Files
management/STATUS.md
T
Thore CimbalandClaude Opus 4.8 51c05edb2d docs(issues): review all waiting issues, close #0041 and #0025
Went through the seven imported waiting issues and replaced the generic
'reason is in the GitLab history' placeholder with the real blocker, which
completes #0041. Three of the seven were not merely imprecise but wrong:

- #0025: the deploy had long landed; screenshots confirm 24 aggregated messages
  in the security room (limit 29), summing to the known 126 CRITICALs.
- #0014: the A/B/C decision exists as ADR-0008 (option A). Half its open question
  is now answered — MATRIX has no docker group at all, so the root-equivalence
  does not apply there.
- #0027: the blocking Struktur-Workshop happened on 2026-08-06 and produced three
  ADRs, but W1 and W3 were spot-checked and are still unresolved.

The remaining four wait on a named action by sorb. Measured from here: the GAME
exporters are still filtered (and their silences expired on 2026-08-04, so
TargetDown has been firing every 4h since), while CFGMON's 9090/3100 are already
closed from the internet — so #0008 is about making that state deliberate rather
than an acute exposure.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-15 12:00:00 +00:00

7.9 KiB

STATUS

Issues (30 open, 16 closed)

Verteilung: M1 6 · M2 18 · M4 2 · M5 4

Issue Status Meilenstein Priorität Title
0002 waiting M1 medium GAME-01: Host von CFGMON aus nicht erreichbar, 2 Prometheus-Targets down
0004 waiting M1 low OVERMIND-02: e1000e-NIC-Hang — Beobachtung nach EEE-Fix + Firmware-Update
0008 waiting M1 medium CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung
0009 open M2 low CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API
0014 open M2 low CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur
0015 next M2 medium CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen
0018 open M2 low DOC-01: Wiki-Rollout abschließen — CI-Freigaben, Zeitplan, Dokploy-Stack, wiki.lab
0019 open M2 low DOC-02: Veralteten wiki-Branch im gitops-Repo entfernen?
0021 waiting M2 medium OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen
0022 open M4 low BUILD-01: macOS-Client reproduzierbar bauen — aktuell nur manuell auf sorbs Mac
0027 open M2 medium AUDIT-01: Acht Widersprüche aus dem LABNET-02-Nachlauf (Selbst-Audit CFGMON-Session)
0028 open M2 low MIRROR-01: Ein Ausfall der Push-Mirrors bleibt unbemerkt — Produktion friert still ein
0029 open M4 medium UI harmonisieren: gleiche Farben und Formen über alle Oberflächen
0030 in-progress M1 medium Der Restore ist nie geprobt — Sicherungen sind bisher eine Vermutung
0031 open M1 low Stillstandsprüfung: GITEA_TOKEN und Authentik-Teil nachziehen
0032 open M2 medium gameserver hat keinen Push-Mirror — und auf Gitea liegt ein anderer Stand
0033 open M2 low OVERMIND-01 — element-desktop-build von rohana in die Lab-Registry umziehen
0034 open M2 medium CFGMON-11 — Gitea-CI-Rückbau abschließen (sicher rückbaubare Schritte)
0035 open M2 medium Rollout Gruppenregeln-Pointer: axion1337.chat-gitops
0036 open M2 medium Rollout Gruppenregeln-Pointer: ThreadNet-Web
0037 open M2 medium Rollout Gruppenregeln-Pointer: threadnet-call
0038 open M2 medium Rollout Gruppenregeln-Pointer: thread-net-git
0039 open M2 medium Rollout Gruppenregeln-Pointer: threadnet-operating
0040 open M2 low neckbeard-Rückmeldungen aus dem Feldtest einreichen
0042 open M2 high Migration in Betrieb nehmen: Push, erster Spiegel-Lauf, CI-Schedule
0043 open M5 medium Invitation-Flow: case-insensitive Eindeutigkeitsprüfung im Prompt-Stage
0044 open M5 low SOPS-Values-Secret-Änderung startet den konsumierenden Dienst nicht neu
0045 open M1 low Inhalts-Meldung führt ins Leere: kein Kontaktweg für Melder
0051 open M5 high CVE-Remediation-Pass: Schwachstellen-Report abarbeiten
0052 open M5 medium Update-Kadenz festlegen & :latest-Tags beseitigen

Active design docs (0)

none active

ADRs (16)

ADR Status Title
0001 accepted 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert
0002 accepted 0002 — Issues und Management-Repo ziehen ins Lab („das Lab ist die Quelle der Wahrheit")
0003 accepted 0003 — CVE-Meldeweg: aggregierte Alarme, eigener Security-Raum, gleicher Bot
0004 accepted 0004 — Site-to-Site-VPN Hetzner-Projektnetz ↔ Lab, schaltbar über die UDM
0005 accepted 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen
0006 accepted 0006 — Wikis ins Lab konsolidieren, Docusaurus als gemeinsame Lesefläche
0007 superseded 0007 — Wiki-Oberfläche: Docusaurus läuft, BookStack als Gegenentwurf
0008 accepted 0008 — Agenten-Sessions auf CFGMON laufen root-äquivalent über die docker-Gruppe
0009 accepted 0009 — Commit-Konventionen und rückwirkende Anonymisierung der Historie
0010 accepted 0010 — Härtung ist ein eigener Meilenstein (M5); M1 misst nur Kaputtes
0011 accepted 0011 — Provisionierung verweigert Localpart-Kollisionen, statt an bestehende Konten zu verknüpfen
0012 accepted ADR-0012: Issues leben im Repo; GitLab wird deterministisch bespiegelt
0013 accepted ADR-0013: Gruppenregeln kanonisch im management-Repo, Komponenten zeigen und werden geprüft
0014 accepted 0014 — Wiki.js löst Docusaurus ab: abgeschottete Betriebs-/Anwenderdoku, docs-as-code
0015 accepted 0015 — Wiki.js Git-Storage: Inhalt fließt Cluster→Gitea→kanonisiert nach git.lab
0016 accepted 0016 — Das Notfallhandbuch bleibt lab-intern und wird nicht gespiegelt

Open AARs (2)