziert) — damit spiegelt die Standardansicht des Repos jetzt den Live-Stand.
274hosts/cfgmon.md250prose-or-runtimeVerifiziert am 2026-07-30 über die Compose-Labels der laufenden Container
275hosts/cfgmon.md251informationalimage-ref:working_dir: /opt/thread-net-git(`working_dir: /opt/thread-net-git`) und `docker compose ls`. `gitea-data` ist als
276hosts/cfgmon.md255prose-or-runtimeZum Bootstrapping-Problem (Definition von Gitea liegt in Gitea): mitigiert,
277hosts/cfgmon.md256prose-or-runtimeweil das Deploy-Verzeichnis selbst der Checkout ist — fällt Gitea aus, liegt
278hosts/cfgmon.md259informationalid-ok:CFGMON-09[CFGMON-09](#cfgmon-09--gitea-backups-off-host-in-die-storage-box-eigenes-borg-repo).
279hosts/cfgmon.md261informationalid-no-issue:CFGMON-05### CFGMON-05 — Monitoring-Stack unter IaC bringen · erledigt 2026-07-30
280hosts/cfgmon.md263informationalruntime-path:/opt/monitoring;image-ref::latestDer Stack lief aus `/opt/monitoring` ohne Versionierung und mit `:latest`-Tags. Jetzt
281hosts/cfgmon.md264checked-okforge-repo:sorb/threadnet-operating;path-ok:monitoring/@axion1337.chat-gitops(dir),threadnet-operating(dir)in `sorb/threadnet-operating` unter `monitoring/`, Images gepinnt,
282hosts/cfgmon.md268informationalid-no-issue:CFGMON-06### CFGMON-06 — Grafana-Certresolver zeigte ins Leere · erledigt 2026-07-30
283hosts/cfgmon.md273informationalruntime-path:/opt/monitoringaus. Aus dem Altbestand in `/opt/monitoring` unverändert übernommen und dort
284hosts/cfgmon.md276prose-or-runtimeBehoben in `threadnet-operating`, Commit `a400f8a`. Cert von Let's Encrypt (YR2)
285hosts/cfgmon.md277prose-or-runtimehistorical-wordingausgestellt, gültig bis 2026-10-28 — die Nachfolge davon ist
286hosts/cfgmon.md278informationalid-ok:CFGMON-01[CFGMON-01](#cfgmon-01--zertifikatserneuerung-braucht-offene-ports-ipv4-und-ipv6).
287hosts/cfgmon.md280informationalid-no-issue:CFGMON-07### CFGMON-07 — Alloy verlor seine Positions-Datei bei jedem Deploy · erledigt 2026-07-30
288hosts/cfgmon.md282prose-or-runtimehistorical-wording`--storage.path=/var/lib/alloy/data` war gesetzt, aber ohne Volume: die
289hosts/cfgmon.md288prose-or-runtimeBehoben durch ein `alloy_data`-Volume, Commit `edac97e`. Verifiziert: Positions
290hosts/cfgmon.md291informationalid-no-issue:CFGMON-08### CFGMON-08 — Kein Gitea-Actions-Runner registriert, Standort noch offen · erledigt 2026-07-30
291hosts/cfgmon.md294prose-or-runtimeexistiert und wo einer laufen sollte, noch offen sei. Beides falsch — ein Runner
292hosts/cfgmon.md295informationalbranch-ok:rework/stack(`builder-1`) läuft bereits, auf CFGMON, als Teil von `thread-net-git`s `rework/stack`-
293hosts/cfgmon.md297informationalid-no-issue:CFGMON-02[CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07-30) — hier
294hosts/cfgmon.md298checked-okissue-ok:axion1337.chat-gitops#33(closed)nicht dupliziert. [gitops#33](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/33)
295hosts/cfgmon.md299prose-or-runtime(dieselbe falsche Prämisse) entsprechend korrigiert/geschlossen.
296hosts/game.md3prose-or-runtimePterodactyl- / Gameserver-Host.
297hosts/game.md7informationalnet-ref:157.90.155.206| **IPv4** | `157.90.155.206` |
298hosts/game.md10informationalnet-ref:10.0.0.4| **Privat** | `10.0.0.4` (im vSwitch seit 2026-08-02) |
299hosts/game.md20prose-or-runtime[axion1337.chat/game-operating](https://git.lab/axion1337.chat/game-operating)
300hosts/game.md25prose-or-runtimeDeployment ist gewollt, aber bewusst **zurückgestellt, bis das Matrix-Projekt
301hosts/game.md31prose-or-runtime**Pterodactyl** (Gameserver-Verwaltung, in Benutzung durch Bekannte des Betreibers
302hosts/game.md36informationalruntime-path:ghcr.io/pterodactyl/panel:v1.12.0| `pterodactyl` (Panel) | `ghcr.io/pterodactyl/panel:v1.12.0` |
303hosts/game.md37informationalruntime-path:ghcr.io/pterodactyl/wings:v1.12.0| `wings` (Daemon, fährt die Gameserver als Docker-Container) | `ghcr.io/pterodactyl/wings:v1.12.0` |
304hosts/game.md41prose-or-runtime**Eigener Monitoring-Stack** (grafana-oss, prometheus v3.0.0 mit 15 d Retention,
305hosts/game.md42prose-or-runtimeloki 3.1.1, promtail 3.1.1, node-exporter v1.8.1, cadvisor v0.49.2). Wird
306hosts/game.md43prose-or-runtimeperspektivisch von CFGMON abgelöst — siehe unten.
307hosts/game.md47informationalid-ok:GAME-01GAME-01: Auf 9100/8080 des Hosts lauscht nichts, CFGMONs Scrape-Ziele auf der
308hosts/game.md55informationalnet-ref:188.245.193.243;net-ref:178.25.213.70| Port | von CFGMON (`188.245.193.243`, 2026-08-01) | vom Hausanschluss (`178.25.213.70`, 2026-08-02) |
309hosts/game.md57prose-or-runtime| 80 / 443 | offen | offen (HTTP 404 bzw. 503) |
310hosts/game.md58prose-or-runtime| **22** | **Timeout** | **offen** |
311hosts/game.md67prose-or-runtimeEs fehlte also keine Ausnahme für CFGMON. Seit 2026-08-02 liegt der Host im
312hosts/game.md68informationalnet-ref:10.0.0.4vSwitch (`10.0.0.4`); die Monitoring-Anbindung läuft künftig **per Push über das
313hosts/game.md69informationalnet-ref:10.0.0.3private Netz** — Alloy sammelt lokal ein und schiebt nach `10.0.0.3`, wodurch der
314hosts/game.md71checked-okissue-ok:management#2(opened);id-ok:GAME-01k3s-Cluster. Details: [GAME-01](https://git.lab/axion1337.chat/management/-/issues/2).
315hosts/game.md80prose-or-runtimehistorical-wording[management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten.
316hosts/game.md83checked-okissue-ok:management#2(opened);id-ok:GAME-01historical-wording- [GAME-01 — Host von CFGMON aus nicht erreichbar, 2 Targets down (⚠️ Silences bis 2026-08-04)](https://git.lab/axion1337.chat/management/-/issues/2)
317hosts/game.md84checked-okissue-ok:management#3(opened);id-ok:GAME-02- [GAME-02 — `www.game.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/3)
318hosts/matrix.md8informationalnet-ref:49.13.132.245| **IPv4** | `49.13.132.245` |
319hosts/matrix.md10informationalnet-ref:10.0.0.2;net-ref:10.0.0.3| **Privat** | `10.0.0.2` (`enp7s0`, dasselbe Hetzner-Netz wie CFGMON `10.0.0.3`) |
320hosts/matrix.md12prose-or-runtime| **DNS** | `matrix.axion1337.de` **und** `matrix.axion1337.chat` zeigen auf dieselbe IP — ebenso `axion1337.chat` (Apex) und `account.axion1337.chat` (MAS). `axion1337.de` ist die ältere/Registrar-Do
321hosts/matrix.md15informationalruntime-path:~/.ssh/config**Inventarisiert** (direkter SSH-Zugriff, `~/.ssh/config`-Alias `axion1337`, Port 2248):
322hosts/matrix.md18informationalforge-repo:sorb/axion1337.chat-gitops[`sorb/axion1337.chat-gitops`](https://rohana.axion1337.de/sorb/axion1337.chat-gitops) - dieser
323hosts/matrix.md20informationalforge-repo:sorb/ThreadNet-Web;forge-repo:sorb/threadnet-call`sorb/ThreadNet-Web` (Element Web), `sorb/threadnet-call` (Element Call/LiveKit-Widget).
324hosts/matrix.md21informationalforge-repo:sorb/element-web;forge-repo:sorb/ThreadNet-Stackhistorical-wording`sorb/element-web` und `sorb/ThreadNet-Stack` sind **veraltete/abgelöste** Vorgänger-Repos
325hosts/matrix.md24prose-or-runtime`ufw`: aktiv, Default Deny Incoming / Allow Outgoing, explizite Allow-Regeln für
326hosts/matrix.md25prose-or-runtime2248/tcp (SSH), 80/443, TURN/RTC-Ports. `unattended-upgrades` aktiv (Debian-Security +
327hosts/matrix.md26informationalid-no-issue:MATRIX-04Debian-Origin), siehe [MATRIX-04](#matrix-04--host-level-pre-update-benachrichtigung-erledigt).
328hosts/matrix.md31prose-or-runtimehistorical-wording[management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten.
329hosts/matrix.md34checked-okissue-ok:management#1(opened);id-ok:MATRIX-03- [MATRIX-03 — `www.matrix.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/1)
330hosts/matrix.md36informationalid-no-issue:MATRIX-05## MATRIX-05 — node-exporter-DaemonSet in CrashLoopBackOff, Cluster-Scrape seit 2026-08-01 tot
331hosts/matrix.md38prose-or-runtime**Status:** erledigt (2026-08-01 ~04:10, vom Mac aus mit kubectl/SSH)
332hosts/matrix.md41informationalimage-ref:listen tcp 0.0.0.0:9100: bind: address already in useTeil 1 bestätigt per Pod-Log: `listen tcp 0.0.0.0:9100: bind: address already in use`;
333hosts/matrix.md49checked-okissue-ok:axion1337.chat-gitops#45(opened)historical-wording**Fix (gitops `228807f`, Weg A aus gitops#45):** HelmRelease + Alloy-Scrape entfernt,
334hosts/matrix.md52checked-okissue-ok:axion1337.chat-gitops#45(opened)[gitops#45](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/45).
335hosts/matrix.md61prose-or-runtime| Messwert | Stand 2026-08-01 |
336hosts/matrix.md67prose-or-runtime| `waiting_reason` / `ready` | `CrashLoopBackOff` / `0` |
337hosts/matrix.md73informationalimage-ref:hostNetwork: true**Vermutete Ursache, nicht verifiziert:** Der Pod läuft mit `hostNetwork: true` und will
338hosts/matrix.md75informationalimage-ref:10.0.0.2:9100derselbe, den CFGMON als Job `k3s_host_node` direkt auf `10.0.0.2:9100` scrapt und der
339hosts/matrix.md86prose-or-runtime### Teil 2 — der Cluster-Scrape ist am 2026-08-01 01:19 UTC ausgefallen (akut)
340hosts/matrix.md96informationalnet-ref:49.13.132.245`hostNetwork`, sein Pod-IP ist die öffentliche `49.13.132.245`, dorthin zeigt der
341hosts/matrix.md103informationalimage-ref:10.0.0.2:9100| `10.0.0.2:9100` (privat) | offen, 2706 Metriken |
342hosts/matrix.md104informationalimage-ref:49.13.132.245:9100| `49.13.132.245:9100` (öffentlich) | **keine Antwort** |
343hosts/matrix.md105informationalimage-ref:49.13.132.245:80;image-ref::443| `49.13.132.245:80` / `:443` | offen — Host lebt |
344hosts/matrix.md110informationalimage-ref:10.0.0.2:9100;image-ref:0.0.0.0:91001. Der Exporter bindet jetzt `10.0.0.2:9100` statt `0.0.0.0:9100`.
