verify_claims.py gives all 813 claim rows a mechanical disposition; the 28 flags were adjudicated by hand (REPORT.md appendix). Two survived as genuine drift (F-017): a closed issue still described as open in shared/lab-netzwerk.md, and a 'pending' decision block in hosts/cfgmon.md whose premise the same file records as executed. Also: narrow the vendored-path filter (it silently dropped 7 tracked icon files and produced false path-miss flags), record the confirmed canonical author identity in F-003, verify the Gitea#48->GitLab#46 numbering shift by title in F-005, and add the ADR-0010 draft under analysis/drafts/ for the human to git-mv into decisions/. Branch renamed to Neckbeard-v0.1.1-analyse-1 per the human.
124 KiB
124 KiB
| 1 | path | line | status | checks | flags | hint | claim_text |
|---|---|---|---|---|---|---|---|
| 2 | .gitlab/issue_templates/Deploy-Übergabe.md | 14 | prose-or-runtime | Beispiel: axion1337.chat/threadnet-operating @ main, b6007c5 --> | |||
| 3 | .gitlab/issue_templates/Deploy-Übergabe.md | 67 | prose-or-runtime | historical-wording | Datensammlung und Zustellung getrennt scharf zu schalten ist fast immer | ||
| 4 | .gitlab/issue_templates/Deploy-Übergabe.md | 75 | prose-or-runtime | ## Bewusst offen gelassen | |||
| 5 | CLAUDE.md | 1 | prose-or-runtime | # CLAUDE.md — übergreifende Arbeitskonventionen (kanonisch) | |||
| 6 | CLAUDE.md | 4 | prose-or-runtime | Gruppe (axion1337.chat-Stack, ThreadNet-Repos, CFGMON/threadnet-operating, | |||
| 7 | CLAUDE.md | 10 | informational | runtime-path:https://rohana.axion1337.de/sorb/management | > Push-Mirror unter `https://rohana.axion1337.de/sorb/management` von überall | ||
| 8 | CLAUDE.md | 11 | prose-or-runtime | > **lesbar** — dort diese Datei und die ADRs nachschlagen. Nur pushen ist tabu. | |||
| 9 | CLAUDE.md | 18 | prose-or-runtime | ## Projektrealitäten (Stand 2026-08-01) | |||
| 10 | CLAUDE.md | 20 | prose-or-runtime | **Das Lab ist die Quelle der Wahrheit** ([ADR-0002](decisions/0002-issues-und-management-ins-lab.md)): | |||
| 11 | CLAUDE.md | 22 | informational | runtime-path:git.lab/axion1337.chat/* | - Kanonische Repos liegen auf `git.lab/axion1337.chat/*` (nur im Lab/VPN | ||
| 12 | CLAUDE.md | 23 | prose-or-runtime | auflösbar). Gitea/rohana wird per **Push-Mirror** beliefert und bleibt | |||
| 13 | CLAUDE.md | 24 | prose-or-runtime | Flux-Source, Container-/npm-Registry und Release-Download | |||
| 14 | CLAUDE.md | 25 | prose-or-runtime | ([ADR-0001](decisions/0001-gitlab-kanonisch-push-mirror.md)). | |||
| 15 | CLAUDE.md | 27 | prose-or-runtime | liegen die *Baupläne*, auf Gitea eine Kopie, die der Cluster **ohne verfügbares | |||
| 16 | CLAUDE.md | 34 | prose-or-runtime | - **Nie direkt zu Gitea pushen** (gespiegelte Repos) — der Mirror überschreibt | |||
| 17 | CLAUDE.md | 36 | prose-or-runtime | - **Gespiegelt wird nur die Gruppe `axion1337.chat`** (die fünf Produkt-Repos und | |||
| 18 | CLAUDE.md | 37 | prose-or-runtime | `management`). Die Gruppe **`homelab`** (`docs`, `wiki`, `wiki-bookstack`) hat | |||
| 19 | CLAUDE.md | 43 | checked-ok | path-ok:verfahren/aar/@management(dir) | `verfahren/aar/` (dieses Repo ist gespiegelt), nicht nur in die READMEs der | ||
| 20 | CLAUDE.md | 45 | prose-or-runtime | - Landet doch ein Commit auf Gitea (z. B. aus einer Host-Session ohne Lab-Route): | |||
| 21 | CLAUDE.md | 48 | prose-or-runtime | von Gitea ziehen, `git am` (erhält Autorschaft), Push über git.lab. | |||
| 22 | CLAUDE.md | 49 | prose-or-runtime | historical-wording | - **Issues leben auf git.lab.** Die alten Gitea-Issues sind geschlossen und | ||
| 23 | CLAUDE.md | 52 | prose-or-runtime | meinen die Gitea-Nummer; verbindlich ist der Migrations-Fußtext im Issue. | |||
| 24 | CLAUDE.md | 54 | prose-or-runtime | TURN-Rotations-CronJob schreibt weiter nach Gitea, weil er im Cluster läuft und | |||
| 25 | CLAUDE.md | 56 | prose-or-runtime | **Die Rotation nicht von Hand nachziehen und den PR nie auf Gitea mergen** — | |||
| 26 | CLAUDE.md | 57 | prose-or-runtime | das erledigt seit 2026-08-02 der geplante CI-Job `canonize_rotation` im | |||
| 27 | CLAUDE.md | 58 | prose-or-runtime | gitops-Repo täglich von git.lab aus. Scheitert er, bleibt die Pipeline rot; | |||
| 28 | CLAUDE.md | 62 | prose-or-runtime | Das gitops-Wiki liegt seit 2026-08-02 auf git.lab (*Wiki*-Reiter im Projekt); | |||
| 29 | CLAUDE.md | 63 | checked-ok | path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir) | ⚠️ der `wiki`-**Branch** im gitops-Repo ist ein überholter Mai-Abzug von `docs/` | ||
| 30 | CLAUDE.md | 65 | informational | forge-repo:homelab/wiki | **axionwiki.lab** ([`homelab/wiki`](https://git.lab/homelab/wiki), Docusaurus) — | ||
| 31 | CLAUDE.md | 72 | prose-or-runtime | - **Alles Offene ist ein Issue** — host-/infra-Scope hier im management-Projekt | |||
| 32 | CLAUDE.md | 73 | informational | image-ref:host:;id-ok:CFGMON-01 | historical-wording | (`host:`-Labels, alte IDs wie `CFGMON-01` bleiben im Titel), Projekt-Scope im | |
| 33 | CLAUDE.md | 74 | checked-ok | path-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir) | jeweiligen Projekt. Kein neues Backlog-Markdown anlegen; `hosts/`/`shared/` | ||
| 34 | CLAUDE.md | 90 | prose-or-runtime | - **Der Titel trägt keine Priorität.** Präfixe wie `[HIGH]`/`[MEDIUM]`/`[LOW]` | |||
| 35 | CLAUDE.md | 92 | informational | id-ok:CFGMON-01 | historical-wording | Alte Kennungen wie `CFGMON-01` bleiben, die benennen den Gegenstand, nicht die | |
| 36 | CLAUDE.md | 94 | prose-or-runtime | ⚠️ Der Grund ist keine Ästhetik: Aus der Gitea-Migration trugen 34 Issues ein | |||
| 37 | CLAUDE.md | 97 | prose-or-runtime | über dieselbe Sache sind schlimmer als eine unvollständige. Bereinigt 2026-08-06. | |||
| 38 | CLAUDE.md | 101 | prose-or-runtime | einzahlt**. Ein Issue ohne Meilenstein taucht in keiner Roadmap-Ansicht auf und | |||
| 39 | CLAUDE.md | 112 | informational | runtime-path:~/.config/gitlab-lab/token | `~/.config/gitlab-lab/token`) oder maskierte CI-Variablen. | ||
| 40 | CLAUDE.md | 116 | prose-or-runtime | ## Commit-Konventionen (seit 2026-08-07) | |||
| 41 | CLAUDE.md | 136 | prose-or-runtime | historical-wording | 📎 Die Umstellung der Alt-Historie am 2026-08-07 hat 251 Commits neue SHAs | ||
| 42 | CLAUDE.md | 138 | checked-ok | path-ok:shared/commit-zuordnung-2026-08-07.md@management | [`shared/commit-zuordnung-2026-08-07.md`](shared/commit-zuordnung-2026-08-07.md) | ||
| 43 | CLAUDE.md | 146 | prose-or-runtime | öffentlichen Gitea-Spiegel. Wer daraus wirklich keine Muster ableitbar haben | |||
| 44 | CLAUDE.md | 151 | prose-or-runtime | - **Aussagen mit Quelle:** Verifiziert (Messung/Konsole) klar von Vermutung | |||
| 45 | README.md | 1 | prose-or-runtime | # management | |||
| 46 | README.md | 8 | prose-or-runtime | historical-wording | *(Bis 2026-08-01 hieß dieses Repo `Backlogs` und führte offene Punkte als | ||
| 47 | README.md | 11 | prose-or-runtime | ## Repo-Topologie (seit 2026-08-01) | |||
| 48 | README.md | 13 | informational | runtime-path:git.lab;forge-repo:axion1337.chat/management | **Kanonisch lebt dieses Repo auf `git.lab`** (`axion1337.chat/management`, nur im | ||
| 49 | README.md | 15 | prose-or-runtime | [ADR-0002](decisions/0002-issues-und-management-ins-lab.md)). | |||
| 50 | README.md | 16 | informational | runtime-path:rohana.axion1337.de/sorb/management | `rohana.axion1337.de/sorb/management` ist ein **Push-Mirror**: git.lab | ||
| 51 | README.md | 17 | prose-or-runtime | überschreibt ihn bei jedem Push per Force. Deshalb **nie direkt zu Gitea | |||
| 52 | README.md | 18 | prose-or-runtime | pushen** — solche Commits gehen beim nächsten Mirror-Lauf verloren (Rettung: | |||
| 53 | README.md | 19 | prose-or-runtime | `.patch` von Gitea ziehen + `git am`, siehe | |||
| 54 | README.md | 22 | prose-or-runtime | historical-wording | **Keine Ausnahmen mehr.** Die **Deploy-Übergabe-Issues** liefen bis 2026-08-02 auf | ||
| 55 | README.md | 23 | informational | runtime-path:git.lab | dem Gitea-Tracker, weil Hosts außerhalb des Labs `git.lab` nicht erreichten. Mit dem | ||
| 56 | README.md | 25 | prose-or-runtime | Grund entfallen — bei eingeschaltetem Tunnel erreicht CFGMON git.lab. Sie sind | |||
| 57 | README.md | 26 | informational | id-ok:LABNET-03 | umgezogen (LABNET-03), der Gitea-Tracker ist leer, die Vorlage liegt als | ||
| 58 | README.md | 33 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | | [`CLAUDE.md`](CLAUDE.md) | **Kanonische Arbeitskonventionen für alle Agenten-Sessions** (Topologie, Framework, Secrets, Karpathy-Guidelines) | | ||
| 59 | README.md | 34 | checked-ok | path-ok:vision/@management(dir) | | `vision/` | Eine Vision je Linie: Community (axion1337.chat), Tool (ThreadNet), Plattform (Homelab) | | ||
| 60 | README.md | 35 | checked-ok | path-ok:roadmap.md@management | historical-wording | | `roadmap.md` | Linien, Meilenstein-Kandidaten, Kadenz — GitLab-Milestones halten den Stand | | |
| 61 | README.md | 36 | checked-ok | path-ok:decisions/@management(dir) | | `decisions/` | ADRs — Pflicht bei Architekturentscheidungen **und dauerhaften Ausnahmen** | | ||
| 62 | README.md | 37 | checked-ok | path-ok:verfahren/@management(dir) | | `verfahren/` | Wie wir arbeiten: [Deploy-Übergabe/DoD](verfahren/deploy-uebergabe.md), [Refinement & Retro](verfahren/refinement.md), [AARs](verfahren/aar/), Werkzeuge | | ||
| 63 | README.md | 38 | checked-ok | path-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir) | | `hosts/`, `shared/` | **Bestand + Historie** je Host/Thema — u. a. [Branding](shared/branding.md) (Marke, Paletten, wo welches Theme eingestellt ist); offene Punkte sind Issues | | ||
| 64 | README.md | 43 | informational | forge-repo:homelab/wiki | [`homelab/wiki`](https://git.lab/homelab/wiki)). **Geändert wird immer hier, nie dort.** | ||
| 65 | README.md | 48 | informational | image-ref:host:;id-ok:CFGMON-01 | historical-wording | `host:`-Labels; die alten IDs wie `CFGMON-01` bleiben im Titel) bzw. in den | |
| 66 | README.md | 64 | informational | id-ok:CFGMON-01;id-ok:ZONE-01 | **IDs** (`CFGMON-01`, `ZONE-01`, …) werden **nie wiederverwendet**; sie leben in | ||
| 67 | README.md | 72 | prose-or-runtime | **Erledigtes und Verworfenes** bleibt sichtbar: Issues werden geschlossen (nicht | |||
| 68 | README.md | 78 | prose-or-runtime | Konfiguration lebt in den Projekt-Repos (z. B. `threadnet-operating` für den | |||
| 69 | decisions/0001-gitlab-kanonisch-push-mirror.md | 1 | prose-or-runtime | # 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert | |||
| 70 | decisions/0001-gitlab-kanonisch-push-mirror.md | 8 | prose-or-runtime | 3,7-GiB-Host) und Gitea Actions zeigte mehrere echte Bugs. Das Homelab-GitLab | |||
| 71 | decisions/0001-gitlab-kanonisch-push-mirror.md | 14 | informational | runtime-path:git.lab/axion1337.chat/* | `git.lab/axion1337.chat/*` ist die kanonische Heimat aller Repos; Gitea/rohana | ||
| 72 | decisions/0001-gitlab-kanonisch-push-mirror.md | 15 | prose-or-runtime | wird über Push-Mirrors beliefert und bleibt Flux-Source, Container-Registry, | |||
| 73 | decisions/0001-gitlab-kanonisch-push-mirror.md | 16 | prose-or-runtime | npm-Registry und Release-Download. **Direkte Pushes zu Gitea sind für gespiegelte | |||
| 74 | decisions/0001-gitlab-kanonisch-push-mirror.md | 17 | prose-or-runtime | Repos verboten** — der Mirror überschreibt divergenten Stand per Force. | |||
| 75 | decisions/0001-gitlab-kanonisch-push-mirror.md | 22 | prose-or-runtime | - Commits, die doch auf Gitea landen (z. B. Cluster-CronJobs ohne Lab-Route), | |||
| 76 | decisions/0001-gitlab-kanonisch-push-mirror.md | 23 | checked-ok | path-ok:verfahren/deploy-uebergabe.md@management | brauchen das Kanonisierungs-Verfahren (`verfahren/deploy-uebergabe.md`): | ||
| 77 | decisions/0001-gitlab-kanonisch-push-mirror.md | 24 | prose-or-runtime | `.patch` ziehen, `git am`, Push über git.lab. Zweimal live gebraucht. | |||
| 78 | decisions/0001-gitlab-kanonisch-push-mirror.md | 29 | informational | id-no-issue:CFGMON-10 | - CFGMON-CI aufrüsten (Swap/Limits): strukturell zu klein, verworfen mit CFGMON-10. | ||
| 79 | decisions/0002-issues-und-management-ins-lab.md | 8 | prose-or-runtime | weiter auf Gitea — zwei Wahrheiten, driftgefährdet. Erreichbarkeits-Blocker | |||
| 80 | decisions/0002-issues-und-management-ins-lab.md | 9 | informational | id-ok:LABNET-01 | LABNET-01 (WireGuard-Roadwarrior) wurde am 2026-08-01 gelöst. | ||
| 81 | decisions/0002-issues-und-management-ins-lab.md | 13 | prose-or-runtime | Alle Projekt-Issues leben auf git.lab (62 migriert, Gitea-Issues geschlossen mit | |||
| 82 | decisions/0002-issues-und-management-ins-lab.md | 14 | informational | forge-repo:axion1337.chat/management | Verweis); das Backlogs-Repo zieht als `axion1337.chat/management` ins Lab | ||
| 83 | decisions/0002-issues-und-management-ins-lab.md | 15 | informational | forge-repo:sorb/management | (Push-Mirror → `sorb/management` auf Gitea). Das Lab ist die Quelle der Wahrheit. | ||
| 84 | decisions/0002-issues-und-management-ins-lab.md | 19 | prose-or-runtime | - ⚠️ gitops-Issue-Nummern haben sich verschoben (Gitea zählte PRs mit); die | |||
| 85 | decisions/0002-issues-und-management-ins-lab.md | 21 | prose-or-runtime | - ~~**Befristete Ausnahme:** Deploy-Übergabe-Issues laufen auf dem Gitea-Tracker | |||
| 86 | decisions/0002-issues-und-management-ins-lab.md | 22 | informational | forge-repo:sorb/management | von `sorb/management`, weil CFGMON git.lab (noch) nicht erreicht.~~ | ||
| 87 | decisions/0002-issues-und-management-ins-lab.md | 23 | checked-ok | issue-ok:management#13(closed);id-ok:LABNET-03 | ✅ **Zurückgebaut am 2026-08-02** (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)): | ||
| 88 | decisions/0002-issues-und-management-ins-lab.md | 25 | checked-ok | issue-ok:management#25(opened) | sind nach git.lab gewandert ([#25](https://git.lab/axion1337.chat/management/-/issues/25), | ||
| 89 | decisions/0002-issues-und-management-ins-lab.md | 26 | checked-ok | issue-ok:management#26(closed) | [#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist | ||
| 90 | decisions/0002-issues-und-management-ins-lab.md | 27 | checked-ok | path-ok:.gitlab/issue_templates/@management(dir) | leer, die Vorlage liegt als `.gitlab/issue_templates/`. **Damit gilt diese ADR | ||
| 91 | decisions/0002-issues-und-management-ins-lab.md | 29 | checked-ok | path-ok:README.md@ThreadNet-Web,axion1337.chat-gitops,management | historical-wording | Ausnahmen (siehe `README.md`) — dass sie befristet war und die Frist gehalten hat, | |
| 92 | decisions/0002-issues-und-management-ins-lab.md | 31 | prose-or-runtime | - Releases bleiben auf Gitea (öffentlicher Download-Pfad), ebenso das gitops-Wiki. | |||
| 93 | decisions/0002-issues-und-management-ins-lab.md | 35 | prose-or-runtime | - Issues auf Gitea belassen: dauerhafte Doppelführung, Roadmap/Boards unmöglich. | |||
| 94 | decisions/0003-cve-meldeweg-aggregiert.md | 8 | checked-ok | path-ok:verfahren/aar/@management(dir);issue-ok:axion1337.chat-gitops#51(opened) | Nachrichten und musste stummgeschaltet werden (gitops#51, AAR in `verfahren/aar/`). | ||
| 95 | decisions/0003-cve-meldeweg-aggregiert.md | 9 | informational | id-no-issue:CFGMON-13 | historical-wording | Gleichzeitig war entschieden (CFGMON-13), Release-/Security-Meldungen von | |
| 96 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 3 | checked-ok | issue-ok:management#12(closed);issue-ok:management#12(closed) | **Status:** akzeptiert (umgesetzt und abgenommen 2026-08-01, Testreihe 1–7 in [management#12](https://git.lab/axion1337.chat/management/-/issues/12)) · **Datum:** 2026-08-01 · **Entscheider:** sorb | ||
| 97 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 14 | informational | net-ref:10.0.0.0/24;net-ref:10.58.73.0/24 | historical-wording | Hetzner-Projektnetz `10.0.0.0/24` mit dem Lab-VLAN `10.58.73.0/24`. Der An/Aus-Schalter | |
| 98 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 29 | informational | runtime-path:~lab;net-ref:10.58.73.1 | | **CFGMON** | WG-**Client/Initiator**, dauerhaft aktiv (`enable`) + `PersistentKeepalive 25`; AllowedIPs nur `10.58.73.0/24, 10.58.75.1/32`; Split-DNS nur `~lab` → `10.58.73.1`; `ip_forward` + iptabl | ||
| 99 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 30 | informational | net-ref:192.168.178.20 | | **Fritzbox** | Portfreigabe UDP **51841** → `192.168.178.20` | | ||
| 100 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 31 | informational | net-ref:10.0.0.0/8 | | **Hetzner** | Netz-Range auf **`10.0.0.0/8`** erweitert, Route `10.58.73.0/24 → 10.0.0.3` — damit erreichen alle Server im Netz das Lab **ohne eigene Konfiguration** | | ||
