run_all.sh reproduces every file under analysis/data/ from zero: it clones the in-scope components if missing, exports group issue metadata from git.lab, and regenerates the inventories. Reruns are diff-clean -- no wall-clock time enters an output; 'days since' is measured against the management repo's HEAD date. The management repo is inventoried at main, not at the analysis branch, so this analysis does not observe its own commits. inv_repo.py aborts the run if anything outside analysis/ was modified.
119 KiB
119 KiB
| 1 | path | line | triggers | in_code_block | doc_last_commit_date | doc_days_since_change | claim_text |
|---|---|---|---|---|---|---|---|
| 2 | .gitlab/issue_templates/Deploy-Übergabe.md | 14 | component-ref | no | 2026-08-02 | 7 | Beispiel: axion1337.chat/threadnet-operating @ main, b6007c5 --> |
| 3 | .gitlab/issue_templates/Deploy-Übergabe.md | 67 | status | no | 2026-08-02 | 7 | Datensammlung und Zustellung getrennt scharf zu schalten ist fast immer |
| 4 | .gitlab/issue_templates/Deploy-Übergabe.md | 75 | status | no | 2026-08-02 | 7 | ## Bewusst offen gelassen |
| 5 | CLAUDE.md | 1 | status;mirror-topology | no | 2026-08-09 | 0 | # CLAUDE.md — übergreifende Arbeitskonventionen (kanonisch) |
| 6 | CLAUDE.md | 4 | component-ref | no | 2026-08-09 | 0 | Gruppe (axion1337.chat-Stack, ThreadNet-Repos, CFGMON/threadnet-operating, |
| 7 | CLAUDE.md | 10 | component-ref;path-claim;mirror-topology | no | 2026-08-09 | 0 | > Push-Mirror unter `https://rohana.axion1337.de/sorb/management` von überall |
| 8 | CLAUDE.md | 11 | status | no | 2026-08-09 | 0 | > **lesbar** — dort diese Datei und die ADRs nachschlagen. Nur pushen ist tabu. |
| 9 | CLAUDE.md | 18 | date-claim | no | 2026-08-09 | 0 | ## Projektrealitäten (Stand 2026-08-01) |
| 10 | CLAUDE.md | 20 | component-ref | no | 2026-08-09 | 0 | **Das Lab ist die Quelle der Wahrheit** ([ADR-0002](decisions/0002-issues-und-management-ins-lab.md)): |
| 11 | CLAUDE.md | 22 | path-claim | no | 2026-08-09 | 0 | - Kanonische Repos liegen auf `git.lab/axion1337.chat/*` (nur im Lab/VPN |
| 12 | CLAUDE.md | 23 | mirror-topology | no | 2026-08-09 | 0 | auflösbar). Gitea/rohana wird per **Push-Mirror** beliefert und bleibt |
| 13 | CLAUDE.md | 24 | mirror-topology | no | 2026-08-09 | 0 | Flux-Source, Container-/npm-Registry und Release-Download |
| 14 | CLAUDE.md | 25 | status;mirror-topology | no | 2026-08-09 | 0 | ([ADR-0001](decisions/0001-gitlab-kanonisch-push-mirror.md)). |
| 15 | CLAUDE.md | 27 | mirror-topology | no | 2026-08-09 | 0 | liegen die *Baupläne*, auf Gitea eine Kopie, die der Cluster **ohne verfügbares |
| 16 | CLAUDE.md | 34 | mirror-topology | no | 2026-08-09 | 0 | - **Nie direkt zu Gitea pushen** (gespiegelte Repos) — der Mirror überschreibt |
| 17 | CLAUDE.md | 36 | count;mirror-topology | no | 2026-08-09 | 0 | - **Gespiegelt wird nur die Gruppe `axion1337.chat`** (die fünf Produkt-Repos und |
| 18 | CLAUDE.md | 37 | component-ref | no | 2026-08-09 | 0 | `management`). Die Gruppe **`homelab`** (`docs`, `wiki`, `wiki-bookstack`) hat |
| 19 | CLAUDE.md | 43 | path-claim;mirror-topology | no | 2026-08-09 | 0 | `verfahren/aar/` (dieses Repo ist gespiegelt), nicht nur in die READMEs der |
| 20 | CLAUDE.md | 45 | count;mirror-topology | no | 2026-08-09 | 0 | - Landet doch ein Commit auf Gitea (z. B. aus einer Host-Session ohne Lab-Route): |
| 21 | CLAUDE.md | 48 | mirror-topology | no | 2026-08-09 | 0 | von Gitea ziehen, `git am` (erhält Autorschaft), Push über git.lab. |
| 22 | CLAUDE.md | 49 | status;mirror-topology | no | 2026-08-09 | 0 | - **Issues leben auf git.lab.** Die alten Gitea-Issues sind geschlossen und |
| 23 | CLAUDE.md | 52 | mirror-topology | no | 2026-08-09 | 0 | meinen die Gitea-Nummer; verbindlich ist der Migrations-Fußtext im Issue. |
| 24 | CLAUDE.md | 54 | mirror-topology | no | 2026-08-09 | 0 | TURN-Rotations-CronJob schreibt weiter nach Gitea, weil er im Cluster läuft und |
| 25 | CLAUDE.md | 56 | mirror-topology | no | 2026-08-09 | 0 | **Die Rotation nicht von Hand nachziehen und den PR nie auf Gitea mergen** — |
| 26 | CLAUDE.md | 57 | status;date-claim | no | 2026-08-09 | 0 | das erledigt seit 2026-08-02 der geplante CI-Job `canonize_rotation` im |
| 27 | CLAUDE.md | 58 | status | no | 2026-08-09 | 0 | gitops-Repo täglich von git.lab aus. Scheitert er, bleibt die Pipeline rot; |
| 28 | CLAUDE.md | 62 | date-claim | no | 2026-08-09 | 0 | Das gitops-Wiki liegt seit 2026-08-02 auf git.lab (*Wiki*-Reiter im Projekt); |
| 29 | CLAUDE.md | 63 | path-claim | no | 2026-08-09 | 0 | ⚠️ der `wiki`-**Branch** im gitops-Repo ist ein überholter Mai-Abzug von `docs/` |
| 30 | CLAUDE.md | 65 | path-claim | no | 2026-08-09 | 0 | **axionwiki.lab** ([`homelab/wiki`](https://git.lab/homelab/wiki), Docusaurus) — |
| 31 | CLAUDE.md | 72 | component-ref;count | no | 2026-08-09 | 0 | - **Alles Offene ist ein Issue** — host-/infra-Scope hier im management-Projekt |
| 32 | CLAUDE.md | 73 | issue-ref | no | 2026-08-09 | 0 | (`host:`-Labels, alte IDs wie `CFGMON-01` bleiben im Titel), Projekt-Scope im |
| 33 | CLAUDE.md | 74 | path-claim | no | 2026-08-09 | 0 | jeweiligen Projekt. Kein neues Backlog-Markdown anlegen; `hosts/`/`shared/` |
| 34 | CLAUDE.md | 90 | path-claim | no | 2026-08-09 | 0 | - **Der Titel trägt keine Priorität.** Präfixe wie `[HIGH]`/`[MEDIUM]`/`[LOW]` |
| 35 | CLAUDE.md | 92 | issue-ref | no | 2026-08-09 | 0 | Alte Kennungen wie `CFGMON-01` bleiben, die benennen den Gegenstand, nicht die |
| 36 | CLAUDE.md | 94 | count;mirror-topology | no | 2026-08-09 | 0 | ⚠️ Der Grund ist keine Ästhetik: Aus der Gitea-Migration trugen 34 Issues ein |
| 37 | CLAUDE.md | 97 | status | no | 2026-08-09 | 0 | über dieselbe Sache sind schlimmer als eine unvollständige. Bereinigt 2026-08-06. |
| 38 | CLAUDE.md | 101 | count | no | 2026-08-09 | 0 | einzahlt**. Ein Issue ohne Meilenstein taucht in keiner Roadmap-Ansicht auf und |
| 39 | CLAUDE.md | 112 | path-claim | no | 2026-08-09 | 0 | `~/.config/gitlab-lab/token`) oder maskierte CI-Variablen. |
| 40 | CLAUDE.md | 116 | date-claim | no | 2026-08-09 | 0 | ## Commit-Konventionen (seit 2026-08-07) |
| 41 | CLAUDE.md | 136 | count;date-claim | no | 2026-08-09 | 0 | 📎 Die Umstellung der Alt-Historie am 2026-08-07 hat 251 Commits neue SHAs |
| 42 | CLAUDE.md | 138 | path-claim | no | 2026-08-09 | 0 | [`shared/commit-zuordnung-2026-08-07.md`](shared/commit-zuordnung-2026-08-07.md) |
| 43 | CLAUDE.md | 146 | mirror-topology | no | 2026-08-09 | 0 | öffentlichen Gitea-Spiegel. Wer daraus wirklich keine Muster ableitbar haben |
| 44 | CLAUDE.md | 151 | status | no | 2026-08-09 | 0 | - **Aussagen mit Quelle:** Verifiziert (Messung/Konsole) klar von Vermutung |
| 45 | README.md | 1 | component-ref | no | 2026-08-02 | 7 | # management |
| 46 | README.md | 8 | date-claim | no | 2026-08-02 | 7 | *(Bis 2026-08-01 hieß dieses Repo `Backlogs` und führte offene Punkte als |
| 47 | README.md | 11 | date-claim | no | 2026-08-02 | 7 | ## Repo-Topologie (seit 2026-08-01) |
| 48 | README.md | 13 | component-ref;status;path-claim;mirror-topology | no | 2026-08-02 | 7 | **Kanonisch lebt dieses Repo auf `git.lab`** (`axion1337.chat/management`, nur im |
| 49 | README.md | 15 | component-ref | no | 2026-08-02 | 7 | [ADR-0002](decisions/0002-issues-und-management-ins-lab.md)). |
| 50 | README.md | 16 | component-ref;path-claim;mirror-topology | no | 2026-08-02 | 7 | `rohana.axion1337.de/sorb/management` ist ein **Push-Mirror**: git.lab |
| 51 | README.md | 17 | mirror-topology | no | 2026-08-02 | 7 | überschreibt ihn bei jedem Push per Force. Deshalb **nie direkt zu Gitea |
| 52 | README.md | 18 | mirror-topology | no | 2026-08-02 | 7 | pushen** — solche Commits gehen beim nächsten Mirror-Lauf verloren (Rettung: |
| 53 | README.md | 19 | mirror-topology | no | 2026-08-02 | 7 | `.patch` von Gitea ziehen + `git am`, siehe |
| 54 | README.md | 22 | date-claim | no | 2026-08-02 | 7 | **Keine Ausnahmen mehr.** Die **Deploy-Übergabe-Issues** liefen bis 2026-08-02 auf |
| 55 | README.md | 23 | mirror-topology | no | 2026-08-02 | 7 | dem Gitea-Tracker, weil Hosts außerhalb des Labs `git.lab` nicht erreichten. Mit dem |
| 56 | README.md | 25 | status | no | 2026-08-02 | 7 | Grund entfallen — bei eingeschaltetem Tunnel erreicht CFGMON git.lab. Sie sind |
| 57 | README.md | 26 | status;mirror-topology;issue-ref | no | 2026-08-02 | 7 | umgezogen (LABNET-03), der Gitea-Tracker ist leer, die Vorlage liegt als |
| 58 | README.md | 33 | path-claim | no | 2026-08-02 | 7 | | [`CLAUDE.md`](CLAUDE.md) | **Kanonische Arbeitskonventionen für alle Agenten-Sessions** (Topologie, Framework, Secrets, Karpathy-Guidelines) | |
| 59 | README.md | 34 | path-claim | no | 2026-08-02 | 7 | | `vision/` | Eine Vision je Linie: Community (axion1337.chat), Tool (ThreadNet), Plattform (Homelab) | |
| 60 | README.md | 35 | path-claim | no | 2026-08-02 | 7 | | `roadmap.md` | Linien, Meilenstein-Kandidaten, Kadenz — GitLab-Milestones halten den Stand | |
| 61 | README.md | 36 | path-claim | no | 2026-08-02 | 7 | | `decisions/` | ADRs — Pflicht bei Architekturentscheidungen **und dauerhaften Ausnahmen** | |
| 62 | README.md | 37 | path-claim | no | 2026-08-02 | 7 | | `verfahren/` | Wie wir arbeiten: [Deploy-Übergabe/DoD](verfahren/deploy-uebergabe.md), [Refinement & Retro](verfahren/refinement.md), [AARs](verfahren/aar/), Werkzeuge | |
| 63 | README.md | 38 | path-claim | no | 2026-08-02 | 7 | | `hosts/`, `shared/` | **Bestand + Historie** je Host/Thema — u. a. [Branding](shared/branding.md) (Marke, Paletten, wo welches Theme eingestellt ist); offene Punkte sind Issues | |
| 64 | README.md | 43 | path-claim | no | 2026-08-02 | 7 | [`homelab/wiki`](https://git.lab/homelab/wiki)). **Geändert wird immer hier, nie dort.** |
| 65 | README.md | 48 | issue-ref | no | 2026-08-02 | 7 | `host:`-Labels; die alten IDs wie `CFGMON-01` bleiben im Titel) bzw. in den |
| 66 | README.md | 64 | issue-ref | no | 2026-08-02 | 7 | **IDs** (`CFGMON-01`, `ZONE-01`, …) werden **nie wiederverwendet**; sie leben in |
| 67 | README.md | 72 | status | no | 2026-08-02 | 7 | **Erledigtes und Verworfenes** bleibt sichtbar: Issues werden geschlossen (nicht |
| 68 | README.md | 78 | component-ref | no | 2026-08-02 | 7 | Konfiguration lebt in den Projekt-Repos (z. B. `threadnet-operating` für den |
| 69 | decisions/0001-gitlab-kanonisch-push-mirror.md | 1 | status;mirror-topology | no | 2026-08-01 | 8 | # 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert |
| 70 | decisions/0001-gitlab-kanonisch-push-mirror.md | 8 | mirror-topology | no | 2026-08-01 | 8 | 3,7-GiB-Host) und Gitea Actions zeigte mehrere echte Bugs. Das Homelab-GitLab |
| 71 | decisions/0001-gitlab-kanonisch-push-mirror.md | 14 | path-claim;mirror-topology | no | 2026-08-01 | 8 | `git.lab/axion1337.chat/*` ist die kanonische Heimat aller Repos; Gitea/rohana |
| 72 | decisions/0001-gitlab-kanonisch-push-mirror.md | 15 | mirror-topology | no | 2026-08-01 | 8 | wird über Push-Mirrors beliefert und bleibt Flux-Source, Container-Registry, |
| 73 | decisions/0001-gitlab-kanonisch-push-mirror.md | 16 | mirror-topology | no | 2026-08-01 | 8 | npm-Registry und Release-Download. **Direkte Pushes zu Gitea sind für gespiegelte |
| 74 | decisions/0001-gitlab-kanonisch-push-mirror.md | 17 | mirror-topology | no | 2026-08-01 | 8 | Repos verboten** — der Mirror überschreibt divergenten Stand per Force. |
| 75 | decisions/0001-gitlab-kanonisch-push-mirror.md | 22 | mirror-topology | no | 2026-08-01 | 8 | - Commits, die doch auf Gitea landen (z. B. Cluster-CronJobs ohne Lab-Route), |
| 76 | decisions/0001-gitlab-kanonisch-push-mirror.md | 23 | path-claim | no | 2026-08-01 | 8 | brauchen das Kanonisierungs-Verfahren (`verfahren/deploy-uebergabe.md`): |
| 77 | decisions/0001-gitlab-kanonisch-push-mirror.md | 24 | status | no | 2026-08-01 | 8 | `.patch` ziehen, `git am`, Push über git.lab. Zweimal live gebraucht. |
| 78 | decisions/0001-gitlab-kanonisch-push-mirror.md | 29 | issue-ref | no | 2026-08-01 | 8 | - CFGMON-CI aufrüsten (Swap/Limits): strukturell zu klein, verworfen mit CFGMON-10. |
| 79 | decisions/0002-issues-und-management-ins-lab.md | 8 | mirror-topology | no | 2026-08-02 | 7 | weiter auf Gitea — zwei Wahrheiten, driftgefährdet. Erreichbarkeits-Blocker |
| 80 | decisions/0002-issues-und-management-ins-lab.md | 9 | date-claim;issue-ref | no | 2026-08-02 | 7 | LABNET-01 (WireGuard-Roadwarrior) wurde am 2026-08-01 gelöst. |