345hosts/matrix.md123informationalimage-ref:10.0.0.2:9100auf `10.0.0.2:9100` zeigen lassen. Beendet den Crashloop und erhält die enge Bindung ans
346hosts/matrix.md127informationalnet-ref:0.0.0.0Ebenfalls sauber, aber er bindet dann wieder `0.0.0.0` — also auch die öffentliche IP,
347hosts/matrix.md131prose-or-runtime### Nebenbefund — Job-Label kollidiert zwischen zwei Hosts
348hosts/matrix.md137code-blockup=1 instance=node-exporter:9100 -> CFGMON (Kernel 6.8.0-136-generic)
349hosts/matrix.md152informationalpackage-ref:@matrix.axion1337.de;id-no-issue:MATRIX-01### MATRIX-01 — Klären, ob der Server Mail als `@matrix.axion1337.de` verschickt · erledigt 2026-07-30
350hosts/matrix.md154prose-or-runtimeFür `matrix.axion1337.de` existiert der komplette IONOS-Mail-Satz: `MX mx00/mx01`,
351hosts/matrix.md157prose-or-runtimeoffen, weil Matrix-Homeserver typischerweise Mail für Registrierung/Passwort-Reset
352hosts/matrix.md160prose-or-runtime**Antwort, verifiziert per Config** (nicht nur vermutet) — direkt im IaC-Repo
353hosts/matrix.md161informationalforge-repo:sorb/axion1337.chat-gitops`sorb/axion1337.chat-gitops`, dem tatsächlich hier deployten Stand geprüft:
354hosts/matrix.md163checked-okpath-ok:apps/production/custom-configs/synapse-values.yaml@axion1337.chat-gitops;image-ref:email:- `apps/production/custom-configs/synapse-values.yaml` — kein `email:`/`smtp_host`/
355hosts/matrix.md165checked-okpath-ok:apps/production/custom-configs/mas-secret.yaml@axion1337.chat-gitops- `apps/production/custom-configs/mas-secret.yaml` (SOPS-entschlüsselt geprüft) — kein
356hosts/matrix.md166prose-or-runtime`email`/`smtp`/`mailer`-Eintrag.
357hosts/matrix.md167checked-okpath-ok:apps/production/element-server-suite.yaml@axion1337.chat-gitops- `apps/production/element-server-suite.yaml` (HelmRelease values) — dito, nichts.
358hosts/matrix.md174informationalid-ok:ZONE-02[ZONE-02](../shared/zone-axion1337.md) an dieser Stelle entblockt.
359hosts/matrix.md179informationalid-no-issue:MATRIX-04MATRIX-04 unten. Nutzt die ohnehin am Apex laufende echte IONOS-Mail-Infrastruktur,
360hosts/matrix.md182informationalid-no-issue:MATRIX-02### MATRIX-02 — Pusht per Remote-Write auf einen offenen Prometheus · erledigt 2026-07-30
361hosts/matrix.md187informationalnet-ref:10.0.0.2selbst die private IP `10.0.0.2` (verifiziert per `ip -4 addr show` auf dem Host).
362hosts/matrix.md189checked-okpath-ok:apps/monitoring/alloy-config.yaml@axion1337.chat-gitopsVerifiziert in `apps/monitoring/alloy-config.yaml` (diesem Cluster): Der Remote-Write-Push
363hosts/matrix.md190informationalruntime-path:http://10.0.0.3:9090/api/v1/write;runtime-path:http://10.0.0.3:3100/...geht bereits an `http://10.0.0.3:9090/api/v1/write` und Loki an `http://10.0.0.3:3100/...` -
364hosts/matrix.md191informationalimage-ref:188.245.193.243:9090**private IP, nicht die öffentliche** `188.245.193.243:9090`. Von dieser Seite aus ist hier
365hosts/matrix.md194informationalid-ok:CFGMON-03[CFGMON-03](cfgmon.md#cfgmon-03--prometheus-remote-write-und-loki-sind-öffentlich-ohne-auth)
366hosts/matrix.md197informationalid-no-issue:MATRIX-04### MATRIX-04 — Host-Level Pre-Update-Benachrichtigung · erledigt 2026-07-30
367hosts/matrix.md200checked-okpath-ok:docs/deployment-guides/07-host-maintenance-notifications.md@axion1337.chat-gitops`docs/deployment-guides/07-host-maintenance-notifications.md` im gitops-Repo,
368hosts/matrix.md201checked-okissue-ok:management#24(opened)[Issue #24](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/24)):
369hosts/matrix.md202prose-or-runtimehistorical-wording`unattended-upgrades` war bereits aktiv, neu ergänzt ist ein systemd-Timer
370hosts/overmind.md10informationalruntime-path:git.lab;net-ref:10.58.73.17| **DNS (Lab)** | `git.lab` → `10.58.73.17` (TLS via Dokploy-Proxy, Zertifikate von der aXionLabs-CA: step-ca, 24h-Leaf, Intermediate bis 2035) |
371hosts/overmind.md11prose-or-runtime| **CPU/RAM** | 14 Kerne, 30 Gi (Stand 2026-07-31: ~11 Gi verfügbar) |
372hosts/overmind.md12prose-or-runtime| **Disk** | 444 G NVMe (~278 G frei, Stand 2026-07-31) |
373hosts/overmind.md13informationalruntime-path:/dev/kvm| **KVM** | `/dev/kvm` vorhanden — Basis für die Windows-Build-VM |
374hosts/overmind.md20informationalimage-ref:external_url https://git.lab| GitLab CE 18.7.1 + Postgres 16 + Redis 7 | Dokploy-Stack `management-gitlabce` | `external_url https://git.lab`, SSH 2224; TLS terminiert der Dokploy-Proxy (GitLab-nginx lauscht nur :80) |
375hosts/overmind.md21informationalruntime-path:git.lab;image-ref:extra_hosts: git.lab:10.58.73.17;runtime-path:/etc/gitlab-runner/certs/git.lab.crt| gitlab-runner `lab-builder-1` (v18.7.0) | gleicher Stack, Service `gitlab-runner` | Docker-Executor + Socket, `concurrent = 1`. **Stolpersteine, live gefunden**: (1) Docker-interner DNS löst `git.la
376hosts/overmind.md27prose-or-runtimegit.lab ist seit 2026-07-31 **kanonisch** für die gespiegelten Repos der Gruppe
377hosts/overmind.md28prose-or-runtime`axion1337.chat` — Stand 2026-08-09 **sieben**: die sechs Produkt-Repos (ThreadNet-Web,
378hosts/overmind.md29prose-or-runtimethreadnet-call, thread-net-git, threadnet-operating, axion1337.chat-gitops, seit heute auch
379hosts/overmind.md30prose-or-runtime`game-operating`) **und `management`, also dieses Repo**. Push-Mirrors nach rohana/Gitea,
380hosts/overmind.md31prose-or-runtimedirekte Gitea-Pushes tabu.
381hosts/overmind.md33prose-or-runtime⚠️ `gameserver` (achtes Projekt der Gruppe) hat **keinen** Mirror — offen in
382hosts/overmind.md34checked-okissue-ok:management#32(opened);issue-ok:management#32(opened)[management#32](https://git.lab/axion1337.chat/management/-/issues/32), dort liegt auf Gitea
383hosts/overmind.md37prose-or-runtimeGitea bleibt: Flux-Source (via Mirror beliefert), Registry, Packages.
384hosts/overmind.md38prose-or-runtime**Issues nicht mehr** — die sind am 2026-08-01/02 nach git.lab gewandert
385hosts/overmind.md39prose-or-runtime([ADR-0002](../decisions/0002-issues-und-management-ins-lab.md)). Die letzte Ausnahme,
386hosts/overmind.md40informationalforge-repo:sorb/managementdie Deploy-Übergabe-Issues auf dem Gitea-Tracker `sorb/management`, ist am 2026-08-02
387hosts/overmind.md41checked-okissue-ok:management#25(opened);issue-ok:management#26(closed);id-ok:LABNET-03mit LABNET-03 zurückgebaut: beide umgezogen (#25, #26), der Tracker ist leer.
388hosts/overmind.md45prose-or-runtimeseit der Umwidmung zum Management-Repo `management` und wird seither gespiegelt,
389hosts/overmind.md48informationalid-no-issue:OVERMIND-01## OVERMIND-01 — GitLab-Container-Registry aktivieren, Images nach Konsument sortieren
390hosts/overmind.md50prose-or-runtime**Status:** erledigt (2026-08-01)
391hosts/overmind.md53informationalruntime-path:registry.git.lab/axion1337.chat/threadnet-web/desktop-build:bullseye`registry.git.lab/axion1337.chat/threadnet-web/desktop-build:bullseye` (Job 386 grün,
392hosts/overmind.md55prose-or-runtimedamit grün durch (Job 398 - beweist auch den anonymen Pull des public Projekts durch
393hosts/overmind.md56prose-or-runtimeden Runner-Daemon). Die rohana-`REGISTRY_*`-Variablen bleiben nur noch für den
394hosts/overmind.md61prose-or-runtimeLab-CI → rohana (Prod, Internet) → zurück ins Lab — koppelt Lab-Infrastruktur unnötig an
395hosts/overmind.md65informationalforge-repo:sorb/threadnet-web- **rohana (Gitea) behält**: `sorb/threadnet-web` (App-Image — Flux/Prod pullt es),
396hosts/overmind.md71informationalimage-ref:registry_external_url 'https://registry.git.lab'1. Omnibus-Config: `registry_external_url 'https://registry.git.lab'`,
397hosts/overmind.md74informationalruntime-path:registry.git.lab;net-ref:10.58.73.172. Lab-DNS: `registry.git.lab` → `10.58.73.17`
398hosts/overmind.md78informationalruntime-path:/etc/docker/certs.d/registry.git.lab/ca.crt`/etc/docker/certs.d/registry.git.lab/ca.crt` (Datei liegt schon als
399hosts/overmind.md79informationalruntime-path:/tmp/git.lab.crt`/tmp/git.lab.crt` vom Runner-Setup — kopieren reicht; kein Daemon-Restart nötig)
400hosts/overmind.md80informationalforge-repo:vendor/windows;runtime-path:registry.git.lab5. CI-Umstellung: `vendor/windows` pusht nach `registry.git.lab` (Bonus: GitLabs
401hosts/overmind.md81informationalruntime-path:$CI_REGISTRY;runtime-path:$CI_JOB_TOKENeingebaute `$CI_REGISTRY`/`$CI_JOB_TOKEN`-Auth statt Gruppen-Secrets),
402hosts/overmind.md82prose-or-runtime`desktop_image`/`desktop_linux` in ThreadNet-Web folgen; Registry-Speicher liegt im
403hosts/overmind.md85prose-or-runtime**Fortschritt 2026-07-31**: Punkte 1–4 umgesetzt (Registry live auf
404hosts/overmind.md86informationalruntime-path:registry.git.lab;forge-repo:vendor/windows`registry.git.lab`, 401/Bearer-Auth korrekt, CA-Trust auf dem Host); `vendor/windows`
405hosts/overmind.md87prose-or-runtimepusht per `CI_JOB_TOKEN` in die Lab-Registry — verifiziert, Tags `5bc25447` + `stable`
406hosts/overmind.md90prose-or-runtime**Nächster Schritt:** `element-desktop-build` von rohana in die Lab-Registry umziehen
407hosts/overmind.md91prose-or-runtime(ThreadNet-Web-CI: `desktop_image`-Push-Ziel + `desktop_linux`-Image-Referenz) — bewusst
408hosts/overmind.md92prose-or-runtimehistorical-wordingzurückgestellt, bis kein Auto-Job das alte Image parallel referenziert (Reihenfolge:
409hosts/overmind.md95informationalid-ok:OVERMIND-02## OVERMIND-02 — Host-Ausfall 2026-07-31 ~19:15 lokal (NIC-Hang, Fix aktiv)
410hosts/overmind.md97checked-okissue-ok:management#4(opened)**Status:** Fix aktiv — die Beobachtung läuft als [Issue #4](https://git.lab/axion1337.chat/management/-/issues/4)
411hosts/overmind.md107prose-or-runtime**Fix (2026-07-31, Overmind-Session):** `ethtool --set-eee eno1 eee off` live gesetzt
412hosts/overmind.md108informationalruntime-path:/etc/udev/rules.d/71-disable-eee-eno1.rules+ persistente udev-Regel `/etc/udev/rules.d/71-disable-eee-eno1.rules` (greift bei
413hosts/overmind.md112prose-or-runtime- ~~NIC-/BIOS-Firmware-Update 2.4.0.0 → 2.5.2.0~~ **erledigt** (Wartungsfenster
414hosts/overmind.md121prose-or-runtime- 19:05–19:12 — Provision-Job 409 grün (Rust 1.97.1 maschinenweit, Strawberry Perl,
415hosts/overmind.md137prose-or-runtime8G. Nach dem NIC-Fix lief die Kette durch: **desktop_windows Job 438 grün**
416hosts/overmind.md138prose-or-runtime(2026-07-31 ~21:50 lokal, `Element Setup 1.12.17.exe`, 141 MB, unsigniert) —
417hosts/overmind.md139checked-okissue-ok:ThreadNet-Web#5(closed);issue-ok:ThreadNet-Web#6(opened)ThreadNet-Web#5 geschlossen, Folgethemen (Signing/Branding) in ThreadNet-Web#6.