| 101 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 32 | informational | net-ref:10.58.75.0/24;net-ref:10.0.0.0/24;image-ref:10.58.73.17:443;image-ref:10.58.73.1:53 | | **UniFi-Firewall** | Trennung vom Roadwarrior über **Quell-/Ziel-IP** (`10.58.75.0/24` + `10.0.0.0/24`), nicht über eine eigene Zone: erlaubt sind nur `10.58.73.17:443` (git.lab/Registry) und `10.58 | ||
| 102 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 36 | checked-ok | issue-ok:management#13(closed);id-ok:LABNET-03 | - ✅ **Eingelöst am 2026-08-02 (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)):** | ||
| 103 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 37 | prose-or-runtime | Übergabe-Issues können nicht nur umziehen — sie sind umgezogen | |||
| 104 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 38 | checked-ok | issue-ok:management#25(opened) | ([#25](https://git.lab/axion1337.chat/management/-/issues/25), | ||
| 105 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 39 | checked-ok | issue-ok:management#26(closed) | [#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist | ||
| 106 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 40 | prose-or-runtime | leer, die Vorlage liegt als GitLab-Issue-Template, und die Ausnahme aus ADR-0002 ist | |||
| 107 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 50 | prose-or-runtime | Gitea-PR-Ausnahme bleibt bewusst bestehen. | |||
| 108 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 54 | prose-or-runtime | historical-wording | Job läuft im Lab und erreicht Gitea öffentlich. Das war der eigentliche Grund für | ||
| 109 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 56 | informational | id-ok:GAME-01 | - game.axion1337.de profitiert erst nach Aufnahme in den vSwitch (GAME-01). | ||
| 110 | decisions/0005-pm-framework-kanban.md | 1 | prose-or-runtime | # 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen | |||
| 111 | decisions/0005-pm-framework-kanban.md | 22 | checked-ok | path-ok:vision/@management(dir) | | Product Goal / Vision | `vision/` (eine Datei je Linie) | | ||
| 112 | decisions/0005-pm-framework-kanban.md | 24 | checked-ok | path-ok:verfahren/aar/@management(dir) | | Review/Retro | AARs (`verfahren/aar/`) nach Deploys/Incidents | | ||
| 113 | decisions/0005-pm-framework-kanban.md | 25 | checked-ok | path-ok:verfahren/deploy-uebergabe.md@management | | Definition of Done | Deploy-Übergabe-Verfahren (`verfahren/deploy-uebergabe.md`) | | ||
| 114 | decisions/0005-pm-framework-kanban.md | 26 | checked-ok | path-ok:roadmap.md@management | | Roadmap/Meilensteine | Gruppen-Milestones + `roadmap.md` (CE: keine Epics/Roadmap-View) | | ||
| 115 | decisions/0005-pm-framework-kanban.md | 27 | checked-ok | path-ok:decisions/@management(dir) | | Entscheidungen | ADRs in `decisions/` | | ||
| 116 | decisions/0005-pm-framework-kanban.md | 32 | informational | forge-repo:axion1337.chat/management | - Das Backlogs-Repo wird zum Management-Repo `axion1337.chat/management`; | ||
| 117 | decisions/0005-pm-framework-kanban.md | 33 | checked-ok | path-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir);image-ref:host: | offene Punkte aus `hosts/`/`shared/` sind Issues mit `host:`-Labels, | ||
| 118 | decisions/0006-wikis-konsolidieren-docusaurus.md | 9 | prose-or-runtime | historical-wording | 1. **Gitea-Wiki-Repo** `…gitops.wiki.git` — 15 Seiten, gepflegt bis 2026-07-31. | ||
| 119 | decisions/0006-wikis-konsolidieren-docusaurus.md | 10 | prose-or-runtime | Vom Push-Mirror **nicht** erfasst: ein Wiki ist ein eigenes Repo, kein Branch. | |||
| 120 | decisions/0006-wikis-konsolidieren-docusaurus.md | 11 | prose-or-runtime | 2. **`wiki`-Branch im gitops-Repo** — Stand 2026-05-14, mitgezogen, weil der Mirror | |||
| 121 | decisions/0006-wikis-konsolidieren-docusaurus.md | 12 | checked-ok | path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir) | historical-wording | alle Branches trägt. Inhalt: ein damaliger Abzug von `docs/`, kein gepflegtes Wiki. | |
| 122 | decisions/0006-wikis-konsolidieren-docusaurus.md | 13 | checked-ok | path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir) | 3. **`docs/` im main-Branch** — die eigentliche, laufend gepflegte Repo-Doku. | ||
| 123 | decisions/0006-wikis-konsolidieren-docusaurus.md | 15 | prose-or-runtime | historical-wording | Dazu waren die GitLab-Wikis aller Projekte **leer**, und die Wiki-Inhalte enthielten | ||
| 124 | decisions/0006-wikis-konsolidieren-docusaurus.md | 26 | informational | forge-repo:homelab/wiki | [`homelab/wiki`](https://git.lab/homelab/wiki) baut mit Docusaurus eine Seite unter | ||
| 125 | decisions/0006-wikis-konsolidieren-docusaurus.md | 28 | informational | forge-repo:homelab/docs | historical-wording | Homelab (`homelab/docs`), Arbeitsweise (`management`). Die Inhalte werden beim Bau | |
| 126 | decisions/0006-wikis-konsolidieren-docusaurus.md | 33 | FLAG | path-miss:content/ | path-miss:content/ | - **Änderungen gehören ins Quell-Repo**, nie ins Wiki-Repo — was dort in `content/` | |
| 127 | decisions/0006-wikis-konsolidieren-docusaurus.md | 43 | prose-or-runtime | `.md` wird als CommonMark statt MDX geparst. | |||
| 128 | decisions/0006-wikis-konsolidieren-docusaurus.md | 44 | prose-or-runtime | - **Der `wiki`-Branch im gitops-Repo ist überholt.** Er bleibt vorerst als Historie | |||
| 129 | decisions/0006-wikis-konsolidieren-docusaurus.md | 47 | checked-ok | issue-ok:management#19(opened) | ([Issue #19](https://git.lab/axion1337.chat/management/-/issues/19)). | ||
| 130 | decisions/0006-wikis-konsolidieren-docusaurus.md | 51 | prose-or-runtime | - **Alles in ein Repo verschmelzen:** Die Quellen haben unterschiedliche Leser und | |||
| 131 | decisions/0006-wikis-konsolidieren-docusaurus.md | 53 | prose-or-runtime | - **Wiki auf Gitea belassen:** widerspricht ADR-0002 und hielt eine Ausnahme am | |||
| 132 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 3 | checked-ok | issue-ok:management#20(opened) | **Status:** vorgeschlagen (Entscheidung offen → [Issue #20](https://git.lab/axion1337.chat/management/-/issues/20)) · **Datum:** 2026-08-02 · **Entscheider:** sorb | ||
| 133 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 8 | informational | runtime-path:axionwiki.lab | Docusaurus als Lesefläche gebaut — läuft seit 2026-08-02 unter `axionwiki.lab`. | ||
| 134 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 42 | prose-or-runtime | Wahrheit neben git.lab — genau das, was [ADR-0002](0002-issues-und-management-ins-lab.md) | |||
| 135 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 52 | informational | id-ok:CFGMON-09 | Datenbank ohne Sicherung ist eine Zeitbombe (vgl. CFGMON-09, wo genau das seit | ||
| 136 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 53 | prose-or-runtime | 2026-07-30 offen ist). | |||
| 137 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 54 | FLAG | path-miss:import/ | path-miss:import/ | - **Ein Einweg-Import zum Befüllen, aber keine Synchronisation** (`import/` im | |
| 138 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 56 | FLAG | path-miss:provision.py | path-miss:provision.py | vergleichen, deshalb legt `provision.py` dieselben drei Bereiche an wie das | |
| 139 | decisions/0008-agenten-sessions-root-aequivalent.md | 3 | checked-ok | issue-ok:management#17(closed) | **Status:** akzeptiert · **Datum:** 2026-08-06 (Struktur-Workshop [#17](https://git.lab/axion1337.chat/management/-/issues/17)) · **Entscheider:** sorb | ||
| 140 | decisions/0008-agenten-sessions-root-aequivalent.md | 9 | informational | id-ok:LABNET-02 | LABNET-02-Nacht lief deshalb über die **docker-Gruppenmitgliedschaft** des Kontos | ||
| 141 | decisions/0008-agenten-sessions-root-aequivalent.md | 24 | checked-ok | issue-ok:management#14(opened) | [#14](https://git.lab/axion1337.chat/management/-/issues/14). | ||
| 142 | decisions/0008-agenten-sessions-root-aequivalent.md | 46 | informational | id-ok:LABNET-02 | ohne diese Entscheidung wäre LABNET-02 gar nicht durchführbar gewesen. | ||
| 143 | decisions/0008-agenten-sessions-root-aequivalent.md | 55 | prose-or-runtime | Kommt einer dazu, wird diese ADR abgelöst. | |||
| 144 | decisions/0008-agenten-sessions-root-aequivalent.md | 57 | prose-or-runtime | ## Offen, bewusst nicht vor der Entscheidung geklärt | |||
| 145 | decisions/0008-agenten-sessions-root-aequivalent.md | 66 | checked-ok | issue-ok:management#14(opened) | historical-wording | nächsten Host-Session, festgehalten in #14. | |
| 146 | decisions/0008-agenten-sessions-root-aequivalent.md | 80 | checked-ok | path-ok:hosts/cfgmon.md@management | und nicht bloß ein Absatz in `hosts/cfgmon.md`. | ||
| 147 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 5 | prose-or-runtime | > Nachgetragen am 2026-08-09 in der [Retro](../verfahren/retro/2026-08-09.md). Die | |||
| 148 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 13 | prose-or-runtime | öffentlichem Gitea-Spiegel heißt das: Jeder, der die Repos liest, kann ablesen, an | |||
| 149 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 23 | prose-or-runtime | **Regel ab 2026-08-07**, gültig für alle Repos der Gruppe `axion1337.chat` und die | |||
| 150 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 29 | prose-or-runtime | **Rückwirkend angewandt am 2026-08-09** auf **251 Commits** — alles aus dieser | |||
| 151 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 34 | prose-or-runtime | | gitops | 117 von 264 | ab 2026-07-27 | | |||
| 152 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 35 | prose-or-runtime | | management | 78 von 78 | vollständig | | |||
| 153 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 36 | prose-or-runtime | | ThreadNet-Web | 47 von 50 | ab 2026-07-28 | | |||
| 154 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 37 | prose-or-runtime | | threadnet-call | 9 von 9 | vollständig | | |||
| 155 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 39 | prose-or-runtime | Dabei wurden 17 Tags mit umgezogen und die Autoren-Identitäten vereinheitlicht — | |||
| 156 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 54 | checked-ok | path-ok:shared/commit-zuordnung-2026-08-07.md@management | [`shared/commit-zuordnung-2026-08-07.md`](../shared/commit-zuordnung-2026-08-07.md). | ||
| 157 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 61 | prose-or-runtime | wieder aktiv. | |||
| 158 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 66 | prose-or-runtime | liegen im selben GitLab und teilweise auf dem öffentlichen Spiegel — und sind | |||
| 159 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 72 | prose-or-runtime | Das Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines | |||
| 160 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 74 | informational | tag-ok:v0.4.0 | `v0.4.0` aus altem Quellcode gegen heutige Basis-Images neu gebaut und | ||
| 161 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 77 | checked-ok | issue-ok:ThreadNet-Web#14(closed) | ThreadNet-Web#14; die Sperre ist seit `3cb43f5` scharf. | ||
| 162 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 86 | prose-or-runtime | angefasst (`Scrublord@Mac.Bad`, 135 Commits aus der Zeit vor dieser | |||
| 163 | decisions/README.md | 6 | prose-or-runtime | auf `abgelöst durch NNNN` gesetzt. | |||
| 164 | decisions/template.md | 3 | prose-or-runtime | **Status:** vorgeschlagen | akzeptiert | abgelöst durch NNNN · **Datum:** JJJJ-MM-TT · **Entscheider:** sorb | |||
| 165 | hosts/cfgmon.md | 3 | prose-or-runtime | Monitoring-Stack, Gitea und der Reverse Proxy für alles Öffentliche. | |||
| 166 | hosts/cfgmon.md | 8 | prose-or-runtime | | **OS** | Ubuntu 24.04.4 LTS | | |||
| 167 | hosts/cfgmon.md | 9 | informational | net-ref:188.245.193.243 | | **IPv4** | `188.245.193.243` | | ||
| 168 | hosts/cfgmon.md | 11 | informational | net-ref:10.0.0.3;net-ref:10.0.0.2 | | **Privat** | `10.0.0.3` (`enp7s0`, Hetzner-Netz — dort liegt auch k3s auf `10.0.0.2`) | | ||
| 169 | hosts/cfgmon.md | 12 | informational | runtime-path:rohana.axion1337.de | | **DNS** | `rohana.axion1337.de` → Gitea, `selendis.axion1337.de` → Grafana | | ||
| 170 | hosts/cfgmon.md | 19 | checked-ok | image-ref:prom/prometheus:v3.3.1;forge-repo:sorb/threadnet-operating;path-ok:monitoring/@axion1337.chat-gitops(dir),threadnet-operating(dir) | | prometheus | `prom/prometheus:v3.3.1` | `monitoring` | `sorb/threadnet-operating`, `monitoring/` | | ||
| 171 | hosts/cfgmon.md | 20 | informational | image-ref:grafana/loki:3.7.1 | | loki | `grafana/loki:3.7.1` | `monitoring` | dito | | ||
| 172 | hosts/cfgmon.md | 21 | informational | image-ref:grafana/grafana:12.0.0 | | grafana | `grafana/grafana:12.0.0` | `monitoring` | dito | | ||
| 173 | hosts/cfgmon.md | 22 | informational | image-ref:grafana/alloy:v1.16.0 | | alloy | `grafana/alloy:v1.16.0` | `monitoring` | dito | | ||
| 174 | hosts/cfgmon.md | 23 | informational | image-ref:prom/node-exporter:v1.9.1 | | node-exporter | `prom/node-exporter:v1.9.1` | `monitoring` | dito | | ||
| 175 | hosts/cfgmon.md | 24 | informational | image-ref:traefik:v3.7.9;forge-repo:sorb/thread-net-git;id-no-issue:CFGMON-02 | | traefik | `traefik:v3.7.9` | `thread-net-git` | `sorb/thread-net-git`, seit 2026-07-30 in `main` (siehe [CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07 | ||
| 176 | hosts/cfgmon.md | 25 | informational | image-ref:gitea/gitea:1.27.0;image-ref::latest | historical-wording | | gitea | `gitea/gitea:1.27.0` | `thread-net-git` | dito, gepinnt (war `:latest`) | | |
| 177 | hosts/cfgmon.md | 26 | informational | runtime-path:gcr.io/cadvisor/cadvisor:v0.49.1;image-ref::latest | historical-wording | | cadvisor | `gcr.io/cadvisor/cadvisor:v0.49.1` | `thread-net-git` | dito, gepinnt (war `:latest`) | | |
| 178 | hosts/cfgmon.md | 27 | informational | image-ref:gitea/act_runner:0.6.1;id-no-issue:CFGMON-02 | | runner | `gitea/act_runner:0.6.1` | `thread-net-git` | dito, Container `gitea-runner`, siehe CFGMON-02 | | ||
| 179 | hosts/cfgmon.md | 28 | informational | image-ref:portainer/agent:2.27.5 | | portainer_agent | `portainer/agent:2.27.5` | — | standalone, kein Compose | | ||
| 180 | hosts/cfgmon.md | 32 | informational | image-ref:10.0.0.2:9100 | (`10.0.0.2:9100`), `pterodactyl_host_node` und `gameserver_cadvisor` | ||
| 181 | hosts/cfgmon.md | 33 | informational | net-ref:157.90.155.206 | (beide `157.90.155.206`, siehe [game](game.md)). | ||
| 182 | hosts/cfgmon.md | 38 | prose-or-runtime | historical-wording | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. | ||
| 183 | hosts/cfgmon.md | 41 | checked-ok | issue-ok:management#7(opened);id-ok:CFGMON-01 | - [CFGMON-01 — Zertifikatserneuerung braucht offene Ports (zeitkritisch ab 2026-09-28)](https://git.lab/axion1337.chat/management/-/issues/7) | ||
| 184 | hosts/cfgmon.md | 42 | checked-ok | issue-ok:management#8(opened);id-ok:CFGMON-03 | - [CFGMON-03 — Prometheus-Remote-Write/Loki öffentlich ohne Auth (Weg A, nachgelagerte Prüfung)](https://git.lab/axion1337.chat/management/-/issues/8) | ||
| 185 | hosts/cfgmon.md | 43 | checked-ok | issue-ok:management#9(opened);id-ok:CFGMON-04 | - [CFGMON-04 — Grafana-Admin-Credentials aus `.env` gelten nicht für die API](https://git.lab/axion1337.chat/management/-/issues/9) | ||
| 186 | hosts/cfgmon.md | 44 | checked-ok | issue-ok:management#10(opened);id-ok:CFGMON-09 | - [CFGMON-09 — Gitea-Backups off-host (⚠️ Backup-Cron deaktiviert)](https://git.lab/axion1337.chat/management/-/issues/10) | ||
| 187 | hosts/cfgmon.md | 46 | informational | id-no-issue:CFGMON-11 | ## CFGMON-11 — Gitea-CI-Rückbau nach GitLab-Umzug | ||
| 188 | hosts/cfgmon.md | 48 | prose-or-runtime | **Status:** erledigt (2026-07-31 spätabends) — bis auf einen kosmetischen Handgriff: | |||
| 189 | hosts/cfgmon.md | 49 | prose-or-runtime | auf CFGMON `cd /opt/thread-net-git && git checkout main && git pull` (Checkout parkt | |||
| 190 | hosts/cfgmon.md | 52 | informational | runtime-path:/opt/threadnet-operating | **Dazu neu (2026-08-01 ~05:00):** Auch `/opt/threadnet-operating` braucht einmal | ||
| 191 | hosts/cfgmon.md | 53 | prose-or-runtime | `git fetch && git reset --hard origin/main` — der State-Persistenz-Commit wurde | |||
| 192 | hosts/cfgmon.md | 54 | prose-or-runtime | dort direkt nach Gitea gepusht (dfe04c4a), vom Mirror überschrieben, vom Mac aus | |||
| 193 | hosts/cfgmon.md | 55 | prose-or-runtime | per Patch gerettet und kanonisch als `6ffab68` neu aufgelegt (inhaltsgleich, | |||
| 194 | hosts/cfgmon.md | 58 | prose-or-runtime | **Erledigt (2026-08-01, autonom):** | |||
| 195 | hosts/cfgmon.md | 59 | prose-or-runtime | - Actions-Toggles deaktiviert: `ThreadNet-Web`, `threadnet-call`, `axion1337.chat-gitops` | |||
| 196 | hosts/cfgmon.md | 60 | checked-ok | path-ok:.github/workflows/@threadnet-call(dir) | historical-wording | - `ThreadNet-Web`: alle `.github/workflows/`-Dateien entfernt (Commit `a876758`) | |