| 81 | decisions/0002-issues-und-management-ins-lab.md | 13 | status;mirror-topology | no | 2026-08-02 | 7 | Alle Projekt-Issues leben auf git.lab (62 migriert, Gitea-Issues geschlossen mit |
| 82 | decisions/0002-issues-und-management-ins-lab.md | 14 | component-ref;path-claim | no | 2026-08-02 | 7 | Verweis); das Backlogs-Repo zieht als `axion1337.chat/management` ins Lab |
| 83 | decisions/0002-issues-und-management-ins-lab.md | 15 | component-ref;path-claim;mirror-topology | no | 2026-08-02 | 7 | (Push-Mirror → `sorb/management` auf Gitea). Das Lab ist die Quelle der Wahrheit. |
| 84 | decisions/0002-issues-und-management-ins-lab.md | 19 | mirror-topology | no | 2026-08-02 | 7 | - ⚠️ gitops-Issue-Nummern haben sich verschoben (Gitea zählte PRs mit); die |
| 85 | decisions/0002-issues-und-management-ins-lab.md | 21 | mirror-topology | no | 2026-08-02 | 7 | - ~~**Befristete Ausnahme:** Deploy-Übergabe-Issues laufen auf dem Gitea-Tracker |
| 86 | decisions/0002-issues-und-management-ins-lab.md | 22 | component-ref;path-claim | no | 2026-08-02 | 7 | von `sorb/management`, weil CFGMON git.lab (noch) nicht erreicht.~~ |
| 87 | decisions/0002-issues-und-management-ins-lab.md | 23 | component-ref;date-claim;issue-ref | no | 2026-08-02 | 7 | ✅ **Zurückgebaut am 2026-08-02** (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)): |
| 88 | decisions/0002-issues-und-management-ins-lab.md | 25 | component-ref;issue-ref | no | 2026-08-02 | 7 | sind nach git.lab gewandert ([#25](https://git.lab/axion1337.chat/management/-/issues/25), |
| 89 | decisions/0002-issues-und-management-ins-lab.md | 26 | component-ref;mirror-topology;issue-ref | no | 2026-08-02 | 7 | [#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist |
| 90 | decisions/0002-issues-und-management-ins-lab.md | 27 | status;path-claim | no | 2026-08-02 | 7 | leer, die Vorlage liegt als `.gitlab/issue_templates/`. **Damit gilt diese ADR |
| 91 | decisions/0002-issues-und-management-ins-lab.md | 29 | path-claim | no | 2026-08-02 | 7 | Ausnahmen (siehe `README.md`) — dass sie befristet war und die Frist gehalten hat, |
| 92 | decisions/0002-issues-und-management-ins-lab.md | 31 | mirror-topology | no | 2026-08-02 | 7 | - Releases bleiben auf Gitea (öffentlicher Download-Pfad), ebenso das gitops-Wiki. |
| 93 | decisions/0002-issues-und-management-ins-lab.md | 35 | mirror-topology | no | 2026-08-02 | 7 | - Issues auf Gitea belassen: dauerhafte Doppelführung, Roadmap/Boards unmöglich. |
| 94 | decisions/0003-cve-meldeweg-aggregiert.md | 8 | path-claim;issue-ref | no | 2026-08-01 | 8 | Nachrichten und musste stummgeschaltet werden (gitops#51, AAR in `verfahren/aar/`). |
| 95 | decisions/0003-cve-meldeweg-aggregiert.md | 9 | issue-ref | no | 2026-08-01 | 8 | Gleichzeitig war entschieden (CFGMON-13), Release-/Security-Meldungen von |
| 96 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 3 | component-ref;issue-ref | no | 2026-08-02 | 7 | **Status:** akzeptiert (umgesetzt und abgenommen 2026-08-01, Testreihe 1–7 in [management#12](https://git.lab/axion1337.chat/management/-/issues/12)) · **Datum:** 2026-08-01 · **Entscheider:** sorb |
| 97 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 14 | version;path-claim | no | 2026-08-02 | 7 | Hetzner-Projektnetz `10.0.0.0/24` mit dem Lab-VLAN `10.58.73.0/24`. Der An/Aus-Schalter |
| 98 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 29 | status;version;path-claim | no | 2026-08-02 | 7 | | **CFGMON** | WG-**Client/Initiator**, dauerhaft aktiv (`enable`) + `PersistentKeepalive 25`; AllowedIPs nur `10.58.73.0/24, 10.58.75.1/32`; Split-DNS nur `~lab` → `10.58.73.1`; `ip_forward` + iptables-ACCEPT in `DOCKER-USER` (ufw ist dort inaktiv), **kein NAT** | |
| 99 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 30 | version | no | 2026-08-02 | 7 | | **Fritzbox** | Portfreigabe UDP **51841** → `192.168.178.20` | |
| 100 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 31 | version;path-claim | no | 2026-08-02 | 7 | | **Hetzner** | Netz-Range auf **`10.0.0.0/8`** erweitert, Route `10.58.73.0/24 → 10.0.0.3` — damit erreichen alle Server im Netz das Lab **ohne eigene Konfiguration** | |
| 101 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 32 | version;path-claim | no | 2026-08-02 | 7 | | **UniFi-Firewall** | Trennung vom Roadwarrior über **Quell-/Ziel-IP** (`10.58.75.0/24` + `10.0.0.0/24`), nicht über eine eigene Zone: erlaubt sind nur `10.58.73.17:443` (git.lab/Registry) und `10.58.73.1:53` (DNS); IoT und Arbeit sind für alle VPNs komplett gesperrt | |
| 102 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 36 | component-ref;date-claim;issue-ref | no | 2026-08-02 | 7 | - ✅ **Eingelöst am 2026-08-02 (LABNET-03, [#13](https://git.lab/axion1337.chat/management/-/issues/13)):** |
| 103 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 37 | status | no | 2026-08-02 | 7 | Übergabe-Issues können nicht nur umziehen — sie sind umgezogen |
| 104 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 38 | component-ref;issue-ref | no | 2026-08-02 | 7 | ([#25](https://git.lab/axion1337.chat/management/-/issues/25), |
| 105 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 39 | component-ref;mirror-topology;issue-ref | no | 2026-08-02 | 7 | [#26](https://git.lab/axion1337.chat/management/-/issues/26)), der Gitea-Tracker ist |
| 106 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 40 | status | no | 2026-08-02 | 7 | leer, die Vorlage liegt als GitLab-Issue-Template, und die Ausnahme aus ADR-0002 ist |
| 107 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 50 | mirror-topology | no | 2026-08-02 | 7 | Gitea-PR-Ausnahme bleibt bewusst bestehen. |
| 108 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 54 | mirror-topology | no | 2026-08-02 | 7 | Job läuft im Lab und erreicht Gitea öffentlich. Das war der eigentliche Grund für |
| 109 | decisions/0004-site-to-site-vpn-hetzner-lab.md | 56 | issue-ref | no | 2026-08-02 | 7 | - game.axion1337.de profitiert erst nach Aufnahme in den vSwitch (GAME-01). |
| 110 | decisions/0005-pm-framework-kanban.md | 1 | component-ref | no | 2026-08-01 | 8 | # 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen |
| 111 | decisions/0005-pm-framework-kanban.md | 22 | path-claim | no | 2026-08-01 | 8 | | Product Goal / Vision | `vision/` (eine Datei je Linie) | |
| 112 | decisions/0005-pm-framework-kanban.md | 24 | path-claim | no | 2026-08-01 | 8 | | Review/Retro | AARs (`verfahren/aar/`) nach Deploys/Incidents | |
| 113 | decisions/0005-pm-framework-kanban.md | 25 | path-claim | no | 2026-08-01 | 8 | | Definition of Done | Deploy-Übergabe-Verfahren (`verfahren/deploy-uebergabe.md`) | |
| 114 | decisions/0005-pm-framework-kanban.md | 26 | path-claim | no | 2026-08-01 | 8 | | Roadmap/Meilensteine | Gruppen-Milestones + `roadmap.md` (CE: keine Epics/Roadmap-View) | |
| 115 | decisions/0005-pm-framework-kanban.md | 27 | path-claim | no | 2026-08-01 | 8 | | Entscheidungen | ADRs in `decisions/` | |
| 116 | decisions/0005-pm-framework-kanban.md | 32 | component-ref;path-claim | no | 2026-08-01 | 8 | - Das Backlogs-Repo wird zum Management-Repo `axion1337.chat/management`; |
| 117 | decisions/0005-pm-framework-kanban.md | 33 | path-claim | no | 2026-08-01 | 8 | offene Punkte aus `hosts/`/`shared/` sind Issues mit `host:`-Labels, |
| 118 | decisions/0006-wikis-konsolidieren-docusaurus.md | 9 | date-claim;mirror-topology | no | 2026-08-02 | 7 | 1. **Gitea-Wiki-Repo** `…gitops.wiki.git` — 15 Seiten, gepflegt bis 2026-07-31. |
| 119 | decisions/0006-wikis-konsolidieren-docusaurus.md | 10 | mirror-topology | no | 2026-08-02 | 7 | Vom Push-Mirror **nicht** erfasst: ein Wiki ist ein eigenes Repo, kein Branch. |
| 120 | decisions/0006-wikis-konsolidieren-docusaurus.md | 11 | date-claim;mirror-topology | no | 2026-08-02 | 7 | 2. **`wiki`-Branch im gitops-Repo** — Stand 2026-05-14, mitgezogen, weil der Mirror |
| 121 | decisions/0006-wikis-konsolidieren-docusaurus.md | 12 | path-claim | no | 2026-08-02 | 7 | alle Branches trägt. Inhalt: ein damaliger Abzug von `docs/`, kein gepflegtes Wiki. |
| 122 | decisions/0006-wikis-konsolidieren-docusaurus.md | 13 | path-claim | no | 2026-08-02 | 7 | 3. **`docs/` im main-Branch** — die eigentliche, laufend gepflegte Repo-Doku. |
| 123 | decisions/0006-wikis-konsolidieren-docusaurus.md | 15 | status | no | 2026-08-02 | 7 | Dazu waren die GitLab-Wikis aller Projekte **leer**, und die Wiki-Inhalte enthielten |
| 124 | decisions/0006-wikis-konsolidieren-docusaurus.md | 26 | path-claim | no | 2026-08-02 | 7 | [`homelab/wiki`](https://git.lab/homelab/wiki) baut mit Docusaurus eine Seite unter |
| 125 | decisions/0006-wikis-konsolidieren-docusaurus.md | 28 | component-ref;path-claim | no | 2026-08-02 | 7 | Homelab (`homelab/docs`), Arbeitsweise (`management`). Die Inhalte werden beim Bau |
| 126 | decisions/0006-wikis-konsolidieren-docusaurus.md | 33 | path-claim | no | 2026-08-02 | 7 | - **Änderungen gehören ins Quell-Repo**, nie ins Wiki-Repo — was dort in `content/` |
| 127 | decisions/0006-wikis-konsolidieren-docusaurus.md | 43 | path-claim | no | 2026-08-02 | 7 | `.md` wird als CommonMark statt MDX geparst. |
| 128 | decisions/0006-wikis-konsolidieren-docusaurus.md | 44 | status | no | 2026-08-02 | 7 | - **Der `wiki`-Branch im gitops-Repo ist überholt.** Er bleibt vorerst als Historie |
| 129 | decisions/0006-wikis-konsolidieren-docusaurus.md | 47 | component-ref;issue-ref | no | 2026-08-02 | 7 | ([Issue #19](https://git.lab/axion1337.chat/management/-/issues/19)). |
| 130 | decisions/0006-wikis-konsolidieren-docusaurus.md | 51 | count | no | 2026-08-02 | 7 | - **Alles in ein Repo verschmelzen:** Die Quellen haben unterschiedliche Leser und |
| 131 | decisions/0006-wikis-konsolidieren-docusaurus.md | 53 | mirror-topology | no | 2026-08-02 | 7 | - **Wiki auf Gitea belassen:** widerspricht ADR-0002 und hielt eine Ausnahme am |
| 132 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 3 | component-ref;status;issue-ref | no | 2026-08-02 | 7 | **Status:** vorgeschlagen (Entscheidung offen → [Issue #20](https://git.lab/axion1337.chat/management/-/issues/20)) · **Datum:** 2026-08-02 · **Entscheider:** sorb |
| 133 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 8 | date-claim | no | 2026-08-02 | 7 | Docusaurus als Lesefläche gebaut — läuft seit 2026-08-02 unter `axionwiki.lab`. |
| 134 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 42 | component-ref | no | 2026-08-02 | 7 | Wahrheit neben git.lab — genau das, was [ADR-0002](0002-issues-und-management-ins-lab.md) |
| 135 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 52 | issue-ref | no | 2026-08-02 | 7 | Datenbank ohne Sicherung ist eine Zeitbombe (vgl. CFGMON-09, wo genau das seit |
| 136 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 53 | status | no | 2026-08-02 | 7 | 2026-07-30 offen ist). |
| 137 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 54 | path-claim | no | 2026-08-02 | 7 | - **Ein Einweg-Import zum Befüllen, aber keine Synchronisation** (`import/` im |
| 138 | decisions/0007-wiki-oberflaeche-docusaurus-vs-bookstack.md | 56 | path-claim | no | 2026-08-02 | 7 | vergleichen, deshalb legt `provision.py` dieselben drei Bereiche an wie das |
| 139 | decisions/0008-agenten-sessions-root-aequivalent.md | 3 | component-ref;issue-ref | no | 2026-08-06 | 3 | **Status:** akzeptiert · **Datum:** 2026-08-06 (Struktur-Workshop [#17](https://git.lab/axion1337.chat/management/-/issues/17)) · **Entscheider:** sorb |
| 140 | decisions/0008-agenten-sessions-root-aequivalent.md | 9 | issue-ref | no | 2026-08-06 | 3 | LABNET-02-Nacht lief deshalb über die **docker-Gruppenmitgliedschaft** des Kontos |
| 141 | decisions/0008-agenten-sessions-root-aequivalent.md | 24 | component-ref;issue-ref | no | 2026-08-06 | 3 | [#14](https://git.lab/axion1337.chat/management/-/issues/14). |
| 142 | decisions/0008-agenten-sessions-root-aequivalent.md | 46 | issue-ref | no | 2026-08-06 | 3 | ohne diese Entscheidung wäre LABNET-02 gar nicht durchführbar gewesen. |
| 143 | decisions/0008-agenten-sessions-root-aequivalent.md | 55 | status | no | 2026-08-06 | 3 | Kommt einer dazu, wird diese ADR abgelöst. |
| 144 | decisions/0008-agenten-sessions-root-aequivalent.md | 57 | status | no | 2026-08-06 | 3 | ## Offen, bewusst nicht vor der Entscheidung geklärt |
| 145 | decisions/0008-agenten-sessions-root-aequivalent.md | 66 | issue-ref | no | 2026-08-06 | 3 | nächsten Host-Session, festgehalten in #14. |
| 146 | decisions/0008-agenten-sessions-root-aequivalent.md | 80 | path-claim | no | 2026-08-06 | 3 | und nicht bloß ein Absatz in `hosts/cfgmon.md`. |