418hosts/overmind.md141prose-or-runtime(resumefähiges Prefetch-Skript im ThreadNet-Web-Repo, Jobs 415/416/424/431).
419hosts/overmind.md145checked-okissue-ok:ThreadNet-Web#5(closed)Weitere CI-Betriebsthemen laufen über die Projekt-Issues (ThreadNet-Web#5
420hosts/overmind.md146checked-okissue-ok:threadnet-call#1(closed);id-no-issue:CFGMON-11Windows-Strecke, threadnet-call#1 npm-Ziel) und CFGMON-11 (Gitea-CI-Rückbau).
421roadmap.md3prose-or-runtime> Stand 2026-08-06. Diese Datei hält die **Linien und die Reihenfolge**,
422roadmap.md6prose-or-runtime> Die Gruppen-Milestones M1–M4 sind angelegt, und seit 2026-08-06 hängt **jedes
423roadmap.md20prose-or-runtime1. **CVE-Meldeweg v2 live** — aggregierte Alarme deployen
424roadmap.md21checked-okissue-ok:management#25(opened)([Übergabe-Issue #25](https://git.lab/axion1337.chat/management/-/issues/25)),
425roadmap.md23checked-okissue-ok:axion1337.chat-gitops#45(opened);issue-ok:axion1337.chat-gitops#45(opened)(Follow-up-Wunsch sorb). [gitops#45](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/45),
426roadmap.md24checked-okissue-ok:axion1337.chat-gitops#49(opened)[#49](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/49)
427roadmap.md26checked-okissue-ok:management#7(opened);id-ok:CFGMON-01[CFGMON-01 (#7)](https://git.lab/axion1337.chat/management/-/issues/7) ⏰
428roadmap.md27checked-okissue-ok:management#10(opened);id-ok:CFGMON-093. **Backups wiederherstellen** — [CFGMON-09 (#10)](https://git.lab/axion1337.chat/management/-/issues/10)
429roadmap.md29checked-okissue-ok:axion1337.chat-gitops#25(opened);id-ok:CFGMON-034. K3s-API-Härtung (gitops#25, gemeinsame Session), CFGMON-03-Konsolen-Klärung.
430roadmap.md33prose-or-runtime1. ✅ **Site-to-Site-VPN** Hetzner ↔ Lab — erledigt 2026-08-01
431roadmap.md34checked-okissue-ok:management#12(closed)([#12](https://git.lab/axion1337.chat/management/-/issues/12), ADR-0004 akzeptiert,
432roadmap.md35checked-okissue-ok:management#13(closed);id-ok:LABNET-03zwei AARs). Ernte daraus: ✅ **LABNET-03 (#13)** — Übergabe-Issues sind am
433roadmap.md36prose-or-runtime2026-08-02 ins Lab gewandert, die Gitea-Ausnahme ist zurückgebaut.
434roadmap.md37informationalid-ok:GAME-012. GAME-01-Erreichbarkeit + vSwitch-Aufnahme —
435roadmap.md38checked-okissue-ok:management#2(opened)historical-wording[#2](https://git.lab/axion1337.chat/management/-/issues/2) (Silences bis 2026-08-04!)
436roadmap.md39checked-okissue-ok:axion1337.chat-gitops#46(opened)3. Roadmap-/Board-Ausbau in GitLab (Rest von gitops#46: Milestones, Boards).
437roadmap.md40checked-okissue-ok:management#20(opened);id-ok:DOC-034. **Wiki-Oberfläche entscheiden** — [DOC-03 (#20)](https://git.lab/axion1337.chat/management/-/issues/20):
438roadmap.md45checked-okissue-ok:management#14(opened);id-ok:CFGMON-14[CFGMON-14 (#14)](https://git.lab/axion1337.chat/management/-/issues/14) docker-Gruppe
439roadmap.md47checked-okissue-ok:management#15(opened);id-ok:CFGMON-15[CFGMON-15 (#15)](https://git.lab/axion1337.chat/management/-/issues/15) Token-Hygiene,
440roadmap.md48checked-okissue-ok:management#16(closed);id-ok:LABNET-04[LABNET-04 (#16)](https://git.lab/axion1337.chat/management/-/issues/16) Nacharbeiten.
441roadmap.md52prose-or-runtime1. **Rebrand fortsetzen** — Desktop-Client heißt seit 2026-08-02 **ThreadNet** und
442roadmap.md53checked-okissue-ok:ThreadNet-Web#10(closed);issue-ok:ThreadNet-Web#10(closed)trägt die eigene Marke ([ThreadNet-Web#10](https://git.lab/axion1337.chat/ThreadNet-Web/-/issues/10),
443roadmap.md54prose-or-runtimeCommit `6b0261d`). Offen: Web-Client-Icons/`brand`, About-Attribution.
444roadmap.md55checked-okissue-ok:ThreadNet-Web#6(opened)2. Signing/Notarisierung (ThreadNet-Web#6) — ohne Signatur muss jeder Nutzer auf
445roadmap.md57checked-okissue-ok:management#22(opened);id-ok:BUILD-013. **macOS reproduzierbar bauen** — [BUILD-01 (#22)](https://git.lab/axion1337.chat/management/-/issues/22):
446roadmap.md59checked-okissue-ok:axion1337.chat-gitops#47(opened)4. **Raidplaner** (gitops#47) — Lean-Experiment: HumHub-Kandidat evaluieren.
447roadmap.md60checked-okissue-ok:axion1337.chat-gitops#48(opened)5. **Gäste-Invite-Workflow** (gitops#48) — Design steht (@concierge,
448roadmap.md62checked-okissue-ok:ThreadNet-Web#9(opened)6. Zammad-artiges Feedback-Tool als spätere Ergänzung (ThreadNet-Web#9).
449roadmap.md66checked-okpath-ok:vision/axion1337-chat.md@management- Rebranding-Runde (bewusst vertagt; Leitplanke in `vision/axion1337-chat.md`).
450roadmap.md79checked-okissue-ok:management#17(closed)**Der Einstieg ist erfolgt:** [Struktur-Workshop (#17)](https://git.lab/axion1337.chat/management/-/issues/17)
451roadmap.md80prose-or-runtimeam 2026-08-06 — Visionen geschärft, M1–M4 angelegt, Board gesichtet, Kadenz und
452roadmap.md88prose-or-runtimehistorical-wordingTitel-Präfixe aus der Gitea-Migration sind am 2026-08-06 entfernt; zwei davon
453roadmap.md90checked-okissue-ok:ThreadNet-Web#7(opened);issue-ok:management#1(opened)(ThreadNet-Web#7 und #1, jeweils im Issue begründet).
454shared/branding.md8prose-or-runtimeHier im `management`-Repo, weil es als einziges der beteiligten Repos
455shared/branding.md9prose-or-runtime**gespiegelt** ist und jede Werkzeugentscheidung überlebt: Wird das
456shared/branding.md16FLAGpath-miss:static/img/path-miss:static/img/Schriftzug), erstellt von sorb. Sie liegen im Wiki-Repo unter `static/img/` und
457shared/branding.md28prose-or-runtimeIcon-Slots fällt das sofort auf. Korrigiert am 2026-08-06 auf 21 % oben wie unten.
458shared/branding.md37informationaltag-ok:v0.4.0Elf Artefakte, alle aus einer Quelle (Stand 2026-08-06, `v0.4.0`):
459shared/branding.md41checked-okpath-ok:apps/web/res/vector-icons/@ThreadNet-Web(dir)| `apps/web/res/vector-icons/` | 1024, 512, 180, 152, 144, 120, 24 px |
460shared/branding.md42checked-okpath-ok:apps/desktop/build/icon.png@ThreadNet-Web| `apps/desktop/build/icon.png` | App-/Installer-Icon |
461shared/branding.md43checked-okpath-ok:apps/desktop/build/icon.ico@ThreadNet-Web| `apps/desktop/build/icon.ico` | Windows, 7 Größen von 16 bis 256 |
462shared/branding.md44checked-okpath-ok:apps/desktop/build/icon.icns@ThreadNet-Web| `apps/desktop/build/icon.icns` | macOS, via `iconutil` aus einem `.iconset` |
463shared/branding.md45checked-okpath-ok:apps/desktop/build/icon.icon/Assets/element.png@ThreadNet-Web| `apps/desktop/build/icon.icon/Assets/element.png` | Layer des macOS-Icon-Composers |
464shared/branding.md47checked-okpath-ok:vector-icons/1024.png@ThreadNet-WebPrüfen lässt sich die Gleichheit über die Prüfsumme von `vector-icons/1024.png`
465shared/branding.md48checked-okpath-ok:build/icon.png@ThreadNet-Webgegen `build/icon.png` — weichen sie ab, ist eine Seite nachgezogen worden und die
466shared/branding.md55prose-or-runtimeGruvbox Dark. Grundtöne `#282828` / `#1d2021`, Text `#ebdbb2`, Akzent `#bd93f9`,
467shared/branding.md63prose-or-runtimeAm 2026-08-02 in der BookStack-Oberfläche eingestellt und von dort extrahiert
468shared/branding.md65prose-or-runtimeder Coolors-Satz `#264653 · #2A9D8F · #E9C46A · #F4A261 · #E76F51`:
469shared/branding.md69prose-or-runtime| Primäre Farbe | `#264653` | Charcoal |
470shared/branding.md74prose-or-runtime| Seitenfarbe | `#77bb41` | Grün |
471shared/branding.md75prose-or-runtime| Seitenentwurfsfarbe | `#e32400` | Rot |
472shared/branding.md86prose-or-runtimeje Theme vier Farben plus ein Schriftpaar. Sie sind seit 2026-08-02 **wörtlich
473shared/branding.md93prose-or-runtime| Sunset Boulevard | `#264653` | dunkel | `#e76f51` · `#f4a261` · `#e9c46a` |
474shared/branding.md95prose-or-runtime| Modern Minimalist | `#ffffff` | hell | `#36454f` · `#708090` · `#d3d3d3` |
475shared/branding.md103prose-or-runtime⚠️ **Ob ein Theme hell oder dunkel gemeint ist, steht nicht verlässlich in den
476shared/branding.md121checked-okpath-ok:apps/desktop/axion1337/build.json@ThreadNet-Web;path-ok:apps/web/res/manifest.json@ThreadNet-Web| Betriebssystem, Startmenü, Installer, PWA | **ThreadNet** | `productName` in `apps/desktop/axion1337/build.json`, `name` in `apps/web/res/manifest.json` |
477shared/branding.md122checked-okpath-ok:element-values.yaml@axion1337.chat-gitops;path-ok:apps/desktop/axion1337/config.json@ThreadNet-Web| in der Anwendung | **aXion1337.Chat** | `brand` in `element-values.yaml` (Prod) und `apps/desktop/axion1337/config.json` |
478shared/branding.md123checked-okpath-ok:.env.production@threadnet-call| eingebettetes Call-Widget | **aXion1337.Chat** | `VITE_PRODUCT_NAME` in `.env.production` (threadnet-call) |