| 197 | hosts/cfgmon.md | 61 | FLAG | path-miss:.gitea/workflows/ | path-miss:.gitea/workflows/ | historical-wording | - gitops: Verifikations-Job nach GitLab portiert + `.gitea/workflows/` entfernt |
| 198 | hosts/cfgmon.md | 62 | FLAG | path-miss:milestone-release.yml | path-miss:milestone-release.yml | (Commit `5e46a24`, Pipeline grün, Mirror→Gitea verifiziert; `milestone-release.yml` | |
| 199 | hosts/cfgmon.md | 63 | FLAG | issue-miss:management#33 | issue-miss:management#33 | historical-wording | war toter Code, siehe #33). Flux unberührt. |
| 200 | hosts/cfgmon.md | 64 | checked-ok | path-ok:.env.example@threadnet-call,threadnet-operating | historical-wording | - `thread-net-git`: Runner-Service/Config/`.env.example` per Commit `d904734` entfernt | |
| 201 | hosts/cfgmon.md | 65 | prose-or-runtime | (auf git.lab; Mirror trägt nach Gitea) — **noch nicht deployt**, siehe unten. | |||
| 202 | hosts/cfgmon.md | 66 | informational | package-ref:@sorb/threadnet-call-embedded | - Registry-Entscheidung npm final (Evidenz: `@sorb/threadnet-call-embedded` ist | ||
| 203 | hosts/cfgmon.md | 67 | checked-ok | path-ok:apps/web@ThreadNet-Web(dir) | pnpm-Dependency von `apps/web`, Lockfile pinnt Tarball-URL auf rohana): **bleibt Gitea**. | ||
| 204 | hosts/cfgmon.md | 70 | prose-or-runtime | 1. ~~`thread-net-git`-Stand deployen~~ **erledigt (2026-07-31 spätabends, via | |||
| 205 | hosts/cfgmon.md | 71 | FLAG | path-miss:runner-data/ | path-miss:runner-data/ | historical-wording | CFGMON-Session)**: Runner-Container/Netz/`runner-data/`/`.env`-Zeile entfernt, |
| 206 | hosts/cfgmon.md | 72 | prose-or-runtime | historical-wording | `builder-1` aus der Gitea-Admin-UI gelöscht, Actions-Registrierungstoken rotiert. | ||
| 207 | hosts/cfgmon.md | 75 | checked-ok | issue-ok:thread-net-git#1(closed) | Mac→git.lab→Mirror (`15c8f2d`), Hergang in thread-net-git#1 (geschlossen). | ||
| 208 | hosts/cfgmon.md | 77 | prose-or-runtime | historical-wording | getippte Token (`a89bfb…`) war der Gitea-**Actions-Runner-Registrierungstoken** | ||
| 209 | hosts/cfgmon.md | 82 | prose-or-runtime | 3. ~~Token-Rotation b~~ **erledigt (2026-07-31 abends)**: Generalschlüssel | |||
| 210 | hosts/cfgmon.md | 87 | informational | runtime-path:~/.config/gitea-rohana/token | `~/.config/gitea-rohana/token` auf dem Mac), `claude-push` (write:repository, | ||
| 211 | hosts/cfgmon.md | 88 | informational | runtime-path:~/.config/gitea-rohana/push-token | `~/.config/gitea-rohana/push-token`). Erster CI-Publish `0.19.2-threadnet.6` | ||
| 212 | hosts/cfgmon.md | 89 | checked-ok | issue-ok:threadnet-call#1(closed) | historical-wording | verifiziert → threadnet-call#1 geschlossen. Alle Klartext-Reste entfernt | |
| 213 | hosts/cfgmon.md | 94 | informational | runtime-path:git.lab/axion1337.chat | (`git.lab/axion1337.chat`, Gruppe mit importierten Projekten angelegt; die Domain ist | ||
| 214 | hosts/cfgmon.md | 97 | prose-or-runtime | pausieren). Der am 2026-07-30 auf Gitea-Seite aufgebaute CI-Unterbau wird damit teilweise | |||
| 215 | hosts/cfgmon.md | 102 | prose-or-runtime | - **Actions-Toggle** `has_actions` bei `ThreadNet-Web` (am 2026-07-30 per API aktiviert) | |||
| 216 | hosts/cfgmon.md | 103 | prose-or-runtime | wieder deaktivieren, ebenso bei `threadnet-call` (stoppt die fehlschlagende | |||
| 217 | hosts/cfgmon.md | 105 | checked-ok | path-ok:.github/workflows/@threadnet-call(dir) | - **`.github/workflows/` in `ThreadNet-Web`** (der kuratierte 6-Dateien-Satz) — wird durch | ||
| 218 | hosts/cfgmon.md | 106 | checked-ok | path-ok:.gitlab-ci.yml@ThreadNet-Web,axion1337.chat-gitops,management | `.gitlab-ci.yml` ersetzt. Die Erkenntnisse aus den Läufen vom 2026-07-30 mitnehmen: | ||
| 219 | hosts/cfgmon.md | 110 | prose-or-runtime | - **Geerbte Upstream-Workflows in `threadnet-call`** (build/publish/test/translations/ | |||
| 220 | hosts/cfgmon.md | 113 | FLAG | path-miss:runner-data/.runner | path-miss:runner-data/.runner | der Gitea-Admin-UI deregistrieren und `runner-data/.runner` auf dem Host entfernen. | |
| 221 | hosts/cfgmon.md | 114 | FLAG | path-miss:embedded/web/.npmrc | path-miss:embedded/web/.npmrc | - **Token: npm-Token in `threadnet-call`s untracked `embedded/web/.npmrc`** (Klartext im | |
| 222 | hosts/cfgmon.md | 121 | prose-or-runtime | - **Runner-Service in `thread-net-git` ganz entfernen?** Hängt daran, ob das gitops-Repo | |||
| 223 | hosts/cfgmon.md | 122 | FLAG | path-miss:deploy-on-push.yml | path-miss:deploy-on-push.yml | seinen leichten `deploy-on-push.yml` (YAML-Validierung/Notification, läuft sauber) | |
| 224 | hosts/cfgmon.md | 124 | FLAG | path-miss:runner/config.yaml | path-miss:runner/config.yaml | Revert-Commit in `thread-net-git`: Compose-Service `runner`, `runner/config.yaml`, | |
| 225 | hosts/cfgmon.md | 125 | FLAG | path-ok:.env.example@threadnet-call,threadnet-operating;path-miss:runner-data/ | path-miss:runner-data/ | `.env.example` (RUNNER_TOKEN), Cache-Port-Bindung 8088, `runner-data/`. | |
| 226 | hosts/cfgmon.md | 126 | informational | package-ref:@sorb/threadnet-call-embedded | - **Registry-Ziel für `@sorb/threadnet-call-embedded`**: bleibt die Gitea-npm-Registry | ||
| 227 | hosts/cfgmon.md | 128 | prose-or-runtime | GitLab-Package-Registry (dann läuft die Gitea-Package-Seite leer). | |||
| 228 | hosts/cfgmon.md | 129 | prose-or-runtime | - **Container-Images bleiben in der rohana-Registry** (Flux/k8s pullt von dort — spricht | |||
| 229 | hosts/cfgmon.md | 131 | prose-or-runtime | **neuen** Deploy-/Push-Token für die rohana-Registry (Neuanlage, kein Rückbau). | |||
| 230 | hosts/cfgmon.md | 135 | prose-or-runtime | Gitea selbst, gitops-Repo als Flux-Source, Issues/Wiki/dieses Repo, der | |||
| 231 | hosts/cfgmon.md | 136 | informational | id-ok:CFGMON-09 | API-Token für Issue-Verwaltung, das Gitea-Backup-Script (CFGMON-09). | ||
| 232 | hosts/cfgmon.md | 139 | prose-or-runtime | umgezogen — [ADR-0002](../decisions/0002-issues-und-management-ins-lab.md) —, | |||
| 233 | hosts/cfgmon.md | 140 | prose-or-runtime | das Repo dabei von `Backlogs` zu `management` umgewidmet | |||
| 234 | hosts/cfgmon.md | 142 | prose-or-runtime | den damaligen Rückbau der Gitea-CI, nicht auf Dauer.)* | |||
| 235 | hosts/cfgmon.md | 145 | checked-ok | issue-ok:ThreadNet-Web#2(closed) | [ThreadNet-Web#2](https://rohana.axion1337.de/sorb/ThreadNet-Web/issues/2), | ||
| 236 | hosts/cfgmon.md | 146 | checked-ok | issue-ok:threadnet-call#1(closed) | [threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1). | ||
| 237 | hosts/cfgmon.md | 148 | prose-or-runtime | **Nächster Schritt:** die drei manuellen Schritte oben, dann → erledigt. | |||
| 238 | hosts/cfgmon.md | 150 | informational | id-no-issue:CFGMON-13 | ## CFGMON-13 — Absender-Design für Release-/CVE-Meldungen: eigener Bot? | ||
| 239 | hosts/cfgmon.md | 154 | checked-ok | issue-ok:axion1337.chat-gitops#47(opened) | Alertmanager-Routing: [gitops#47](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/47). | ||
| 240 | hosts/cfgmon.md | 160 | checked-ok | issue-ok:axion1337.chat-gitops#22(opened) | 1. **release-watch** (gitops#22, deploybereit): Upstream-Releases/Security-Releases | ||
| 241 | hosts/cfgmon.md | 162 | checked-ok | issue-ok:axion1337.chat-gitops#31(opened) | 2. **Trivy-CVE-Scans** (gitops#31, läuft wöchentlich in der Lab-CI): Funde landen | ||
| 242 | hosts/cfgmon.md | 168 | informational | package-ref:@alerts | scharf/stumm schaltbar bleibt? Oder bewusst alles über `@alerts` bündeln? | ||
| 243 | hosts/cfgmon.md | 174 | informational | id-no-issue:CFGMON-12 | ## CFGMON-12 — Gitea-Projektmetadaten nach GitLab umziehen/integrieren | ||
| 244 | hosts/cfgmon.md | 176 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | **Status:** abgelöst durch [gitops#48](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/48) (2026-08-01, sorb: HOHE Priorität — vollständige Issue-Migration + zentrale Gruppen-Roadmap; Pl | ||
| 245 | hosts/cfgmon.md | 178 | prose-or-runtime | ✅ **Umgesetzt am 2026-08-01/02**: Die Migration ist durch — 62 Issues liegen auf | |||
| 246 | hosts/cfgmon.md | 179 | prose-or-runtime | git.lab, die Gitea-Issues sind geschlossen und tragen einen Migrations-Fußtext. | |||
| 247 | hosts/cfgmon.md | 182 | informational | id-ok:LABNET-03 | für Deploy-Übergabe-Issues ist am 2026-08-02 mit LABNET-03 ebenfalls zurückgebaut. | ||
| 248 | hosts/cfgmon.md | 187 | prose-or-runtime | Projektmetadaten liegen weiterhin auf Gitea/rohana. Verifiziert per API am | |||
| 249 | hosts/cfgmon.md | 190 | prose-or-runtime | Noch auf Gitea: | |||
| 250 | hosts/cfgmon.md | 192 | checked-ok | issue-ok:management#2(opened);issue-ok:management#5(opened);issue-ok:management#1(opened) | - **Issues** inkl. Kommentare/Labels: ThreadNet-Web (#2, #5, …), threadnet-call (#1), | ||
| 251 | hosts/cfgmon.md | 193 | checked-ok | issue-ok:management#24(opened);issue-ok:management#25(opened);issue-ok:management#32(opened) | gitops (#24, #25, #32, …) | ||
| 252 | hosts/cfgmon.md | 195 | FLAG | path-miss:00-TASKS.md | path-miss:00-TASKS.md | - **Wiki** (gitops-Wiki mit `00-TASKS.md`-Log — bisher bewusst direkt-Gitea) | |
| 253 | hosts/cfgmon.md | 197 | informational | id-no-issue:CFGMON-11 | [CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug) auf rohana — bei | ||
| 254 | hosts/cfgmon.md | 202 | prose-or-runtime | 1. **GitLab-Gitea-Importer vs. API-Skript** — der Importer verliert Autorenschaft | |||
| 255 | hosts/cfgmon.md | 205 | prose-or-runtime | 2. **Erreichbarkeit**: rohana ist von überall erreichbar, git.lab nur im Homelab — | |||
| 256 | hosts/cfgmon.md | 208 | prose-or-runtime | direkt-Gitea). | |||
| 257 | hosts/cfgmon.md | 219 | informational | id-no-issue:CFGMON-10 | ### CFGMON-10 — threadnet-call-CI schlägt am Artifact-Schritt fehl · verworfen 2026-07-30 | ||
| 258 | hosts/cfgmon.md | 221 | prose-or-runtime | Ausgelöst durch einen Push nach `threadnet-call` am 2026-07-30: der Runner (`builder-1`) | |||
| 259 | hosts/cfgmon.md | 226 | prose-or-runtime | **Hypothese inzwischen im Kern bestätigt** — beim parallelen ThreadNet-Web-CI-Versuch | |||
| 260 | hosts/cfgmon.md | 229 | prose-or-runtime | ohne Swap, trägt daneben Gitea/Traefik/Monitoring) kann das strukturell nicht liefern. | |||
| 261 | hosts/cfgmon.md | 233 | informational | id-no-issue:CFGMON-11 | [CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug)), CFGMON bleibt bei leichten | ||
| 262 | hosts/cfgmon.md | 234 | checked-ok | issue-ok:threadnet-call#1(closed) | Jobs. Issue-Seite: [threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1). | ||
| 263 | hosts/cfgmon.md | 236 | informational | id-no-issue:CFGMON-02 | ### CFGMON-02 — Traefik, Gitea, cAdvisor und Runner unter IaC gebracht · erledigt 2026-07-30 | ||
| 264 | hosts/cfgmon.md | 238 | informational | runtime-path:/data/compose/8 | Liefen ursprünglich im Compose-Projekt `thread-net-git` aus `/data/compose/8`, einem von | ||
| 265 | hosts/cfgmon.md | 239 | informational | forge-repo:sorb/thread-net-git;image-ref::latest | Portainer verwalteten Stack ohne Repo dazu. Jetzt in `sorb/thread-net-git`: `:latest`-Tags | ||
| 266 | hosts/cfgmon.md | 240 | prose-or-runtime | historical-wording | gepinnt (Gitea `1.27.0`, cAdvisor `v0.49.1`), Projektname `thread-net-git` beibehalten | ||
| 267 | hosts/cfgmon.md | 242 | prose-or-runtime | Volume-Namen, Downgrade-Verbot für Gitea), nächtliches Backup-Script. Zusätzlich neu: ein | |||
| 268 | hosts/cfgmon.md | 243 | informational | image-ref:gitea/act_runner:0.6.1 | `runner`-Service (`gitea/act_runner:0.6.1`, Container `gitea-runner`, Labels | ||
| 269 | hosts/cfgmon.md | 244 | prose-or-runtime | `ubuntu-latest`/`linux-build`/`win-wine` — die letzten beiden gezielt für Electron-Builds) | |||
| 270 | hosts/cfgmon.md | 245 | informational | id-no-issue:CFGMON-08 | — ursprünglich unter [CFGMON-08](#cfgmon-08) als offene Frage gelistet, siehe dort. | ||
| 271 | hosts/cfgmon.md | 247 | informational | branch-ok:rework/stack | Entstanden auf Branch `rework/stack`, zunächst nicht gemergt (produktiv aber schon aktiv). | ||
| 272 | hosts/cfgmon.md | 248 | informational | branch-ok:origin/main;branch-ok:origin/rework/stack | **2026-07-30 nach `main` gemergt** (`origin/main` == `origin/rework/stack` auf `02b3224`, | ||
| 273 | hosts/cfgmon.md | 249 | prose-or-runtime | verifiziert) — damit spiegelt die Standardansicht des Repos jetzt den Live-Stand. | |||
| 274 | hosts/cfgmon.md | 250 | prose-or-runtime | Verifiziert am 2026-07-30 über die Compose-Labels der laufenden Container | |||
| 275 | hosts/cfgmon.md | 251 | informational | image-ref:working_dir: /opt/thread-net-git | (`working_dir: /opt/thread-net-git`) und `docker compose ls`. `gitea-data` ist als | ||
| 276 | hosts/cfgmon.md | 255 | prose-or-runtime | Zum Bootstrapping-Problem (Definition von Gitea liegt in Gitea): mitigiert, | |||
| 277 | hosts/cfgmon.md | 256 | prose-or-runtime | weil das Deploy-Verzeichnis selbst der Checkout ist — fällt Gitea aus, liegt | |||
| 278 | hosts/cfgmon.md | 259 | informational | id-ok:CFGMON-09 | [CFGMON-09](#cfgmon-09--gitea-backups-off-host-in-die-storage-box-eigenes-borg-repo). | ||
| 279 | hosts/cfgmon.md | 261 | informational | id-no-issue:CFGMON-05 | ### CFGMON-05 — Monitoring-Stack unter IaC bringen · erledigt 2026-07-30 | ||
| 280 | hosts/cfgmon.md | 263 | informational | runtime-path:/opt/monitoring;image-ref::latest | Der Stack lief aus `/opt/monitoring` ohne Versionierung und mit `:latest`-Tags. Jetzt | ||
| 281 | hosts/cfgmon.md | 264 | checked-ok | forge-repo:sorb/threadnet-operating;path-ok:monitoring/@axion1337.chat-gitops(dir),threadnet-operating(dir) | in `sorb/threadnet-operating` unter `monitoring/`, Images gepinnt, | ||
| 282 | hosts/cfgmon.md | 268 | informational | id-no-issue:CFGMON-06 | ### CFGMON-06 — Grafana-Certresolver zeigte ins Leere · erledigt 2026-07-30 | ||
| 283 | hosts/cfgmon.md | 273 | informational | runtime-path:/opt/monitoring | aus. Aus dem Altbestand in `/opt/monitoring` unverändert übernommen und dort | ||
| 284 | hosts/cfgmon.md | 276 | prose-or-runtime | Behoben in `threadnet-operating`, Commit `a400f8a`. Cert von Let's Encrypt (YR2) | |||
| 285 | hosts/cfgmon.md | 277 | prose-or-runtime | historical-wording | ausgestellt, gültig bis 2026-10-28 — die Nachfolge davon ist | ||
| 286 | hosts/cfgmon.md | 278 | informational | id-ok:CFGMON-01 | [CFGMON-01](#cfgmon-01--zertifikatserneuerung-braucht-offene-ports-ipv4-und-ipv6). | ||
| 287 | hosts/cfgmon.md | 280 | informational | id-no-issue:CFGMON-07 | ### CFGMON-07 — Alloy verlor seine Positions-Datei bei jedem Deploy · erledigt 2026-07-30 | ||
| 288 | hosts/cfgmon.md | 282 | prose-or-runtime | historical-wording | `--storage.path=/var/lib/alloy/data` war gesetzt, aber ohne Volume: die | ||
| 289 | hosts/cfgmon.md | 288 | prose-or-runtime | Behoben durch ein `alloy_data`-Volume, Commit `edac97e`. Verifiziert: Positions | |||
| 290 | hosts/cfgmon.md | 291 | informational | id-no-issue:CFGMON-08 | ### CFGMON-08 — Kein Gitea-Actions-Runner registriert, Standort noch offen · erledigt 2026-07-30 | ||
| 291 | hosts/cfgmon.md | 294 | prose-or-runtime | existiert und wo einer laufen sollte, noch offen sei. Beides falsch — ein Runner | |||
| 292 | hosts/cfgmon.md | 295 | informational | branch-ok:rework/stack | (`builder-1`) läuft bereits, auf CFGMON, als Teil von `thread-net-git`s `rework/stack`- | ||
| 293 | hosts/cfgmon.md | 297 | informational | id-no-issue:CFGMON-02 | [CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07-30) — hier | ||
| 294 | hosts/cfgmon.md | 298 | checked-ok | issue-ok:axion1337.chat-gitops#33(closed) | nicht dupliziert. [gitops#33](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/33) | ||
| 295 | hosts/cfgmon.md | 299 | prose-or-runtime | (dieselbe falsche Prämisse) entsprechend korrigiert/geschlossen. | |||
| 296 | hosts/game.md | 3 | prose-or-runtime | Pterodactyl- / Gameserver-Host. | |||
| 297 | hosts/game.md | 7 | informational | net-ref:157.90.155.206 | | **IPv4** | `157.90.155.206` | | ||
| 298 | hosts/game.md | 10 | informational | net-ref:10.0.0.4 | | **Privat** | `10.0.0.4` (im vSwitch seit 2026-08-02) | | ||
| 299 | hosts/game.md | 20 | prose-or-runtime | [axion1337.chat/game-operating](https://git.lab/axion1337.chat/game-operating) | |||
| 300 | hosts/game.md | 25 | prose-or-runtime | Deployment ist gewollt, aber bewusst **zurückgestellt, bis das Matrix-Projekt | |||
| 301 | hosts/game.md | 31 | prose-or-runtime | **Pterodactyl** (Gameserver-Verwaltung, in Benutzung durch Bekannte des Betreibers | |||
| 302 | hosts/game.md | 36 | informational | runtime-path:ghcr.io/pterodactyl/panel:v1.12.0 | | `pterodactyl` (Panel) | `ghcr.io/pterodactyl/panel:v1.12.0` | | ||
