#0055 is done: ThreadNet-Web be323ed checks in an .npmrc binding @sorb to rohana. The bump that mattered was not the file but what upstream's .gitignore does with it - it ignores /.npmrc, so the naive fix would have stayed local while CI kept resolving against npmjs. Measured in an isolated tree: without the file pnpm goes to npmjs and fails, with it the scope resolves to rohana at the integrity hash the lockfile already carries, and with rohana unreachable the install fails instead of falling back. threadnet-call only publishes and already sets the scope in its own CI; gitops never touches it. ThreadNet-Web was the only consumer. Four issues no longer describe reality, each verified rather than assumed: - #0091 (gitops#61) was fixed when it was written - on_conflict: fail shipped in ef04d86 and the MAS pod has run that config since 2026-08-11T14:08:41Z. Its one deliberate remainder became #0043, which is closed and verified live. - #0079 (gitops#46) asked for the Gitea migration and a central view. The migration ran; the central view was decided the other way round - repo canonical, GitLab mirrored (ADR-0012/0019) - which also answers the reachability trade-off it left open, and better than its three options did. - #0075 (gitops#40) is rejected, not done: it wanted new issues to appear in the Gitea kanban automatically. Issues no longer live in Gitea and the board is script-written. Nothing was accomplished; the question dissolved. - #0098 is a rollout record whose only remainder, the macOS build, is #0022. Three AARs move to harvested - every open item in them is tracked as an issue. Checked and still accurate, so left alone: the wiki branch still exists on both remotes (#0019), docs/TASKS.md and oldwiki/ are still there (#0085), element-web-docs still names live resources (#0086), res/themes/element persists (#0100), only WIKI_CANONIZE_TOKEN is set so TURN rotation still lacks its token (#0084), gameserver still has zero push mirrors (#0032), the broken .6 package is still published (#0101), and options.ts still builds simulcast layers regardless of codec, which is what blocks VP9 (#0057). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
14 KiB
14 KiB
STATUS
Issues (63 open, 33 closed)
Verteilung: M1 16 · M2 17 · M3 4 · M4 11 · M5 15
| Issue | Status | Meilenstein | Priorität | Title |
|---|---|---|---|---|
| 0002 | waiting | M1 | medium | GAME-01: Host von CFGMON aus nicht erreichbar, 2 Prometheus-Targets down |
| 0004 | waiting | M1 | low | OVERMIND-02: e1000e-NIC-Hang — Beobachtung nach EEE-Fix + Firmware-Update |
| 0008 | waiting | M1 | medium | CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung |
| 0009 | open | M2 | low | CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API |
| 0014 | open | M2 | low | CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur |
| 0015 | waiting | M2 | medium | CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen |
| 0019 | open | M2 | low | DOC-02: Veralteten wiki-Branch im gitops-Repo entfernen? |
| 0021 | waiting | M2 | medium | OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen |
| 0022 | open | M4 | low | BUILD-01: macOS-Client reproduzierbar bauen — aktuell nur manuell auf sorbs Mac |
| 0027 | open | M2 | medium | AUDIT-01: Acht Widersprüche aus dem LABNET-02-Nachlauf (Selbst-Audit CFGMON-Session) |
| 0029 | open | M4 | medium | UI harmonisieren: gleiche Farben und Formen über alle Oberflächen |