| 147 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 5 | date-claim | no | 2026-08-09 | 0 | > Nachgetragen am 2026-08-09 in der [Retro](../verfahren/retro/2026-08-09.md). Die |
| 148 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 13 | mirror-topology | no | 2026-08-09 | 0 | öffentlichem Gitea-Spiegel heißt das: Jeder, der die Repos liest, kann ablesen, an |
| 149 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 23 | date-claim | no | 2026-08-09 | 0 | **Regel ab 2026-08-07**, gültig für alle Repos der Gruppe `axion1337.chat` und die |
| 150 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 29 | count;date-claim | no | 2026-08-09 | 0 | **Rückwirkend angewandt am 2026-08-09** auf **251 Commits** — alles aus dieser |
| 151 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 34 | date-claim | no | 2026-08-09 | 0 | | gitops | 117 von 264 | ab 2026-07-27 | |
| 152 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 35 | component-ref | no | 2026-08-09 | 0 | | management | 78 von 78 | vollständig | |
| 153 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 36 | component-ref;date-claim | no | 2026-08-09 | 0 | | ThreadNet-Web | 47 von 50 | ab 2026-07-28 | |
| 154 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 37 | component-ref | no | 2026-08-09 | 0 | | threadnet-call | 9 von 9 | vollständig | |
| 155 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 39 | status | no | 2026-08-09 | 0 | Dabei wurden 17 Tags mit umgezogen und die Autoren-Identitäten vereinheitlicht — |
| 156 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 54 | path-claim | no | 2026-08-09 | 0 | [`shared/commit-zuordnung-2026-08-07.md`](../shared/commit-zuordnung-2026-08-07.md). |
| 157 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 61 | status | no | 2026-08-09 | 0 | wieder aktiv. |
| 158 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 66 | mirror-topology | no | 2026-08-09 | 0 | liegen im selben GitLab und teilweise auf dem öffentlichen Spiegel — und sind |
| 159 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 72 | component-ref | no | 2026-08-09 | 0 | Das Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines |
| 160 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 74 | version | no | 2026-08-09 | 0 | `v0.4.0` aus altem Quellcode gegen heutige Basis-Images neu gebaut und |
| 161 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 77 | component-ref;status;issue-ref | no | 2026-08-09 | 0 | ThreadNet-Web#14; die Sperre ist seit `3cb43f5` scharf. |
| 162 | decisions/0009-commit-konventionen-und-historien-anonymisierung.md | 86 | count | no | 2026-08-09 | 0 | angefasst (`Scrublord@Mac.Bad`, 135 Commits aus der Zeit vor dieser |
| 163 | decisions/README.md | 6 | status | no | 2026-08-01 | 8 | auf `abgelöst durch NNNN` gesetzt. |
| 164 | decisions/template.md | 3 | status | no | 2026-08-01 | 8 | **Status:** vorgeschlagen | akzeptiert | abgelöst durch NNNN · **Datum:** JJJJ-MM-TT · **Entscheider:** sorb |
| 165 | hosts/cfgmon.md | 3 | mirror-topology | no | 2026-08-09 | 0 | Monitoring-Stack, Gitea und der Reverse Proxy für alles Öffentliche. |
| 166 | hosts/cfgmon.md | 8 | version | no | 2026-08-09 | 0 | | **OS** | Ubuntu 24.04.4 LTS | |
| 167 | hosts/cfgmon.md | 9 | version | no | 2026-08-09 | 0 | | **IPv4** | `188.245.193.243` | |
| 168 | hosts/cfgmon.md | 11 | version | no | 2026-08-09 | 0 | | **Privat** | `10.0.0.3` (`enp7s0`, Hetzner-Netz — dort liegt auch k3s auf `10.0.0.2`) | |
| 169 | hosts/cfgmon.md | 12 | mirror-topology | no | 2026-08-09 | 0 | | **DNS** | `rohana.axion1337.de` → Gitea, `selendis.axion1337.de` → Grafana | |
| 170 | hosts/cfgmon.md | 19 | component-ref;version;path-claim | no | 2026-08-09 | 0 | | prometheus | `prom/prometheus:v3.3.1` | `monitoring` | `sorb/threadnet-operating`, `monitoring/` | |
| 171 | hosts/cfgmon.md | 20 | version;path-claim | no | 2026-08-09 | 0 | | loki | `grafana/loki:3.7.1` | `monitoring` | dito | |
| 172 | hosts/cfgmon.md | 21 | version;path-claim | no | 2026-08-09 | 0 | | grafana | `grafana/grafana:12.0.0` | `monitoring` | dito | |
| 173 | hosts/cfgmon.md | 22 | version;path-claim | no | 2026-08-09 | 0 | | alloy | `grafana/alloy:v1.16.0` | `monitoring` | dito | |
| 174 | hosts/cfgmon.md | 23 | version;path-claim | no | 2026-08-09 | 0 | | node-exporter | `prom/node-exporter:v1.9.1` | `monitoring` | dito | |
| 175 | hosts/cfgmon.md | 24 | component-ref;status;version;path-claim;date-claim;mirror-topology;issue-ref | no | 2026-08-09 | 0 | | traefik | `traefik:v3.7.9` | `thread-net-git` | `sorb/thread-net-git`, seit 2026-07-30 in `main` (siehe [CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07-30)) | |
| 176 | hosts/cfgmon.md | 25 | component-ref;version;path-claim;mirror-topology | no | 2026-08-09 | 0 | | gitea | `gitea/gitea:1.27.0` | `thread-net-git` | dito, gepinnt (war `:latest`) | |
| 177 | hosts/cfgmon.md | 26 | component-ref;version;path-claim | no | 2026-08-09 | 0 | | cadvisor | `gcr.io/cadvisor/cadvisor:v0.49.1` | `thread-net-git` | dito, gepinnt (war `:latest`) | |
| 178 | hosts/cfgmon.md | 27 | component-ref;version;path-claim;mirror-topology;issue-ref | no | 2026-08-09 | 0 | | runner | `gitea/act_runner:0.6.1` | `thread-net-git` | dito, Container `gitea-runner`, siehe CFGMON-02 | |
| 179 | hosts/cfgmon.md | 28 | version;path-claim | no | 2026-08-09 | 0 | | portainer_agent | `portainer/agent:2.27.5` | — | standalone, kein Compose | |
| 180 | hosts/cfgmon.md | 32 | component-ref;version | no | 2026-08-09 | 0 | (`10.0.0.2:9100`), `pterodactyl_host_node` und `gameserver_cadvisor` |
| 181 | hosts/cfgmon.md | 33 | version | no | 2026-08-09 | 0 | (beide `157.90.155.206`, siehe [game](game.md)). |
| 182 | hosts/cfgmon.md | 38 | component-ref | no | 2026-08-09 | 0 | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. |
| 183 | hosts/cfgmon.md | 41 | component-ref;date-claim;issue-ref | no | 2026-08-09 | 0 | - [CFGMON-01 — Zertifikatserneuerung braucht offene Ports (zeitkritisch ab 2026-09-28)](https://git.lab/axion1337.chat/management/-/issues/7) |
| 184 | hosts/cfgmon.md | 42 | component-ref;issue-ref | no | 2026-08-09 | 0 | - [CFGMON-03 — Prometheus-Remote-Write/Loki öffentlich ohne Auth (Weg A, nachgelagerte Prüfung)](https://git.lab/axion1337.chat/management/-/issues/8) |
| 185 | hosts/cfgmon.md | 43 | component-ref;issue-ref | no | 2026-08-09 | 0 | - [CFGMON-04 — Grafana-Admin-Credentials aus `.env` gelten nicht für die API](https://git.lab/axion1337.chat/management/-/issues/9) |
| 186 | hosts/cfgmon.md | 44 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | - [CFGMON-09 — Gitea-Backups off-host (⚠️ Backup-Cron deaktiviert)](https://git.lab/axion1337.chat/management/-/issues/10) |
| 187 | hosts/cfgmon.md | 46 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | ## CFGMON-11 — Gitea-CI-Rückbau nach GitLab-Umzug |
| 188 | hosts/cfgmon.md | 48 | status | no | 2026-08-09 | 0 | **Status:** erledigt (2026-07-31 spätabends) — bis auf einen kosmetischen Handgriff: |
| 189 | hosts/cfgmon.md | 49 | component-ref;path-claim | no | 2026-08-09 | 0 | auf CFGMON `cd /opt/thread-net-git && git checkout main && git pull` (Checkout parkt |
| 190 | hosts/cfgmon.md | 52 | component-ref;path-claim | no | 2026-08-09 | 0 | **Dazu neu (2026-08-01 ~05:00):** Auch `/opt/threadnet-operating` braucht einmal |
| 191 | hosts/cfgmon.md | 53 | path-claim | no | 2026-08-09 | 0 | `git fetch && git reset --hard origin/main` — der State-Persistenz-Commit wurde |
| 192 | hosts/cfgmon.md | 54 | mirror-topology | no | 2026-08-09 | 0 | dort direkt nach Gitea gepusht (dfe04c4a), vom Mirror überschrieben, vom Mac aus |
| 193 | hosts/cfgmon.md | 55 | status;mirror-topology | no | 2026-08-09 | 0 | per Patch gerettet und kanonisch als `6ffab68` neu aufgelegt (inhaltsgleich, |
| 194 | hosts/cfgmon.md | 58 | status | no | 2026-08-09 | 0 | **Erledigt (2026-08-01, autonom):** |
| 195 | hosts/cfgmon.md | 59 | component-ref | no | 2026-08-09 | 0 | - Actions-Toggles deaktiviert: `ThreadNet-Web`, `threadnet-call`, `axion1337.chat-gitops` |
| 196 | hosts/cfgmon.md | 60 | component-ref;path-claim | no | 2026-08-09 | 0 | - `ThreadNet-Web`: alle `.github/workflows/`-Dateien entfernt (Commit `a876758`) |
| 197 | hosts/cfgmon.md | 61 | path-claim;mirror-topology | no | 2026-08-09 | 0 | - gitops: Verifikations-Job nach GitLab portiert + `.gitea/workflows/` entfernt |
| 198 | hosts/cfgmon.md | 62 | status;path-claim;mirror-topology | no | 2026-08-09 | 0 | (Commit `5e46a24`, Pipeline grün, Mirror→Gitea verifiziert; `milestone-release.yml` |
| 199 | hosts/cfgmon.md | 63 | issue-ref | no | 2026-08-09 | 0 | war toter Code, siehe #33). Flux unberührt. |
| 200 | hosts/cfgmon.md | 64 | component-ref;path-claim | no | 2026-08-09 | 0 | - `thread-net-git`: Runner-Service/Config/`.env.example` per Commit `d904734` entfernt |
| 201 | hosts/cfgmon.md | 65 | mirror-topology | no | 2026-08-09 | 0 | (auf git.lab; Mirror trägt nach Gitea) — **noch nicht deployt**, siehe unten. |
| 202 | hosts/cfgmon.md | 66 | component-ref;path-claim | no | 2026-08-09 | 0 | - Registry-Entscheidung npm final (Evidenz: `@sorb/threadnet-call-embedded` ist |
| 203 | hosts/cfgmon.md | 67 | path-claim;mirror-topology | no | 2026-08-09 | 0 | pnpm-Dependency von `apps/web`, Lockfile pinnt Tarball-URL auf rohana): **bleibt Gitea**. |
| 204 | hosts/cfgmon.md | 70 | component-ref;status | no | 2026-08-09 | 0 | 1. ~~`thread-net-git`-Stand deployen~~ **erledigt (2026-07-31 spätabends, via |
| 205 | hosts/cfgmon.md | 71 | path-claim | no | 2026-08-09 | 0 | CFGMON-Session)**: Runner-Container/Netz/`runner-data/`/`.env`-Zeile entfernt, |
| 206 | hosts/cfgmon.md | 72 | mirror-topology | no | 2026-08-09 | 0 | `builder-1` aus der Gitea-Admin-UI gelöscht, Actions-Registrierungstoken rotiert. |
| 207 | hosts/cfgmon.md | 75 | component-ref;status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | Mac→git.lab→Mirror (`15c8f2d`), Hergang in thread-net-git#1 (geschlossen). |
| 208 | hosts/cfgmon.md | 77 | mirror-topology | no | 2026-08-09 | 0 | getippte Token (`a89bfb…`) war der Gitea-**Actions-Runner-Registrierungstoken** |
| 209 | hosts/cfgmon.md | 82 | status | no | 2026-08-09 | 0 | 3. ~~Token-Rotation b~~ **erledigt (2026-07-31 abends)**: Generalschlüssel |
| 210 | hosts/cfgmon.md | 87 | path-claim;mirror-topology | no | 2026-08-09 | 0 | `~/.config/gitea-rohana/token` auf dem Mac), `claude-push` (write:repository, |
| 211 | hosts/cfgmon.md | 88 | version;path-claim;mirror-topology | no | 2026-08-09 | 0 | `~/.config/gitea-rohana/push-token`). Erster CI-Publish `0.19.2-threadnet.6` |
| 212 | hosts/cfgmon.md | 89 | component-ref;status;issue-ref | no | 2026-08-09 | 0 | verifiziert → threadnet-call#1 geschlossen. Alle Klartext-Reste entfernt |
| 213 | hosts/cfgmon.md | 94 | path-claim | no | 2026-08-09 | 0 | (`git.lab/axion1337.chat`, Gruppe mit importierten Projekten angelegt; die Domain ist |
| 214 | hosts/cfgmon.md | 97 | date-claim;mirror-topology | no | 2026-08-09 | 0 | pausieren). Der am 2026-07-30 auf Gitea-Seite aufgebaute CI-Unterbau wird damit teilweise |
| 215 | hosts/cfgmon.md | 102 | component-ref;date-claim | no | 2026-08-09 | 0 | - **Actions-Toggle** `has_actions` bei `ThreadNet-Web` (am 2026-07-30 per API aktiviert) |
| 216 | hosts/cfgmon.md | 103 | component-ref | no | 2026-08-09 | 0 | wieder deaktivieren, ebenso bei `threadnet-call` (stoppt die fehlschlagende |
| 217 | hosts/cfgmon.md | 105 | component-ref;path-claim | no | 2026-08-09 | 0 | - **`.github/workflows/` in `ThreadNet-Web`** (der kuratierte 6-Dateien-Satz) — wird durch |
| 218 | hosts/cfgmon.md | 106 | path-claim | no | 2026-08-09 | 0 | `.gitlab-ci.yml` ersetzt. Die Erkenntnisse aus den Läufen vom 2026-07-30 mitnehmen: |
| 219 | hosts/cfgmon.md | 110 | component-ref | no | 2026-08-09 | 0 | - **Geerbte Upstream-Workflows in `threadnet-call`** (build/publish/test/translations/ |
| 220 | hosts/cfgmon.md | 113 | path-claim;mirror-topology | no | 2026-08-09 | 0 | der Gitea-Admin-UI deregistrieren und `runner-data/.runner` auf dem Host entfernen. |
| 221 | hosts/cfgmon.md | 114 | component-ref;path-claim | no | 2026-08-09 | 0 | - **Token: npm-Token in `threadnet-call`s untracked `embedded/web/.npmrc`** (Klartext im |
| 222 | hosts/cfgmon.md | 121 | component-ref | no | 2026-08-09 | 0 | - **Runner-Service in `thread-net-git` ganz entfernen?** Hängt daran, ob das gitops-Repo |