| 303 | hosts/game.md | 37 | informational | runtime-path:ghcr.io/pterodactyl/wings:v1.12.0 | | `wings` (Daemon, fährt die Gameserver als Docker-Container) | `ghcr.io/pterodactyl/wings:v1.12.0` | | ||
| 304 | hosts/game.md | 41 | prose-or-runtime | **Eigener Monitoring-Stack** (grafana-oss, prometheus v3.0.0 mit 15 d Retention, | |||
| 305 | hosts/game.md | 42 | prose-or-runtime | loki 3.1.1, promtail 3.1.1, node-exporter v1.8.1, cadvisor v0.49.2). Wird | |||
| 306 | hosts/game.md | 43 | prose-or-runtime | perspektivisch von CFGMON abgelöst — siehe unten. | |||
| 307 | hosts/game.md | 47 | informational | id-ok:GAME-01 | GAME-01: Auf 9100/8080 des Hosts lauscht nichts, CFGMONs Scrape-Ziele auf der | ||
| 308 | hosts/game.md | 55 | informational | net-ref:188.245.193.243;net-ref:178.25.213.70 | | Port | von CFGMON (`188.245.193.243`, 2026-08-01) | vom Hausanschluss (`178.25.213.70`, 2026-08-02) | | ||
| 309 | hosts/game.md | 57 | prose-or-runtime | | 80 / 443 | offen | offen (HTTP 404 bzw. 503) | | |||
| 310 | hosts/game.md | 58 | prose-or-runtime | | **22** | **Timeout** | **offen** | | |||
| 311 | hosts/game.md | 67 | prose-or-runtime | Es fehlte also keine Ausnahme für CFGMON. Seit 2026-08-02 liegt der Host im | |||
| 312 | hosts/game.md | 68 | informational | net-ref:10.0.0.4 | vSwitch (`10.0.0.4`); die Monitoring-Anbindung läuft künftig **per Push über das | ||
| 313 | hosts/game.md | 69 | informational | net-ref:10.0.0.3 | private Netz** — Alloy sammelt lokal ein und schiebt nach `10.0.0.3`, wodurch der | ||
| 314 | hosts/game.md | 71 | checked-ok | issue-ok:management#2(opened);id-ok:GAME-01 | k3s-Cluster. Details: [GAME-01](https://git.lab/axion1337.chat/management/-/issues/2). | ||
| 315 | hosts/game.md | 80 | prose-or-runtime | historical-wording | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. | ||
| 316 | hosts/game.md | 83 | checked-ok | issue-ok:management#2(opened);id-ok:GAME-01 | historical-wording | - [GAME-01 — Host von CFGMON aus nicht erreichbar, 2 Targets down (⚠️ Silences bis 2026-08-04)](https://git.lab/axion1337.chat/management/-/issues/2) | |
| 317 | hosts/game.md | 84 | checked-ok | issue-ok:management#3(opened);id-ok:GAME-02 | - [GAME-02 — `www.game.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/3) | ||
| 318 | hosts/matrix.md | 8 | informational | net-ref:49.13.132.245 | | **IPv4** | `49.13.132.245` | | ||
| 319 | hosts/matrix.md | 10 | informational | net-ref:10.0.0.2;net-ref:10.0.0.3 | | **Privat** | `10.0.0.2` (`enp7s0`, dasselbe Hetzner-Netz wie CFGMON `10.0.0.3`) | | ||
| 320 | hosts/matrix.md | 12 | prose-or-runtime | | **DNS** | `matrix.axion1337.de` **und** `matrix.axion1337.chat` zeigen auf dieselbe IP — ebenso `axion1337.chat` (Apex) und `account.axion1337.chat` (MAS). `axion1337.de` ist die ältere/Registrar-Do | |||
| 321 | hosts/matrix.md | 15 | informational | runtime-path:~/.ssh/config | **Inventarisiert** (direkter SSH-Zugriff, `~/.ssh/config`-Alias `axion1337`, Port 2248): | ||
| 322 | hosts/matrix.md | 18 | informational | forge-repo:sorb/axion1337.chat-gitops | [`sorb/axion1337.chat-gitops`](https://rohana.axion1337.de/sorb/axion1337.chat-gitops) - dieser | ||
| 323 | hosts/matrix.md | 20 | informational | forge-repo:sorb/ThreadNet-Web;forge-repo:sorb/threadnet-call | `sorb/ThreadNet-Web` (Element Web), `sorb/threadnet-call` (Element Call/LiveKit-Widget). | ||
| 324 | hosts/matrix.md | 21 | informational | forge-repo:sorb/element-web;forge-repo:sorb/ThreadNet-Stack | historical-wording | `sorb/element-web` und `sorb/ThreadNet-Stack` sind **veraltete/abgelöste** Vorgänger-Repos | |
| 325 | hosts/matrix.md | 24 | prose-or-runtime | `ufw`: aktiv, Default Deny Incoming / Allow Outgoing, explizite Allow-Regeln für | |||
| 326 | hosts/matrix.md | 25 | prose-or-runtime | 2248/tcp (SSH), 80/443, TURN/RTC-Ports. `unattended-upgrades` aktiv (Debian-Security + | |||
| 327 | hosts/matrix.md | 26 | informational | id-no-issue:MATRIX-04 | Debian-Origin), siehe [MATRIX-04](#matrix-04--host-level-pre-update-benachrichtigung-erledigt). | ||
| 328 | hosts/matrix.md | 31 | prose-or-runtime | historical-wording | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. | ||
| 329 | hosts/matrix.md | 34 | checked-ok | issue-ok:management#1(opened);id-ok:MATRIX-03 | - [MATRIX-03 — `www.matrix.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/1) | ||
| 330 | hosts/matrix.md | 36 | informational | id-no-issue:MATRIX-05 | ## MATRIX-05 — node-exporter-DaemonSet in CrashLoopBackOff, Cluster-Scrape seit 2026-08-01 tot | ||
| 331 | hosts/matrix.md | 38 | prose-or-runtime | **Status:** erledigt (2026-08-01 ~04:10, vom Mac aus mit kubectl/SSH) | |||
| 332 | hosts/matrix.md | 41 | informational | image-ref:listen tcp 0.0.0.0:9100: bind: address already in use | Teil 1 bestätigt per Pod-Log: `listen tcp 0.0.0.0:9100: bind: address already in use`; | ||
| 333 | hosts/matrix.md | 49 | checked-ok | issue-ok:axion1337.chat-gitops#45(opened) | historical-wording | **Fix (gitops `228807f`, Weg A aus gitops#45):** HelmRelease + Alloy-Scrape entfernt, | |
| 334 | hosts/matrix.md | 52 | checked-ok | issue-ok:axion1337.chat-gitops#45(opened) | [gitops#45](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/45). | ||
| 335 | hosts/matrix.md | 61 | prose-or-runtime | | Messwert | Stand 2026-08-01 | | |||
| 336 | hosts/matrix.md | 67 | prose-or-runtime | | `waiting_reason` / `ready` | `CrashLoopBackOff` / `0` | | |||
| 337 | hosts/matrix.md | 73 | informational | image-ref:hostNetwork: true | **Vermutete Ursache, nicht verifiziert:** Der Pod läuft mit `hostNetwork: true` und will | ||
| 338 | hosts/matrix.md | 75 | informational | image-ref:10.0.0.2:9100 | derselbe, den CFGMON als Job `k3s_host_node` direkt auf `10.0.0.2:9100` scrapt und der | ||
| 339 | hosts/matrix.md | 86 | prose-or-runtime | ### Teil 2 — der Cluster-Scrape ist am 2026-08-01 01:19 UTC ausgefallen (akut) | |||
| 340 | hosts/matrix.md | 96 | informational | net-ref:49.13.132.245 | `hostNetwork`, sein Pod-IP ist die öffentliche `49.13.132.245`, dorthin zeigt der | ||
| 341 | hosts/matrix.md | 103 | informational | image-ref:10.0.0.2:9100 | | `10.0.0.2:9100` (privat) | offen, 2706 Metriken | | ||
| 342 | hosts/matrix.md | 104 | informational | image-ref:49.13.132.245:9100 | | `49.13.132.245:9100` (öffentlich) | **keine Antwort** | | ||
| 343 | hosts/matrix.md | 105 | informational | image-ref:49.13.132.245:80;image-ref::443 | | `49.13.132.245:80` / `:443` | offen — Host lebt | | ||
| 344 | hosts/matrix.md | 110 | informational | image-ref:10.0.0.2:9100;image-ref:0.0.0.0:9100 | 1. Der Exporter bindet jetzt `10.0.0.2:9100` statt `0.0.0.0:9100`. | ||
| 345 | hosts/matrix.md | 123 | informational | image-ref:10.0.0.2:9100 | auf `10.0.0.2:9100` zeigen lassen. Beendet den Crashloop und erhält die enge Bindung ans | ||
| 346 | hosts/matrix.md | 127 | informational | net-ref:0.0.0.0 | Ebenfalls sauber, aber er bindet dann wieder `0.0.0.0` — also auch die öffentliche IP, | ||
| 347 | hosts/matrix.md | 131 | prose-or-runtime | ### Nebenbefund — Job-Label kollidiert zwischen zwei Hosts | |||
| 348 | hosts/matrix.md | 137 | code-block | up=1 instance=node-exporter:9100 -> CFGMON (Kernel 6.8.0-136-generic) | |||
| 349 | hosts/matrix.md | 152 | informational | package-ref:@matrix.axion1337.de;id-no-issue:MATRIX-01 | ### MATRIX-01 — Klären, ob der Server Mail als `@matrix.axion1337.de` verschickt · erledigt 2026-07-30 | ||
| 350 | hosts/matrix.md | 154 | prose-or-runtime | Für `matrix.axion1337.de` existiert der komplette IONOS-Mail-Satz: `MX mx00/mx01`, | |||
| 351 | hosts/matrix.md | 157 | prose-or-runtime | offen, weil Matrix-Homeserver typischerweise Mail für Registrierung/Passwort-Reset | |||
| 352 | hosts/matrix.md | 160 | prose-or-runtime | **Antwort, verifiziert per Config** (nicht nur vermutet) — direkt im IaC-Repo | |||
| 353 | hosts/matrix.md | 161 | informational | forge-repo:sorb/axion1337.chat-gitops | `sorb/axion1337.chat-gitops`, dem tatsächlich hier deployten Stand geprüft: | ||
| 354 | hosts/matrix.md | 163 | checked-ok | path-ok:apps/production/custom-configs/synapse-values.yaml@axion1337.chat-gitops;image-ref:email: | - `apps/production/custom-configs/synapse-values.yaml` — kein `email:`/`smtp_host`/ | ||
| 355 | hosts/matrix.md | 165 | checked-ok | path-ok:apps/production/custom-configs/mas-secret.yaml@axion1337.chat-gitops | - `apps/production/custom-configs/mas-secret.yaml` (SOPS-entschlüsselt geprüft) — kein | ||
| 356 | hosts/matrix.md | 166 | prose-or-runtime | `email`/`smtp`/`mailer`-Eintrag. | |||
| 357 | hosts/matrix.md | 167 | checked-ok | path-ok:apps/production/element-server-suite.yaml@axion1337.chat-gitops | - `apps/production/element-server-suite.yaml` (HelmRelease values) — dito, nichts. | ||
| 358 | hosts/matrix.md | 174 | informational | id-ok:ZONE-02 | [ZONE-02](../shared/zone-axion1337.md) an dieser Stelle entblockt. | ||
| 359 | hosts/matrix.md | 179 | informational | id-no-issue:MATRIX-04 | MATRIX-04 unten. Nutzt die ohnehin am Apex laufende echte IONOS-Mail-Infrastruktur, | ||
| 360 | hosts/matrix.md | 182 | informational | id-no-issue:MATRIX-02 | ### MATRIX-02 — Pusht per Remote-Write auf einen offenen Prometheus · erledigt 2026-07-30 | ||
| 361 | hosts/matrix.md | 187 | informational | net-ref:10.0.0.2 | selbst die private IP `10.0.0.2` (verifiziert per `ip -4 addr show` auf dem Host). | ||
| 362 | hosts/matrix.md | 189 | checked-ok | path-ok:apps/monitoring/alloy-config.yaml@axion1337.chat-gitops | Verifiziert in `apps/monitoring/alloy-config.yaml` (diesem Cluster): Der Remote-Write-Push | ||
| 363 | hosts/matrix.md | 190 | informational | runtime-path:http://10.0.0.3:9090/api/v1/write;runtime-path:http://10.0.0.3:3100/... | geht bereits an `http://10.0.0.3:9090/api/v1/write` und Loki an `http://10.0.0.3:3100/...` - | ||
| 364 | hosts/matrix.md | 191 | informational | image-ref:188.245.193.243:9090 | **private IP, nicht die öffentliche** `188.245.193.243:9090`. Von dieser Seite aus ist hier | ||
| 365 | hosts/matrix.md | 194 | informational | id-ok:CFGMON-03 | [CFGMON-03](cfgmon.md#cfgmon-03--prometheus-remote-write-und-loki-sind-öffentlich-ohne-auth) | ||
| 366 | hosts/matrix.md | 197 | informational | id-no-issue:MATRIX-04 | ### MATRIX-04 — Host-Level Pre-Update-Benachrichtigung · erledigt 2026-07-30 | ||
| 367 | hosts/matrix.md | 200 | checked-ok | path-ok:docs/deployment-guides/07-host-maintenance-notifications.md@axion1337.chat-gitops | `docs/deployment-guides/07-host-maintenance-notifications.md` im gitops-Repo, | ||
| 368 | hosts/matrix.md | 201 | checked-ok | issue-ok:management#24(opened) | [Issue #24](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/24)): | ||
| 369 | hosts/matrix.md | 202 | prose-or-runtime | historical-wording | `unattended-upgrades` war bereits aktiv, neu ergänzt ist ein systemd-Timer | ||
| 370 | hosts/overmind.md | 10 | informational | runtime-path:git.lab;net-ref:10.58.73.17 | | **DNS (Lab)** | `git.lab` → `10.58.73.17` (TLS via Dokploy-Proxy, Zertifikate von der aXionLabs-CA: step-ca, 24h-Leaf, Intermediate bis 2035) | | ||
| 371 | hosts/overmind.md | 11 | prose-or-runtime | | **CPU/RAM** | 14 Kerne, 30 Gi (Stand 2026-07-31: ~11 Gi verfügbar) | | |||
| 372 | hosts/overmind.md | 12 | prose-or-runtime | | **Disk** | 444 G NVMe (~278 G frei, Stand 2026-07-31) | | |||
| 373 | hosts/overmind.md | 13 | informational | runtime-path:/dev/kvm | | **KVM** | `/dev/kvm` vorhanden — Basis für die Windows-Build-VM | | ||
| 374 | hosts/overmind.md | 20 | informational | image-ref:external_url https://git.lab | | GitLab CE 18.7.1 + Postgres 16 + Redis 7 | Dokploy-Stack `management-gitlabce` | `external_url https://git.lab`, SSH 2224; TLS terminiert der Dokploy-Proxy (GitLab-nginx lauscht nur :80) | | ||
| 375 | hosts/overmind.md | 21 | informational | runtime-path:git.lab;image-ref:extra_hosts: git.lab:10.58.73.17;runtime-path:/etc/gitlab-runner/certs/git.lab.crt | | gitlab-runner `lab-builder-1` (v18.7.0) | gleicher Stack, Service `gitlab-runner` | Docker-Executor + Socket, `concurrent = 1`. **Stolpersteine, live gefunden**: (1) Docker-interner DNS löst `git.la | ||
| 376 | hosts/overmind.md | 27 | prose-or-runtime | git.lab ist seit 2026-07-31 **kanonisch** für die gespiegelten Repos der Gruppe | |||
| 377 | hosts/overmind.md | 28 | prose-or-runtime | `axion1337.chat` — Stand 2026-08-09 **sieben**: die sechs Produkt-Repos (ThreadNet-Web, | |||
| 378 | hosts/overmind.md | 29 | prose-or-runtime | threadnet-call, thread-net-git, threadnet-operating, axion1337.chat-gitops, seit heute auch | |||
| 379 | hosts/overmind.md | 30 | prose-or-runtime | `game-operating`) **und `management`, also dieses Repo**. Push-Mirrors nach rohana/Gitea, | |||
| 380 | hosts/overmind.md | 31 | prose-or-runtime | direkte Gitea-Pushes tabu. | |||
| 381 | hosts/overmind.md | 33 | prose-or-runtime | ⚠️ `gameserver` (achtes Projekt der Gruppe) hat **keinen** Mirror — offen in | |||
| 382 | hosts/overmind.md | 34 | checked-ok | issue-ok:management#32(opened);issue-ok:management#32(opened) | [management#32](https://git.lab/axion1337.chat/management/-/issues/32), dort liegt auf Gitea | ||
| 383 | hosts/overmind.md | 37 | prose-or-runtime | Gitea bleibt: Flux-Source (via Mirror beliefert), Registry, Packages. | |||
| 384 | hosts/overmind.md | 38 | prose-or-runtime | **Issues nicht mehr** — die sind am 2026-08-01/02 nach git.lab gewandert | |||
| 385 | hosts/overmind.md | 39 | prose-or-runtime | ([ADR-0002](../decisions/0002-issues-und-management-ins-lab.md)). Die letzte Ausnahme, | |||
| 386 | hosts/overmind.md | 40 | informational | forge-repo:sorb/management | die Deploy-Übergabe-Issues auf dem Gitea-Tracker `sorb/management`, ist am 2026-08-02 | ||
| 387 | hosts/overmind.md | 41 | checked-ok | issue-ok:management#25(opened);issue-ok:management#26(closed);id-ok:LABNET-03 | mit LABNET-03 zurückgebaut: beide umgezogen (#25, #26), der Tracker ist leer. | ||
| 388 | hosts/overmind.md | 45 | prose-or-runtime | seit der Umwidmung zum Management-Repo `management` und wird seither gespiegelt, | |||
| 389 | hosts/overmind.md | 48 | informational | id-no-issue:OVERMIND-01 | ## OVERMIND-01 — GitLab-Container-Registry aktivieren, Images nach Konsument sortieren | ||
| 390 | hosts/overmind.md | 50 | prose-or-runtime | **Status:** erledigt (2026-08-01) | |||
| 391 | hosts/overmind.md | 53 | informational | runtime-path:registry.git.lab/axion1337.chat/threadnet-web/desktop-build:bullseye | `registry.git.lab/axion1337.chat/threadnet-web/desktop-build:bullseye` (Job 386 grün, | ||
| 392 | hosts/overmind.md | 55 | prose-or-runtime | damit grün durch (Job 398 - beweist auch den anonymen Pull des public Projekts durch | |||
| 393 | hosts/overmind.md | 56 | prose-or-runtime | den Runner-Daemon). Die rohana-`REGISTRY_*`-Variablen bleiben nur noch für den | |||
| 394 | hosts/overmind.md | 61 | prose-or-runtime | Lab-CI → rohana (Prod, Internet) → zurück ins Lab — koppelt Lab-Infrastruktur unnötig an | |||
| 395 | hosts/overmind.md | 65 | informational | forge-repo:sorb/threadnet-web | - **rohana (Gitea) behält**: `sorb/threadnet-web` (App-Image — Flux/Prod pullt es), | ||
| 396 | hosts/overmind.md | 71 | informational | image-ref:registry_external_url 'https://registry.git.lab' | 1. Omnibus-Config: `registry_external_url 'https://registry.git.lab'`, | ||
| 397 | hosts/overmind.md | 74 | informational | runtime-path:registry.git.lab;net-ref:10.58.73.17 | 2. Lab-DNS: `registry.git.lab` → `10.58.73.17` | ||
| 398 | hosts/overmind.md | 78 | informational | runtime-path:/etc/docker/certs.d/registry.git.lab/ca.crt | `/etc/docker/certs.d/registry.git.lab/ca.crt` (Datei liegt schon als | ||
| 399 | hosts/overmind.md | 79 | informational | runtime-path:/tmp/git.lab.crt | `/tmp/git.lab.crt` vom Runner-Setup — kopieren reicht; kein Daemon-Restart nötig) | ||
| 400 | hosts/overmind.md | 80 | informational | forge-repo:vendor/windows;runtime-path:registry.git.lab | 5. CI-Umstellung: `vendor/windows` pusht nach `registry.git.lab` (Bonus: GitLabs | ||
| 401 | hosts/overmind.md | 81 | informational | runtime-path:$CI_REGISTRY;runtime-path:$CI_JOB_TOKEN | eingebaute `$CI_REGISTRY`/`$CI_JOB_TOKEN`-Auth statt Gruppen-Secrets), | ||
| 402 | hosts/overmind.md | 82 | prose-or-runtime | `desktop_image`/`desktop_linux` in ThreadNet-Web folgen; Registry-Speicher liegt im | |||
| 403 | hosts/overmind.md | 85 | prose-or-runtime | **Fortschritt 2026-07-31**: Punkte 1–4 umgesetzt (Registry live auf | |||
| 404 | hosts/overmind.md | 86 | informational | runtime-path:registry.git.lab;forge-repo:vendor/windows | `registry.git.lab`, 401/Bearer-Auth korrekt, CA-Trust auf dem Host); `vendor/windows` | ||