479shared/branding.md124checked-okpath-ok:apps/authentik/authentik-blueprints.yaml@axion1337.chat-gitops| Anmeldeseite (Authentik) | **ThreadNet** | `branding_title` im Brand-Blueprint (gitops, `apps/authentik/authentik-blueprints.yaml`) |
480shared/branding.md130checked-okpath-ok:vision/threadnet.md@managementDie Leitplanke dahinter steht in [`vision/threadnet.md`](../vision/threadnet.md):
481shared/branding.md149checked-okpath-ok:apps/production/custom-configs/element-values.yaml@axion1337.chat-gitops| Element/ThreadNet-Web | `apps/production/custom-configs/element-values.yaml` (gitops), `setting_defaults.custom_themes` | 17 Themes; Änderungen chirurgisch, **nie die YAML neu serialisieren** |
482shared/branding.md150checked-okpath-ok:apps/web/res/vector-icons/@ThreadNet-Web(dir);path-ok:apps/web/res/manifest.json@ThreadNet-Web| Web-Icons + PWA | `apps/web/res/vector-icons/`, `apps/web/res/manifest.json` (ThreadNet-Web) | `theme_color` = `#ed4f4c`, die Markenfarbe — nicht Elements `#76CFA6` |
483shared/branding.md151checked-okpath-ok:apps/desktop/build/@ThreadNet-Web(dir)| Desktop-Icons | `apps/desktop/build/` (ThreadNet-Web) | `.png`, `.ico`, `.icns`, Layer-Asset — alle aus derselben Quelle |
484shared/branding.md152checked-okpath-ok:apps/desktop/axion1337/config.json@ThreadNet-Web| ThreadNet Desktop | `apps/desktop/axion1337/config.json` (ThreadNet-Web) | eigene Kopie derselben Themes — beim Ändern beide mitziehen |
485shared/branding.md153FLAGpath-miss:theme/sorbs-palette.mdpath-miss:theme/sorbs-palette.md| BookStack | *Settings → Customization*, getrennt für hell und dunkel | liegt in der Datenbank, **nicht im Repo** — schriftlich hier und in `theme/sorbs-palette.md` |
486shared/branding.md154prose-or-runtime| BookStack (Feinschliff) | `theme/*.css` im Wiki-BookStack-Repo | nur Flächen, Text, Ränder — die sieben Farben oben gehören in die Oberfläche |
487shared/branding.md155FLAGpath-miss:src/css/custom.csspath-miss:src/css/custom.css| Docusaurus-Wiki | `src/css/custom.css` (homelab/wiki) | bislang nur Akzentfarbe |
488shared/branding.md156checked-okpath-ok:apps/web/res/themes/element/img/backgrounds/alpenglow.jpg@ThreadNet-Web;path-ok:SdkConfig.ts@ThreadNet-Web| Titelbild Login | `apps/web/res/themes/element/img/backgrounds/alpenglow.jpg` (ThreadNet-Web), gesetzt in `SdkConfig.ts` | siehe unten — Bilddatei kommt nur über einen Build in den Container |
489shared/branding.md157checked-okpath-ok:apps/authentik/authentik-blueprints.yaml@axion1337.chat-gitops;issue-ok:axion1337.chat-gitops#55(opened)| Anmeldeseite Authentik | Brand-Blueprint in `apps/authentik/authentik-blueprints.yaml` (gitops) | Favicon und Hintergrund werden **von axion1337.chat referenziert**, nicht hochgeladen. **Logo ist no
490shared/branding.md161prose-or-runtimeSeit 2026-08-06 zeigt die Login-Seite ein Alpenglühen über einer Bergkette statt
491shared/branding.md173prose-or-runtimeFotografen namentlich. Nur `en`/`de` anzupassen hätte in 29 Sprachen eine **falsche
492shared/branding.md179informationalruntime-path:https://axion1337.chat/themes/element/img/backgrounds/alpenglow.jpg`https://axion1337.chat/themes/element/img/backgrounds/alpenglow.jpg`. Wer das Bild im
493shared/branding.md185checked-okpath-ok:vector-icons/512.png@ThreadNet-WebDer erste Versuch setzte `branding_logo` auf `vector-icons/512.png`. Ergebnis: das
494shared/branding.md190prose-or-runtimeZurückgesetzt am 2026-08-06 auf Authentiks eigenes Logo. Ein Ersatz braucht eine
495shared/branding.md192FLAGpath-miss:threadnet-logo-wortmarke.pngpath-miss:threadnet-logo-wortmarke.pngauch `threadnet-logo-wortmarke.png` (Bildmarke *über* Schriftzug). Offen in
496shared/branding.md204FLAGpath-miss:theme/sorbs-palette.mdpath-miss:theme/sorbs-palette.md`theme/sorbs-palette.md` im BookStack-Repo ist die betriebsnahe Kopie mit den
497shared/branding.md214checked-okpath-ok:vision/threadnet.md@management;issue-ok:ThreadNet-Web#10(closed)(→ [`vision/threadnet.md`](../vision/threadnet.md), ThreadNet-Web#10).
498shared/commit-zuordnung-2026-08-07.md3prose-or-runtimeAm 2026-08-07 wurden die Zeitstempel aller Commits aus dieser Zusammenarbeit auf
499shared/commit-zuordnung-2026-08-07.md14prose-or-runtime`backup-vor-rewrite`-Branches rekonstruiert und **paarweise verifiziert**: Für jedes
500shared/commit-zuordnung-2026-08-07.md26prose-or-runtimeDas Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines
501shared/commit-zuordnung-2026-08-07.md27informationaltag-ok:v0.3.0;tag-ok:v0.4.0neu gestartet** (`v0.3.0`, `v0.4.0`, `desktop-v1.12.17-clientscan`). Ein Tag ist
502shared/commit-zuordnung-2026-08-07.md33informationalimage-ref:threadnet-web:v0.4.0;tag-ok:v0.4.0Glück, keine Planung:** Mit stehender Tag-Protection wäre `threadnet-web:v0.4.0`
503shared/commit-zuordnung-2026-08-07.md37checked-okissue-ok:ThreadNet-Web#14(closed)ThreadNet-Web#14.
504shared/commit-zuordnung-2026-08-07.md42prose-or-runtimeThreadNet-Web vor dem 2026-07-28 (3 Commits), gitops vor dem 2026-07-27 (147).
505shared/commit-zuordnung-2026-08-07.md47prose-or-runtime## gitops — 117 Commits
506shared/commit-zuordnung-2026-08-07.md169prose-or-runtime## management — 78 Commits
507shared/commit-zuordnung-2026-08-07.md252prose-or-runtime## ThreadNet-Web — 47 Commits
508shared/commit-zuordnung-2026-08-07.md304prose-or-runtime## threadnet-call — 9 Commits
509shared/lab-netzwerk.md10checked-okissue-ok:management#12(closed)> (Testreihe 1–7 in [#12](https://git.lab/axion1337.chat/management/-/issues/12)).
510shared/lab-netzwerk.md11checked-okissue-ok:management#11(closed)> Es gibt dazu **keine offenen Issues mehr** — auch die Restpunkte #11
511shared/lab-netzwerk.md12checked-okissue-ok:management#16(closed);id-ok:LABNET-04> (MacBook-Profil) und #16 (LABNET-04, Feinschliff an den UniFi-Regeln) sind
512shared/lab-netzwerk.md13prose-or-runtime> geschlossen. Alles Folgende ist **Bestand und Historie**, keine offene Arbeit.
513shared/lab-netzwerk.md15prose-or-runtime**Zwei WireGuard-Zugänge (Stand 2026-08-01, beide gelöst/abgenommen):**
514shared/lab-netzwerk.md22informationalforge-repo:homelab/docs### Verhältnis zu `homelab/docs`
515shared/lab-netzwerk.md30prose-or-runtimeDer Grund für die Doppelung ist der Mirror-Geltungsbereich aus der
516shared/lab-netzwerk.md35informationalforge-repo:homelab/docsdarüber hinaus. **Bei Widerspruch gilt `homelab/docs`.**
517shared/lab-netzwerk.md39informationalid-ok:LABNET-01## LABNET-01 — WireGuard-Roadwarrior ins Lab kaputt (seit einigen Monaten)
518shared/lab-netzwerk.md42checked-okissue-ok:axion1337.chat-gitops#48(opened)Damit ist die Cutover-Voraussetzung für gitops#48 erfüllt.
519shared/lab-netzwerk.md46informationalnet-ref:178.25.213.70der Fritzbox ihre öffentliche IP nicht) → Fix: Endpunkt `178.25.213.70`;
520shared/lab-netzwerk.md52informationalnet-ref:192.168.0.0/20/20-Blöcke in 192.168.0.0/16; `192.168.0.0/20` verschluckte das VPN-Subnetz
521shared/lab-netzwerk.md53prose-or-runtime192.168.5.0/24 → Antworten an VPN-Clients endeten in der Bridge (SYN kam an,
522shared/lab-netzwerk.md55prose-or-runtimefremde Hosts funktionierten) → Fix: **VPN-Subnetz auf 10.58.74.0/24** (Docker
523shared/lab-netzwerk.md58checked-okissue-ok:management#11(closed)**Restarbeiten:** MacBook-WG-Profil → [Issue #11](https://git.lab/axion1337.chat/management/-/issues/11). ⚠️ Latente Wiederholungsgefahr
524shared/lab-netzwerk.md59informationalnet-ref:192.168.176.0/20notiert: Overminds Docker-Pool deckt auch `192.168.176.0/20` ab = kollidiert mit
525shared/lab-netzwerk.md60prose-or-runtimedem Fritzbox-Netz 192.168.178.x — aktuell folgenlos, aber bei künftigen Subnetz-
526shared/lab-netzwerk.md66prose-or-runtime(192.168.178.20) als Endpunkt — die UDM kennt hinter der Fritzbox ihre
527shared/lab-netzwerk.md69prose-or-runtime178.25.213.70 ändern!).
528shared/lab-netzwerk.md73prose-or-runtimeeinem Port). Fix: UDM-WG auf **51840** umgezogen + Freigabe angepasst.
529shared/lab-netzwerk.md85prose-or-runtime**Diagnose-Plan von VOR der Lösung** — ⚠️ abgearbeitet und überholt, steht hier
530shared/lab-netzwerk.md102checked-okissue-ok:axion1337.chat-gitops#48(opened)**Verwandt:** gitops#48 (Cutover erst nach Lösung), perspektivisch ersetzt ein
531shared/lab-netzwerk.md105prose-or-runtime## Zugehörige Issues — alle geschlossen
532shared/lab-netzwerk.md108prose-or-runtimehistorical-wording[management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten.