| 223 | hosts/cfgmon.md | 122 | path-claim | no | 2026-08-09 | 0 | seinen leichten `deploy-on-push.yml` (YAML-Validierung/Notification, läuft sauber) |
| 224 | hosts/cfgmon.md | 124 | component-ref;path-claim | no | 2026-08-09 | 0 | Revert-Commit in `thread-net-git`: Compose-Service `runner`, `runner/config.yaml`, |
| 225 | hosts/cfgmon.md | 125 | path-claim | no | 2026-08-09 | 0 | `.env.example` (RUNNER_TOKEN), Cache-Port-Bindung 8088, `runner-data/`. |
| 226 | hosts/cfgmon.md | 126 | component-ref;path-claim;mirror-topology | no | 2026-08-09 | 0 | - **Registry-Ziel für `@sorb/threadnet-call-embedded`**: bleibt die Gitea-npm-Registry |
| 227 | hosts/cfgmon.md | 128 | status;mirror-topology | no | 2026-08-09 | 0 | GitLab-Package-Registry (dann läuft die Gitea-Package-Seite leer). |
| 228 | hosts/cfgmon.md | 129 | mirror-topology | no | 2026-08-09 | 0 | - **Container-Images bleiben in der rohana-Registry** (Flux/k8s pullt von dort — spricht |
| 229 | hosts/cfgmon.md | 131 | mirror-topology | no | 2026-08-09 | 0 | **neuen** Deploy-/Push-Token für die rohana-Registry (Neuanlage, kein Rückbau). |
| 230 | hosts/cfgmon.md | 135 | mirror-topology | no | 2026-08-09 | 0 | Gitea selbst, gitops-Repo als Flux-Source, Issues/Wiki/dieses Repo, der |
| 231 | hosts/cfgmon.md | 136 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | API-Token für Issue-Verwaltung, das Gitea-Backup-Script (CFGMON-09). |
| 232 | hosts/cfgmon.md | 139 | component-ref;status | no | 2026-08-09 | 0 | umgezogen — [ADR-0002](../decisions/0002-issues-und-management-ins-lab.md) —, |
| 233 | hosts/cfgmon.md | 140 | component-ref | no | 2026-08-09 | 0 | das Repo dabei von `Backlogs` zu `management` umgewidmet |
| 234 | hosts/cfgmon.md | 142 | mirror-topology | no | 2026-08-09 | 0 | den damaligen Rückbau der Gitea-CI, nicht auf Dauer.)* |
| 235 | hosts/cfgmon.md | 145 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [ThreadNet-Web#2](https://rohana.axion1337.de/sorb/ThreadNet-Web/issues/2), |
| 236 | hosts/cfgmon.md | 146 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1). |
| 237 | hosts/cfgmon.md | 148 | status | no | 2026-08-09 | 0 | **Nächster Schritt:** die drei manuellen Schritte oben, dann → erledigt. |
| 238 | hosts/cfgmon.md | 150 | issue-ref | no | 2026-08-09 | 0 | ## CFGMON-13 — Absender-Design für Release-/CVE-Meldungen: eigener Bot? |
| 239 | hosts/cfgmon.md | 154 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | Alertmanager-Routing: [gitops#47](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/47). |
| 240 | hosts/cfgmon.md | 160 | issue-ref | no | 2026-08-09 | 0 | 1. **release-watch** (gitops#22, deploybereit): Upstream-Releases/Security-Releases |
| 241 | hosts/cfgmon.md | 162 | issue-ref | no | 2026-08-09 | 0 | 2. **Trivy-CVE-Scans** (gitops#31, läuft wöchentlich in der Lab-CI): Funde landen |
| 242 | hosts/cfgmon.md | 168 | status | no | 2026-08-09 | 0 | scharf/stumm schaltbar bleibt? Oder bewusst alles über `@alerts` bündeln? |
| 243 | hosts/cfgmon.md | 174 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | ## CFGMON-12 — Gitea-Projektmetadaten nach GitLab umziehen/integrieren |
| 244 | hosts/cfgmon.md | 176 | component-ref;status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | **Status:** abgelöst durch [gitops#48](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/48) (2026-08-01, sorb: HOHE Priorität — vollständige Issue-Migration + zentrale Gruppen-Roadmap; Plan-Skizze und die offene Erreichbarkeits-Entscheidung git.lab-only vs. extern stehen dort) |
| 245 | hosts/cfgmon.md | 178 | count;date-claim | no | 2026-08-09 | 0 | ✅ **Umgesetzt am 2026-08-01/02**: Die Migration ist durch — 62 Issues liegen auf |
| 246 | hosts/cfgmon.md | 179 | status;mirror-topology | no | 2026-08-09 | 0 | git.lab, die Gitea-Issues sind geschlossen und tragen einen Migrations-Fußtext. |
| 247 | hosts/cfgmon.md | 182 | date-claim;issue-ref | no | 2026-08-09 | 0 | für Deploy-Übergabe-Issues ist am 2026-08-02 mit LABNET-03 ebenfalls zurückgebaut. |
| 248 | hosts/cfgmon.md | 187 | status;mirror-topology | no | 2026-08-09 | 0 | Projektmetadaten liegen weiterhin auf Gitea/rohana. Verifiziert per API am |
| 249 | hosts/cfgmon.md | 190 | mirror-topology | no | 2026-08-09 | 0 | Noch auf Gitea: |
| 250 | hosts/cfgmon.md | 192 | component-ref;issue-ref | no | 2026-08-09 | 0 | - **Issues** inkl. Kommentare/Labels: ThreadNet-Web (#2, #5, …), threadnet-call (#1), |
| 251 | hosts/cfgmon.md | 193 | issue-ref | no | 2026-08-09 | 0 | gitops (#24, #25, #32, …) |
| 252 | hosts/cfgmon.md | 195 | path-claim;mirror-topology | no | 2026-08-09 | 0 | - **Wiki** (gitops-Wiki mit `00-TASKS.md`-Log — bisher bewusst direkt-Gitea) |
| 253 | hosts/cfgmon.md | 197 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | [CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug) auf rohana — bei |
| 254 | hosts/cfgmon.md | 202 | mirror-topology | no | 2026-08-09 | 0 | 1. **GitLab-Gitea-Importer vs. API-Skript** — der Importer verliert Autorenschaft |
| 255 | hosts/cfgmon.md | 205 | mirror-topology | no | 2026-08-09 | 0 | 2. **Erreichbarkeit**: rohana ist von überall erreichbar, git.lab nur im Homelab — |
| 256 | hosts/cfgmon.md | 208 | mirror-topology | no | 2026-08-09 | 0 | direkt-Gitea). |
| 257 | hosts/cfgmon.md | 219 | component-ref;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-10 — threadnet-call-CI schlägt am Artifact-Schritt fehl · verworfen 2026-07-30 |
| 258 | hosts/cfgmon.md | 221 | component-ref;date-claim | no | 2026-08-09 | 0 | Ausgelöst durch einen Push nach `threadnet-call` am 2026-07-30: der Runner (`builder-1`) |
| 259 | hosts/cfgmon.md | 226 | component-ref | no | 2026-08-09 | 0 | **Hypothese inzwischen im Kern bestätigt** — beim parallelen ThreadNet-Web-CI-Versuch |
| 260 | hosts/cfgmon.md | 229 | mirror-topology | no | 2026-08-09 | 0 | ohne Swap, trägt daneben Gitea/Traefik/Monitoring) kann das strukturell nicht liefern. |
| 261 | hosts/cfgmon.md | 233 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | [CFGMON-11](#cfgmon-11--gitea-ci-rückbau-nach-gitlab-umzug)), CFGMON bleibt bei leichten |
| 262 | hosts/cfgmon.md | 234 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | Jobs. Issue-Seite: [threadnet-call#1](https://rohana.axion1337.de/sorb/threadnet-call/issues/1). |
| 263 | hosts/cfgmon.md | 236 | status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-02 — Traefik, Gitea, cAdvisor und Runner unter IaC gebracht · erledigt 2026-07-30 |
| 264 | hosts/cfgmon.md | 238 | component-ref;path-claim | no | 2026-08-09 | 0 | Liefen ursprünglich im Compose-Projekt `thread-net-git` aus `/data/compose/8`, einem von |
| 265 | hosts/cfgmon.md | 239 | component-ref;path-claim | no | 2026-08-09 | 0 | Portainer verwalteten Stack ohne Repo dazu. Jetzt in `sorb/thread-net-git`: `:latest`-Tags |
| 266 | hosts/cfgmon.md | 240 | component-ref;version;mirror-topology | no | 2026-08-09 | 0 | gepinnt (Gitea `1.27.0`, cAdvisor `v0.49.1`), Projektname `thread-net-git` beibehalten |
| 267 | hosts/cfgmon.md | 242 | mirror-topology | no | 2026-08-09 | 0 | Volume-Namen, Downgrade-Verbot für Gitea), nächtliches Backup-Script. Zusätzlich neu: ein |
| 268 | hosts/cfgmon.md | 243 | version;path-claim;mirror-topology | no | 2026-08-09 | 0 | `runner`-Service (`gitea/act_runner:0.6.1`, Container `gitea-runner`, Labels |
| 269 | hosts/cfgmon.md | 244 | path-claim | no | 2026-08-09 | 0 | `ubuntu-latest`/`linux-build`/`win-wine` — die letzten beiden gezielt für Electron-Builds) |
| 270 | hosts/cfgmon.md | 245 | issue-ref | no | 2026-08-09 | 0 | — ursprünglich unter [CFGMON-08](#cfgmon-08) als offene Frage gelistet, siehe dort. |
| 271 | hosts/cfgmon.md | 247 | status;path-claim | no | 2026-08-09 | 0 | Entstanden auf Branch `rework/stack`, zunächst nicht gemergt (produktiv aber schon aktiv). |
| 272 | hosts/cfgmon.md | 248 | path-claim | no | 2026-08-09 | 0 | **2026-07-30 nach `main` gemergt** (`origin/main` == `origin/rework/stack` auf `02b3224`, |
| 273 | hosts/cfgmon.md | 249 | status | no | 2026-08-09 | 0 | verifiziert) — damit spiegelt die Standardansicht des Repos jetzt den Live-Stand. |
| 274 | hosts/cfgmon.md | 250 | status;date-claim | no | 2026-08-09 | 0 | Verifiziert am 2026-07-30 über die Compose-Labels der laufenden Container |
| 275 | hosts/cfgmon.md | 251 | component-ref;path-claim;mirror-topology | no | 2026-08-09 | 0 | (`working_dir: /opt/thread-net-git`) und `docker compose ls`. `gitea-data` ist als |
| 276 | hosts/cfgmon.md | 255 | mirror-topology | no | 2026-08-09 | 0 | Zum Bootstrapping-Problem (Definition von Gitea liegt in Gitea): mitigiert, |
| 277 | hosts/cfgmon.md | 256 | mirror-topology | no | 2026-08-09 | 0 | weil das Deploy-Verzeichnis selbst der Checkout ist — fällt Gitea aus, liegt |
| 278 | hosts/cfgmon.md | 259 | mirror-topology;issue-ref | no | 2026-08-09 | 0 | [CFGMON-09](#cfgmon-09--gitea-backups-off-host-in-die-storage-box-eigenes-borg-repo). |
| 279 | hosts/cfgmon.md | 261 | status;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-05 — Monitoring-Stack unter IaC bringen · erledigt 2026-07-30 |
| 280 | hosts/cfgmon.md | 263 | path-claim | no | 2026-08-09 | 0 | Der Stack lief aus `/opt/monitoring` ohne Versionierung und mit `:latest`-Tags. Jetzt |
| 281 | hosts/cfgmon.md | 264 | component-ref;path-claim | no | 2026-08-09 | 0 | in `sorb/threadnet-operating` unter `monitoring/`, Images gepinnt, |
| 282 | hosts/cfgmon.md | 268 | status;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-06 — Grafana-Certresolver zeigte ins Leere · erledigt 2026-07-30 |
| 283 | hosts/cfgmon.md | 273 | path-claim | no | 2026-08-09 | 0 | aus. Aus dem Altbestand in `/opt/monitoring` unverändert übernommen und dort |
| 284 | hosts/cfgmon.md | 276 | component-ref | no | 2026-08-09 | 0 | Behoben in `threadnet-operating`, Commit `a400f8a`. Cert von Let's Encrypt (YR2) |
| 285 | hosts/cfgmon.md | 277 | date-claim | no | 2026-08-09 | 0 | ausgestellt, gültig bis 2026-10-28 — die Nachfolge davon ist |
| 286 | hosts/cfgmon.md | 278 | issue-ref | no | 2026-08-09 | 0 | [CFGMON-01](#cfgmon-01--zertifikatserneuerung-braucht-offene-ports-ipv4-und-ipv6). |
| 287 | hosts/cfgmon.md | 280 | status;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-07 — Alloy verlor seine Positions-Datei bei jedem Deploy · erledigt 2026-07-30 |
| 288 | hosts/cfgmon.md | 282 | path-claim | no | 2026-08-09 | 0 | `--storage.path=/var/lib/alloy/data` war gesetzt, aber ohne Volume: die |
| 289 | hosts/cfgmon.md | 288 | status | no | 2026-08-09 | 0 | Behoben durch ein `alloy_data`-Volume, Commit `edac97e`. Verifiziert: Positions |
| 290 | hosts/cfgmon.md | 291 | status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | ### CFGMON-08 — Kein Gitea-Actions-Runner registriert, Standort noch offen · erledigt 2026-07-30 |
| 291 | hosts/cfgmon.md | 294 | status | no | 2026-08-09 | 0 | existiert und wo einer laufen sollte, noch offen sei. Beides falsch — ein Runner |
| 292 | hosts/cfgmon.md | 295 | component-ref;path-claim | no | 2026-08-09 | 0 | (`builder-1`) läuft bereits, auf CFGMON, als Teil von `thread-net-git`s `rework/stack`- |
| 293 | hosts/cfgmon.md | 297 | status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [CFGMON-02](#cfgmon-02--traefik-gitea-cadvisor-und-runner-unter-iac-gebracht--erledigt-2026-07-30) — hier |
| 294 | hosts/cfgmon.md | 298 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | nicht dupliziert. [gitops#33](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/33) |
| 295 | hosts/cfgmon.md | 299 | status | no | 2026-08-09 | 0 | (dieselbe falsche Prämisse) entsprechend korrigiert/geschlossen. |
| 296 | hosts/game.md | 3 | component-ref | no | 2026-08-02 | 7 | Pterodactyl- / Gameserver-Host. |
| 297 | hosts/game.md | 7 | version | no | 2026-08-02 | 7 | | **IPv4** | `157.90.155.206` | |
| 298 | hosts/game.md | 10 | version;date-claim | no | 2026-08-02 | 7 | | **Privat** | `10.0.0.4` (im vSwitch seit 2026-08-02) | |
| 299 | hosts/game.md | 20 | component-ref | no | 2026-08-02 | 7 | [axion1337.chat/game-operating](https://git.lab/axion1337.chat/game-operating) |
| 300 | hosts/game.md | 25 | status | no | 2026-08-02 | 7 | Deployment ist gewollt, aber bewusst **zurückgestellt, bis das Matrix-Projekt |
| 301 | hosts/game.md | 31 | component-ref | no | 2026-08-02 | 7 | **Pterodactyl** (Gameserver-Verwaltung, in Benutzung durch Bekannte des Betreibers |
| 302 | hosts/game.md | 36 | version;path-claim | no | 2026-08-02 | 7 | | `pterodactyl` (Panel) | `ghcr.io/pterodactyl/panel:v1.12.0` | |