| 405 | hosts/overmind.md | 87 | prose-or-runtime | pusht per `CI_JOB_TOKEN` in die Lab-Registry — verifiziert, Tags `5bc25447` + `stable` | |||
| 406 | hosts/overmind.md | 90 | prose-or-runtime | **Nächster Schritt:** `element-desktop-build` von rohana in die Lab-Registry umziehen | |||
| 407 | hosts/overmind.md | 91 | prose-or-runtime | (ThreadNet-Web-CI: `desktop_image`-Push-Ziel + `desktop_linux`-Image-Referenz) — bewusst | |||
| 408 | hosts/overmind.md | 92 | prose-or-runtime | historical-wording | zurückgestellt, bis kein Auto-Job das alte Image parallel referenziert (Reihenfolge: | ||
| 409 | hosts/overmind.md | 95 | informational | id-ok:OVERMIND-02 | ## OVERMIND-02 — Host-Ausfall 2026-07-31 ~19:15 lokal (NIC-Hang, Fix aktiv) | ||
| 410 | hosts/overmind.md | 97 | checked-ok | issue-ok:management#4(opened) | **Status:** Fix aktiv — die Beobachtung läuft als [Issue #4](https://git.lab/axion1337.chat/management/-/issues/4) | ||
| 411 | hosts/overmind.md | 107 | prose-or-runtime | **Fix (2026-07-31, Overmind-Session):** `ethtool --set-eee eno1 eee off` live gesetzt | |||
| 412 | hosts/overmind.md | 108 | informational | runtime-path:/etc/udev/rules.d/71-disable-eee-eno1.rules | + persistente udev-Regel `/etc/udev/rules.d/71-disable-eee-eno1.rules` (greift bei | ||
| 413 | hosts/overmind.md | 112 | prose-or-runtime | - ~~NIC-/BIOS-Firmware-Update 2.4.0.0 → 2.5.2.0~~ **erledigt** (Wartungsfenster | |||
| 414 | hosts/overmind.md | 121 | prose-or-runtime | - 19:05–19:12 — Provision-Job 409 grün (Rust 1.97.1 maschinenweit, Strawberry Perl, | |||
| 415 | hosts/overmind.md | 137 | prose-or-runtime | 8G. Nach dem NIC-Fix lief die Kette durch: **desktop_windows Job 438 grün** | |||
| 416 | hosts/overmind.md | 138 | prose-or-runtime | (2026-07-31 ~21:50 lokal, `Element Setup 1.12.17.exe`, 141 MB, unsigniert) — | |||
| 417 | hosts/overmind.md | 139 | checked-ok | issue-ok:ThreadNet-Web#5(closed);issue-ok:ThreadNet-Web#6(opened) | ThreadNet-Web#5 geschlossen, Folgethemen (Signing/Branding) in ThreadNet-Web#6. | ||
| 418 | hosts/overmind.md | 141 | prose-or-runtime | (resumefähiges Prefetch-Skript im ThreadNet-Web-Repo, Jobs 415/416/424/431). | |||
| 419 | hosts/overmind.md | 145 | checked-ok | issue-ok:ThreadNet-Web#5(closed) | Weitere CI-Betriebsthemen laufen über die Projekt-Issues (ThreadNet-Web#5 | ||
| 420 | hosts/overmind.md | 146 | checked-ok | issue-ok:threadnet-call#1(closed);id-no-issue:CFGMON-11 | Windows-Strecke, threadnet-call#1 npm-Ziel) und CFGMON-11 (Gitea-CI-Rückbau). | ||
| 421 | roadmap.md | 3 | prose-or-runtime | > Stand 2026-08-06. Diese Datei hält die **Linien und die Reihenfolge**, | |||
| 422 | roadmap.md | 6 | prose-or-runtime | > Die Gruppen-Milestones M1–M4 sind angelegt, und seit 2026-08-06 hängt **jedes | |||
| 423 | roadmap.md | 20 | prose-or-runtime | 1. **CVE-Meldeweg v2 live** — aggregierte Alarme deployen | |||
| 424 | roadmap.md | 21 | checked-ok | issue-ok:management#25(opened) | ([Übergabe-Issue #25](https://git.lab/axion1337.chat/management/-/issues/25)), | ||
| 425 | roadmap.md | 23 | checked-ok | issue-ok:axion1337.chat-gitops#45(opened);issue-ok:axion1337.chat-gitops#45(opened) | (Follow-up-Wunsch sorb). [gitops#45](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/45), | ||
| 426 | roadmap.md | 24 | checked-ok | issue-ok:axion1337.chat-gitops#49(opened) | [#49](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/49) | ||
| 427 | roadmap.md | 26 | checked-ok | issue-ok:management#7(opened);id-ok:CFGMON-01 | [CFGMON-01 (#7)](https://git.lab/axion1337.chat/management/-/issues/7) ⏰ | ||
| 428 | roadmap.md | 27 | checked-ok | issue-ok:management#10(opened);id-ok:CFGMON-09 | 3. **Backups wiederherstellen** — [CFGMON-09 (#10)](https://git.lab/axion1337.chat/management/-/issues/10) | ||
| 429 | roadmap.md | 29 | checked-ok | issue-ok:axion1337.chat-gitops#25(opened);id-ok:CFGMON-03 | 4. K3s-API-Härtung (gitops#25, gemeinsame Session), CFGMON-03-Konsolen-Klärung. | ||
| 430 | roadmap.md | 33 | prose-or-runtime | 1. ✅ **Site-to-Site-VPN** Hetzner ↔ Lab — erledigt 2026-08-01 | |||
| 431 | roadmap.md | 34 | checked-ok | issue-ok:management#12(closed) | ([#12](https://git.lab/axion1337.chat/management/-/issues/12), ADR-0004 akzeptiert, | ||
| 432 | roadmap.md | 35 | checked-ok | issue-ok:management#13(closed);id-ok:LABNET-03 | zwei AARs). Ernte daraus: ✅ **LABNET-03 (#13)** — Übergabe-Issues sind am | ||
| 433 | roadmap.md | 36 | prose-or-runtime | 2026-08-02 ins Lab gewandert, die Gitea-Ausnahme ist zurückgebaut. | |||
| 434 | roadmap.md | 37 | informational | id-ok:GAME-01 | 2. GAME-01-Erreichbarkeit + vSwitch-Aufnahme — | ||
| 435 | roadmap.md | 38 | checked-ok | issue-ok:management#2(opened) | historical-wording | [#2](https://git.lab/axion1337.chat/management/-/issues/2) (Silences bis 2026-08-04!) | |
| 436 | roadmap.md | 39 | checked-ok | issue-ok:axion1337.chat-gitops#46(opened) | 3. Roadmap-/Board-Ausbau in GitLab (Rest von gitops#46: Milestones, Boards). | ||
| 437 | roadmap.md | 40 | checked-ok | issue-ok:management#20(opened);id-ok:DOC-03 | 4. **Wiki-Oberfläche entscheiden** — [DOC-03 (#20)](https://git.lab/axion1337.chat/management/-/issues/20): | ||
| 438 | roadmap.md | 45 | checked-ok | issue-ok:management#14(opened);id-ok:CFGMON-14 | [CFGMON-14 (#14)](https://git.lab/axion1337.chat/management/-/issues/14) docker-Gruppe | ||
| 439 | roadmap.md | 47 | checked-ok | issue-ok:management#15(opened);id-ok:CFGMON-15 | [CFGMON-15 (#15)](https://git.lab/axion1337.chat/management/-/issues/15) Token-Hygiene, | ||
| 440 | roadmap.md | 48 | checked-ok | issue-ok:management#16(closed);id-ok:LABNET-04 | [LABNET-04 (#16)](https://git.lab/axion1337.chat/management/-/issues/16) Nacharbeiten. | ||
| 441 | roadmap.md | 52 | prose-or-runtime | 1. **Rebrand fortsetzen** — Desktop-Client heißt seit 2026-08-02 **ThreadNet** und | |||
| 442 | roadmap.md | 53 | checked-ok | issue-ok:ThreadNet-Web#10(closed);issue-ok:ThreadNet-Web#10(closed) | trägt die eigene Marke ([ThreadNet-Web#10](https://git.lab/axion1337.chat/ThreadNet-Web/-/issues/10), | ||
| 443 | roadmap.md | 54 | prose-or-runtime | Commit `6b0261d`). Offen: Web-Client-Icons/`brand`, About-Attribution. | |||
| 444 | roadmap.md | 55 | checked-ok | issue-ok:ThreadNet-Web#6(opened) | 2. Signing/Notarisierung (ThreadNet-Web#6) — ohne Signatur muss jeder Nutzer auf | ||
| 445 | roadmap.md | 57 | checked-ok | issue-ok:management#22(opened);id-ok:BUILD-01 | 3. **macOS reproduzierbar bauen** — [BUILD-01 (#22)](https://git.lab/axion1337.chat/management/-/issues/22): | ||
| 446 | roadmap.md | 59 | checked-ok | issue-ok:axion1337.chat-gitops#47(opened) | 4. **Raidplaner** (gitops#47) — Lean-Experiment: HumHub-Kandidat evaluieren. | ||
| 447 | roadmap.md | 60 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | 5. **Gäste-Invite-Workflow** (gitops#48) — Design steht (@concierge, | ||
| 448 | roadmap.md | 62 | checked-ok | issue-ok:ThreadNet-Web#9(opened) | 6. Zammad-artiges Feedback-Tool als spätere Ergänzung (ThreadNet-Web#9). | ||
| 449 | roadmap.md | 66 | checked-ok | path-ok:vision/axion1337-chat.md@management | - Rebranding-Runde (bewusst vertagt; Leitplanke in `vision/axion1337-chat.md`). | ||
| 450 | roadmap.md | 79 | checked-ok | issue-ok:management#17(closed) | **Der Einstieg ist erfolgt:** [Struktur-Workshop (#17)](https://git.lab/axion1337.chat/management/-/issues/17) | ||
| 451 | roadmap.md | 80 | prose-or-runtime | am 2026-08-06 — Visionen geschärft, M1–M4 angelegt, Board gesichtet, Kadenz und | |||
| 452 | roadmap.md | 88 | prose-or-runtime | historical-wording | Titel-Präfixe aus der Gitea-Migration sind am 2026-08-06 entfernt; zwei davon | ||
| 453 | roadmap.md | 90 | checked-ok | issue-ok:ThreadNet-Web#7(opened);issue-ok:management#1(opened) | (ThreadNet-Web#7 und #1, jeweils im Issue begründet). | ||
| 454 | shared/branding.md | 8 | prose-or-runtime | Hier im `management`-Repo, weil es als einziges der beteiligten Repos | |||
| 455 | shared/branding.md | 9 | prose-or-runtime | **gespiegelt** ist und jede Werkzeugentscheidung überlebt: Wird das | |||
| 456 | shared/branding.md | 16 | FLAG | path-miss:static/img/ | path-miss:static/img/ | Schriftzug), erstellt von sorb. Sie liegen im Wiki-Repo unter `static/img/` und | |
| 457 | shared/branding.md | 28 | prose-or-runtime | Icon-Slots fällt das sofort auf. Korrigiert am 2026-08-06 auf 21 % oben wie unten. | |||
| 458 | shared/branding.md | 37 | informational | tag-ok:v0.4.0 | Elf Artefakte, alle aus einer Quelle (Stand 2026-08-06, `v0.4.0`): | ||
| 459 | shared/branding.md | 41 | checked-ok | path-ok:apps/web/res/vector-icons/@ThreadNet-Web(dir) | | `apps/web/res/vector-icons/` | 1024, 512, 180, 152, 144, 120, 24 px | | ||
| 460 | shared/branding.md | 42 | checked-ok | path-ok:apps/desktop/build/icon.png@ThreadNet-Web | | `apps/desktop/build/icon.png` | App-/Installer-Icon | | ||
| 461 | shared/branding.md | 43 | checked-ok | path-ok:apps/desktop/build/icon.ico@ThreadNet-Web | | `apps/desktop/build/icon.ico` | Windows, 7 Größen von 16 bis 256 | | ||
| 462 | shared/branding.md | 44 | checked-ok | path-ok:apps/desktop/build/icon.icns@ThreadNet-Web | | `apps/desktop/build/icon.icns` | macOS, via `iconutil` aus einem `.iconset` | | ||
| 463 | shared/branding.md | 45 | checked-ok | path-ok:apps/desktop/build/icon.icon/Assets/element.png@ThreadNet-Web | | `apps/desktop/build/icon.icon/Assets/element.png` | Layer des macOS-Icon-Composers | | ||
| 464 | shared/branding.md | 47 | checked-ok | path-ok:vector-icons/1024.png@ThreadNet-Web | Prüfen lässt sich die Gleichheit über die Prüfsumme von `vector-icons/1024.png` | ||
| 465 | shared/branding.md | 48 | checked-ok | path-ok:build/icon.png@ThreadNet-Web | gegen `build/icon.png` — weichen sie ab, ist eine Seite nachgezogen worden und die | ||
| 466 | shared/branding.md | 55 | prose-or-runtime | Gruvbox Dark. Grundtöne `#282828` / `#1d2021`, Text `#ebdbb2`, Akzent `#bd93f9`, | |||
| 467 | shared/branding.md | 63 | prose-or-runtime | Am 2026-08-02 in der BookStack-Oberfläche eingestellt und von dort extrahiert | |||
| 468 | shared/branding.md | 65 | prose-or-runtime | der Coolors-Satz `#264653 · #2A9D8F · #E9C46A · #F4A261 · #E76F51`: | |||
| 469 | shared/branding.md | 69 | prose-or-runtime | | Primäre Farbe | `#264653` | Charcoal | | |||
| 470 | shared/branding.md | 74 | prose-or-runtime | | Seitenfarbe | `#77bb41` | Grün | | |||
| 471 | shared/branding.md | 75 | prose-or-runtime | | Seitenentwurfsfarbe | `#e32400` | Rot | | |||
| 472 | shared/branding.md | 86 | prose-or-runtime | je Theme vier Farben plus ein Schriftpaar. Sie sind seit 2026-08-02 **wörtlich | |||
| 473 | shared/branding.md | 93 | prose-or-runtime | | Sunset Boulevard | `#264653` | dunkel | `#e76f51` · `#f4a261` · `#e9c46a` | | |||
| 474 | shared/branding.md | 95 | prose-or-runtime | | Modern Minimalist | `#ffffff` | hell | `#36454f` · `#708090` · `#d3d3d3` | | |||
| 475 | shared/branding.md | 103 | prose-or-runtime | ⚠️ **Ob ein Theme hell oder dunkel gemeint ist, steht nicht verlässlich in den | |||
| 476 | shared/branding.md | 121 | checked-ok | path-ok:apps/desktop/axion1337/build.json@ThreadNet-Web;path-ok:apps/web/res/manifest.json@ThreadNet-Web | | Betriebssystem, Startmenü, Installer, PWA | **ThreadNet** | `productName` in `apps/desktop/axion1337/build.json`, `name` in `apps/web/res/manifest.json` | | ||
| 477 | shared/branding.md | 122 | checked-ok | path-ok:element-values.yaml@axion1337.chat-gitops;path-ok:apps/desktop/axion1337/config.json@ThreadNet-Web | | in der Anwendung | **aXion1337.Chat** | `brand` in `element-values.yaml` (Prod) und `apps/desktop/axion1337/config.json` | | ||
| 478 | shared/branding.md | 123 | checked-ok | path-ok:.env.production@threadnet-call | | eingebettetes Call-Widget | **aXion1337.Chat** | `VITE_PRODUCT_NAME` in `.env.production` (threadnet-call) | | ||
| 479 | shared/branding.md | 124 | checked-ok | path-ok:apps/authentik/authentik-blueprints.yaml@axion1337.chat-gitops | | Anmeldeseite (Authentik) | **ThreadNet** | `branding_title` im Brand-Blueprint (gitops, `apps/authentik/authentik-blueprints.yaml`) | | ||
| 480 | shared/branding.md | 130 | checked-ok | path-ok:vision/threadnet.md@management | Die Leitplanke dahinter steht in [`vision/threadnet.md`](../vision/threadnet.md): | ||
| 481 | shared/branding.md | 149 | checked-ok | path-ok:apps/production/custom-configs/element-values.yaml@axion1337.chat-gitops | | Element/ThreadNet-Web | `apps/production/custom-configs/element-values.yaml` (gitops), `setting_defaults.custom_themes` | 17 Themes; Änderungen chirurgisch, **nie die YAML neu serialisieren** | | ||
| 482 | shared/branding.md | 150 | checked-ok | path-ok:apps/web/res/vector-icons/@ThreadNet-Web(dir);path-ok:apps/web/res/manifest.json@ThreadNet-Web | | Web-Icons + PWA | `apps/web/res/vector-icons/`, `apps/web/res/manifest.json` (ThreadNet-Web) | `theme_color` = `#ed4f4c`, die Markenfarbe — nicht Elements `#76CFA6` | | ||
| 483 | shared/branding.md | 151 | checked-ok | path-ok:apps/desktop/build/@ThreadNet-Web(dir) | | Desktop-Icons | `apps/desktop/build/` (ThreadNet-Web) | `.png`, `.ico`, `.icns`, Layer-Asset — alle aus derselben Quelle | | ||
| 484 | shared/branding.md | 152 | checked-ok | path-ok:apps/desktop/axion1337/config.json@ThreadNet-Web | | ThreadNet Desktop | `apps/desktop/axion1337/config.json` (ThreadNet-Web) | eigene Kopie derselben Themes — beim Ändern beide mitziehen | | ||
| 485 | shared/branding.md | 153 | FLAG | path-miss:theme/sorbs-palette.md | path-miss:theme/sorbs-palette.md | | BookStack | *Settings → Customization*, getrennt für hell und dunkel | liegt in der Datenbank, **nicht im Repo** — schriftlich hier und in `theme/sorbs-palette.md` | | |
| 486 | shared/branding.md | 154 | prose-or-runtime | | BookStack (Feinschliff) | `theme/*.css` im Wiki-BookStack-Repo | nur Flächen, Text, Ränder — die sieben Farben oben gehören in die Oberfläche | | |||
| 487 | shared/branding.md | 155 | FLAG | path-miss:src/css/custom.css | path-miss:src/css/custom.css | | Docusaurus-Wiki | `src/css/custom.css` (homelab/wiki) | bislang nur Akzentfarbe | | |
| 488 | shared/branding.md | 156 | checked-ok | path-ok:apps/web/res/themes/element/img/backgrounds/alpenglow.jpg@ThreadNet-Web;path-ok:SdkConfig.ts@ThreadNet-Web | | Titelbild Login | `apps/web/res/themes/element/img/backgrounds/alpenglow.jpg` (ThreadNet-Web), gesetzt in `SdkConfig.ts` | siehe unten — Bilddatei kommt nur über einen Build in den Container | | ||
| 489 | shared/branding.md | 157 | checked-ok | path-ok:apps/authentik/authentik-blueprints.yaml@axion1337.chat-gitops;issue-ok:axion1337.chat-gitops#55(opened) | | Anmeldeseite Authentik | Brand-Blueprint in `apps/authentik/authentik-blueprints.yaml` (gitops) | Favicon und Hintergrund werden **von axion1337.chat referenziert**, nicht hochgeladen. **Logo ist no | ||
| 490 | shared/branding.md | 161 | prose-or-runtime | Seit 2026-08-06 zeigt die Login-Seite ein Alpenglühen über einer Bergkette statt | |||
| 491 | shared/branding.md | 173 | prose-or-runtime | Fotografen namentlich. Nur `en`/`de` anzupassen hätte in 29 Sprachen eine **falsche | |||
| 492 | shared/branding.md | 179 | informational | runtime-path:https://axion1337.chat/themes/element/img/backgrounds/alpenglow.jpg | `https://axion1337.chat/themes/element/img/backgrounds/alpenglow.jpg`. Wer das Bild im | ||
| 493 | shared/branding.md | 185 | checked-ok | path-ok:vector-icons/512.png@ThreadNet-Web | Der erste Versuch setzte `branding_logo` auf `vector-icons/512.png`. Ergebnis: das | ||
| 494 | shared/branding.md | 190 | prose-or-runtime | Zurückgesetzt am 2026-08-06 auf Authentiks eigenes Logo. Ein Ersatz braucht eine | |||
| 495 | shared/branding.md | 192 | FLAG | path-miss:threadnet-logo-wortmarke.png | path-miss:threadnet-logo-wortmarke.png | auch `threadnet-logo-wortmarke.png` (Bildmarke *über* Schriftzug). Offen in | |
| 496 | shared/branding.md | 204 | FLAG | path-miss:theme/sorbs-palette.md | path-miss:theme/sorbs-palette.md | `theme/sorbs-palette.md` im BookStack-Repo ist die betriebsnahe Kopie mit den | |
| 497 | shared/branding.md | 214 | checked-ok | path-ok:vision/threadnet.md@management;issue-ok:ThreadNet-Web#10(closed) | (→ [`vision/threadnet.md`](../vision/threadnet.md), ThreadNet-Web#10). | ||
| 498 | shared/commit-zuordnung-2026-08-07.md | 3 | prose-or-runtime | Am 2026-08-07 wurden die Zeitstempel aller Commits aus dieser Zusammenarbeit auf | |||
| 499 | shared/commit-zuordnung-2026-08-07.md | 14 | prose-or-runtime | `backup-vor-rewrite`-Branches rekonstruiert und **paarweise verifiziert**: Für jedes | |||
| 500 | shared/commit-zuordnung-2026-08-07.md | 26 | prose-or-runtime | Das Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines | |||