533shared/lab-netzwerk.md111prose-or-runtimeZum Netz/VPN ist **nichts mehr offen** (Stand 2026-08-02):
534shared/lab-netzwerk.md115checked-okissue-ok:management#11(closed);id-ok:LABNET-01| [#11](https://git.lab/axion1337.chat/management/-/issues/11) | LABNET-01-Rest — MacBook-WireGuard-Profil | geschlossen |
535shared/lab-netzwerk.md116checked-okissue-ok:management#12(closed);id-ok:LABNET-02| [#12](https://git.lab/axion1337.chat/management/-/issues/12) | LABNET-02 — Site-to-Site-VPN (Design: [ADR-0004](../decisions/0004-site-to-site-vpn-hetzner-lab.md)) | geschlossen, Testreihe 1–7 proto
536shared/lab-netzwerk.md117checked-okissue-ok:management#16(closed);id-ok:LABNET-04| [#16](https://git.lab/axion1337.chat/management/-/issues/16) | LABNET-04 — Feinschliff UniFi-Regeln | geschlossen |
537shared/lab-netzwerk.md120FLAGissue-state:management#13=closed,text-says-openedissue-state:management#13bleiben offen: [#13](https://git.lab/axion1337.chat/management/-/issues/13)
538shared/lab-netzwerk.md121informationalid-ok:LABNET-03(LABNET-03, Rückbau der Gitea-Ausnahme für Übergabe-Issues — durch den Tunnel
539shared/lab-netzwerk.md123checked-okissue-ok:management#15(opened);id-ok:CFGMON-15[#15](https://git.lab/axion1337.chat/management/-/issues/15) (CFGMON-15,
540shared/lab-netzwerk.md124informationalid-ok:LABNET-02Widerruf der Einmal-Tokens aus der LABNET-02-Nacht — Credential-Hygiene, und der
541shared/lab-netzwerk.md125prose-or-runtimeWiderruf kann still einen Push-Mirror brechen, solange dessen hinterlegtes Token
542shared/zone-axion1337.md9informationalnet-ref:217.160.0.140;image-ref:2001:8d8:100f:f000::2e9| **Apex** | `217.160.0.140` / `2001:8d8:100f:f000::2e9` — IONOS-Hosting, nicht eigene Infrastruktur |
543shared/zone-axion1337.md18informationalruntime-path:rohanahistorical-wording| `rohana` | löst auf ❌ | gelöscht | **gelöscht** ⚠️ | fehlt | ⚠️ schwächer als vorher |
544shared/zone-axion1337.md20informationalruntime-path:~all| `matrix` | löst auf ❌ | IONOS ❌ | `~all` ❌ | fehlt | offen |
545shared/zone-axion1337.md22informationalruntime-path:~all;id-ok:ZONE-02| **Apex** | legitim ✅ | IONOS (genutzt) | `~all` | **`p=none`** ⚠️ | siehe ZONE-02 |
546shared/zone-axion1337.md36informationalnet-ref:217.160.0.140;image-ref:2001:8d8:100f:f000::2e9| `axion1337.de` | `217.160.0.140` | `2001:8d8:100f:f000::2e9` | IONOS-Hosting |
547shared/zone-axion1337.md37informationalnet-ref:217.160.0.140| `www` | `217.160.0.140` | dito | IONOS-Hosting — hier ist `www` **legitim** |
548shared/zone-axion1337.md38informationalruntime-path:rohana;net-ref:188.245.193.243;image-ref:2a01:4f8:c17:93eb::1| `rohana` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Gitea |
549shared/zone-axion1337.md39informationalnet-ref:188.245.193.243;image-ref:2a01:4f8:c17:93eb::1| `selendis` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Grafana |
550shared/zone-axion1337.md40informationalnet-ref:157.90.155.206| `game` | `157.90.155.206` | — | Pterodactyl |
551shared/zone-axion1337.md41informationalnet-ref:49.13.132.245| `matrix` | `49.13.132.245` | — | Matrix-Homeserver |
552shared/zone-axion1337.md42informationalnet-ref:217.160.233.227;image-ref:2001:8d8:1000:30f5:…| `ftp` | `217.160.233.227` | `2001:8d8:1000:30f5:…` | IONOS-Default |
553shared/zone-axion1337.md43informationalid-ok:ZONE-01| `www.rohana`, `www.selendis`, `www.game`, `www.matrix` | wie ohne `www` | teils | überflüssig, siehe ZONE-01 |
554shared/zone-axion1337.md46informationalruntime-path:rohana`autodiscover`), auf `rohana` und `game` nicht.
555shared/zone-axion1337.md50checked-okissue-ok:management#5(opened);id-ok:ZONE-01Damit die Rezepte in [ZONE-01](https://git.lab/axion1337.chat/management/-/issues/5)
556shared/zone-axion1337.md57prose-or-runtimekann `rechnung@rohana.axion1337.de` in den Umschlag schreiben. Die folgenden
557shared/zone-axion1337.md72informationalruntime-path:rohanaGenau die richtige Aussage für `rohana`, `selendis`, `matrix` — die verschicken keine
558shared/zone-axion1337.md73informationalid-no-issue:MATRIX-01Mail (für `matrix` verifiziert in MATRIX-01: weder Synapse noch MAS senden).
559shared/zone-axion1337.md99prose-or-runtime⚠️ **DMARC wird vererbt.** Fehlt `_dmarc.rohana`, gilt die Policy des
560shared/zone-axion1337.md101checked-okissue-ok:management#6(opened);id-ok:ZONE-02([ZONE-02](https://git.lab/axion1337.chat/management/-/issues/6)) — **damit erben
561shared/zone-axion1337.md129informationalruntime-path:rohanahistorical-wording**Real eingetreten:** Bei `rohana` sind MX und SPF gelöscht, die Ersatz-Records
562shared/zone-axion1337.md137prose-or-runtimehistorical-wording[management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten.
563shared/zone-axion1337.md140checked-okissue-ok:management#5(opened);id-ok:ZONE-01- [ZONE-01 — IONOS-Default-Records bereinigen (Rezepte im Issue; rohana/selendis in Arbeit)](https://git.lab/axion1337.chat/management/-/issues/5)
564shared/zone-axion1337.md141checked-okissue-ok:management#6(opened);id-ok:ZONE-02- [ZONE-02 — Apex-DMARC ist `p=none` und schützt nichts](https://git.lab/axion1337.chat/management/-/issues/6)
565verfahren/README.md10prose-or-runtime| [aar/](aar/) | Abgelegte AARs, benannt `JJJJ-MM-TT-<vorhaben>.md` |
566verfahren/README.md12checked-okpath-ok:textbloecke.md@management[`textbloecke.md`](textbloecke.md) hält kurze, kopierbare Blöcke, die man einer
567verfahren/README.md18checked-okpath-ok:.gitlab/issue_templates/Deploy-Übergabe.md@management`.gitlab/issue_templates/Deploy-Übergabe.md` und erscheint beim Anlegen eines
568verfahren/README.md22checked-okpath-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir)historical-wordingAbgrenzung zum Rest des Repos: `hosts/` und `shared/` halten **offene Punkte**,
569verfahren/aar-vorlage.md7prose-or-runtimeWas ist live und verifiziert. Was ist bewusst **nicht** live, und warum.
570verfahren/aar/2026-08-01-cve-pipeline-gitops47.md1checked-okissue-ok:axion1337.chat-gitops#47(opened)# AAR — CVE-Pipeline `gitops#47`
571verfahren/aar/2026-08-01-cve-pipeline-gitops47.md3informationalruntime-path:/opt/threadnet-operating/monitoring**Datum:** 2026-08-01 · **Host/Stack:** CFGMON, `/opt/threadnet-operating/monitoring`
572verfahren/aar/2026-08-01-cve-pipeline-gitops47.md9prose-or-runtime**Live und verifiziert:** Scanner (29/29 Images gescannt), Exporter, Prometheus-Job
573verfahren/aar/2026-08-01-cve-pipeline-gitops47.md13checked-okpath-ok:alertmanager.yml@threadnet-operating`alertmanager.yml` auf einen Null-Receiver (Commit `2b715ca` in
574verfahren/aar/2026-08-01-cve-pipeline-gitops47.md14informationalforge-repo:sorb/threadnet-operating`sorb/threadnet-operating`). Grund siehe Befund 1.
575verfahren/aar/2026-08-01-cve-pipeline-gitops47.md20prose-or-runtime| 1 | Eine Matrix-Nachricht pro CVE. 126 CRITICAL landen in **einer** Alertmanager-Gruppe, nach 24 h kommen 1222 HIGH dazu. Dazu steht `save_state()` in `do_POST` hinter der Sende-Schleife: bricht ein
576verfahren/aar/2026-08-01-cve-pipeline-gitops47.md21checked-okissue-ok:axion1337.chat-gitops#52(opened)historical-wording| 2 | `docker compose up -d` aktiviert geänderte Configs nicht. Einzeldatei-Mounts hängen am Inode, `git pull` benennt um. Prometheus lief nach dem Deploy mit alten Regeln — `promtool` fand 9, Prometh
577verfahren/aar/2026-08-01-cve-pipeline-gitops47.md22checked-okissue-ok:axion1337.chat-gitops#51(opened)| 3 | `TrivyScanStale` kann ein nie erfolgreich gescanntes Image nicht melden — ohne ersten Report existiert keine Serie, an der `time() - trivy_last_scan_timestamp` hängen könnte | LOW | notiert in `
578verfahren/aar/2026-08-01-cve-pipeline-gitops47.md23checked-okimage-ref:except: continue;issue-ok:axion1337.chat-gitops#51(opened)| 4 | Der Exporter prunt den First-Seen-State bei **jedem** Scrape. Ein transienter Lesefehler (`except: continue`) löscht die Erstfund-Zeitstempel des Targets dauerhaft | LOW | notiert in `gitops#51`
579verfahren/aar/2026-08-01-cve-pipeline-gitops47.md27informationalimage-ref:goauthentik/server:2026.2.31316 LOW. Spitzenreiter `goauthentik/server:2026.2.3` mit 369 CRITICAL+HIGH.
580verfahren/aar/2026-08-01-cve-pipeline-gitops47.md34informationalruntime-path:rohana.axion1337.de| Private Registry `rohana.axion1337.de` braucht Credentials für Trivy | Anonymer Pull | zieht anonym, keine Credentials nötig |
581verfahren/aar/2026-08-01-cve-pipeline-gitops47.md35checked-okpath-ok:hosts/game.md@management| Zwei down-Targets könnten Folge des Deploys sein | `avg_over_time(up[3h])` | 0.00 — schon 3 h vorher tot, in `hosts/game.md` erfasst |
582verfahren/aar/2026-08-01-cve-pipeline-gitops47.md58checked-okissue-ok:axion1337.chat-gitops#51(opened)Richtungsentscheidung zu `gitops#51`, bevor die Alarme scharf gehen: entweder
583verfahren/aar/2026-08-01-cve-pipeline-gitops47.md59checked-okpath-ok:matrix-alerts.py@threadnet-operating`matrix-alerts.py` auf eine Sammelnachricht pro Webhook-Batch umbauen (die fünf
584verfahren/aar/2026-08-01-cve-pipeline-gitops47.md65informationalimage-ref:coturn/coturn:latestNebenbefund ohne Handlungsbedarf von hier: `coturn/coturn:latest` ist das einzige
585verfahren/aar/2026-08-01-cve-pipeline-gitops47.md66checked-okissue-ok:axion1337.chat-gitops#47(opened)ungepinnte Image (bereits in `gitops#47` notiert).
586verfahren/aar/2026-08-01-labnet02-cfgmon.md1checked-okforge-repo:sorb/management#2;issue-ok:management#2(opened);id-ok:LABNET-02# AAR — LABNET-02, CFGMON-Seite (Übergabe `sorb/management#2`)
587verfahren/aar/2026-08-01-labnet02-cfgmon.md8informationalruntime-path:/etc/wireguard/lab.conf**Live:** `wireguard-tools` installiert, Keypair erzeugt, `/etc/wireguard/lab.conf`
588verfahren/aar/2026-08-01-labnet02-cfgmon.md10informationalnet-ref:10.58.75.2/24`enabled`. Interface `lab` steht mit `10.58.75.2/24`, Routen und Forward-Regeln aktiv,
589verfahren/aar/2026-08-01-labnet02-cfgmon.md11informationalnet-ref:10.58.73.1;runtime-path:~labSplit-DNS gesetzt (`10.58.73.1`, `~lab`).