| 303 | hosts/game.md | 37 | component-ref;version;path-claim | no | 2026-08-02 | 7 | | `wings` (Daemon, fährt die Gameserver als Docker-Container) | `ghcr.io/pterodactyl/wings:v1.12.0` | |
| 304 | hosts/game.md | 41 | version | no | 2026-08-02 | 7 | **Eigener Monitoring-Stack** (grafana-oss, prometheus v3.0.0 mit 15 d Retention, |
| 305 | hosts/game.md | 42 | version | no | 2026-08-02 | 7 | loki 3.1.1, promtail 3.1.1, node-exporter v1.8.1, cadvisor v0.49.2). Wird |
| 306 | hosts/game.md | 43 | status | no | 2026-08-02 | 7 | perspektivisch von CFGMON abgelöst — siehe unten. |
| 307 | hosts/game.md | 47 | issue-ref | no | 2026-08-02 | 7 | GAME-01: Auf 9100/8080 des Hosts lauscht nichts, CFGMONs Scrape-Ziele auf der |
| 308 | hosts/game.md | 55 | version | no | 2026-08-02 | 7 | | Port | von CFGMON (`188.245.193.243`, 2026-08-01) | vom Hausanschluss (`178.25.213.70`, 2026-08-02) | |
| 309 | hosts/game.md | 57 | status | no | 2026-08-02 | 7 | | 80 / 443 | offen | offen (HTTP 404 bzw. 503) | |
| 310 | hosts/game.md | 58 | status | no | 2026-08-02 | 7 | | **22** | **Timeout** | **offen** | |
| 311 | hosts/game.md | 67 | date-claim | no | 2026-08-02 | 7 | Es fehlte also keine Ausnahme für CFGMON. Seit 2026-08-02 liegt der Host im |
| 312 | hosts/game.md | 68 | version | no | 2026-08-02 | 7 | vSwitch (`10.0.0.4`); die Monitoring-Anbindung läuft künftig **per Push über das |
| 313 | hosts/game.md | 69 | version | no | 2026-08-02 | 7 | private Netz** — Alloy sammelt lokal ein und schiebt nach `10.0.0.3`, wodurch der |
| 314 | hosts/game.md | 71 | component-ref;issue-ref | no | 2026-08-02 | 7 | k3s-Cluster. Details: [GAME-01](https://git.lab/axion1337.chat/management/-/issues/2). |
| 315 | hosts/game.md | 80 | component-ref | no | 2026-08-02 | 7 | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. |
| 316 | hosts/game.md | 83 | component-ref;date-claim;issue-ref | no | 2026-08-02 | 7 | - [GAME-01 — Host von CFGMON aus nicht erreichbar, 2 Targets down (⚠️ Silences bis 2026-08-04)](https://git.lab/axion1337.chat/management/-/issues/2) |
| 317 | hosts/game.md | 84 | component-ref;issue-ref | no | 2026-08-02 | 7 | - [GAME-02 — `www.game.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/3) |
| 318 | hosts/matrix.md | 8 | version | no | 2026-08-09 | 0 | | **IPv4** | `49.13.132.245` | |
| 319 | hosts/matrix.md | 10 | version | no | 2026-08-09 | 0 | | **Privat** | `10.0.0.2` (`enp7s0`, dasselbe Hetzner-Netz wie CFGMON `10.0.0.3`) | |
| 320 | hosts/matrix.md | 12 | path-claim | no | 2026-08-09 | 0 | | **DNS** | `matrix.axion1337.de` **und** `matrix.axion1337.chat` zeigen auf dieselbe IP — ebenso `axion1337.chat` (Apex) und `account.axion1337.chat` (MAS). `axion1337.de` ist die ältere/Registrar-Domain (IONOS-Mail läuft dort), `axion1337.chat` die eigentliche Matrix-Service-Domain. | |
| 321 | hosts/matrix.md | 15 | path-claim | no | 2026-08-09 | 0 | **Inventarisiert** (direkter SSH-Zugriff, `~/.ssh/config`-Alias `axion1337`, Port 2248): |
| 322 | hosts/matrix.md | 18 | component-ref;path-claim;mirror-topology | no | 2026-08-09 | 0 | [`sorb/axion1337.chat-gitops`](https://rohana.axion1337.de/sorb/axion1337.chat-gitops) - dieser |
| 323 | hosts/matrix.md | 20 | component-ref;path-claim | no | 2026-08-09 | 0 | `sorb/ThreadNet-Web` (Element Web), `sorb/threadnet-call` (Element Call/LiveKit-Widget). |
| 324 | hosts/matrix.md | 21 | path-claim | no | 2026-08-09 | 0 | `sorb/element-web` und `sorb/ThreadNet-Stack` sind **veraltete/abgelöste** Vorgänger-Repos |
| 325 | hosts/matrix.md | 24 | status | no | 2026-08-09 | 0 | `ufw`: aktiv, Default Deny Incoming / Allow Outgoing, explizite Allow-Regeln für |
| 326 | hosts/matrix.md | 25 | status | no | 2026-08-09 | 0 | 2248/tcp (SSH), 80/443, TURN/RTC-Ports. `unattended-upgrades` aktiv (Debian-Security + |
| 327 | hosts/matrix.md | 26 | status;issue-ref | no | 2026-08-09 | 0 | Debian-Origin), siehe [MATRIX-04](#matrix-04--host-level-pre-update-benachrichtigung-erledigt). |
| 328 | hosts/matrix.md | 31 | component-ref | no | 2026-08-09 | 0 | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. |
| 329 | hosts/matrix.md | 34 | component-ref;issue-ref | no | 2026-08-09 | 0 | - [MATRIX-03 — `www.matrix.axion1337.de` ist überflüssig](https://git.lab/axion1337.chat/management/-/issues/1) |
| 330 | hosts/matrix.md | 36 | date-claim;issue-ref | no | 2026-08-09 | 0 | ## MATRIX-05 — node-exporter-DaemonSet in CrashLoopBackOff, Cluster-Scrape seit 2026-08-01 tot |
| 331 | hosts/matrix.md | 38 | status | no | 2026-08-09 | 0 | **Status:** erledigt (2026-08-01 ~04:10, vom Mac aus mit kubectl/SSH) |
| 332 | hosts/matrix.md | 41 | version | no | 2026-08-09 | 0 | Teil 1 bestätigt per Pod-Log: `listen tcp 0.0.0.0:9100: bind: address already in use`; |
| 333 | hosts/matrix.md | 49 | issue-ref | no | 2026-08-09 | 0 | **Fix (gitops `228807f`, Weg A aus gitops#45):** HelmRelease + Alloy-Scrape entfernt, |
| 334 | hosts/matrix.md | 52 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [gitops#45](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/45). |
| 335 | hosts/matrix.md | 61 | date-claim | no | 2026-08-09 | 0 | | Messwert | Stand 2026-08-01 | |
| 336 | hosts/matrix.md | 67 | path-claim | no | 2026-08-09 | 0 | | `waiting_reason` / `ready` | `CrashLoopBackOff` / `0` | |
| 337 | hosts/matrix.md | 73 | status | no | 2026-08-09 | 0 | **Vermutete Ursache, nicht verifiziert:** Der Pod läuft mit `hostNetwork: true` und will |
| 338 | hosts/matrix.md | 75 | version | no | 2026-08-09 | 0 | derselbe, den CFGMON als Job `k3s_host_node` direkt auf `10.0.0.2:9100` scrapt und der |
| 339 | hosts/matrix.md | 86 | date-claim | no | 2026-08-09 | 0 | ### Teil 2 — der Cluster-Scrape ist am 2026-08-01 01:19 UTC ausgefallen (akut) |
| 340 | hosts/matrix.md | 96 | version | no | 2026-08-09 | 0 | `hostNetwork`, sein Pod-IP ist die öffentliche `49.13.132.245`, dorthin zeigt der |
| 341 | hosts/matrix.md | 103 | status;version | no | 2026-08-09 | 0 | | `10.0.0.2:9100` (privat) | offen, 2706 Metriken | |
| 342 | hosts/matrix.md | 104 | version | no | 2026-08-09 | 0 | | `49.13.132.245:9100` (öffentlich) | **keine Antwort** | |
| 343 | hosts/matrix.md | 105 | status;version;path-claim | no | 2026-08-09 | 0 | | `49.13.132.245:80` / `:443` | offen — Host lebt | |
| 344 | hosts/matrix.md | 110 | version | no | 2026-08-09 | 0 | 1. Der Exporter bindet jetzt `10.0.0.2:9100` statt `0.0.0.0:9100`. |
| 345 | hosts/matrix.md | 123 | version | no | 2026-08-09 | 0 | auf `10.0.0.2:9100` zeigen lassen. Beendet den Crashloop und erhält die enge Bindung ans |
| 346 | hosts/matrix.md | 127 | version | no | 2026-08-09 | 0 | Ebenfalls sauber, aber er bindet dann wieder `0.0.0.0` — also auch die öffentliche IP, |
| 347 | hosts/matrix.md | 131 | count | no | 2026-08-09 | 0 | ### Nebenbefund — Job-Label kollidiert zwischen zwei Hosts |
| 348 | hosts/matrix.md | 137 | version | yes | 2026-08-09 | 0 | up=1 instance=node-exporter:9100 -> CFGMON (Kernel 6.8.0-136-generic) |
| 349 | hosts/matrix.md | 152 | status;issue-ref | no | 2026-08-09 | 0 | ### MATRIX-01 — Klären, ob der Server Mail als `@matrix.axion1337.de` verschickt · erledigt 2026-07-30 |
| 350 | hosts/matrix.md | 154 | path-claim | no | 2026-08-09 | 0 | Für `matrix.axion1337.de` existiert der komplette IONOS-Mail-Satz: `MX mx00/mx01`, |
| 351 | hosts/matrix.md | 157 | status | no | 2026-08-09 | 0 | offen, weil Matrix-Homeserver typischerweise Mail für Registrierung/Passwort-Reset |
| 352 | hosts/matrix.md | 160 | status | no | 2026-08-09 | 0 | **Antwort, verifiziert per Config** (nicht nur vermutet) — direkt im IaC-Repo |
| 353 | hosts/matrix.md | 161 | component-ref;path-claim | no | 2026-08-09 | 0 | `sorb/axion1337.chat-gitops`, dem tatsächlich hier deployten Stand geprüft: |
| 354 | hosts/matrix.md | 163 | path-claim | no | 2026-08-09 | 0 | - `apps/production/custom-configs/synapse-values.yaml` — kein `email:`/`smtp_host`/ |
| 355 | hosts/matrix.md | 165 | path-claim | no | 2026-08-09 | 0 | - `apps/production/custom-configs/mas-secret.yaml` (SOPS-entschlüsselt geprüft) — kein |
| 356 | hosts/matrix.md | 166 | path-claim | no | 2026-08-09 | 0 | `email`/`smtp`/`mailer`-Eintrag. |
| 357 | hosts/matrix.md | 167 | path-claim | no | 2026-08-09 | 0 | - `apps/production/element-server-suite.yaml` (HelmRelease values) — dito, nichts. |
| 358 | hosts/matrix.md | 174 | issue-ref | no | 2026-08-09 | 0 | [ZONE-02](../shared/zone-axion1337.md) an dieser Stelle entblockt. |
| 359 | hosts/matrix.md | 179 | issue-ref | no | 2026-08-09 | 0 | MATRIX-04 unten. Nutzt die ohnehin am Apex laufende echte IONOS-Mail-Infrastruktur, |
| 360 | hosts/matrix.md | 182 | status;issue-ref | no | 2026-08-09 | 0 | ### MATRIX-02 — Pusht per Remote-Write auf einen offenen Prometheus · erledigt 2026-07-30 |
| 361 | hosts/matrix.md | 187 | status;version | no | 2026-08-09 | 0 | selbst die private IP `10.0.0.2` (verifiziert per `ip -4 addr show` auf dem Host). |
| 362 | hosts/matrix.md | 189 | status;path-claim | no | 2026-08-09 | 0 | Verifiziert in `apps/monitoring/alloy-config.yaml` (diesem Cluster): Der Remote-Write-Push |
| 363 | hosts/matrix.md | 190 | version;path-claim | no | 2026-08-09 | 0 | geht bereits an `http://10.0.0.3:9090/api/v1/write` und Loki an `http://10.0.0.3:3100/...` - |
| 364 | hosts/matrix.md | 191 | version | no | 2026-08-09 | 0 | **private IP, nicht die öffentliche** `188.245.193.243:9090`. Von dieser Seite aus ist hier |
| 365 | hosts/matrix.md | 194 | issue-ref | no | 2026-08-09 | 0 | [CFGMON-03](cfgmon.md#cfgmon-03--prometheus-remote-write-und-loki-sind-öffentlich-ohne-auth) |
| 366 | hosts/matrix.md | 197 | status;issue-ref | no | 2026-08-09 | 0 | ### MATRIX-04 — Host-Level Pre-Update-Benachrichtigung · erledigt 2026-07-30 |
| 367 | hosts/matrix.md | 200 | path-claim | no | 2026-08-09 | 0 | `docs/deployment-guides/07-host-maintenance-notifications.md` im gitops-Repo, |
| 368 | hosts/matrix.md | 201 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [Issue #24](https://rohana.axion1337.de/sorb/axion1337.chat-gitops/issues/24)): |
| 369 | hosts/matrix.md | 202 | status | no | 2026-08-09 | 0 | `unattended-upgrades` war bereits aktiv, neu ergänzt ist ein systemd-Timer |
| 370 | hosts/overmind.md | 10 | version | no | 2026-08-09 | 0 | | **DNS (Lab)** | `git.lab` → `10.58.73.17` (TLS via Dokploy-Proxy, Zertifikate von der aXionLabs-CA: step-ca, 24h-Leaf, Intermediate bis 2035) | |
| 371 | hosts/overmind.md | 11 | date-claim | no | 2026-08-09 | 0 | | **CPU/RAM** | 14 Kerne, 30 Gi (Stand 2026-07-31: ~11 Gi verfügbar) | |
| 372 | hosts/overmind.md | 12 | date-claim | no | 2026-08-09 | 0 | | **Disk** | 444 G NVMe (~278 G frei, Stand 2026-07-31) | |
| 373 | hosts/overmind.md | 13 | path-claim | no | 2026-08-09 | 0 | | **KVM** | `/dev/kvm` vorhanden — Basis für die Windows-Build-VM | |
| 374 | hosts/overmind.md | 20 | component-ref;version;path-claim | no | 2026-08-09 | 0 | | GitLab CE 18.7.1 + Postgres 16 + Redis 7 | Dokploy-Stack `management-gitlabce` | `external_url https://git.lab`, SSH 2224; TLS terminiert der Dokploy-Proxy (GitLab-nginx lauscht nur :80) | |
| 375 | hosts/overmind.md | 21 | status;version;path-claim | no | 2026-08-09 | 0 | | gitlab-runner `lab-builder-1` (v18.7.0) | gleicher Stack, Service `gitlab-runner` | Docker-Executor + Socket, `concurrent = 1`. **Stolpersteine, live gefunden**: (1) Docker-interner DNS löst `git.lab` auf den GitLab-Container auf, wo 443 zu ist → `extra_hosts: git.lab:10.58.73.17` nötig; (2) Lab-CA muss nach `/etc/gitlab-runner/certs/git.lab.crt` (Config-Volume, übersteht Redeploys) | |
| 376 | hosts/overmind.md | 27 | status;date-claim;mirror-topology | no | 2026-08-09 | 0 | git.lab ist seit 2026-07-31 **kanonisch** für die gespiegelten Repos der Gruppe |
| 377 | hosts/overmind.md | 28 | component-ref;count;date-claim | no | 2026-08-09 | 0 | `axion1337.chat` — Stand 2026-08-09 **sieben**: die sechs Produkt-Repos (ThreadNet-Web, |
| 378 | hosts/overmind.md | 29 | component-ref | no | 2026-08-09 | 0 | threadnet-call, thread-net-git, threadnet-operating, axion1337.chat-gitops, seit heute auch |
| 379 | hosts/overmind.md | 30 | component-ref;mirror-topology | no | 2026-08-09 | 0 | `game-operating`) **und `management`, also dieses Repo**. Push-Mirrors nach rohana/Gitea, |
| 380 | hosts/overmind.md | 31 | status;mirror-topology | no | 2026-08-09 | 0 | direkte Gitea-Pushes tabu. |
| 381 | hosts/overmind.md | 33 | component-ref;status;mirror-topology | no | 2026-08-09 | 0 | ⚠️ `gameserver` (achtes Projekt der Gruppe) hat **keinen** Mirror — offen in |