| 501 | shared/commit-zuordnung-2026-08-07.md | 27 | informational | tag-ok:v0.3.0;tag-ok:v0.4.0 | neu gestartet** (`v0.3.0`, `v0.4.0`, `desktop-v1.12.17-clientscan`). Ein Tag ist | ||
| 502 | shared/commit-zuordnung-2026-08-07.md | 33 | informational | image-ref:threadnet-web:v0.4.0;tag-ok:v0.4.0 | Glück, keine Planung:** Mit stehender Tag-Protection wäre `threadnet-web:v0.4.0` | ||
| 503 | shared/commit-zuordnung-2026-08-07.md | 37 | checked-ok | issue-ok:ThreadNet-Web#14(closed) | ThreadNet-Web#14. | ||
| 504 | shared/commit-zuordnung-2026-08-07.md | 42 | prose-or-runtime | ThreadNet-Web vor dem 2026-07-28 (3 Commits), gitops vor dem 2026-07-27 (147). | |||
| 505 | shared/commit-zuordnung-2026-08-07.md | 47 | prose-or-runtime | ## gitops — 117 Commits | |||
| 506 | shared/commit-zuordnung-2026-08-07.md | 169 | prose-or-runtime | ## management — 78 Commits | |||
| 507 | shared/commit-zuordnung-2026-08-07.md | 252 | prose-or-runtime | ## ThreadNet-Web — 47 Commits | |||
| 508 | shared/commit-zuordnung-2026-08-07.md | 304 | prose-or-runtime | ## threadnet-call — 9 Commits | |||
| 509 | shared/lab-netzwerk.md | 10 | checked-ok | issue-ok:management#12(closed) | > (Testreihe 1–7 in [#12](https://git.lab/axion1337.chat/management/-/issues/12)). | ||
| 510 | shared/lab-netzwerk.md | 11 | checked-ok | issue-ok:management#11(closed) | > Es gibt dazu **keine offenen Issues mehr** — auch die Restpunkte #11 | ||
| 511 | shared/lab-netzwerk.md | 12 | checked-ok | issue-ok:management#16(closed);id-ok:LABNET-04 | > (MacBook-Profil) und #16 (LABNET-04, Feinschliff an den UniFi-Regeln) sind | ||
| 512 | shared/lab-netzwerk.md | 13 | prose-or-runtime | > geschlossen. Alles Folgende ist **Bestand und Historie**, keine offene Arbeit. | |||
| 513 | shared/lab-netzwerk.md | 15 | prose-or-runtime | **Zwei WireGuard-Zugänge (Stand 2026-08-01, beide gelöst/abgenommen):** | |||
| 514 | shared/lab-netzwerk.md | 22 | informational | forge-repo:homelab/docs | ### Verhältnis zu `homelab/docs` | ||
| 515 | shared/lab-netzwerk.md | 30 | prose-or-runtime | Der Grund für die Doppelung ist der Mirror-Geltungsbereich aus der | |||
| 516 | shared/lab-netzwerk.md | 35 | informational | forge-repo:homelab/docs | darüber hinaus. **Bei Widerspruch gilt `homelab/docs`.** | ||
| 517 | shared/lab-netzwerk.md | 39 | informational | id-ok:LABNET-01 | ## LABNET-01 — WireGuard-Roadwarrior ins Lab kaputt (seit einigen Monaten) | ||
| 518 | shared/lab-netzwerk.md | 42 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | Damit ist die Cutover-Voraussetzung für gitops#48 erfüllt. | ||
| 519 | shared/lab-netzwerk.md | 46 | informational | net-ref:178.25.213.70 | der Fritzbox ihre öffentliche IP nicht) → Fix: Endpunkt `178.25.213.70`; | ||
| 520 | shared/lab-netzwerk.md | 52 | informational | net-ref:192.168.0.0/20 | /20-Blöcke in 192.168.0.0/16; `192.168.0.0/20` verschluckte das VPN-Subnetz | ||
| 521 | shared/lab-netzwerk.md | 53 | prose-or-runtime | 192.168.5.0/24 → Antworten an VPN-Clients endeten in der Bridge (SYN kam an, | |||
| 522 | shared/lab-netzwerk.md | 55 | prose-or-runtime | fremde Hosts funktionierten) → Fix: **VPN-Subnetz auf 10.58.74.0/24** (Docker | |||
| 523 | shared/lab-netzwerk.md | 58 | checked-ok | issue-ok:management#11(closed) | **Restarbeiten:** MacBook-WG-Profil → [Issue #11](https://git.lab/axion1337.chat/management/-/issues/11). ⚠️ Latente Wiederholungsgefahr | ||
| 524 | shared/lab-netzwerk.md | 59 | informational | net-ref:192.168.176.0/20 | notiert: Overminds Docker-Pool deckt auch `192.168.176.0/20` ab = kollidiert mit | ||
| 525 | shared/lab-netzwerk.md | 60 | prose-or-runtime | dem Fritzbox-Netz 192.168.178.x — aktuell folgenlos, aber bei künftigen Subnetz- | |||
| 526 | shared/lab-netzwerk.md | 66 | prose-or-runtime | (192.168.178.20) als Endpunkt — die UDM kennt hinter der Fritzbox ihre | |||
| 527 | shared/lab-netzwerk.md | 69 | prose-or-runtime | 178.25.213.70 ändern!). | |||
| 528 | shared/lab-netzwerk.md | 73 | prose-or-runtime | einem Port). Fix: UDM-WG auf **51840** umgezogen + Freigabe angepasst. | |||
| 529 | shared/lab-netzwerk.md | 85 | prose-or-runtime | **Diagnose-Plan von VOR der Lösung** — ⚠️ abgearbeitet und überholt, steht hier | |||
| 530 | shared/lab-netzwerk.md | 102 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | **Verwandt:** gitops#48 (Cutover erst nach Lösung), perspektivisch ersetzt ein | ||
| 531 | shared/lab-netzwerk.md | 105 | prose-or-runtime | ## Zugehörige Issues — alle geschlossen | |||
| 532 | shared/lab-netzwerk.md | 108 | prose-or-runtime | historical-wording | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. | ||
| 533 | shared/lab-netzwerk.md | 111 | prose-or-runtime | Zum Netz/VPN ist **nichts mehr offen** (Stand 2026-08-02): | |||
| 534 | shared/lab-netzwerk.md | 115 | checked-ok | issue-ok:management#11(closed);id-ok:LABNET-01 | | [#11](https://git.lab/axion1337.chat/management/-/issues/11) | LABNET-01-Rest — MacBook-WireGuard-Profil | geschlossen | | ||
| 535 | shared/lab-netzwerk.md | 116 | checked-ok | issue-ok:management#12(closed);id-ok:LABNET-02 | | [#12](https://git.lab/axion1337.chat/management/-/issues/12) | LABNET-02 — Site-to-Site-VPN (Design: [ADR-0004](../decisions/0004-site-to-site-vpn-hetzner-lab.md)) | geschlossen, Testreihe 1–7 proto | ||
| 536 | shared/lab-netzwerk.md | 117 | checked-ok | issue-ok:management#16(closed);id-ok:LABNET-04 | | [#16](https://git.lab/axion1337.chat/management/-/issues/16) | LABNET-04 — Feinschliff UniFi-Regeln | geschlossen | | ||
| 537 | shared/lab-netzwerk.md | 120 | FLAG | issue-state:management#13=closed,text-says-opened | issue-state:management#13 | bleiben offen: [#13](https://git.lab/axion1337.chat/management/-/issues/13) | |
| 538 | shared/lab-netzwerk.md | 121 | informational | id-ok:LABNET-03 | (LABNET-03, Rückbau der Gitea-Ausnahme für Übergabe-Issues — durch den Tunnel | ||
| 539 | shared/lab-netzwerk.md | 123 | checked-ok | issue-ok:management#15(opened);id-ok:CFGMON-15 | [#15](https://git.lab/axion1337.chat/management/-/issues/15) (CFGMON-15, | ||
| 540 | shared/lab-netzwerk.md | 124 | informational | id-ok:LABNET-02 | Widerruf der Einmal-Tokens aus der LABNET-02-Nacht — Credential-Hygiene, und der | ||
| 541 | shared/lab-netzwerk.md | 125 | prose-or-runtime | Widerruf kann still einen Push-Mirror brechen, solange dessen hinterlegtes Token | |||
| 542 | shared/zone-axion1337.md | 9 | informational | net-ref:217.160.0.140;image-ref:2001:8d8:100f:f000::2e9 | | **Apex** | `217.160.0.140` / `2001:8d8:100f:f000::2e9` — IONOS-Hosting, nicht eigene Infrastruktur | | ||
| 543 | shared/zone-axion1337.md | 18 | informational | runtime-path:rohana | historical-wording | | `rohana` | löst auf ❌ | gelöscht | **gelöscht** ⚠️ | fehlt | ⚠️ schwächer als vorher | | |
| 544 | shared/zone-axion1337.md | 20 | informational | runtime-path:~all | | `matrix` | löst auf ❌ | IONOS ❌ | `~all` ❌ | fehlt | offen | | ||
| 545 | shared/zone-axion1337.md | 22 | informational | runtime-path:~all;id-ok:ZONE-02 | | **Apex** | legitim ✅ | IONOS (genutzt) | `~all` | **`p=none`** ⚠️ | siehe ZONE-02 | | ||
| 546 | shared/zone-axion1337.md | 36 | informational | net-ref:217.160.0.140;image-ref:2001:8d8:100f:f000::2e9 | | `axion1337.de` | `217.160.0.140` | `2001:8d8:100f:f000::2e9` | IONOS-Hosting | | ||
| 547 | shared/zone-axion1337.md | 37 | informational | net-ref:217.160.0.140 | | `www` | `217.160.0.140` | dito | IONOS-Hosting — hier ist `www` **legitim** | | ||
| 548 | shared/zone-axion1337.md | 38 | informational | runtime-path:rohana;net-ref:188.245.193.243;image-ref:2a01:4f8:c17:93eb::1 | | `rohana` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Gitea | | ||
| 549 | shared/zone-axion1337.md | 39 | informational | net-ref:188.245.193.243;image-ref:2a01:4f8:c17:93eb::1 | | `selendis` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Grafana | | ||
| 550 | shared/zone-axion1337.md | 40 | informational | net-ref:157.90.155.206 | | `game` | `157.90.155.206` | — | Pterodactyl | | ||
| 551 | shared/zone-axion1337.md | 41 | informational | net-ref:49.13.132.245 | | `matrix` | `49.13.132.245` | — | Matrix-Homeserver | | ||
| 552 | shared/zone-axion1337.md | 42 | informational | net-ref:217.160.233.227;image-ref:2001:8d8:1000:30f5:… | | `ftp` | `217.160.233.227` | `2001:8d8:1000:30f5:…` | IONOS-Default | | ||
| 553 | shared/zone-axion1337.md | 43 | informational | id-ok:ZONE-01 | | `www.rohana`, `www.selendis`, `www.game`, `www.matrix` | wie ohne `www` | teils | überflüssig, siehe ZONE-01 | | ||
| 554 | shared/zone-axion1337.md | 46 | informational | runtime-path:rohana | `autodiscover`), auf `rohana` und `game` nicht. | ||
| 555 | shared/zone-axion1337.md | 50 | checked-ok | issue-ok:management#5(opened);id-ok:ZONE-01 | Damit die Rezepte in [ZONE-01](https://git.lab/axion1337.chat/management/-/issues/5) | ||
| 556 | shared/zone-axion1337.md | 57 | prose-or-runtime | kann `rechnung@rohana.axion1337.de` in den Umschlag schreiben. Die folgenden | |||
| 557 | shared/zone-axion1337.md | 72 | informational | runtime-path:rohana | Genau die richtige Aussage für `rohana`, `selendis`, `matrix` — die verschicken keine | ||
| 558 | shared/zone-axion1337.md | 73 | informational | id-no-issue:MATRIX-01 | Mail (für `matrix` verifiziert in MATRIX-01: weder Synapse noch MAS senden). | ||
| 559 | shared/zone-axion1337.md | 99 | prose-or-runtime | ⚠️ **DMARC wird vererbt.** Fehlt `_dmarc.rohana`, gilt die Policy des | |||
| 560 | shared/zone-axion1337.md | 101 | checked-ok | issue-ok:management#6(opened);id-ok:ZONE-02 | ([ZONE-02](https://git.lab/axion1337.chat/management/-/issues/6)) — **damit erben | ||
| 561 | shared/zone-axion1337.md | 129 | informational | runtime-path:rohana | historical-wording | **Real eingetreten:** Bei `rohana` sind MX und SPF gelöscht, die Ersatz-Records | |
| 562 | shared/zone-axion1337.md | 137 | prose-or-runtime | historical-wording | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. | ||
| 563 | shared/zone-axion1337.md | 140 | checked-ok | issue-ok:management#5(opened);id-ok:ZONE-01 | - [ZONE-01 — IONOS-Default-Records bereinigen (Rezepte im Issue; rohana/selendis in Arbeit)](https://git.lab/axion1337.chat/management/-/issues/5) | ||
| 564 | shared/zone-axion1337.md | 141 | checked-ok | issue-ok:management#6(opened);id-ok:ZONE-02 | - [ZONE-02 — Apex-DMARC ist `p=none` und schützt nichts](https://git.lab/axion1337.chat/management/-/issues/6) | ||
| 565 | verfahren/README.md | 10 | prose-or-runtime | | [aar/](aar/) | Abgelegte AARs, benannt `JJJJ-MM-TT-<vorhaben>.md` | | |||
| 566 | verfahren/README.md | 12 | checked-ok | path-ok:textbloecke.md@management | [`textbloecke.md`](textbloecke.md) hält kurze, kopierbare Blöcke, die man einer | ||
| 567 | verfahren/README.md | 18 | checked-ok | path-ok:.gitlab/issue_templates/Deploy-Übergabe.md@management | `.gitlab/issue_templates/Deploy-Übergabe.md` und erscheint beim Anlegen eines | ||
| 568 | verfahren/README.md | 22 | checked-ok | path-ok:hosts/@management(dir);path-ok:shared/@ThreadNet-Web(dir),management(dir) | historical-wording | Abgrenzung zum Rest des Repos: `hosts/` und `shared/` halten **offene Punkte**, | |
| 569 | verfahren/aar-vorlage.md | 7 | prose-or-runtime | Was ist live und verifiziert. Was ist bewusst **nicht** live, und warum. | |||
| 570 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 1 | checked-ok | issue-ok:axion1337.chat-gitops#47(opened) | # AAR — CVE-Pipeline `gitops#47` | ||
| 571 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 3 | informational | runtime-path:/opt/threadnet-operating/monitoring | **Datum:** 2026-08-01 · **Host/Stack:** CFGMON, `/opt/threadnet-operating/monitoring` | ||
| 572 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 9 | prose-or-runtime | **Live und verifiziert:** Scanner (29/29 Images gescannt), Exporter, Prometheus-Job | |||
| 573 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 13 | checked-ok | path-ok:alertmanager.yml@threadnet-operating | `alertmanager.yml` auf einen Null-Receiver (Commit `2b715ca` in | ||
| 574 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 14 | informational | forge-repo:sorb/threadnet-operating | `sorb/threadnet-operating`). Grund siehe Befund 1. | ||
| 575 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 20 | prose-or-runtime | | 1 | Eine Matrix-Nachricht pro CVE. 126 CRITICAL landen in **einer** Alertmanager-Gruppe, nach 24 h kommen 1222 HIGH dazu. Dazu steht `save_state()` in `do_POST` hinter der Sende-Schleife: bricht ein | |||
| 576 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 21 | checked-ok | issue-ok:axion1337.chat-gitops#52(opened) | historical-wording | | 2 | `docker compose up -d` aktiviert geänderte Configs nicht. Einzeldatei-Mounts hängen am Inode, `git pull` benennt um. Prometheus lief nach dem Deploy mit alten Regeln — `promtool` fand 9, Prometh | |
| 577 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 22 | checked-ok | issue-ok:axion1337.chat-gitops#51(opened) | | 3 | `TrivyScanStale` kann ein nie erfolgreich gescanntes Image nicht melden — ohne ersten Report existiert keine Serie, an der `time() - trivy_last_scan_timestamp` hängen könnte | LOW | notiert in ` | ||
| 578 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 23 | checked-ok | image-ref:except: continue;issue-ok:axion1337.chat-gitops#51(opened) | | 4 | Der Exporter prunt den First-Seen-State bei **jedem** Scrape. Ein transienter Lesefehler (`except: continue`) löscht die Erstfund-Zeitstempel des Targets dauerhaft | LOW | notiert in `gitops#51` | ||
| 579 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 27 | informational | image-ref:goauthentik/server:2026.2.3 | 1316 LOW. Spitzenreiter `goauthentik/server:2026.2.3` mit 369 CRITICAL+HIGH. | ||
| 580 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 34 | informational | runtime-path:rohana.axion1337.de | | Private Registry `rohana.axion1337.de` braucht Credentials für Trivy | Anonymer Pull | zieht anonym, keine Credentials nötig | | ||
| 581 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 35 | checked-ok | path-ok:hosts/game.md@management | | Zwei down-Targets könnten Folge des Deploys sein | `avg_over_time(up[3h])` | 0.00 — schon 3 h vorher tot, in `hosts/game.md` erfasst | | ||
| 582 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 58 | checked-ok | issue-ok:axion1337.chat-gitops#51(opened) | Richtungsentscheidung zu `gitops#51`, bevor die Alarme scharf gehen: entweder | ||
| 583 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 59 | checked-ok | path-ok:matrix-alerts.py@threadnet-operating | `matrix-alerts.py` auf eine Sammelnachricht pro Webhook-Batch umbauen (die fünf | ||
| 584 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 65 | informational | image-ref:coturn/coturn:latest | Nebenbefund ohne Handlungsbedarf von hier: `coturn/coturn:latest` ist das einzige | ||
| 585 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 66 | checked-ok | issue-ok:axion1337.chat-gitops#47(opened) | ungepinnte Image (bereits in `gitops#47` notiert). | ||
| 586 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 1 | checked-ok | forge-repo:sorb/management#2;issue-ok:management#2(opened);id-ok:LABNET-02 | # AAR — LABNET-02, CFGMON-Seite (Übergabe `sorb/management#2`) | ||
| 587 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 8 | informational | runtime-path:/etc/wireguard/lab.conf | **Live:** `wireguard-tools` installiert, Keypair erzeugt, `/etc/wireguard/lab.conf` | ||
| 588 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 10 | informational | net-ref:10.58.75.2/24 | `enabled`. Interface `lab` steht mit `10.58.75.2/24`, Routen und Forward-Regeln aktiv, | ||
| 589 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 11 | informational | net-ref:10.58.73.1;runtime-path:~lab | Split-DNS gesetzt (`10.58.73.1`, `~lab`). | ||
| 590 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 28 | prose-or-runtime | historical-wording | | 1 | `enp7s0` seit 18:11 DOWN, Privatnetz-Route weg. Auslöser war die Hetzner-Range-Umstellung /16 → /8: die private NIC wurde ab- und neu angehängt (`renamed from eth1`), danach wurde `hc-net-ifup@e | ||
| 591 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 30 | prose-or-runtime | | 3 | `sudo` ist aus einer Agenten-Session nicht bedienbar (kein TTY). Die Schritte liefen über die **docker-Gruppenmitgliedschaft** des Kontos (privilegierter Container + `nsenter`) — das ist root-äq | |||
| 592 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 31 | informational | net-ref:10.58.73.0/24 | historical-wording | | 4 | Hetzner-Range war tatsächlich /16 — unabhängig aus der Routing-Tabelle verifiziert (`10.0.0.0/16 via 10.0.0.1 dev enp7s0`), `10.58.73.0/24` lag außerhalb | LOW | bestätigt, Umstellung durch sorb | |