590verfahren/aar/2026-08-01-labnet02-cfgmon.md28prose-or-runtimehistorical-wording| 1 | `enp7s0` seit 18:11 DOWN, Privatnetz-Route weg. Auslöser war die Hetzner-Range-Umstellung /16 → /8: die private NIC wurde ab- und neu angehängt (`renamed from eth1`), danach wurde `hc-net-ifup@e
591verfahren/aar/2026-08-01-labnet02-cfgmon.md30prose-or-runtime| 3 | `sudo` ist aus einer Agenten-Session nicht bedienbar (kein TTY). Die Schritte liefen über die **docker-Gruppenmitgliedschaft** des Kontos (privilegierter Container + `nsenter`) — das ist root-äq
592verfahren/aar/2026-08-01-labnet02-cfgmon.md31informationalnet-ref:10.58.73.0/24historical-wording| 4 | Hetzner-Range war tatsächlich /16 — unabhängig aus der Routing-Tabelle verifiziert (`10.0.0.0/16 via 10.0.0.1 dev enp7s0`), `10.58.73.0/24` lag außerhalb | LOW | bestätigt, Umstellung durch sorb
593verfahren/aar/2026-08-01-labnet02-cfgmon.md38prose-or-runtime| Split-Tunnel biegt den Default-Weg um | `ip route get 8.8.8.8` | unverändert über `eth0`; öffentliches DNS und HTTPS funktionieren |
594verfahren/aar/2026-08-01-labnet02-cfgmon.md42prose-or-runtime**Nicht verifiziert:** ob der k3s-Host selbst läuft. Er ist unerreichbar, *weil* CFGMON
595verfahren/aar/2026-08-01-labnet02-cfgmon.md65informationalnet-ref:10.58.75.2eintragen (`Networks behind client = 10.0.0.0/24`, Client-IP `10.58.75.2`):
596verfahren/aar/2026-08-01-labnet02-cfgmon.md74informationalnet-ref:10.0.0.31. `ip -brief addr show enp7s0` → UP mit `10.0.0.3`
597verfahren/aar/2026-08-01-labnet02-cfgmon.md75informationalnet-ref:10.0.0.0/8;runtime-path:/162. `ip route | grep '^10\.'` → neue Route sollte `10.0.0.0/8` zeigen, nicht mehr `/16`
598verfahren/aar/2026-08-01-labnet02-cfgmon.md85prose-or-runtime**Entscheidung offen:** ob der Root-Zugang über die docker-Gruppe so bleiben soll
599verfahren/aar/2026-08-01-labnet02-cfgmon.md115informationalruntime-path:/etc/systemd/system/wg-quick@lab.service.d/10-after-docker.conf1. Drop-in `/etc/systemd/system/wg-quick@lab.service.d/10-after-docker.conf` mit
600verfahren/aar/2026-08-01-labnet02-cfgmon.md118prose-or-runtime`PostUp = iptables -N DOCKER-USER 2>/dev/null || true` — Rückfall, falls Docker
601verfahren/aar/2026-08-01-labnet02-cfgmon.md121prose-or-runtimeVerifiziert: `systemctl show -p After` listet `docker.service`, `restart` läuft sauber
602verfahren/aar/2026-08-01-labnet02-cfgmon.md123prose-or-runtimehistorical-wordingkorrekt ab, keine Dubletten bei Neustarts). **Nicht verifiziert:** das Verhalten bei
603verfahren/aar/2026-08-01-labnet02-cfgmon.md143checked-okissue-ok:management#2(opened)(`oFRxWU…Z0o=`, Kommentar 399 in `management#2`) **gehört zu keinem Server auf der
604verfahren/aar/2026-08-01-labnet02-cfgmon.md145informationalid-ok:LABNET-02historical-wording`wgsrv3 = sVuM0pgT…ZyM=` (LABNET-02, 51841). Jede Initiation von CFGMON war damit
605verfahren/aar/2026-08-01-labnet02-cfgmon.md158informationalruntime-path:~lab.de;runtime-path:~axion1337.de;runtime-path:~axionlabs.de;net-ref:10.58.73.1`~lab.de`, `~axion1337.de`, `~axionlabs.de` über `10.58.73.1`; aXionLabs-Root-CA
606verfahren/aar/2026-08-01-labnet02-cfgmon.md159prose-or-runtimeim Truststore (verifiziert gegen die git.lab-Kette und per Fingerprint-Abgleich
607verfahren/aar/2026-08-01-labnet02-cfgmon.md160prose-or-runtimegegen die step-ca, Port 666). Voller Dienst-Neustart aus der Datei verifiziert
608verfahren/aar/2026-08-01-labnet02-cfgmon.md170prose-or-runtime**Offen nach diesem Nachtrag:** Testreihe 1–7 (inkl. Gateway-Rolle), Reboot-Beweis,
609verfahren/aar/2026-08-01-labnet02-cfgmon.md171informationalforge-repo:sorb/bufferSchlüsselrotation (Client-Private-Key lief beim Bootstrap über `sorb/buffer` auf
610verfahren/aar/2026-08-01-labnet02-cfgmon.md172prose-or-runtimerohana; Repo wird laut sorb vernichtet, Rotation danach trotzdem empfohlen),
611verfahren/aar/2026-08-01-labnet02-cfgmon.md173FLAGpath-miss:lab.confpath-miss:lab.confRepo-Zuhause für `lab.conf` + systemd-Drop-in (zurückgestellt bis nach der
612verfahren/aar/2026-08-01-labnet02-cfgmon.md181informationalruntime-path:git.labSplit-DNS-Zonen aktiv; `git.lab` auflösbar und pingbar. Damit sind der Bootfix
613verfahren/aar/2026-08-01-labnet02-cfgmon.md183prose-or-runtimeaus Nachtrag 2 im Ernstfall verifiziert. Aus der Offen-Liste von Nachtrag 2
614verfahren/aar/2026-08-01-labnet02-lab.md1informationalid-ok:LABNET-02# AAR — LABNET-02, Lab-Seite (UDM/UniFi, Einzäunung und Abnahme)
615verfahren/aar/2026-08-01-labnet02-lab.md5checked-okissue-ok:management#12(closed)**Gegenstück:** [CFGMON-Seite](2026-08-01-labnet02-cfgmon.md) · Issue: `management#12`
616verfahren/aar/2026-08-01-labnet02-lab.md14checked-okissue-ok:management#12(closed)Testreihe 1–7 vollständig bestanden (Protokolle in `management#12`), zusätzlich der
617verfahren/aar/2026-08-01-labnet02-lab.md23informationalnet-ref:10.0.0.0/24UDM (Port 51841), **CFGMON als Client/Initiator**, `10.0.0.0/24` als Netz hinter dem
618verfahren/aar/2026-08-01-labnet02-lab.md38informationalnet-ref:10.0.0.0/16;net-ref:10.58.73.0/24;net-ref:10.0.0.0/8| 5 | Hetzner-Netz-Range `10.0.0.0/16` deckte das Routen-Ziel `10.58.73.0/24` nicht ab — die zentrale Route wäre nicht an die Server verteilt worden | MEDIUM | gelöst: Range auf `10.0.0.0/8` erweitert
619verfahren/aar/2026-08-01-labnet02-lab.md43informationalnet-ref:10.58.75.2;net-ref:10.0.0.3historical-wording`10.58.75.2` (Tunnel) *und* `10.0.0.3` (Hetzner-Netz) erreichbar. Vom Lab aus war die
620verfahren/aar/2026-08-01-labnet02-lab.md44prose-or-runtimeerste Adresse geblockt, die zweite offen — dieselbe Maschine, dieselben Dienste,
621verfahren/aar/2026-08-01-labnet02-lab.md75prose-or-runtime- IoT- und Arbeit-Sperren sind **nicht verifiziert** — keine Gegenstelle in diesen
622verfahren/aar/2026-08-01-labnet02-lab.md77informationalid-ok:LABNET-02- Regel-Beschreibungsfelder in UniFi sind leer; Verweis auf LABNET-02/ADR-0004 fehlt.
623verfahren/aar/2026-08-01-labnet02-lab.md80prose-or-runtimeGitea-Ausnahme in ADR-0002/README/CLAUDE.md zurückbauen.
624verfahren/aar/2026-08-02-wiki-und-desktop-clients.md12informationalruntime-path:axionwiki.lab| Docusaurus-Wiki unter `axionwiki.lab` | ✅ live, eigenes Zertifikat |
625verfahren/aar/2026-08-02-wiki-und-desktop-clients.md13informationalforge-repo:homelab/wiki-bookstack| BookStack als Gegenentwurf (`homelab/wiki-bookstack`) | ✅ live unter `bookstack.lab` |
626verfahren/aar/2026-08-02-wiki-und-desktop-clients.md14prose-or-runtime| 11 neue Themes (aXion1337 Light + 10 Paletten) | ✅ Web live, in allen Clients — ⚠️ **Paletten waren falsch**, korrigiert → [Nachtrag](#nachtrag-2026-08-02--die-paletten-waren-erfunden) |
627verfahren/aar/2026-08-02-wiki-und-desktop-clients.md15prose-or-runtime| Desktop-Clients Linux/Windows/macOS | ✅ Release `desktop-1.12.17-themes` |
628verfahren/aar/2026-08-02-wiki-und-desktop-clients.md22checked-okpath-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir);path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir);issue-ok:management#19(opened)historical-wording| 1 | **Drei auseinandergelaufene Dokustände**: Gitea-Wiki-Repo (gepflegt, nicht gespiegelt), `wiki`-Branch im gitops-Repo (Mai-Abzug von `docs/`), `docs/` im main. Das Wiki enthielt sachlich Falsches
629verfahren/aar/2026-08-02-wiki-und-desktop-clients.md24FLAGruntime-path:/favicon.ico;path-miss:text/htmlpath-miss:text/html| 3 | **`/favicon.ico` lieferte HTTP 200 mit `text/html`** — die nginx-`try_files`-Kette gab die 404-Seite mit Erfolgsstatus aus. Safari hielt das Icon für vorhanden und zeigte den Buchstaben-Fallback
630verfahren/aar/2026-08-02-wiki-und-desktop-clients.md27checked-okpath-ok:res/vector-icons/@ThreadNet-Web(dir);path-ok:manifest.json@ThreadNet-Web| 6 | **Nur macOS bekam neue Icons** — Windows (`.ico`) und Web (`res/vector-icons/`, `manifest.json`) blieben auf Element | MEDIUM | gelöst, `c51b681` |
631verfahren/aar/2026-08-02-wiki-und-desktop-clients.md29checked-okissue-ok:management#21(opened)historical-wording| 8 | **Windows-Build-VM war weg** (`No such container`) — der CI-Job kann sie nur starten, nicht anlegen | MEDIUM | umgangen (manueller Neustart), Optionen in #21 |
632verfahren/aar/2026-08-02-wiki-und-desktop-clients.md30checked-okissue-ok:management#22(opened)| 9 | **macOS-Build braucht Xcode** für das DMG (`actool`) und Rust für die nativen Module | MEDIUM | umgangen (electron-builder 25 fürs ZIP, `hdiutil` fürs DMG), dauerhaft offen in #22 |
633verfahren/aar/2026-08-02-wiki-und-desktop-clients.md67prose-or-runtimeRelease-Notes stand ein Link auf ein Issue, das ich nie angelegt hatte (fiel
634verfahren/aar/2026-08-02-wiki-und-desktop-clients.md79informationalruntime-path:/login| 3 | **Healthcheck auf `/login` schlug fehl → Container `unhealthy` → Traefik überspringt ihn komplett** | Default-Zertifikat + leeres 404, **identisch zum Bild eines fehlenden Netzes** |
635verfahren/aar/2026-08-02-wiki-und-desktop-clients.md86prose-or-runtimeim laufenden Container verifiziert wurde, ist damit kein Sicherheitsnetz, sondern
636verfahren/aar/2026-08-02-wiki-und-desktop-clients.md87informationalruntime-path:/status;runtime-path:/loginein Risiko. Ich hatte ihn zweimal ungeprüft geändert (`/status` → `/login`).
637verfahren/aar/2026-08-02-wiki-und-desktop-clients.md91informationalruntime-path:/opt`/opt`-Pfad — und die CI braucht `VARIANT_PATH`, sonst greift die Variante gar
638verfahren/aar/2026-08-02-wiki-und-desktop-clients.md98prose-or-runtimeTest, ein Issue-Verweis ohne Existenzprüfung, ein Icon-Skript ohne Blick aufs
639verfahren/aar/2026-08-02-wiki-und-desktop-clients.md104checked-okissue-ok:management#20(opened);id-ok:DOC-03- **Entscheidung DOC-03 (#20)**: Docusaurus oder BookStack — beide laufen jetzt,
640verfahren/aar/2026-08-02-wiki-und-desktop-clients.md109checked-okissue-ok:management#22(opened);issue-ok:management#21(opened)- **macOS reproduzierbar bauen** (#22), **Windows-VM-Robustheit** (#21).
641verfahren/aar/2026-08-02-wiki-und-desktop-clients.md111checked-okissue-ok:ThreadNet-Web#6(opened)Signing (ThreadNet-Web#6) — ohne Signatur bleibt für Nutzer auf macOS der
642verfahren/aar/2026-08-02-wiki-und-desktop-clients.md118prose-or-runtimehistorical-wording**Was war.** Die zehn Themes aus dem Rollout trugen nicht die Farben aus Anthropics
643verfahren/aar/2026-08-02-wiki-und-desktop-clients.md126prose-or-runtime**Warum es nicht auffiel.** Erfundene Farben sehen nicht falsch aus. Ein Theme
644verfahren/aar/2026-08-02-wiki-und-desktop-clients.md131prose-or-runtime**Falle für die nächste Runde.** Ob ein Theme hell oder dunkel gemeint ist, steht
645verfahren/aar/2026-08-02-wiki-und-desktop-clients.md135checked-okpath-ok:shared/branding.md@managementstehen in [`shared/branding.md`](../../shared/branding.md).