| 382 | hosts/overmind.md | 34 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | [management#32](https://git.lab/axion1337.chat/management/-/issues/32), dort liegt auf Gitea |
| 383 | hosts/overmind.md | 37 | mirror-topology | no | 2026-08-09 | 0 | Gitea bleibt: Flux-Source (via Mirror beliefert), Registry, Packages. |
| 384 | hosts/overmind.md | 38 | date-claim | no | 2026-08-09 | 0 | **Issues nicht mehr** — die sind am 2026-08-01/02 nach git.lab gewandert |
| 385 | hosts/overmind.md | 39 | component-ref | no | 2026-08-09 | 0 | ([ADR-0002](../decisions/0002-issues-und-management-ins-lab.md)). Die letzte Ausnahme, |
| 386 | hosts/overmind.md | 40 | component-ref;path-claim;date-claim;mirror-topology | no | 2026-08-09 | 0 | die Deploy-Übergabe-Issues auf dem Gitea-Tracker `sorb/management`, ist am 2026-08-02 |
| 387 | hosts/overmind.md | 41 | status;issue-ref | no | 2026-08-09 | 0 | mit LABNET-03 zurückgebaut: beide umgezogen (#25, #26), der Tracker ist leer. |
| 388 | hosts/overmind.md | 45 | component-ref;mirror-topology | no | 2026-08-09 | 0 | seit der Umwidmung zum Management-Repo `management` und wird seither gespiegelt, |
| 389 | hosts/overmind.md | 48 | issue-ref | no | 2026-08-09 | 0 | ## OVERMIND-01 — GitLab-Container-Registry aktivieren, Images nach Konsument sortieren |
| 390 | hosts/overmind.md | 50 | status | no | 2026-08-09 | 0 | **Status:** erledigt (2026-08-01) |
| 391 | hosts/overmind.md | 53 | component-ref;status;path-claim | no | 2026-08-09 | 0 | `registry.git.lab/axion1337.chat/threadnet-web/desktop-build:bullseye` (Job 386 grün, |
| 392 | hosts/overmind.md | 55 | status | no | 2026-08-09 | 0 | damit grün durch (Job 398 - beweist auch den anonymen Pull des public Projekts durch |
| 393 | hosts/overmind.md | 56 | mirror-topology | no | 2026-08-09 | 0 | den Runner-Daemon). Die rohana-`REGISTRY_*`-Variablen bleiben nur noch für den |
| 394 | hosts/overmind.md | 61 | mirror-topology | no | 2026-08-09 | 0 | Lab-CI → rohana (Prod, Internet) → zurück ins Lab — koppelt Lab-Infrastruktur unnötig an |
| 395 | hosts/overmind.md | 65 | component-ref;path-claim;mirror-topology | no | 2026-08-09 | 0 | - **rohana (Gitea) behält**: `sorb/threadnet-web` (App-Image — Flux/Prod pullt es), |
| 396 | hosts/overmind.md | 71 | path-claim | no | 2026-08-09 | 0 | 1. Omnibus-Config: `registry_external_url 'https://registry.git.lab'`, |
| 397 | hosts/overmind.md | 74 | version | no | 2026-08-09 | 0 | 2. Lab-DNS: `registry.git.lab` → `10.58.73.17` |
| 398 | hosts/overmind.md | 78 | path-claim | no | 2026-08-09 | 0 | `/etc/docker/certs.d/registry.git.lab/ca.crt` (Datei liegt schon als |
| 399 | hosts/overmind.md | 79 | path-claim | no | 2026-08-09 | 0 | `/tmp/git.lab.crt` vom Runner-Setup — kopieren reicht; kein Daemon-Restart nötig) |
| 400 | hosts/overmind.md | 80 | path-claim | no | 2026-08-09 | 0 | 5. CI-Umstellung: `vendor/windows` pusht nach `registry.git.lab` (Bonus: GitLabs |
| 401 | hosts/overmind.md | 81 | path-claim | no | 2026-08-09 | 0 | eingebaute `$CI_REGISTRY`/`$CI_JOB_TOKEN`-Auth statt Gruppen-Secrets), |
| 402 | hosts/overmind.md | 82 | component-ref;path-claim | no | 2026-08-09 | 0 | `desktop_image`/`desktop_linux` in ThreadNet-Web folgen; Registry-Speicher liegt im |
| 403 | hosts/overmind.md | 85 | status | no | 2026-08-09 | 0 | **Fortschritt 2026-07-31**: Punkte 1–4 umgesetzt (Registry live auf |
| 404 | hosts/overmind.md | 86 | path-claim | no | 2026-08-09 | 0 | `registry.git.lab`, 401/Bearer-Auth korrekt, CA-Trust auf dem Host); `vendor/windows` |
| 405 | hosts/overmind.md | 87 | status | no | 2026-08-09 | 0 | pusht per `CI_JOB_TOKEN` in die Lab-Registry — verifiziert, Tags `5bc25447` + `stable` |
| 406 | hosts/overmind.md | 90 | mirror-topology | no | 2026-08-09 | 0 | **Nächster Schritt:** `element-desktop-build` von rohana in die Lab-Registry umziehen |
| 407 | hosts/overmind.md | 91 | component-ref | no | 2026-08-09 | 0 | (ThreadNet-Web-CI: `desktop_image`-Push-Ziel + `desktop_linux`-Image-Referenz) — bewusst |
| 408 | hosts/overmind.md | 92 | status | no | 2026-08-09 | 0 | zurückgestellt, bis kein Auto-Job das alte Image parallel referenziert (Reihenfolge: |
| 409 | hosts/overmind.md | 95 | status;issue-ref | no | 2026-08-09 | 0 | ## OVERMIND-02 — Host-Ausfall 2026-07-31 ~19:15 lokal (NIC-Hang, Fix aktiv) |
| 410 | hosts/overmind.md | 97 | component-ref;status;issue-ref | no | 2026-08-09 | 0 | **Status:** Fix aktiv — die Beobachtung läuft als [Issue #4](https://git.lab/axion1337.chat/management/-/issues/4) |
| 411 | hosts/overmind.md | 107 | status | no | 2026-08-09 | 0 | **Fix (2026-07-31, Overmind-Session):** `ethtool --set-eee eno1 eee off` live gesetzt |
| 412 | hosts/overmind.md | 108 | path-claim | no | 2026-08-09 | 0 | + persistente udev-Regel `/etc/udev/rules.d/71-disable-eee-eno1.rules` (greift bei |
| 413 | hosts/overmind.md | 112 | status;version | no | 2026-08-09 | 0 | - ~~NIC-/BIOS-Firmware-Update 2.4.0.0 → 2.5.2.0~~ **erledigt** (Wartungsfenster |
| 414 | hosts/overmind.md | 121 | status;version | no | 2026-08-09 | 0 | - 19:05–19:12 — Provision-Job 409 grün (Rust 1.97.1 maschinenweit, Strawberry Perl, |
| 415 | hosts/overmind.md | 137 | status | no | 2026-08-09 | 0 | 8G. Nach dem NIC-Fix lief die Kette durch: **desktop_windows Job 438 grün** |
| 416 | hosts/overmind.md | 138 | version | no | 2026-08-09 | 0 | (2026-07-31 ~21:50 lokal, `Element Setup 1.12.17.exe`, 141 MB, unsigniert) — |
| 417 | hosts/overmind.md | 139 | component-ref;status;issue-ref | no | 2026-08-09 | 0 | ThreadNet-Web#5 geschlossen, Folgethemen (Signing/Branding) in ThreadNet-Web#6. |
| 418 | hosts/overmind.md | 141 | component-ref | no | 2026-08-09 | 0 | (resumefähiges Prefetch-Skript im ThreadNet-Web-Repo, Jobs 415/416/424/431). |
| 419 | hosts/overmind.md | 145 | component-ref;issue-ref | no | 2026-08-09 | 0 | Weitere CI-Betriebsthemen laufen über die Projekt-Issues (ThreadNet-Web#5 |
| 420 | hosts/overmind.md | 146 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | Windows-Strecke, threadnet-call#1 npm-Ziel) und CFGMON-11 (Gitea-CI-Rückbau). |
| 421 | roadmap.md | 3 | date-claim | no | 2026-08-09 | 0 | > Stand 2026-08-06. Diese Datei hält die **Linien und die Reihenfolge**, |
| 422 | roadmap.md | 6 | date-claim | no | 2026-08-09 | 0 | > Die Gruppen-Milestones M1–M4 sind angelegt, und seit 2026-08-06 hängt **jedes |
| 423 | roadmap.md | 20 | status | no | 2026-08-09 | 0 | 1. **CVE-Meldeweg v2 live** — aggregierte Alarme deployen |
| 424 | roadmap.md | 21 | component-ref;issue-ref | no | 2026-08-09 | 0 | ([Übergabe-Issue #25](https://git.lab/axion1337.chat/management/-/issues/25)), |
| 425 | roadmap.md | 23 | component-ref;issue-ref | no | 2026-08-09 | 0 | (Follow-up-Wunsch sorb). [gitops#45](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/45), |
| 426 | roadmap.md | 24 | component-ref;issue-ref | no | 2026-08-09 | 0 | [#49](https://git.lab/axion1337.chat/axion1337.chat-gitops/-/issues/49) |
| 427 | roadmap.md | 26 | component-ref;issue-ref | no | 2026-08-09 | 0 | [CFGMON-01 (#7)](https://git.lab/axion1337.chat/management/-/issues/7) ⏰ |
| 428 | roadmap.md | 27 | component-ref;issue-ref | no | 2026-08-09 | 0 | 3. **Backups wiederherstellen** — [CFGMON-09 (#10)](https://git.lab/axion1337.chat/management/-/issues/10) |
| 429 | roadmap.md | 29 | issue-ref | no | 2026-08-09 | 0 | 4. K3s-API-Härtung (gitops#25, gemeinsame Session), CFGMON-03-Konsolen-Klärung. |
| 430 | roadmap.md | 33 | status | no | 2026-08-09 | 0 | 1. ✅ **Site-to-Site-VPN** Hetzner ↔ Lab — erledigt 2026-08-01 |
| 431 | roadmap.md | 34 | component-ref;issue-ref | no | 2026-08-09 | 0 | ([#12](https://git.lab/axion1337.chat/management/-/issues/12), ADR-0004 akzeptiert, |
| 432 | roadmap.md | 35 | issue-ref | no | 2026-08-09 | 0 | zwei AARs). Ernte daraus: ✅ **LABNET-03 (#13)** — Übergabe-Issues sind am |
| 433 | roadmap.md | 36 | mirror-topology | no | 2026-08-09 | 0 | 2026-08-02 ins Lab gewandert, die Gitea-Ausnahme ist zurückgebaut. |
| 434 | roadmap.md | 37 | issue-ref | no | 2026-08-09 | 0 | 2. GAME-01-Erreichbarkeit + vSwitch-Aufnahme — |
| 435 | roadmap.md | 38 | component-ref;date-claim;issue-ref | no | 2026-08-09 | 0 | [#2](https://git.lab/axion1337.chat/management/-/issues/2) (Silences bis 2026-08-04!) |
| 436 | roadmap.md | 39 | issue-ref | no | 2026-08-09 | 0 | 3. Roadmap-/Board-Ausbau in GitLab (Rest von gitops#46: Milestones, Boards). |
| 437 | roadmap.md | 40 | component-ref;issue-ref | no | 2026-08-09 | 0 | 4. **Wiki-Oberfläche entscheiden** — [DOC-03 (#20)](https://git.lab/axion1337.chat/management/-/issues/20): |
| 438 | roadmap.md | 45 | component-ref;issue-ref | no | 2026-08-09 | 0 | [CFGMON-14 (#14)](https://git.lab/axion1337.chat/management/-/issues/14) docker-Gruppe |
| 439 | roadmap.md | 47 | component-ref;issue-ref | no | 2026-08-09 | 0 | [CFGMON-15 (#15)](https://git.lab/axion1337.chat/management/-/issues/15) Token-Hygiene, |
| 440 | roadmap.md | 48 | component-ref;issue-ref | no | 2026-08-09 | 0 | [LABNET-04 (#16)](https://git.lab/axion1337.chat/management/-/issues/16) Nacharbeiten. |
| 441 | roadmap.md | 52 | date-claim | no | 2026-08-09 | 0 | 1. **Rebrand fortsetzen** — Desktop-Client heißt seit 2026-08-02 **ThreadNet** und |
| 442 | roadmap.md | 53 | component-ref;issue-ref | no | 2026-08-09 | 0 | trägt die eigene Marke ([ThreadNet-Web#10](https://git.lab/axion1337.chat/ThreadNet-Web/-/issues/10), |
| 443 | roadmap.md | 54 | status;path-claim | no | 2026-08-09 | 0 | Commit `6b0261d`). Offen: Web-Client-Icons/`brand`, About-Attribution. |
| 444 | roadmap.md | 55 | component-ref;issue-ref | no | 2026-08-09 | 0 | 2. Signing/Notarisierung (ThreadNet-Web#6) — ohne Signatur muss jeder Nutzer auf |
| 445 | roadmap.md | 57 | component-ref;issue-ref | no | 2026-08-09 | 0 | 3. **macOS reproduzierbar bauen** — [BUILD-01 (#22)](https://git.lab/axion1337.chat/management/-/issues/22): |
| 446 | roadmap.md | 59 | issue-ref | no | 2026-08-09 | 0 | 4. **Raidplaner** (gitops#47) — Lean-Experiment: HumHub-Kandidat evaluieren. |
| 447 | roadmap.md | 60 | issue-ref | no | 2026-08-09 | 0 | 5. **Gäste-Invite-Workflow** (gitops#48) — Design steht (@concierge, |
| 448 | roadmap.md | 62 | component-ref;issue-ref | no | 2026-08-09 | 0 | 6. Zammad-artiges Feedback-Tool als spätere Ergänzung (ThreadNet-Web#9). |
| 449 | roadmap.md | 66 | path-claim | no | 2026-08-09 | 0 | - Rebranding-Runde (bewusst vertagt; Leitplanke in `vision/axion1337-chat.md`). |
| 450 | roadmap.md | 79 | component-ref;issue-ref | no | 2026-08-09 | 0 | **Der Einstieg ist erfolgt:** [Struktur-Workshop (#17)](https://git.lab/axion1337.chat/management/-/issues/17) |
| 451 | roadmap.md | 80 | date-claim | no | 2026-08-09 | 0 | am 2026-08-06 — Visionen geschärft, M1–M4 angelegt, Board gesichtet, Kadenz und |
| 452 | roadmap.md | 88 | date-claim;mirror-topology | no | 2026-08-09 | 0 | Titel-Präfixe aus der Gitea-Migration sind am 2026-08-06 entfernt; zwei davon |
| 453 | roadmap.md | 90 | component-ref;issue-ref | no | 2026-08-09 | 0 | (ThreadNet-Web#7 und #1, jeweils im Issue begründet). |
| 454 | shared/branding.md | 8 | component-ref | no | 2026-08-09 | 0 | Hier im `management`-Repo, weil es als einziges der beteiligten Repos |
| 455 | shared/branding.md | 9 | mirror-topology | no | 2026-08-09 | 0 | **gespiegelt** ist und jede Werkzeugentscheidung überlebt: Wird das |
| 456 | shared/branding.md | 16 | path-claim | no | 2026-08-09 | 0 | Schriftzug), erstellt von sorb. Sie liegen im Wiki-Repo unter `static/img/` und |
| 457 | shared/branding.md | 28 | date-claim | no | 2026-08-09 | 0 | Icon-Slots fällt das sofort auf. Korrigiert am 2026-08-06 auf 21 % oben wie unten. |
| 458 | shared/branding.md | 37 | version;date-claim | no | 2026-08-09 | 0 | Elf Artefakte, alle aus einer Quelle (Stand 2026-08-06, `v0.4.0`): |
| 459 | shared/branding.md | 41 | path-claim | no | 2026-08-09 | 0 | | `apps/web/res/vector-icons/` | 1024, 512, 180, 152, 144, 120, 24 px | |
| 460 | shared/branding.md | 42 | path-claim | no | 2026-08-09 | 0 | | `apps/desktop/build/icon.png` | App-/Installer-Icon | |
| 461 | shared/branding.md | 43 | path-claim | no | 2026-08-09 | 0 | | `apps/desktop/build/icon.ico` | Windows, 7 Größen von 16 bis 256 | |
| 462 | shared/branding.md | 44 | path-claim | no | 2026-08-09 | 0 | | `apps/desktop/build/icon.icns` | macOS, via `iconutil` aus einem `.iconset` | |
| 463 | shared/branding.md | 45 | path-claim | no | 2026-08-09 | 0 | | `apps/desktop/build/icon.icon/Assets/element.png` | Layer des macOS-Icon-Composers | |