| 593 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 38 | prose-or-runtime | | Split-Tunnel biegt den Default-Weg um | `ip route get 8.8.8.8` | unverändert über `eth0`; öffentliches DNS und HTTPS funktionieren | | |||
| 594 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 42 | prose-or-runtime | **Nicht verifiziert:** ob der k3s-Host selbst läuft. Er ist unerreichbar, *weil* CFGMON | |||
| 595 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 65 | informational | net-ref:10.58.75.2 | eintragen (`Networks behind client = 10.0.0.0/24`, Client-IP `10.58.75.2`): | ||
| 596 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 74 | informational | net-ref:10.0.0.3 | 1. `ip -brief addr show enp7s0` → UP mit `10.0.0.3` | ||
| 597 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 75 | informational | net-ref:10.0.0.0/8;runtime-path:/16 | 2. `ip route | grep '^10\.'` → neue Route sollte `10.0.0.0/8` zeigen, nicht mehr `/16` | ||
| 598 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 85 | prose-or-runtime | **Entscheidung offen:** ob der Root-Zugang über die docker-Gruppe so bleiben soll | |||
| 599 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 115 | informational | runtime-path:/etc/systemd/system/wg-quick@lab.service.d/10-after-docker.conf | 1. Drop-in `/etc/systemd/system/wg-quick@lab.service.d/10-after-docker.conf` mit | ||
| 600 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 118 | prose-or-runtime | `PostUp = iptables -N DOCKER-USER 2>/dev/null || true` — Rückfall, falls Docker | |||
| 601 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 121 | prose-or-runtime | Verifiziert: `systemctl show -p After` listet `docker.service`, `restart` läuft sauber | |||
| 602 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 123 | prose-or-runtime | historical-wording | korrekt ab, keine Dubletten bei Neustarts). **Nicht verifiziert:** das Verhalten bei | ||
| 603 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 143 | checked-ok | issue-ok:management#2(opened) | (`oFRxWU…Z0o=`, Kommentar 399 in `management#2`) **gehört zu keinem Server auf der | ||
| 604 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 145 | informational | id-ok:LABNET-02 | historical-wording | `wgsrv3 = sVuM0pgT…ZyM=` (LABNET-02, 51841). Jede Initiation von CFGMON war damit | |
| 605 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 158 | informational | runtime-path:~lab.de;runtime-path:~axion1337.de;runtime-path:~axionlabs.de;net-ref:10.58.73.1 | `~lab.de`, `~axion1337.de`, `~axionlabs.de` über `10.58.73.1`; aXionLabs-Root-CA | ||
| 606 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 159 | prose-or-runtime | im Truststore (verifiziert gegen die git.lab-Kette und per Fingerprint-Abgleich | |||
| 607 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 160 | prose-or-runtime | gegen die step-ca, Port 666). Voller Dienst-Neustart aus der Datei verifiziert | |||
| 608 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 170 | prose-or-runtime | **Offen nach diesem Nachtrag:** Testreihe 1–7 (inkl. Gateway-Rolle), Reboot-Beweis, | |||
| 609 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 171 | informational | forge-repo:sorb/buffer | Schlüsselrotation (Client-Private-Key lief beim Bootstrap über `sorb/buffer` auf | ||
| 610 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 172 | prose-or-runtime | rohana; Repo wird laut sorb vernichtet, Rotation danach trotzdem empfohlen), | |||
| 611 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 173 | FLAG | path-miss:lab.conf | path-miss:lab.conf | Repo-Zuhause für `lab.conf` + systemd-Drop-in (zurückgestellt bis nach der | |
| 612 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 181 | informational | runtime-path:git.lab | Split-DNS-Zonen aktiv; `git.lab` auflösbar und pingbar. Damit sind der Bootfix | ||
| 613 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 183 | prose-or-runtime | aus Nachtrag 2 im Ernstfall verifiziert. Aus der Offen-Liste von Nachtrag 2 | |||
| 614 | verfahren/aar/2026-08-01-labnet02-lab.md | 1 | informational | id-ok:LABNET-02 | # AAR — LABNET-02, Lab-Seite (UDM/UniFi, Einzäunung und Abnahme) | ||
| 615 | verfahren/aar/2026-08-01-labnet02-lab.md | 5 | checked-ok | issue-ok:management#12(closed) | **Gegenstück:** [CFGMON-Seite](2026-08-01-labnet02-cfgmon.md) · Issue: `management#12` | ||
| 616 | verfahren/aar/2026-08-01-labnet02-lab.md | 14 | checked-ok | issue-ok:management#12(closed) | Testreihe 1–7 vollständig bestanden (Protokolle in `management#12`), zusätzlich der | ||
| 617 | verfahren/aar/2026-08-01-labnet02-lab.md | 23 | informational | net-ref:10.0.0.0/24 | UDM (Port 51841), **CFGMON als Client/Initiator**, `10.0.0.0/24` als Netz hinter dem | ||
| 618 | verfahren/aar/2026-08-01-labnet02-lab.md | 38 | informational | net-ref:10.0.0.0/16;net-ref:10.58.73.0/24;net-ref:10.0.0.0/8 | | 5 | Hetzner-Netz-Range `10.0.0.0/16` deckte das Routen-Ziel `10.58.73.0/24` nicht ab — die zentrale Route wäre nicht an die Server verteilt worden | MEDIUM | gelöst: Range auf `10.0.0.0/8` erweitert | ||
| 619 | verfahren/aar/2026-08-01-labnet02-lab.md | 43 | informational | net-ref:10.58.75.2;net-ref:10.0.0.3 | historical-wording | `10.58.75.2` (Tunnel) *und* `10.0.0.3` (Hetzner-Netz) erreichbar. Vom Lab aus war die | |
| 620 | verfahren/aar/2026-08-01-labnet02-lab.md | 44 | prose-or-runtime | erste Adresse geblockt, die zweite offen — dieselbe Maschine, dieselben Dienste, | |||
| 621 | verfahren/aar/2026-08-01-labnet02-lab.md | 75 | prose-or-runtime | - IoT- und Arbeit-Sperren sind **nicht verifiziert** — keine Gegenstelle in diesen | |||
| 622 | verfahren/aar/2026-08-01-labnet02-lab.md | 77 | informational | id-ok:LABNET-02 | - Regel-Beschreibungsfelder in UniFi sind leer; Verweis auf LABNET-02/ADR-0004 fehlt. | ||
| 623 | verfahren/aar/2026-08-01-labnet02-lab.md | 80 | prose-or-runtime | Gitea-Ausnahme in ADR-0002/README/CLAUDE.md zurückbauen. | |||
| 624 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 12 | informational | runtime-path:axionwiki.lab | | Docusaurus-Wiki unter `axionwiki.lab` | ✅ live, eigenes Zertifikat | | ||
| 625 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 13 | informational | forge-repo:homelab/wiki-bookstack | | BookStack als Gegenentwurf (`homelab/wiki-bookstack`) | ✅ live unter `bookstack.lab` | | ||
| 626 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 14 | prose-or-runtime | | 11 neue Themes (aXion1337 Light + 10 Paletten) | ✅ Web live, in allen Clients — ⚠️ **Paletten waren falsch**, korrigiert → [Nachtrag](#nachtrag-2026-08-02--die-paletten-waren-erfunden) | | |||
| 627 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 15 | prose-or-runtime | | Desktop-Clients Linux/Windows/macOS | ✅ Release `desktop-1.12.17-themes` | | |||
| 628 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 22 | checked-ok | path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir);path-ok:docs/@ThreadNet-Web(dir),axion1337.chat-gitops(dir),threadnet-call(dir);issue-ok:management#19(opened) | historical-wording | | 1 | **Drei auseinandergelaufene Dokustände**: Gitea-Wiki-Repo (gepflegt, nicht gespiegelt), `wiki`-Branch im gitops-Repo (Mai-Abzug von `docs/`), `docs/` im main. Das Wiki enthielt sachlich Falsches | |
| 629 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 24 | FLAG | runtime-path:/favicon.ico;path-miss:text/html | path-miss:text/html | | 3 | **`/favicon.ico` lieferte HTTP 200 mit `text/html`** — die nginx-`try_files`-Kette gab die 404-Seite mit Erfolgsstatus aus. Safari hielt das Icon für vorhanden und zeigte den Buchstaben-Fallback | |
| 630 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 27 | checked-ok | path-ok:res/vector-icons/@ThreadNet-Web(dir);path-ok:manifest.json@ThreadNet-Web | | 6 | **Nur macOS bekam neue Icons** — Windows (`.ico`) und Web (`res/vector-icons/`, `manifest.json`) blieben auf Element | MEDIUM | gelöst, `c51b681` | | ||
| 631 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 29 | checked-ok | issue-ok:management#21(opened) | historical-wording | | 8 | **Windows-Build-VM war weg** (`No such container`) — der CI-Job kann sie nur starten, nicht anlegen | MEDIUM | umgangen (manueller Neustart), Optionen in #21 | | |
| 632 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 30 | checked-ok | issue-ok:management#22(opened) | | 9 | **macOS-Build braucht Xcode** für das DMG (`actool`) und Rust für die nativen Module | MEDIUM | umgangen (electron-builder 25 fürs ZIP, `hdiutil` fürs DMG), dauerhaft offen in #22 | | ||
| 633 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 67 | prose-or-runtime | Release-Notes stand ein Link auf ein Issue, das ich nie angelegt hatte (fiel | |||
| 634 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 79 | informational | runtime-path:/login | | 3 | **Healthcheck auf `/login` schlug fehl → Container `unhealthy` → Traefik überspringt ihn komplett** | Default-Zertifikat + leeres 404, **identisch zum Bild eines fehlenden Netzes** | | ||
| 635 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 86 | prose-or-runtime | im laufenden Container verifiziert wurde, ist damit kein Sicherheitsnetz, sondern | |||
| 636 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 87 | informational | runtime-path:/status;runtime-path:/login | ein Risiko. Ich hatte ihn zweimal ungeprüft geändert (`/status` → `/login`). | ||
| 637 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 91 | informational | runtime-path:/opt | `/opt`-Pfad — und die CI braucht `VARIANT_PATH`, sonst greift die Variante gar | ||
| 638 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 98 | prose-or-runtime | Test, ein Issue-Verweis ohne Existenzprüfung, ein Icon-Skript ohne Blick aufs | |||
| 639 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 104 | checked-ok | issue-ok:management#20(opened);id-ok:DOC-03 | - **Entscheidung DOC-03 (#20)**: Docusaurus oder BookStack — beide laufen jetzt, | ||
| 640 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 109 | checked-ok | issue-ok:management#22(opened);issue-ok:management#21(opened) | - **macOS reproduzierbar bauen** (#22), **Windows-VM-Robustheit** (#21). | ||
| 641 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 111 | checked-ok | issue-ok:ThreadNet-Web#6(opened) | Signing (ThreadNet-Web#6) — ohne Signatur bleibt für Nutzer auf macOS der | ||
| 642 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 118 | prose-or-runtime | historical-wording | **Was war.** Die zehn Themes aus dem Rollout trugen nicht die Farben aus Anthropics | ||
| 643 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 126 | prose-or-runtime | **Warum es nicht auffiel.** Erfundene Farben sehen nicht falsch aus. Ein Theme | |||
| 644 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 131 | prose-or-runtime | **Falle für die nächste Runde.** Ob ein Theme hell oder dunkel gemeint ist, steht | |||
| 645 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 135 | checked-ok | path-ok:shared/branding.md@management | stehen in [`shared/branding.md`](../../shared/branding.md). | ||
| 646 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 144 | prose-or-runtime | Sunset-Boulevard-Palette sind bis auf zwei Ziffern identisch (`#e76e51`/`#e76f51`, | |||
| 647 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 145 | prose-or-runtime | `#f3a261`/`#f4a261`) — unabhängig voneinander auf demselben Coolors-Satz gelandet. | |||
| 648 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 147 | prose-or-runtime | **Korrigiert:** gitops `b10b607` (Web, live verifiziert) · ThreadNet-Web `80fcf6c` | |||
| 649 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 150 | FLAG | path-miss:resources/webapp.asar | path-miss:resources/webapp.asar | stecken in `resources/webapp.asar`. Abgestimmt so belassen; der nächste reguläre | |
| 650 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 151 | checked-ok | image-ref:status:wartet;issue-ok:ThreadNet-Web#11(opened) | historical-wording | Build zieht die Korrektur mit (nachgehalten in ThreadNet-Web#11, `status:wartet`). | |
| 651 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 3 | prose-or-runtime | **Datum:** 2026-08-09 · **Host/Stack:** git.lab, Gitea, K3s-Cluster (Authentik, | |||
| 652 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 9 | prose-or-runtime | **Live und verifiziert:** | |||
| 653 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 17 | prose-or-runtime | - 251 Commits über vier Repos auf 12:00-UTC-Zeitstempel umgeschrieben, Force- | |||
| 654 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 18 | prose-or-runtime | gepusht, Mirrors und Flux verifiziert synchron | |||
| 655 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 20 | prose-or-runtime | vorher unbekannte Repos ohne Push-Mirror | |||
| 656 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 21 | prose-or-runtime | - `game-operating` gespiegelt und secret-frei verifiziert (Coolify- | |||
| 657 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 26 | prose-or-runtime | **Bewusst nicht live:** | |||
| 658 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 33 | prose-or-runtime | - `gameserver` weiterhin ohne Mirror — zwei Repos gleichen Namens mit | |||
| 659 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 40 | prose-or-runtime | | 1 | `matrix-recovery-flow`-Blueprint scheiterte seit Tagen bei jedem Lauf, während Flux grün meldete | HIGH | behoben | | |||
| 660 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 42 | checked-ok | path-ok:develop/config.json@ThreadNet-Web | | 3 | Web-Client sendete Fehlerberichte an `rageshakes.element.io` — die Desktop-Bereinigung vom 2026-08-01 hatte den Web-Build nie erreicht, weil der beim Bauen Elements eigene `develop/config.json` | ||
| 661 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 43 | checked-ok | issue-ok:management#32(opened) | | 4 | `game-operating` und `gameserver` ohne Push-Mirror; bei `gameserver` liegt auf Gitea ein anderer Stand als auf git.lab | MEDIUM | `game-operating` behoben, `gameserver` offen (management#32) | | ||
| 662 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 44 | prose-or-runtime | | 5 | Nach dem Privat-Stellen von `game-operating` auf Gitea übersprang die Stillstandsprüfung den Mirror-Abgleich klaglos, statt es als Befund zu werten | MEDIUM | behoben | | |||
| 663 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 46 | prose-or-runtime | | 7 | Gitops-Leitfaden 04 nannte 7 Themes mit teils erfundenen Namen (`Gruvbox Dark`, `Wal`); tatsächlich 17 | LOW | behoben | | |||
| 664 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 47 | prose-or-runtime | | 8 | threadnet-call-Doku beschrieb einen manuellen npm-Publish, der seit 2026-08-06 automatisiert läuft | LOW | behoben | | |||
| 665 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 50 | checked-ok | issue-ok:ThreadNet-Web#14(closed);tag-ok:v0.4.0 | historical-wording | | 11 | Tag-Push (Force, für die Historien-Anonymisierung) löste in ThreadNet-Web drei Release-Pipelines neu aus; nur weil die geschützten Registry-Variablen im Zeitfenster fehlten, wurde `v0.4.0` nich | |
| 666 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 54 | prose-or-runtime | - **`game-operating` öffentlich auf Gitea** — Secret-Scan über alle fünf | |||
| 667 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 68 | checked-ok | issue-ok:management#1(opened) | Flux-Status.** Blueprint-Fehler #1/#2 waren nur so sichtbar — Flux, die | ||
| 668 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 69 | prose-or-runtime | ConfigMap und der Cluster-Zustand insgesamt meldeten durchgehend grün. | |||
| 669 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 71 | checked-ok | issue-ok:management#2(opened) | verdeckten Fehler #2 erst zugänglich gemacht — der reguläre Weg (Worker-Log) | ||
| 670 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 74 | checked-ok | issue-ok:management#3(opened) | zu glauben** hat Befund #3 aufgedeckt — die Annahme im Issue betraf nur den | ||
| 671 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 75 | checked-ok | path-ok:config.json@ThreadNet-Web | Desktop-Client, `config.json` auf dem Web-Server sagte etwas anderes. | ||
| 672 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 77 | checked-ok | issue-ok:management#4(opened) | Befund #4 im ersten Lauf gefunden — eine dynamische Projektliste statt einer | ||
| 673 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 78 | prose-or-runtime | im Code gepflegten hat zwei Repos zutage gebracht, die niemand auf dem | |||
| 674 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 84 | prose-or-runtime | 251 Paaren über Tree *und* Commit-Nachricht verifiziert, keine Annahme. | |||