| 0030 | in-progress | M1 | medium | Der Restore ist nie geprobt — Sicherungen sind bisher eine Vermutung |
| 0031 | open | M1 | low | Stillstandsprüfung: GITEA_TOKEN und Authentik-Teil nachziehen |
| 0032 | open | M2 | medium | gameserver hat keinen Push-Mirror — und auf Gitea liegt ein anderer Stand |
| 0033 | open | M2 | low | OVERMIND-01 — element-desktop-build von rohana in die Lab-Registry umziehen |
| 0034 | open | M2 | medium | CFGMON-11 — Gitea-CI-Rückbau abschließen (sicher rückbaubare Schritte) |
| 0040 | open | M2 | low | neckbeard-Rückmeldungen aus dem Feldtest einreichen |
| 0042 | open | M2 | high | Migration in Betrieb nehmen: Push, erster Spiegel-Lauf, CI-Schedule |
| 0051 | open | M5 | high | CVE-Remediation-Pass: Schwachstellen-Report abarbeiten |
| 0053 | open | M2 | low | Historien-Durchgang: acht nicht-kanonische Commits mitziehen |
| 0056 | open | M1 | high | External PostgreSQL Migration: CloudNativePG or Hetzner |
| 0057 | open | M4 | medium | Element Call: VP9 codec retry |
| 0058 | open | M5 | medium | Web Application Firewall (WAF) |
| 0059 | open | M5 | medium | Pod Security Admission (Restricted) |
| 0060 | open | M1 | medium | Federation allowlist or closed federation decision |
| 0061 | open | M2 | low | External-Secrets Operator vs. current SOPS setup |
| 0062 | open | M5 | medium | Renovate/Dependabot for chart and image updates |
| 0063 | open | M5 | medium | Security advisory monitoring (ESS/Element) |
| 0064 | open | M5 | medium | Disable automountServiceAccountToken where not needed |
| 0065 | open | M5 | high | K3s API security hardening |
| 0066 | open | M5 | medium | auditd for file integrity & syscall audit |
| 0067 | open | M5 | medium | Kernel hardening (sysctl) |
| 0068 | open | M5 | medium | Lynis security baseline |
| 0069 | open | M5 | medium | CrowdSec integration |
| 0070 | open | M5 | medium | Falco runtime monitoring |
| 0071 | open | M5 | low | Trivy image scanning for CVEs |
| 0072 | open | M1 | low | DSGVO/Datenschutz-Compliance konkretisieren |
| 0073 | open | M2 | medium | Architektur: Monorepo-Umbau mit generalisiertem Config-Overlay |
| 0074 | open | M2 | low | Cleanup-Checkliste (laufend) |
| 0076 | open | M2 | low | Registry-/Git-Traffic zum Gitea-Host ueber privates Hetzner-Netzwerk statt oeffentlichem Internet routen |
| 0077 | open | M1 | low | Grafana-Dashboard für ClamAV-Scan-Ergebnisse (Issue #19) |
| 0078 | open | M1 | medium | CVE-Meldeweg v2: Metriken, Grafana-Dashboard, Alerts in eigenen Matrix-Raum |
| 0080 | open | M3 | medium | Raidplaner mit sozialer Komponente (Verfügbarkeiten, Aufgaben, Roadmap, Fotoalbum) |
| 0081 | open | M3 | medium | Gäste-Invite-Workflow per Bot (3-Tage-Accounts, Admin-Freischaltung, begrenzte Reaktivierung) |
| 0082 | open | M1 | high | CVE-Alarme: eine Matrix-Nachricht pro CVE flutet den Security-Raum -- Zustellung derzeit stumm |
| 0083 | open | M1 | medium | Monitoring-Deploy: geaenderte Configs greifen nicht ohne --force-recreate (Inode-Falle bei Einzeldatei-Mounts) |
| 0084 | next | M1 | medium | CI: CANONIZE_TOKEN für die automatische TURN-Rotation hinterlegen |
| 0085 | open | M2 | low | docs/ trägt zwei Altbestände abgeschlossener Umzüge: TASKS.md und oldwiki/ |
| 0086 | open | M4 | low | k8s-Ressourcen heißen noch element-web-docs (Rest des ThreadNet-Rebrands) |
| 0087 | waiting | M4 | low | Logo für die Authentik-Anmeldemaske entwerfen (Querformat/SVG) |