| 464 | shared/branding.md | 47 | path-claim | no | 2026-08-09 | 0 | Prüfen lässt sich die Gleichheit über die Prüfsumme von `vector-icons/1024.png` |
| 465 | shared/branding.md | 48 | path-claim | no | 2026-08-09 | 0 | gegen `build/icon.png` — weichen sie ab, ist eine Seite nachgezogen worden und die |
| 466 | shared/branding.md | 55 | path-claim;issue-ref | no | 2026-08-09 | 0 | Gruvbox Dark. Grundtöne `#282828` / `#1d2021`, Text `#ebdbb2`, Akzent `#bd93f9`, |
| 467 | shared/branding.md | 63 | date-claim | no | 2026-08-09 | 0 | Am 2026-08-02 in der BookStack-Oberfläche eingestellt und von dort extrahiert |
| 468 | shared/branding.md | 65 | issue-ref | no | 2026-08-09 | 0 | der Coolors-Satz `#264653 · #2A9D8F · #E9C46A · #F4A261 · #E76F51`: |
| 469 | shared/branding.md | 69 | issue-ref | no | 2026-08-09 | 0 | | Primäre Farbe | `#264653` | Charcoal | |
| 470 | shared/branding.md | 74 | status | no | 2026-08-09 | 0 | | Seitenfarbe | `#77bb41` | Grün | |
| 471 | shared/branding.md | 75 | status | no | 2026-08-09 | 0 | | Seitenentwurfsfarbe | `#e32400` | Rot | |
| 472 | shared/branding.md | 86 | date-claim | no | 2026-08-09 | 0 | je Theme vier Farben plus ein Schriftpaar. Sie sind seit 2026-08-02 **wörtlich |
| 473 | shared/branding.md | 93 | issue-ref | no | 2026-08-09 | 0 | | Sunset Boulevard | `#264653` | dunkel | `#e76f51` · `#f4a261` · `#e9c46a` | |
| 474 | shared/branding.md | 95 | issue-ref | no | 2026-08-09 | 0 | | Modern Minimalist | `#ffffff` | hell | `#36454f` · `#708090` · `#d3d3d3` | |
| 475 | shared/branding.md | 103 | count | no | 2026-08-09 | 0 | ⚠️ **Ob ein Theme hell oder dunkel gemeint ist, steht nicht verlässlich in den |
| 476 | shared/branding.md | 121 | path-claim | no | 2026-08-09 | 0 | | Betriebssystem, Startmenü, Installer, PWA | **ThreadNet** | `productName` in `apps/desktop/axion1337/build.json`, `name` in `apps/web/res/manifest.json` | |
| 477 | shared/branding.md | 122 | path-claim | no | 2026-08-09 | 0 | | in der Anwendung | **aXion1337.Chat** | `brand` in `element-values.yaml` (Prod) und `apps/desktop/axion1337/config.json` | |
| 478 | shared/branding.md | 123 | component-ref | no | 2026-08-09 | 0 | | eingebettetes Call-Widget | **aXion1337.Chat** | `VITE_PRODUCT_NAME` in `.env.production` (threadnet-call) | |
| 479 | shared/branding.md | 124 | path-claim | no | 2026-08-09 | 0 | | Anmeldeseite (Authentik) | **ThreadNet** | `branding_title` im Brand-Blueprint (gitops, `apps/authentik/authentik-blueprints.yaml`) | |
| 480 | shared/branding.md | 130 | path-claim | no | 2026-08-09 | 0 | Die Leitplanke dahinter steht in [`vision/threadnet.md`](../vision/threadnet.md): |
| 481 | shared/branding.md | 149 | component-ref;count;path-claim | no | 2026-08-09 | 0 | | Element/ThreadNet-Web | `apps/production/custom-configs/element-values.yaml` (gitops), `setting_defaults.custom_themes` | 17 Themes; Änderungen chirurgisch, **nie die YAML neu serialisieren** | |
| 482 | shared/branding.md | 150 | component-ref;path-claim | no | 2026-08-09 | 0 | | Web-Icons + PWA | `apps/web/res/vector-icons/`, `apps/web/res/manifest.json` (ThreadNet-Web) | `theme_color` = `#ed4f4c`, die Markenfarbe — nicht Elements `#76CFA6` | |
| 483 | shared/branding.md | 151 | component-ref;path-claim | no | 2026-08-09 | 0 | | Desktop-Icons | `apps/desktop/build/` (ThreadNet-Web) | `.png`, `.ico`, `.icns`, Layer-Asset — alle aus derselben Quelle | |
| 484 | shared/branding.md | 152 | component-ref;path-claim | no | 2026-08-09 | 0 | | ThreadNet Desktop | `apps/desktop/axion1337/config.json` (ThreadNet-Web) | eigene Kopie derselben Themes — beim Ändern beide mitziehen | |
| 485 | shared/branding.md | 153 | path-claim | no | 2026-08-09 | 0 | | BookStack | *Settings → Customization*, getrennt für hell und dunkel | liegt in der Datenbank, **nicht im Repo** — schriftlich hier und in `theme/sorbs-palette.md` | |
| 486 | shared/branding.md | 154 | path-claim | no | 2026-08-09 | 0 | | BookStack (Feinschliff) | `theme/*.css` im Wiki-BookStack-Repo | nur Flächen, Text, Ränder — die sieben Farben oben gehören in die Oberfläche | |
| 487 | shared/branding.md | 155 | path-claim | no | 2026-08-09 | 0 | | Docusaurus-Wiki | `src/css/custom.css` (homelab/wiki) | bislang nur Akzentfarbe | |
| 488 | shared/branding.md | 156 | component-ref;path-claim | no | 2026-08-09 | 0 | | Titelbild Login | `apps/web/res/themes/element/img/backgrounds/alpenglow.jpg` (ThreadNet-Web), gesetzt in `SdkConfig.ts` | siehe unten — Bilddatei kommt nur über einen Build in den Container | |
| 489 | shared/branding.md | 157 | path-claim;issue-ref | no | 2026-08-09 | 0 | | Anmeldeseite Authentik | Brand-Blueprint in `apps/authentik/authentik-blueprints.yaml` (gitops) | Favicon und Hintergrund werden **von axion1337.chat referenziert**, nicht hochgeladen. **Logo ist noch Authentiks eigenes** → gitops#55 | |
| 490 | shared/branding.md | 161 | date-claim | no | 2026-08-09 | 0 | Seit 2026-08-06 zeigt die Login-Seite ein Alpenglühen über einer Bergkette statt |
| 491 | shared/branding.md | 173 | path-claim | no | 2026-08-09 | 0 | Fotografen namentlich. Nur `en`/`de` anzupassen hätte in 29 Sprachen eine **falsche |
| 492 | shared/branding.md | 179 | path-claim | no | 2026-08-09 | 0 | `https://axion1337.chat/themes/element/img/backgrounds/alpenglow.jpg`. Wer das Bild im |
| 493 | shared/branding.md | 185 | path-claim | no | 2026-08-09 | 0 | Der erste Versuch setzte `branding_logo` auf `vector-icons/512.png`. Ergebnis: das |
| 494 | shared/branding.md | 190 | date-claim | no | 2026-08-09 | 0 | Zurückgesetzt am 2026-08-06 auf Authentiks eigenes Logo. Ein Ersatz braucht eine |
| 495 | shared/branding.md | 192 | status | no | 2026-08-09 | 0 | auch `threadnet-logo-wortmarke.png` (Bildmarke *über* Schriftzug). Offen in |
| 496 | shared/branding.md | 204 | path-claim | no | 2026-08-09 | 0 | `theme/sorbs-palette.md` im BookStack-Repo ist die betriebsnahe Kopie mit den |
| 497 | shared/branding.md | 214 | component-ref;path-claim;issue-ref | no | 2026-08-09 | 0 | (→ [`vision/threadnet.md`](../vision/threadnet.md), ThreadNet-Web#10). |
| 498 | shared/commit-zuordnung-2026-08-07.md | 3 | date-claim | no | 2026-08-09 | 0 | Am 2026-08-07 wurden die Zeitstempel aller Commits aus dieser Zusammenarbeit auf |
| 499 | shared/commit-zuordnung-2026-08-07.md | 14 | status | no | 2026-08-09 | 0 | `backup-vor-rewrite`-Branches rekonstruiert und **paarweise verifiziert**: Für jedes |
| 500 | shared/commit-zuordnung-2026-08-07.md | 26 | component-ref | no | 2026-08-09 | 0 | Das Force-Push der umgezogenen Tags hat in ThreadNet-Web **drei Release-Pipelines |
| 501 | shared/commit-zuordnung-2026-08-07.md | 27 | version | no | 2026-08-09 | 0 | neu gestartet** (`v0.3.0`, `v0.4.0`, `desktop-v1.12.17-clientscan`). Ein Tag ist |
| 502 | shared/commit-zuordnung-2026-08-07.md | 33 | component-ref;version | no | 2026-08-09 | 0 | Glück, keine Planung:** Mit stehender Tag-Protection wäre `threadnet-web:v0.4.0` |
| 503 | shared/commit-zuordnung-2026-08-07.md | 37 | component-ref;issue-ref | no | 2026-08-09 | 0 | ThreadNet-Web#14. |
| 504 | shared/commit-zuordnung-2026-08-07.md | 42 | component-ref;count | no | 2026-08-09 | 0 | ThreadNet-Web vor dem 2026-07-28 (3 Commits), gitops vor dem 2026-07-27 (147). |
| 505 | shared/commit-zuordnung-2026-08-07.md | 47 | count | no | 2026-08-09 | 0 | ## gitops — 117 Commits |
| 506 | shared/commit-zuordnung-2026-08-07.md | 169 | component-ref;count | no | 2026-08-09 | 0 | ## management — 78 Commits |
| 507 | shared/commit-zuordnung-2026-08-07.md | 252 | component-ref;count | no | 2026-08-09 | 0 | ## ThreadNet-Web — 47 Commits |
| 508 | shared/commit-zuordnung-2026-08-07.md | 304 | component-ref;count | no | 2026-08-09 | 0 | ## threadnet-call — 9 Commits |
| 509 | shared/lab-netzwerk.md | 10 | component-ref;issue-ref | no | 2026-08-02 | 7 | > (Testreihe 1–7 in [#12](https://git.lab/axion1337.chat/management/-/issues/12)). |
| 510 | shared/lab-netzwerk.md | 11 | issue-ref | no | 2026-08-02 | 7 | > Es gibt dazu **keine offenen Issues mehr** — auch die Restpunkte #11 |
| 511 | shared/lab-netzwerk.md | 12 | issue-ref | no | 2026-08-02 | 7 | > (MacBook-Profil) und #16 (LABNET-04, Feinschliff an den UniFi-Regeln) sind |
| 512 | shared/lab-netzwerk.md | 13 | status | no | 2026-08-02 | 7 | > geschlossen. Alles Folgende ist **Bestand und Historie**, keine offene Arbeit. |
| 513 | shared/lab-netzwerk.md | 15 | date-claim | no | 2026-08-02 | 7 | **Zwei WireGuard-Zugänge (Stand 2026-08-01, beide gelöst/abgenommen):** |
| 514 | shared/lab-netzwerk.md | 22 | path-claim | no | 2026-08-02 | 7 | ### Verhältnis zu `homelab/docs` |
| 515 | shared/lab-netzwerk.md | 30 | mirror-topology | no | 2026-08-02 | 7 | Der Grund für die Doppelung ist der Mirror-Geltungsbereich aus der |
| 516 | shared/lab-netzwerk.md | 35 | path-claim | no | 2026-08-02 | 7 | darüber hinaus. **Bei Widerspruch gilt `homelab/docs`.** |
| 517 | shared/lab-netzwerk.md | 39 | issue-ref | no | 2026-08-02 | 7 | ## LABNET-01 — WireGuard-Roadwarrior ins Lab kaputt (seit einigen Monaten) |
| 518 | shared/lab-netzwerk.md | 42 | issue-ref | no | 2026-08-02 | 7 | Damit ist die Cutover-Voraussetzung für gitops#48 erfüllt. |
| 519 | shared/lab-netzwerk.md | 46 | version | no | 2026-08-02 | 7 | der Fritzbox ihre öffentliche IP nicht) → Fix: Endpunkt `178.25.213.70`; |
| 520 | shared/lab-netzwerk.md | 52 | version;path-claim | no | 2026-08-02 | 7 | /20-Blöcke in 192.168.0.0/16; `192.168.0.0/20` verschluckte das VPN-Subnetz |
| 521 | shared/lab-netzwerk.md | 53 | version | no | 2026-08-02 | 7 | 192.168.5.0/24 → Antworten an VPN-Clients endeten in der Bridge (SYN kam an, |
| 522 | shared/lab-netzwerk.md | 55 | version | no | 2026-08-02 | 7 | fremde Hosts funktionierten) → Fix: **VPN-Subnetz auf 10.58.74.0/24** (Docker |
| 523 | shared/lab-netzwerk.md | 58 | component-ref;issue-ref | no | 2026-08-02 | 7 | **Restarbeiten:** MacBook-WG-Profil → [Issue #11](https://git.lab/axion1337.chat/management/-/issues/11). ⚠️ Latente Wiederholungsgefahr |
| 524 | shared/lab-netzwerk.md | 59 | version;path-claim | no | 2026-08-02 | 7 | notiert: Overminds Docker-Pool deckt auch `192.168.176.0/20` ab = kollidiert mit |
| 525 | shared/lab-netzwerk.md | 60 | version | no | 2026-08-02 | 7 | dem Fritzbox-Netz 192.168.178.x — aktuell folgenlos, aber bei künftigen Subnetz- |
| 526 | shared/lab-netzwerk.md | 66 | version | no | 2026-08-02 | 7 | (192.168.178.20) als Endpunkt — die UDM kennt hinter der Fritzbox ihre |
| 527 | shared/lab-netzwerk.md | 69 | version | no | 2026-08-02 | 7 | 178.25.213.70 ändern!). |
| 528 | shared/lab-netzwerk.md | 73 | status | no | 2026-08-02 | 7 | einem Port). Fix: UDM-WG auf **51840** umgezogen + Freigabe angepasst. |
| 529 | shared/lab-netzwerk.md | 85 | status | no | 2026-08-02 | 7 | **Diagnose-Plan von VOR der Lösung** — ⚠️ abgearbeitet und überholt, steht hier |
| 530 | shared/lab-netzwerk.md | 102 | issue-ref | no | 2026-08-02 | 7 | **Verwandt:** gitops#48 (Cutover erst nach Lösung), perspektivisch ersetzt ein |
| 531 | shared/lab-netzwerk.md | 105 | status | no | 2026-08-02 | 7 | ## Zugehörige Issues — alle geschlossen |
| 532 | shared/lab-netzwerk.md | 108 | component-ref | no | 2026-08-02 | 7 | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. |
| 533 | shared/lab-netzwerk.md | 111 | status;date-claim | no | 2026-08-02 | 7 | Zum Netz/VPN ist **nichts mehr offen** (Stand 2026-08-02): |
| 534 | shared/lab-netzwerk.md | 115 | component-ref;status;issue-ref | no | 2026-08-02 | 7 | | [#11](https://git.lab/axion1337.chat/management/-/issues/11) | LABNET-01-Rest — MacBook-WireGuard-Profil | geschlossen | |
| 535 | shared/lab-netzwerk.md | 116 | component-ref;status;issue-ref | no | 2026-08-02 | 7 | | [#12](https://git.lab/axion1337.chat/management/-/issues/12) | LABNET-02 — Site-to-Site-VPN (Design: [ADR-0004](../decisions/0004-site-to-site-vpn-hetzner-lab.md)) | geschlossen, Testreihe 1–7 protokolliert | |
| 536 | shared/lab-netzwerk.md | 117 | component-ref;status;issue-ref | no | 2026-08-02 | 7 | | [#16](https://git.lab/axion1337.chat/management/-/issues/16) | LABNET-04 — Feinschliff UniFi-Regeln | geschlossen | |
| 537 | shared/lab-netzwerk.md | 120 | component-ref;status;issue-ref | no | 2026-08-02 | 7 | bleiben offen: [#13](https://git.lab/axion1337.chat/management/-/issues/13) |
| 538 | shared/lab-netzwerk.md | 121 | mirror-topology;issue-ref | no | 2026-08-02 | 7 | (LABNET-03, Rückbau der Gitea-Ausnahme für Übergabe-Issues — durch den Tunnel |
| 539 | shared/lab-netzwerk.md | 123 | component-ref;issue-ref | no | 2026-08-02 | 7 | [#15](https://git.lab/axion1337.chat/management/-/issues/15) (CFGMON-15, |