| 675 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 90 | checked-ok | issue-ok:management#32(opened) | - **`gameserver`-Mirror** — Standklärung nötig, management#32 | ||
| 676 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 91 | prose-or-runtime | - **Stillstandsprüfung Authentik-Teil** — `AUTHENTIK_URL`/`AUTHENTIK_TOKEN`, | |||
| 677 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 92 | checked-ok | issue-ok:management#31(opened) | management#31, bewusst aufgeschoben (sorb, 2026-08-09) | ||
| 678 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 94 | checked-ok | issue-ok:ThreadNet-Web#9(opened) | entschieden, ThreadNet-Web#9 | ||
| 679 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 100 | checked-ok | path-ok:decisions/@management(dir) | Lehre aus der Retro, in `decisions/` dokumentiert | ||
| 680 | verfahren/deploy-uebergabe.md | 6 | checked-ok | issue-ok:axion1337.chat-gitops#47(opened) | Eingeführt am 2026-08-01 nach dem Deploy der CVE-Pipeline (`gitops#47`), siehe | ||
| 681 | verfahren/deploy-uebergabe.md | 11 | prose-or-runtime | 1. Wer baut, öffnet **auf git.lab** ein Issue aus der Vorlage **Deploy-Übergabe** | |||
| 682 | verfahren/deploy-uebergabe.md | 12 | checked-ok | path-ok:.gitlab/issue_templates/Deploy-Übergabe.md@management | (`.gitlab/issue_templates/Deploy-Übergabe.md`, im Feld *Description template*). | ||
| 683 | verfahren/deploy-uebergabe.md | 51 | checked-ok | issue-ok:axion1337.chat-gitops#52(opened) | `--force-recreate`. Details: `gitops#52`. | ||
| 684 | verfahren/deploy-uebergabe.md | 55 | prose-or-runtime | historical-wording | Datensammlung und Außenwirkung lassen sich fast immer getrennt scharf schalten. | ||
| 685 | verfahren/deploy-uebergabe.md | 71 | prose-or-runtime | - [ ] Nach dem Deploy **im Container** verifiziert, dass die neue Config aktiv ist | |||
| 686 | verfahren/deploy-uebergabe.md | 83 | prose-or-runtime | direkt auf dem Gitea-Mirror und werden vom nächsten Mirror-Lauf **kommentarlos | |||
| 687 | verfahren/deploy-uebergabe.md | 89 | informational | runtime-path:https://rohana.axion1337.de/sorb/<repo>/commit/<sha>.patch | `https://rohana.axion1337.de/sorb/<repo>/commit/<sha>.patch` ziehen | ||
| 688 | verfahren/deploy-uebergabe.md | 92 | prose-or-runtime | 3. **CFGMON** vor dem nächsten Pull: `git fetch && git reset --hard origin/main` | |||
| 689 | verfahren/issue-migration/README.md | 1 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | # Issue-Migration Gitea → GitLab (gitops#48) | ||
| 690 | verfahren/issue-migration/README.md | 3 | checked-ok | path-ok:migrate.py@management | `migrate.py` überführt Issues (offen **und** geschlossen, inkl. Kommentare) | ||
| 691 | verfahren/issue-migration/README.md | 4 | prose-or-runtime | eines Gitea-Repos in ein bestehendes GitLab-Projekt. Einmal-Werkzeug für den | |||
| 692 | verfahren/issue-migration/README.md | 5 | FLAG | issue-miss:management#48 | issue-miss:management#48 | #48-Cutover; hier versioniert wegen Reproduzierbarkeit. | |
| 693 | verfahren/issue-migration/README.md | 10 | informational | image-ref:<!-- gitea-migration: OWNER/REPO#N --> | - **Idempotent** über Marker `<!-- gitea-migration: OWNER/REPO#N -->` in der | ||
| 694 | verfahren/issue-migration/README.md | 16 | informational | image-ref:host:* | 2026-08-01 sind die 9 Gitea-Labels + 5 `host:*` als Gruppe-13-Labels angelegt) | ||
| 695 | verfahren/issue-migration/README.md | 17 | prose-or-runtime | - PRs werden ausgefiltert, geschlossene Issues nach Anlage geschlossen | |||
| 696 | verfahren/issue-migration/README.md | 26 | informational | runtime-path:~/.config/gitea-rohana/token | Tokens: `~/.config/gitea-rohana/token` (read:issue) und | ||
| 697 | verfahren/issue-migration/README.md | 27 | informational | runtime-path:~/.config/gitlab-lab/token | `~/.config/gitlab-lab/token` (Admin) auf dem Mac. | ||
| 698 | verfahren/issue-migration/README.md | 33 | prose-or-runtime | | sorb/thread-net-git | Projekt 18 | ✅ 2026-08-01 (1 Issue, nummerngleich) | | |||
| 699 | verfahren/issue-migration/README.md | 34 | prose-or-runtime | | sorb/threadnet-call | Projekt 19 | ✅ 2026-08-01 (2 Issues, nummerngleich) | | |||
| 700 | verfahren/issue-migration/README.md | 35 | prose-or-runtime | | sorb/ThreadNet-Web | Projekt 16 | ✅ 2026-08-01 (9 Issues, nummerngleich) | | |||
| 701 | verfahren/issue-migration/README.md | 36 | prose-or-runtime | | sorb/axion1337.chat-gitops | Projekt 17 | ✅ 2026-08-01 (50 Issues, **Nummern verschoben**) | | |||
| 702 | verfahren/issue-migration/README.md | 38 | prose-or-runtime | ⚠️ **gitops-Nummern sind NICHT deckungsgleich**: Gitea hatte Lücken (PRs zählen | |||
| 703 | verfahren/issue-migration/README.md | 39 | prose-or-runtime | mit), GitLab vergibt lückenlos — z. B. Gitea#48 → GitLab#46, Gitea#51 → GitLab#49, | |||
| 704 | verfahren/issue-migration/README.md | 40 | prose-or-runtime | Gitea#52 → GitLab#50. Die verbindliche Zuordnung steht im Migrations-Fußtext | |||
| 705 | verfahren/issue-migration/README.md | 41 | prose-or-runtime | historical-wording | jedes GitLab-Issues (`Migriert aus Gitea …#N`); alte Commit-/Doku-Verweise auf | ||
| 706 | verfahren/issue-migration/README.md | 44 | checked-ok | issue-ok:axion1337.chat-gitops#48(opened) | **Cutover-Nachschritte** (siehe gitops#48): Gitea-Issues schließen/als migriert | ||
| 707 | verfahren/issue-migration/README.md | 47 | prose-or-runtime | aktiven), Bot-/Token-Workflows (claude-issues → GitLab-Äquivalent) offen. | |||
| 708 | verfahren/refinement.md | 20 | prose-or-runtime | des Monats an — dann ist die Vorbereitung (die AARs des Monats) ohnehin offen. | |||
| 709 | verfahren/refinement.md | 29 | prose-or-runtime | 2. **WIP-Limit prüfen** — höchstens zwei Issues in `doing`. Ist es voll, wird nichts | |||
| 710 | verfahren/refinement.md | 44 | prose-or-runtime | - Welche **ADRs** sind durch die Realität überholt (→ neues ADR, altes auf | |||
| 711 | verfahren/refinement.md | 51 | checked-ok | path-ok:retro/@management(dir) | Ergebnisse werden unter [`retro/`](retro/) abgelegt, eine Datei je Termin. Die | ||
| 712 | verfahren/refinement.md | 59 | prose-or-runtime | ermöglicht, welche Lehren, was bleibt offen. **Offene Punkte aus einem AAR werden | |||
| 713 | verfahren/refinement.md | 61 | checked-ok | issue-ok:management#14(opened);issue-ok:management#16(closed) | 2026-08-01, nachgezogen als #14–#16). | ||
| 714 | verfahren/refinement.md | 88 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | - Die **kanonischen Arbeitskonventionen** stehen in [`CLAUDE.md`](../CLAUDE.md) und | ||
| 715 | verfahren/refinement.md | 89 | prose-or-runtime | sind über den Gitea-Mirror von überall lesbar. | |||
| 716 | verfahren/retro/2026-08-09.md | 15 | prose-or-runtime | vergessen, weil sie im Moment des Findens ein Issue bekamen — auch die, für die | |||
| 717 | verfahren/retro/2026-08-09.md | 23 | checked-ok | issue-ok:management#15(opened);issue-ok:management#20(opened) | historical-wording | management#15 und #20 lagen drei Tage ohne Spalte — das ist der beabsichtigte | |
| 718 | verfahren/retro/2026-08-09.md | 31 | informational | image-ref:status:offen | muss. Genau deshalb hat eine Session am 2026-08-06 ein `status:offen` erfunden und | ||
| 719 | verfahren/retro/2026-08-09.md | 40 | prose-or-runtime | ## 2. Welche ADRs sind durch die Realität überholt? | |||
| 720 | verfahren/retro/2026-08-09.md | 42 | prose-or-runtime | **Keine überholt — aber eine Lücke.** | |||
| 721 | verfahren/retro/2026-08-09.md | 45 | prose-or-runtime | gebraucht.** Am 2026-08-07 wurde eine dauerhafte Prozessregel eingeführt (englische | |||
| 722 | verfahren/retro/2026-08-09.md | 46 | prose-or-runtime | Conventional Commits, Zeitstempel auf 12:00 UTC) und am 2026-08-09 rückwirkend auf | |||
| 723 | verfahren/retro/2026-08-09.md | 47 | prose-or-runtime | 251 Commits angewandt — eine **irreversible** Änderung an vier Repos, mit | |||
| 724 | verfahren/retro/2026-08-09.md | 48 | prose-or-runtime | Force-Push durch einen Mirror, von dem Flux liest. | |||
| 725 | verfahren/retro/2026-08-09.md | 51 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | ist das ein Lehrbuchfall. Stattdessen steht die Regel nur in der `CLAUDE.md` und | ||
| 726 | verfahren/retro/2026-08-09.md | 55 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | erweitert (Titel ohne Priorität, Meilenstein-Pflicht) — beides in der `CLAUDE.md`, | ||
| 727 | verfahren/retro/2026-08-09.md | 57 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | die `CLAUDE.md` die *Regel*. Es ist aber genau die Zwei-Orte-Konstruktion, die wir | ||
| 728 | verfahren/retro/2026-08-09.md | 70 | prose-or-runtime | | `build_embedded` (threadnet-call) | grün, seit jeher | lud **nie** ein Artefakt hoch, falscher Pfad | | |||
| 729 | verfahren/retro/2026-08-09.md | 71 | FLAG | path-miss:dist/ | path-miss:dist/ | | npm-Paket `0.19.2-threadnet.6` | veröffentlicht | 12,5 KB statt 12,8 MB, **ohne `dist/`** | | |
| 730 | verfahren/retro/2026-08-09.md | 72 | prose-or-runtime | | Blueprint `matrix-recovery-flow` | Flux grün, ConfigMap aktuell | seit Tagen bei **jedem** Lauf verworfen | | |||
| 731 | verfahren/retro/2026-08-09.md | 74 | prose-or-runtime | | Leere Pipelines | rot | **nichts kaputt** — der umgekehrte Fall, Rauschen, das rot abtrainiert | | |||
| 732 | verfahren/retro/2026-08-09.md | 75 | informational | tag-ok:v0.4.0 | | Release-Pipeline auf `v0.4.0` | lief nach Tag-Push an | hätte ein veröffentlichtes Image überschrieben | | ||
| 733 | verfahren/retro/2026-08-09.md | 87 | checked-ok | issue-ok:axion1337.chat-gitops#50(opened) | Es gibt Issues für Einzelfälle — gitops#50 (Configs greifen nicht ohne Neustart), | ||
| 734 | verfahren/retro/2026-08-09.md | 88 | checked-ok | issue-ok:management#28(opened);issue-ok:ThreadNet-Web#14(closed) | management#28 (Mirror-Ausfall unbemerkt), ThreadNet-Web#14 (Release überschreibbar, | ||
| 735 | verfahren/retro/2026-08-09.md | 91 | informational | tag-ok:v0.4.0 | ⚠️ **Der letzte Fall ist der unangenehmste.** Dass `v0.4.0` nicht überschrieben | ||
| 736 | verfahren/retro/2026-08-09.md | 99 | prose-or-runtime | diesen Monat einzeln und mühsam gelernt haben — Blueprint-Status ≠ error, Mirror | |||
| 737 | verfahren/retro/2026-08-09.md | 103 | checked-ok | issue-ok:management#28(opened) | Das ist die Verallgemeinerung von management#28, das am 2026-08-06 bewusst nach | ||
| 738 | verfahren/retro/2026-08-09.md | 112 | checked-ok | image-ref:status:next;issue-ok:management#15(opened);issue-ok:management#20(opened) | - `status:next`: management#15 und #20 (fällig 31.08.) — Zusage von sorb | ||
| 739 | verfahren/retro/2026-08-09.md | 113 | checked-ok | image-ref:status:wartet;issue-ok:threadnet-call#4(opened);issue-ok:ThreadNet-Web#11(opened) | historical-wording | - `status:wartet` entfernt bei threadnet-call#4 und ThreadNet-Web#11: der im Issue | |
| 740 | verfahren/retro/2026-08-09.md | 115 | prose-or-runtime | - **M5 — Härtung** angelegt, 14 Issues aus M1 verschoben. Trennlinie: *Ist etwas | |||
| 741 | verfahren/retro/2026-08-09.md | 123 | prose-or-runtime | ## Offen aus dieser Retro | |||
| 742 | verfahren/stillstandspruefung.md | 11 | prose-or-runtime | der bei jedem Lauf verworfen wurde, während Flux grün meldete. | |||
| 743 | verfahren/stillstandspruefung.md | 23 | prose-or-runtime | | Repo ohne aktiven Push-Mirror | `game-operating` wurde angelegt und nie gespiegelt — auf Gitea existierte es nicht | | |||
| 744 | verfahren/stillstandspruefung.md | 24 | checked-ok | issue-ok:management#28(opened);id-ok:MIRROR-01 | | Mirror-Drift | MIRROR-01 (management#28): fällt der Mirror aus, liefert Flux still den letzten Stand weiter | | ||
| 745 | verfahren/stillstandspruefung.md | 25 | prose-or-runtime | historical-wording | | Pipeline mit null Jobs | ThreadNet-Web 203/204, threadnet-call 187 — rot, ohne dass etwas kaputt war | | ||
| 746 | verfahren/stillstandspruefung.md | 26 | prose-or-runtime | | Erfolgreicher Job ohne Artefakt | `build_embedded` lief seit jeher grün und lud **nichts** hoch | | |||
| 747 | verfahren/stillstandspruefung.md | 27 | FLAG | path-miss:dist/ | path-miss:dist/ | | npm-Paket zu klein | `0.19.2-threadnet.6`: 12,5 KB statt 12,8 MB, ohne `dist/` | | |
| 748 | verfahren/stillstandspruefung.md | 32 | prose-or-runtime | jahrelang durchrutscht. (Beim ersten Lauf kamen so zwei Projekte zum Vorschein, | |||
| 749 | verfahren/stillstandspruefung.md | 37 | prose-or-runtime | Geplanter CI-Job im management-Repo, zusätzlich von Hand über *Run pipeline* | |||
| 750 | verfahren/stillstandspruefung.md | 38 | prose-or-runtime | auslösbar. Befunde färben die Pipeline **rot** — das ist bei uns die Alarmanlage, | |||
| 751 | verfahren/stillstandspruefung.md | 39 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops | nicht ein zusätzlicher Meldeweg (siehe `gitops/CLAUDE.md` zur TURN-Rotation). | ||
| 752 | verfahren/stillstandspruefung.md | 45 | code-block | export GITEA_TOKEN=$(cat ~/.config/gitea-rohana/push-token) # fuer private Spiegel | |||
| 753 | verfahren/stillstandspruefung.md | 53 | prose-or-runtime | aufgefallen am 2026-08-09: `game-operating` wurde auf Gitea privat gestellt, und | |||
| 754 | verfahren/stillstandspruefung.md | 54 | prose-or-runtime | die Prüfung übersprang den Mirror-Abgleich klaglos. Ein Repo, das gespiegelt wird, | |||
| 755 | verfahren/textbloecke.md | 5 | checked-ok | path-ok:CLAUDE.md@axion1337.chat-gitops,management | Die Konventionen stehen kanonisch in [`CLAUDE.md`](../CLAUDE.md) — aber eine | ||
| 756 | verfahren/textbloecke.md | 14 | checked-ok | path-ok:CLAUDE.md@management | während die `management/CLAUDE.md` zwei nannte. | ||
| 757 | verfahren/textbloecke.md | 24 | code-block | historical-wording | Lies zuerst CLAUDE.md im management-Repo auf git.lab und halte dich daran. | ||
| 758 | verfahren/textbloecke.md | 25 | code-block | Kanonisch ist git.lab; nie direkt nach Gitea pushen. | |||
| 759 | verfahren/textbloecke.md | 27 | code-block | Bevor du ein Issue schließt oder darüber urteilst: vollständig lesen, inklusive | |||
| 760 | verfahren/textbloecke.md | 30 | code-block | Verifiziert und vermutet klar trennen; fremde Messungen als fremde kennzeichnen. | |||
| 761 | verfahren/textbloecke.md | 35 | informational | forge-repo:sorb/Backlogs | > dem Pfad `sorb/Backlogs` statt nach dem Namen `Backlogs`; und ein Issue, von dem | ||
| 762 | verfahren/textbloecke.md | 43 | code-block | Konventionen: CLAUDE.md im management-Repo — von hier lesbar über den Gitea-Mirror | |||
| 763 | verfahren/textbloecke.md | 44 | code-block | rohana.axion1337.de/sorb/management. Dort NUR lesen, niemals hinpushen. | |||
| 764 | verfahren/textbloecke.md | 48 | code-block | Ping auf 10.58.73.17 schlägt IMMER fehl (nur 443 + DNS offen), das ist kein | |||
| 765 | verfahren/textbloecke.md | 64 | code-block | · Außenwirkung und Not-Aus · Rollback · bewusst offen Gelassenes. | |||
| 766 | verfahren/textbloecke.md | 79 | code-block | - Alle Commits über git.lab gepusht, kein Rest im Arbeitsverzeichnis, Mirror grün. | |||
| 767 | verfahren/textbloecke.md | 80 | code-block | - Jeder offene Punkt und Nebenbefund ist ein Issue — nichts bleibt nur im Chat. | |||
| 768 | vision/axion1337-chat.md | 3 | checked-ok | issue-ok:management#17(closed) | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). | ||
| 769 | vision/axion1337-chat.md | 23 | prose-or-runtime | **Kontrolliert wachsend** (entschieden 2026-08-06). Offen für Neue, aber **jeder | |||
| 770 | vision/axion1337-chat.md | 37 | prose-or-runtime | Nicht mehr offen: Das Rebranding wird in **M4 zu Ende gebracht**, nicht separat | |||
| 771 | vision/axion1337-chat.md | 38 | checked-ok | path-ok:threadnet.md@management | terminiert — siehe [`threadnet.md`](threadnet.md). | ||
| 772 | vision/homelab.md | 3 | checked-ok | issue-ok:management#17(closed) | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). | ||
| 773 | vision/homelab.md | 33 | checked-ok | issue-ok:management#10(opened) | [#10](https://git.lab/axion1337.chat/management/-/issues/10) — offen bleibt | ||
| 774 | vision/homelab.md | 35 | prose-or-runtime | Gitea-Datenbank). Siehe dort. | |||
| 775 | vision/threadnet.md | 3 | checked-ok | issue-ok:management#17(closed) | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). | ||
| 776 | vision/threadnet.md | 9 | prose-or-runtime | wiederverwendbare Produkte gedacht: ThreadNet-Web (Element-Web-Fork mit | |||
| 777 | vision/threadnet.md | 10 | prose-or-runtime | Discord-artiger Raumliste), threadnet-call (Call-Fork), thread-net-git, | |||
| 778 | vision/threadnet.md | 11 | prose-or-runtime | threadnet-operating. | |||
| 779 | vision/threadnet.md | 37 | prose-or-runtime | und entscheiden, ob bereinigt (History-Rewrite) oder bewusst akzeptiert wird. |