| 0088 | open | M1 | medium | NetworkPolicy: ausgehender Verkehr ist unbeschränkt (13 Ingress-Regeln, 1 Egress) |
| 0089 | open | M5 | low | Eigene Images sind unsigniert — beim Deploy prüft nichts die Herkunft |
| 0090 | open | M5 | low | Kein Kubernetes-Audit-Log — Zugriffe an der API werden nicht protokolliert |
| 0092 | waiting | M3 | low | Default-Client-Einstellungen (Theme, Features) für Neuinstallationen provisionieren |
| 0093 | open | M4 | medium | Settings normalisieren: Video/Audio-Einstellungen nur im Call-Widget, nicht im Haupt-Client |
| 0094 | open | M3 | medium | Direkter Link zur 2FA/Passkey-Einrichtung in den Account-Settings |
| 0095 | open | M4 | low | Windows-Desktop: Code-Signing (+ Installer-Branding) |
| 0096 | waiting | M4 | medium | Rebranding: Element → aXion1337 (Web + Desktop, Gesamtklammer) |
| 0097 | open | M4 | low | Feedback-/Bugreport-Weg: eigener Rageshake oder Alternative (Zammad nachhalten) |
| 0099 | open | M1 | medium | Upstream-Sicherheitsfixes lassen sich nicht mergen — kein gemeinsamer Vorfahre |
| 0100 | open | M4 | low | Asset-Pfade tragen weiterhin "element" (themes/element/…) |
| 0101 | open | M4 | low | Kaputtes Paket 0.19.2-threadnet.6 in der Registry — Herkunft ungeklärt |
| 0102 | open | M1 | medium | DMARC der Plattform-Zone axion1337.chat steht auf p=none — und gehört IONOS, nicht uns |
Active design docs (0)
none active
ADRs (19)
| ADR | Status | Title |
|---|---|---|
| 0001 | accepted | 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert |
| 0002 | accepted | 0002 — Issues und Management-Repo ziehen ins Lab („das Lab ist die Quelle der Wahrheit") |
| 0003 | accepted | 0003 — CVE-Meldeweg: aggregierte Alarme, eigener Security-Raum, gleicher Bot |
| 0004 | accepted | 0004 — Site-to-Site-VPN Hetzner-Projektnetz ↔ Lab, schaltbar über die UDM |
| 0005 | accepted | 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen |
| 0006 | superseded | 0006 — Wikis ins Lab konsolidieren, Docusaurus als gemeinsame Lesefläche |
| 0007 | superseded | 0007 — Wiki-Oberfläche: Docusaurus läuft, BookStack als Gegenentwurf |
| 0008 | accepted | 0008 — Agenten-Sessions auf CFGMON laufen root-äquivalent über die docker-Gruppe |
| 0009 | accepted | 0009 — Commit-Konventionen und rückwirkende Anonymisierung der Historie |
| 0010 | accepted | 0010 — Härtung ist ein eigener Meilenstein (M5); M1 misst nur Kaputtes |
| 0011 | accepted | 0011 — Provisionierung verweigert Localpart-Kollisionen, statt an bestehende Konten zu verknüpfen |
| 0012 | accepted | ADR-0012: Issues leben im Repo; GitLab wird deterministisch bespiegelt |
| 0013 | accepted | ADR-0013: Gruppenregeln kanonisch im management-Repo, Komponenten zeigen und werden geprüft |
| 0014 | accepted | 0014 — Wiki.js löst Docusaurus ab: abgeschottete Betriebs-/Anwenderdoku, docs-as-code |
| 0015 | accepted | 0015 — Wiki.js Git-Storage: Inhalt fließt Cluster→Gitea→kanonisiert nach git.lab |
| 0016 | accepted | 0016 — Das Notfallhandbuch bleibt lab-intern und wird nicht gespiegelt |
| 0017 | accepted | 0017 — Split-DNS auf CFGMON: vier Zonen statt einer, je Zone begründet |
| 0018 | accepted | 0018 — KI-Geräuschunterdrückung in threadnet-call: client-seitig, opt-in, selbst ausgeliefert |
| 0019 | accepted | ADR-0019: Komponenten-Issues in docs/issues/ adoptiert — eine Nummernwelt für die Gruppe |
Open AARs (0)
none — nothing awaiting harvest