646verfahren/aar/2026-08-02-wiki-und-desktop-clients.md144prose-or-runtimeSunset-Boulevard-Palette sind bis auf zwei Ziffern identisch (`#e76e51`/`#e76f51`,
647verfahren/aar/2026-08-02-wiki-und-desktop-clients.md145prose-or-runtime`#f3a261`/`#f4a261`) — unabhängig voneinander auf demselben Coolors-Satz gelandet.
648verfahren/aar/2026-08-02-wiki-und-desktop-clients.md147prose-or-runtime**Korrigiert:** gitops `b10b607` (Web, live verifiziert) · ThreadNet-Web `80fcf6c`
649verfahren/aar/2026-08-02-wiki-und-desktop-clients.md150FLAGpath-miss:resources/webapp.asarpath-miss:resources/webapp.asarstecken in `resources/webapp.asar`. Abgestimmt so belassen; der nächste reguläre
650verfahren/aar/2026-08-02-wiki-und-desktop-clients.md151checked-okimage-ref:status:wartet;issue-ok:ThreadNet-Web#11(opened)historical-wordingBuild zieht die Korrektur mit (nachgehalten in ThreadNet-Web#11, `status:wartet`).
651verfahren/aar/2026-08-09-refinement-und-betrieb.md3prose-or-runtime**Datum:** 2026-08-09 · **Host/Stack:** git.lab, Gitea, K3s-Cluster (Authentik,
652verfahren/aar/2026-08-09-refinement-und-betrieb.md9prose-or-runtime**Live und verifiziert:**
653verfahren/aar/2026-08-09-refinement-und-betrieb.md17prose-or-runtime- 251 Commits über vier Repos auf 12:00-UTC-Zeitstempel umgeschrieben, Force-
654verfahren/aar/2026-08-09-refinement-und-betrieb.md18prose-or-runtimegepusht, Mirrors und Flux verifiziert synchron
655verfahren/aar/2026-08-09-refinement-und-betrieb.md20prose-or-runtimevorher unbekannte Repos ohne Push-Mirror
656verfahren/aar/2026-08-09-refinement-und-betrieb.md21prose-or-runtime- `game-operating` gespiegelt und secret-frei verifiziert (Coolify-
657verfahren/aar/2026-08-09-refinement-und-betrieb.md26prose-or-runtime**Bewusst nicht live:**
658verfahren/aar/2026-08-09-refinement-und-betrieb.md33prose-or-runtime- `gameserver` weiterhin ohne Mirror — zwei Repos gleichen Namens mit
659verfahren/aar/2026-08-09-refinement-und-betrieb.md40prose-or-runtime| 1 | `matrix-recovery-flow`-Blueprint scheiterte seit Tagen bei jedem Lauf, während Flux grün meldete | HIGH | behoben |
660verfahren/aar/2026-08-09-refinement-und-betrieb.md42checked-okpath-ok:develop/config.json@ThreadNet-Web| 3 | Web-Client sendete Fehlerberichte an `rageshakes.element.io` — die Desktop-Bereinigung vom 2026-08-01 hatte den Web-Build nie erreicht, weil der beim Bauen Elements eigene `develop/config.json`
661verfahren/aar/2026-08-09-refinement-und-betrieb.md43checked-okissue-ok:management#32(opened)| 4 | `game-operating` und `gameserver` ohne Push-Mirror; bei `gameserver` liegt auf Gitea ein anderer Stand als auf git.lab | MEDIUM | `game-operating` behoben, `gameserver` offen (management#32) |
662verfahren/aar/2026-08-09-refinement-und-betrieb.md44prose-or-runtime| 5 | Nach dem Privat-Stellen von `game-operating` auf Gitea übersprang die Stillstandsprüfung den Mirror-Abgleich klaglos, statt es als Befund zu werten | MEDIUM | behoben |
663verfahren/aar/2026-08-09-refinement-und-betrieb.md46prose-or-runtime| 7 | Gitops-Leitfaden 04 nannte 7 Themes mit teils erfundenen Namen (`Gruvbox Dark`, `Wal`); tatsächlich 17 | LOW | behoben |
664verfahren/aar/2026-08-09-refinement-und-betrieb.md47prose-or-runtime| 8 | threadnet-call-Doku beschrieb einen manuellen npm-Publish, der seit 2026-08-06 automatisiert läuft | LOW | behoben |
665verfahren/aar/2026-08-09-refinement-und-betrieb.md50checked-okissue-ok:ThreadNet-Web#14(closed);tag-ok:v0.4.0historical-wording| 11 | Tag-Push (Force, für die Historien-Anonymisierung) löste in ThreadNet-Web drei Release-Pipelines neu aus; nur weil die geschützten Registry-Variablen im Zeitfenster fehlten, wurde `v0.4.0` nich
666verfahren/aar/2026-08-09-refinement-und-betrieb.md54prose-or-runtime- **`game-operating` öffentlich auf Gitea** — Secret-Scan über alle fünf
667verfahren/aar/2026-08-09-refinement-und-betrieb.md68checked-okissue-ok:management#1(opened)Flux-Status.** Blueprint-Fehler #1/#2 waren nur so sichtbar — Flux, die
668verfahren/aar/2026-08-09-refinement-und-betrieb.md69prose-or-runtimeConfigMap und der Cluster-Zustand insgesamt meldeten durchgehend grün.
669verfahren/aar/2026-08-09-refinement-und-betrieb.md71checked-okissue-ok:management#2(opened)verdeckten Fehler #2 erst zugänglich gemacht — der reguläre Weg (Worker-Log)
670verfahren/aar/2026-08-09-refinement-und-betrieb.md74checked-okissue-ok:management#3(opened)zu glauben** hat Befund #3 aufgedeckt — die Annahme im Issue betraf nur den
671verfahren/aar/2026-08-09-refinement-und-betrieb.md75checked-okpath-ok:config.json@ThreadNet-WebDesktop-Client, `config.json` auf dem Web-Server sagte etwas anderes.
672verfahren/aar/2026-08-09-refinement-und-betrieb.md77checked-okissue-ok:management#4(opened)Befund #4 im ersten Lauf gefunden — eine dynamische Projektliste statt einer
673verfahren/aar/2026-08-09-refinement-und-betrieb.md78prose-or-runtimeim Code gepflegten hat zwei Repos zutage gebracht, die niemand auf dem
674verfahren/aar/2026-08-09-refinement-und-betrieb.md84prose-or-runtime251 Paaren über Tree *und* Commit-Nachricht verifiziert, keine Annahme.
675verfahren/aar/2026-08-09-refinement-und-betrieb.md90checked-okissue-ok:management#32(opened)- **`gameserver`-Mirror** — Standklärung nötig, management#32
676verfahren/aar/2026-08-09-refinement-und-betrieb.md91prose-or-runtime- **Stillstandsprüfung Authentik-Teil** — `AUTHENTIK_URL`/`AUTHENTIK_TOKEN`,
677verfahren/aar/2026-08-09-refinement-und-betrieb.md92checked-okissue-ok:management#31(opened)management#31, bewusst aufgeschoben (sorb, 2026-08-09)
678verfahren/aar/2026-08-09-refinement-und-betrieb.md94checked-okissue-ok:ThreadNet-Web#9(opened)entschieden, ThreadNet-Web#9
679verfahren/aar/2026-08-09-refinement-und-betrieb.md100checked-okpath-ok:decisions/@management(dir)Lehre aus der Retro, in `decisions/` dokumentiert
680verfahren/deploy-uebergabe.md6checked-okissue-ok:axion1337.chat-gitops#47(opened)Eingeführt am 2026-08-01 nach dem Deploy der CVE-Pipeline (`gitops#47`), siehe
681verfahren/deploy-uebergabe.md11prose-or-runtime1. Wer baut, öffnet **auf git.lab** ein Issue aus der Vorlage **Deploy-Übergabe**
682verfahren/deploy-uebergabe.md12checked-okpath-ok:.gitlab/issue_templates/Deploy-Übergabe.md@management(`.gitlab/issue_templates/Deploy-Übergabe.md`, im Feld *Description template*).
683verfahren/deploy-uebergabe.md51checked-okissue-ok:axion1337.chat-gitops#52(opened)`--force-recreate`. Details: `gitops#52`.
684verfahren/deploy-uebergabe.md55prose-or-runtimehistorical-wordingDatensammlung und Außenwirkung lassen sich fast immer getrennt scharf schalten.
685verfahren/deploy-uebergabe.md71prose-or-runtime- [ ] Nach dem Deploy **im Container** verifiziert, dass die neue Config aktiv ist
686verfahren/deploy-uebergabe.md83prose-or-runtimedirekt auf dem Gitea-Mirror und werden vom nächsten Mirror-Lauf **kommentarlos
687verfahren/deploy-uebergabe.md89informationalruntime-path:https://rohana.axion1337.de/sorb/<repo>/commit/<sha>.patch`https://rohana.axion1337.de/sorb/<repo>/commit/<sha>.patch` ziehen
688verfahren/deploy-uebergabe.md92prose-or-runtime3. **CFGMON** vor dem nächsten Pull: `git fetch && git reset --hard origin/main`
689verfahren/issue-migration/README.md1checked-okissue-ok:axion1337.chat-gitops#48(opened)# Issue-Migration Gitea → GitLab (gitops#48)
690verfahren/issue-migration/README.md3checked-okpath-ok:migrate.py@management`migrate.py` überführt Issues (offen **und** geschlossen, inkl. Kommentare)
691verfahren/issue-migration/README.md4prose-or-runtimeeines Gitea-Repos in ein bestehendes GitLab-Projekt. Einmal-Werkzeug für den
692verfahren/issue-migration/README.md5FLAGissue-miss:management#48issue-miss:management#48#48-Cutover; hier versioniert wegen Reproduzierbarkeit.
693verfahren/issue-migration/README.md10informationalimage-ref:<!-- gitea-migration: OWNER/REPO#N -->- **Idempotent** über Marker `<!-- gitea-migration: OWNER/REPO#N -->` in der
694verfahren/issue-migration/README.md16informationalimage-ref:host:*2026-08-01 sind die 9 Gitea-Labels + 5 `host:*` als Gruppe-13-Labels angelegt)
695verfahren/issue-migration/README.md17prose-or-runtime- PRs werden ausgefiltert, geschlossene Issues nach Anlage geschlossen
696verfahren/issue-migration/README.md26informationalruntime-path:~/.config/gitea-rohana/tokenTokens: `~/.config/gitea-rohana/token` (read:issue) und
697verfahren/issue-migration/README.md27informationalruntime-path:~/.config/gitlab-lab/token`~/.config/gitlab-lab/token` (Admin) auf dem Mac.
698verfahren/issue-migration/README.md33prose-or-runtime| sorb/thread-net-git | Projekt 18 | ✅ 2026-08-01 (1 Issue, nummerngleich) |
699verfahren/issue-migration/README.md34prose-or-runtime| sorb/threadnet-call | Projekt 19 | ✅ 2026-08-01 (2 Issues, nummerngleich) |
700verfahren/issue-migration/README.md35prose-or-runtime| sorb/ThreadNet-Web | Projekt 16 | ✅ 2026-08-01 (9 Issues, nummerngleich) |
701verfahren/issue-migration/README.md36prose-or-runtime| sorb/axion1337.chat-gitops | Projekt 17 | ✅ 2026-08-01 (50 Issues, **Nummern verschoben**) |
702verfahren/issue-migration/README.md38prose-or-runtime⚠️ **gitops-Nummern sind NICHT deckungsgleich**: Gitea hatte Lücken (PRs zählen
703verfahren/issue-migration/README.md39prose-or-runtimemit), GitLab vergibt lückenlos — z. B. Gitea#48 → GitLab#46, Gitea#51 → GitLab#49,
704verfahren/issue-migration/README.md40prose-or-runtimeGitea#52 → GitLab#50. Die verbindliche Zuordnung steht im Migrations-Fußtext
705verfahren/issue-migration/README.md41prose-or-runtimehistorical-wordingjedes GitLab-Issues (`Migriert aus Gitea …#N`); alte Commit-/Doku-Verweise auf
706verfahren/issue-migration/README.md44checked-okissue-ok:axion1337.chat-gitops#48(opened)**Cutover-Nachschritte** (siehe gitops#48): Gitea-Issues schließen/als migriert
707verfahren/issue-migration/README.md47prose-or-runtimeaktiven), Bot-/Token-Workflows (claude-issues → GitLab-Äquivalent) offen.
708verfahren/refinement.md20prose-or-runtimedes Monats an — dann ist die Vorbereitung (die AARs des Monats) ohnehin offen.
709verfahren/refinement.md29prose-or-runtime2. **WIP-Limit prüfen** — höchstens zwei Issues in `doing`. Ist es voll, wird nichts
710verfahren/refinement.md44prose-or-runtime- Welche **ADRs** sind durch die Realität überholt (→ neues ADR, altes auf
711verfahren/refinement.md51checked-okpath-ok:retro/@management(dir)Ergebnisse werden unter [`retro/`](retro/) abgelegt, eine Datei je Termin. Die
712verfahren/refinement.md59prose-or-runtimeermöglicht, welche Lehren, was bleibt offen. **Offene Punkte aus einem AAR werden
713verfahren/refinement.md61checked-okissue-ok:management#14(opened);issue-ok:management#16(closed)2026-08-01, nachgezogen als #14–#16).
714verfahren/refinement.md88checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,management- Die **kanonischen Arbeitskonventionen** stehen in [`CLAUDE.md`](../CLAUDE.md) und
715verfahren/refinement.md89prose-or-runtimesind über den Gitea-Mirror von überall lesbar.
716verfahren/retro/2026-08-09.md15prose-or-runtimevergessen, weil sie im Moment des Findens ein Issue bekamen — auch die, für die
717verfahren/retro/2026-08-09.md23checked-okissue-ok:management#15(opened);issue-ok:management#20(opened)historical-wordingmanagement#15 und #20 lagen drei Tage ohne Spalte — das ist der beabsichtigte
718verfahren/retro/2026-08-09.md31informationalimage-ref:status:offenmuss. Genau deshalb hat eine Session am 2026-08-06 ein `status:offen` erfunden und
719verfahren/retro/2026-08-09.md40prose-or-runtime## 2. Welche ADRs sind durch die Realität überholt?
720verfahren/retro/2026-08-09.md42prose-or-runtime**Keine überholt — aber eine Lücke.**
721verfahren/retro/2026-08-09.md45prose-or-runtimegebraucht.** Am 2026-08-07 wurde eine dauerhafte Prozessregel eingeführt (englische
722verfahren/retro/2026-08-09.md46prose-or-runtimeConventional Commits, Zeitstempel auf 12:00 UTC) und am 2026-08-09 rückwirkend auf
723verfahren/retro/2026-08-09.md47prose-or-runtime251 Commits angewandt — eine **irreversible** Änderung an vier Repos, mit
724verfahren/retro/2026-08-09.md48prose-or-runtimeForce-Push durch einen Mirror, von dem Flux liest.
725verfahren/retro/2026-08-09.md51checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,managementist das ein Lehrbuchfall. Stattdessen steht die Regel nur in der `CLAUDE.md` und
726verfahren/retro/2026-08-09.md55checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,managementerweitert (Titel ohne Priorität, Meilenstein-Pflicht) — beides in der `CLAUDE.md`,
727verfahren/retro/2026-08-09.md57checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,managementdie `CLAUDE.md` die *Regel*. Es ist aber genau die Zwei-Orte-Konstruktion, die wir
728verfahren/retro/2026-08-09.md70prose-or-runtime| `build_embedded` (threadnet-call) | grün, seit jeher | lud **nie** ein Artefakt hoch, falscher Pfad |
729verfahren/retro/2026-08-09.md71FLAGpath-miss:dist/path-miss:dist/| npm-Paket `0.19.2-threadnet.6` | veröffentlicht | 12,5 KB statt 12,8 MB, **ohne `dist/`** |
730verfahren/retro/2026-08-09.md72prose-or-runtime| Blueprint `matrix-recovery-flow` | Flux grün, ConfigMap aktuell | seit Tagen bei **jedem** Lauf verworfen |
731verfahren/retro/2026-08-09.md74prose-or-runtime| Leere Pipelines | rot | **nichts kaputt** — der umgekehrte Fall, Rauschen, das rot abtrainiert |
732verfahren/retro/2026-08-09.md75informationaltag-ok:v0.4.0| Release-Pipeline auf `v0.4.0` | lief nach Tag-Push an | hätte ein veröffentlichtes Image überschrieben |
733verfahren/retro/2026-08-09.md87checked-okissue-ok:axion1337.chat-gitops#50(opened)Es gibt Issues für Einzelfälle — gitops#50 (Configs greifen nicht ohne Neustart),
734verfahren/retro/2026-08-09.md88checked-okissue-ok:management#28(opened);issue-ok:ThreadNet-Web#14(closed)management#28 (Mirror-Ausfall unbemerkt), ThreadNet-Web#14 (Release überschreibbar,
735verfahren/retro/2026-08-09.md91informationaltag-ok:v0.4.0⚠️ **Der letzte Fall ist der unangenehmste.** Dass `v0.4.0` nicht überschrieben
736verfahren/retro/2026-08-09.md99prose-or-runtimediesen Monat einzeln und mühsam gelernt haben — Blueprint-Status ≠ error, Mirror
737verfahren/retro/2026-08-09.md103checked-okissue-ok:management#28(opened)Das ist die Verallgemeinerung von management#28, das am 2026-08-06 bewusst nach
738verfahren/retro/2026-08-09.md112checked-okimage-ref:status:next;issue-ok:management#15(opened);issue-ok:management#20(opened)- `status:next`: management#15 und #20 (fällig 31.08.) — Zusage von sorb
739verfahren/retro/2026-08-09.md113checked-okimage-ref:status:wartet;issue-ok:threadnet-call#4(opened);issue-ok:ThreadNet-Web#11(opened)historical-wording- `status:wartet` entfernt bei threadnet-call#4 und ThreadNet-Web#11: der im Issue
740verfahren/retro/2026-08-09.md115prose-or-runtime- **M5 — Härtung** angelegt, 14 Issues aus M1 verschoben. Trennlinie: *Ist etwas
741verfahren/retro/2026-08-09.md123prose-or-runtime## Offen aus dieser Retro
742verfahren/stillstandspruefung.md11prose-or-runtimeder bei jedem Lauf verworfen wurde, während Flux grün meldete.
743verfahren/stillstandspruefung.md23prose-or-runtime| Repo ohne aktiven Push-Mirror | `game-operating` wurde angelegt und nie gespiegelt — auf Gitea existierte es nicht |
744verfahren/stillstandspruefung.md24checked-okissue-ok:management#28(opened);id-ok:MIRROR-01| Mirror-Drift | MIRROR-01 (management#28): fällt der Mirror aus, liefert Flux still den letzten Stand weiter |
745verfahren/stillstandspruefung.md25prose-or-runtimehistorical-wording| Pipeline mit null Jobs | ThreadNet-Web 203/204, threadnet-call 187 — rot, ohne dass etwas kaputt war |
746verfahren/stillstandspruefung.md26prose-or-runtime| Erfolgreicher Job ohne Artefakt | `build_embedded` lief seit jeher grün und lud **nichts** hoch |
747verfahren/stillstandspruefung.md27FLAGpath-miss:dist/path-miss:dist/| npm-Paket zu klein | `0.19.2-threadnet.6`: 12,5 KB statt 12,8 MB, ohne `dist/` |
748verfahren/stillstandspruefung.md32prose-or-runtimejahrelang durchrutscht. (Beim ersten Lauf kamen so zwei Projekte zum Vorschein,
749verfahren/stillstandspruefung.md37prose-or-runtimeGeplanter CI-Job im management-Repo, zusätzlich von Hand über *Run pipeline*
750verfahren/stillstandspruefung.md38prose-or-runtimeauslösbar. Befunde färben die Pipeline **rot** — das ist bei uns die Alarmanlage,
751verfahren/stillstandspruefung.md39checked-okpath-ok:CLAUDE.md@axion1337.chat-gitopsnicht ein zusätzlicher Meldeweg (siehe `gitops/CLAUDE.md` zur TURN-Rotation).
752verfahren/stillstandspruefung.md45code-blockexport GITEA_TOKEN=$(cat ~/.config/gitea-rohana/push-token) # fuer private Spiegel
753verfahren/stillstandspruefung.md53prose-or-runtimeaufgefallen am 2026-08-09: `game-operating` wurde auf Gitea privat gestellt, und
754verfahren/stillstandspruefung.md54prose-or-runtimedie Prüfung übersprang den Mirror-Abgleich klaglos. Ein Repo, das gespiegelt wird,
755verfahren/textbloecke.md5checked-okpath-ok:CLAUDE.md@axion1337.chat-gitops,managementDie Konventionen stehen kanonisch in [`CLAUDE.md`](../CLAUDE.md) — aber eine
756verfahren/textbloecke.md14checked-okpath-ok:CLAUDE.md@managementwährend die `management/CLAUDE.md` zwei nannte.
757verfahren/textbloecke.md24code-blockhistorical-wordingLies zuerst CLAUDE.md im management-Repo auf git.lab und halte dich daran.
758verfahren/textbloecke.md25code-blockKanonisch ist git.lab; nie direkt nach Gitea pushen.
759verfahren/textbloecke.md27code-blockBevor du ein Issue schließt oder darüber urteilst: vollständig lesen, inklusive
760verfahren/textbloecke.md30code-blockVerifiziert und vermutet klar trennen; fremde Messungen als fremde kennzeichnen.
761verfahren/textbloecke.md35informationalforge-repo:sorb/Backlogs> dem Pfad `sorb/Backlogs` statt nach dem Namen `Backlogs`; und ein Issue, von dem
762verfahren/textbloecke.md43code-blockKonventionen: CLAUDE.md im management-Repo — von hier lesbar über den Gitea-Mirror
763verfahren/textbloecke.md44code-blockrohana.axion1337.de/sorb/management. Dort NUR lesen, niemals hinpushen.
764verfahren/textbloecke.md48code-blockPing auf 10.58.73.17 schlägt IMMER fehl (nur 443 + DNS offen), das ist kein
765verfahren/textbloecke.md64code-block· Außenwirkung und Not-Aus · Rollback · bewusst offen Gelassenes.
766verfahren/textbloecke.md79code-block- Alle Commits über git.lab gepusht, kein Rest im Arbeitsverzeichnis, Mirror grün.
767verfahren/textbloecke.md80code-block- Jeder offene Punkt und Nebenbefund ist ein Issue — nichts bleibt nur im Chat.
768vision/axion1337-chat.md3checked-okissue-ok:management#17(closed)> **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17).
769vision/axion1337-chat.md23prose-or-runtime**Kontrolliert wachsend** (entschieden 2026-08-06). Offen für Neue, aber **jeder
770vision/axion1337-chat.md37prose-or-runtimeNicht mehr offen: Das Rebranding wird in **M4 zu Ende gebracht**, nicht separat
771vision/axion1337-chat.md38checked-okpath-ok:threadnet.md@managementterminiert — siehe [`threadnet.md`](threadnet.md).
772vision/homelab.md3checked-okissue-ok:management#17(closed)> **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17).
773vision/homelab.md33checked-okissue-ok:management#10(opened)[#10](https://git.lab/axion1337.chat/management/-/issues/10) — offen bleibt
774vision/homelab.md35prose-or-runtimeGitea-Datenbank). Siehe dort.
775vision/threadnet.md3checked-okissue-ok:management#17(closed)> **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17).
776vision/threadnet.md9prose-or-runtimewiederverwendbare Produkte gedacht: ThreadNet-Web (Element-Web-Fork mit
777vision/threadnet.md10prose-or-runtimeDiscord-artiger Raumliste), threadnet-call (Call-Fork), thread-net-git,
778vision/threadnet.md11prose-or-runtimethreadnet-operating.
779vision/threadnet.md37prose-or-runtimeund entscheiden, ob bereinigt (History-Rewrite) oder bewusst akzeptiert wird.