| 540 | shared/lab-netzwerk.md | 124 | issue-ref | no | 2026-08-02 | 7 | Widerruf der Einmal-Tokens aus der LABNET-02-Nacht — Credential-Hygiene, und der |
| 541 | shared/lab-netzwerk.md | 125 | mirror-topology | no | 2026-08-02 | 7 | Widerruf kann still einen Push-Mirror brechen, solange dessen hinterlegtes Token |
| 542 | shared/zone-axion1337.md | 9 | version;path-claim | no | 2026-08-06 | 3 | | **Apex** | `217.160.0.140` / `2001:8d8:100f:f000::2e9` — IONOS-Hosting, nicht eigene Infrastruktur | |
| 543 | shared/zone-axion1337.md | 18 | mirror-topology | no | 2026-08-06 | 3 | | `rohana` | löst auf ❌ | gelöscht | **gelöscht** ⚠️ | fehlt | ⚠️ schwächer als vorher | |
| 544 | shared/zone-axion1337.md | 20 | status | no | 2026-08-06 | 3 | | `matrix` | löst auf ❌ | IONOS ❌ | `~all` ❌ | fehlt | offen | |
| 545 | shared/zone-axion1337.md | 22 | issue-ref | no | 2026-08-06 | 3 | | **Apex** | legitim ✅ | IONOS (genutzt) | `~all` | **`p=none`** ⚠️ | siehe ZONE-02 | |
| 546 | shared/zone-axion1337.md | 36 | version | no | 2026-08-06 | 3 | | `axion1337.de` | `217.160.0.140` | `2001:8d8:100f:f000::2e9` | IONOS-Hosting | |
| 547 | shared/zone-axion1337.md | 37 | version | no | 2026-08-06 | 3 | | `www` | `217.160.0.140` | dito | IONOS-Hosting — hier ist `www` **legitim** | |
| 548 | shared/zone-axion1337.md | 38 | version;mirror-topology | no | 2026-08-06 | 3 | | `rohana` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Gitea | |
| 549 | shared/zone-axion1337.md | 39 | version | no | 2026-08-06 | 3 | | `selendis` | `188.245.193.243` | `2a01:4f8:c17:93eb::1` | CFGMON, Grafana | |
| 550 | shared/zone-axion1337.md | 40 | version | no | 2026-08-06 | 3 | | `game` | `157.90.155.206` | — | Pterodactyl | |
| 551 | shared/zone-axion1337.md | 41 | version | no | 2026-08-06 | 3 | | `matrix` | `49.13.132.245` | — | Matrix-Homeserver | |
| 552 | shared/zone-axion1337.md | 42 | version | no | 2026-08-06 | 3 | | `ftp` | `217.160.233.227` | `2001:8d8:1000:30f5:…` | IONOS-Default | |
| 553 | shared/zone-axion1337.md | 43 | mirror-topology;issue-ref | no | 2026-08-06 | 3 | | `www.rohana`, `www.selendis`, `www.game`, `www.matrix` | wie ohne `www` | teils | überflüssig, siehe ZONE-01 | |
| 554 | shared/zone-axion1337.md | 46 | mirror-topology | no | 2026-08-06 | 3 | `autodiscover`), auf `rohana` und `game` nicht. |
| 555 | shared/zone-axion1337.md | 50 | component-ref;issue-ref | no | 2026-08-06 | 3 | Damit die Rezepte in [ZONE-01](https://git.lab/axion1337.chat/management/-/issues/5) |
| 556 | shared/zone-axion1337.md | 57 | mirror-topology | no | 2026-08-06 | 3 | kann `rechnung@rohana.axion1337.de` in den Umschlag schreiben. Die folgenden |
| 557 | shared/zone-axion1337.md | 72 | mirror-topology | no | 2026-08-06 | 3 | Genau die richtige Aussage für `rohana`, `selendis`, `matrix` — die verschicken keine |
| 558 | shared/zone-axion1337.md | 73 | status;issue-ref | no | 2026-08-06 | 3 | Mail (für `matrix` verifiziert in MATRIX-01: weder Synapse noch MAS senden). |
| 559 | shared/zone-axion1337.md | 99 | mirror-topology | no | 2026-08-06 | 3 | ⚠️ **DMARC wird vererbt.** Fehlt `_dmarc.rohana`, gilt die Policy des |
| 560 | shared/zone-axion1337.md | 101 | component-ref;issue-ref | no | 2026-08-06 | 3 | ([ZONE-02](https://git.lab/axion1337.chat/management/-/issues/6)) — **damit erben |
| 561 | shared/zone-axion1337.md | 129 | mirror-topology | no | 2026-08-06 | 3 | **Real eingetreten:** Bei `rohana` sind MX und SPF gelöscht, die Ersatz-Records |
| 562 | shared/zone-axion1337.md | 137 | component-ref | no | 2026-08-06 | 3 | [management-Projekt](https://git.lab/axion1337.chat/management/-/issues); die IDs bleiben in den Issue-Titeln erhalten. |
| 563 | shared/zone-axion1337.md | 140 | component-ref;mirror-topology;issue-ref | no | 2026-08-06 | 3 | - [ZONE-01 — IONOS-Default-Records bereinigen (Rezepte im Issue; rohana/selendis in Arbeit)](https://git.lab/axion1337.chat/management/-/issues/5) |
| 564 | shared/zone-axion1337.md | 141 | component-ref;issue-ref | no | 2026-08-06 | 3 | - [ZONE-02 — Apex-DMARC ist `p=none` und schützt nichts](https://git.lab/axion1337.chat/management/-/issues/6) |
| 565 | verfahren/README.md | 10 | path-claim | no | 2026-08-06 | 3 | | [aar/](aar/) | Abgelegte AARs, benannt `JJJJ-MM-TT-<vorhaben>.md` | |
| 566 | verfahren/README.md | 12 | path-claim | no | 2026-08-06 | 3 | [`textbloecke.md`](textbloecke.md) hält kurze, kopierbare Blöcke, die man einer |
| 567 | verfahren/README.md | 18 | path-claim | no | 2026-08-06 | 3 | `.gitlab/issue_templates/Deploy-Übergabe.md` und erscheint beim Anlegen eines |
| 568 | verfahren/README.md | 22 | path-claim | no | 2026-08-06 | 3 | Abgrenzung zum Rest des Repos: `hosts/` und `shared/` halten **offene Punkte**, |
| 569 | verfahren/aar-vorlage.md | 7 | status | no | 2026-08-01 | 8 | Was ist live und verifiziert. Was ist bewusst **nicht** live, und warum. |
| 570 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 1 | issue-ref | no | 2026-08-01 | 8 | # AAR — CVE-Pipeline `gitops#47` |
| 571 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 3 | component-ref;path-claim | no | 2026-08-01 | 8 | **Datum:** 2026-08-01 · **Host/Stack:** CFGMON, `/opt/threadnet-operating/monitoring` |
| 572 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 9 | status | no | 2026-08-01 | 8 | **Live und verifiziert:** Scanner (29/29 Images gescannt), Exporter, Prometheus-Job |
| 573 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 13 | path-claim | no | 2026-08-01 | 8 | `alertmanager.yml` auf einen Null-Receiver (Commit `2b715ca` in |
| 574 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 14 | component-ref;path-claim | no | 2026-08-01 | 8 | `sorb/threadnet-operating`). Grund siehe Befund 1. |
| 575 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 20 | issue-ref | no | 2026-08-01 | 8 | | 1 | Eine Matrix-Nachricht pro CVE. 126 CRITICAL landen in **einer** Alertmanager-Gruppe, nach 24 h kommen 1222 HIGH dazu. Dazu steht `save_state()` in `do_POST` hinter der Sende-Schleife: bricht ein Send ab (Synapse rate-limitet nach ~10 mit 429), wird kein State gespeichert, der Receiver antwortet 502, Alertmanager wiederholt die komplette Gruppe — mit leerer Deduplizierung | HIGH | abgefangen, |
| 576 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 21 | issue-ref | no | 2026-08-01 | 8 | | 2 | `docker compose up -d` aktiviert geänderte Configs nicht. Einzeldatei-Mounts hängen am Inode, `git pull` benennt um. Prometheus lief nach dem Deploy mit alten Regeln — `promtool` fand 9, Prometheus kannte 6, kein Fehler im Log | MEDIUM | behoben via `--force-recreate`, `gitops#52` | |
| 577 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 22 | issue-ref | no | 2026-08-01 | 8 | | 3 | `TrivyScanStale` kann ein nie erfolgreich gescanntes Image nicht melden — ohne ersten Report existiert keine Serie, an der `time() - trivy_last_scan_timestamp` hängen könnte | LOW | notiert in `gitops#51` | |
| 578 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 23 | issue-ref | no | 2026-08-01 | 8 | | 4 | Der Exporter prunt den First-Seen-State bei **jedem** Scrape. Ein transienter Lesefehler (`except: continue`) löscht die Erstfund-Zeitstempel des Targets dauerhaft | LOW | notiert in `gitops#51` | |
| 579 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 27 | version;path-claim | no | 2026-08-01 | 8 | 1316 LOW. Spitzenreiter `goauthentik/server:2026.2.3` mit 369 CRITICAL+HIGH. |
| 580 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 34 | mirror-topology | no | 2026-08-01 | 8 | | Private Registry `rohana.axion1337.de` braucht Credentials für Trivy | Anonymer Pull | zieht anonym, keine Credentials nötig | |
| 581 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 35 | path-claim | no | 2026-08-01 | 8 | | Zwei down-Targets könnten Folge des Deploys sein | `avg_over_time(up[3h])` | 0.00 — schon 3 h vorher tot, in `hosts/game.md` erfasst | |
| 582 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 58 | status;issue-ref | no | 2026-08-01 | 8 | Richtungsentscheidung zu `gitops#51`, bevor die Alarme scharf gehen: entweder |
| 583 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 59 | path-claim | no | 2026-08-01 | 8 | `matrix-alerts.py` auf eine Sammelnachricht pro Webhook-Batch umbauen (die fünf |
| 584 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 65 | path-claim | no | 2026-08-01 | 8 | Nebenbefund ohne Handlungsbedarf von hier: `coturn/coturn:latest` ist das einzige |
| 585 | verfahren/aar/2026-08-01-cve-pipeline-gitops47.md | 66 | issue-ref | no | 2026-08-01 | 8 | ungepinnte Image (bereits in `gitops#47` notiert). |
| 586 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 1 | component-ref;path-claim;issue-ref | no | 2026-08-01 | 8 | # AAR — LABNET-02, CFGMON-Seite (Übergabe `sorb/management#2`) |
| 587 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 8 | status;path-claim | no | 2026-08-01 | 8 | **Live:** `wireguard-tools` installiert, Keypair erzeugt, `/etc/wireguard/lab.conf` |
| 588 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 10 | status;version;path-claim | no | 2026-08-01 | 8 | `enabled`. Interface `lab` steht mit `10.58.75.2/24`, Routen und Forward-Regeln aktiv, |
| 589 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 11 | version | no | 2026-08-01 | 8 | Split-DNS gesetzt (`10.58.73.1`, `~lab`). |
| 590 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 28 | status;version;path-claim | no | 2026-08-01 | 8 | | 1 | `enp7s0` seit 18:11 DOWN, Privatnetz-Route weg. Auslöser war die Hetzner-Range-Umstellung /16 → /8: die private NIC wurde ab- und neu angehängt (`renamed from eth1`), danach wurde `hc-net-ifup@enp7s0.service` **übersprungen** (`ConditionPathExists=!/run/systemd/network/10-netplan-enp7s0.network`). Folge: `k3s_host_node` (10.0.0.2) unerreichbar, Gateway-Rolle wirkungslos | HIGH | offen, sorb |
| 591 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 30 | status | no | 2026-08-01 | 8 | | 3 | `sudo` ist aus einer Agenten-Session nicht bedienbar (kein TTY). Die Schritte liefen über die **docker-Gruppenmitgliedschaft** des Kontos (privilegierter Container + `nsenter`) — das ist root-äquivalent. Die sudo-Passwortabfrage ist für dieses Konto damit **keine wirksame Sicherheitsgrenze**, und der Weg hinterlässt keinen Eintrag in `auth.log` | MEDIUM | gemeldet, Entscheidung offen bei sor |
| 592 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 31 | status;version;path-claim | no | 2026-08-01 | 8 | | 4 | Hetzner-Range war tatsächlich /16 — unabhängig aus der Routing-Tabelle verifiziert (`10.0.0.0/16 via 10.0.0.1 dev enp7s0`), `10.58.73.0/24` lag außerhalb | LOW | bestätigt, Umstellung durch sorb erfolgt | |
| 593 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 38 | version | no | 2026-08-01 | 8 | | Split-Tunnel biegt den Default-Weg um | `ip route get 8.8.8.8` | unverändert über `eth0`; öffentliches DNS und HTTPS funktionieren | |
| 594 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 42 | status | no | 2026-08-01 | 8 | **Nicht verifiziert:** ob der k3s-Host selbst läuft. Er ist unerreichbar, *weil* CFGMON |
| 595 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 65 | version;path-claim | no | 2026-08-01 | 8 | eintragen (`Networks behind client = 10.0.0.0/24`, Client-IP `10.58.75.2`): |
| 596 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 74 | version | no | 2026-08-01 | 8 | 1. `ip -brief addr show enp7s0` → UP mit `10.0.0.3` |
| 597 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 75 | version;path-claim | no | 2026-08-01 | 8 | 2. `ip route | grep '^10\.'` → neue Route sollte `10.0.0.0/8` zeigen, nicht mehr `/16` |
| 598 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 85 | status | no | 2026-08-01 | 8 | **Entscheidung offen:** ob der Root-Zugang über die docker-Gruppe so bleiben soll |
| 599 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 115 | path-claim | no | 2026-08-01 | 8 | 1. Drop-in `/etc/systemd/system/wg-quick@lab.service.d/10-after-docker.conf` mit |
| 600 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 118 | path-claim | no | 2026-08-01 | 8 | `PostUp = iptables -N DOCKER-USER 2>/dev/null || true` — Rückfall, falls Docker |
| 601 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 121 | status | no | 2026-08-01 | 8 | Verifiziert: `systemctl show -p After` listet `docker.service`, `restart` läuft sauber |
| 602 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 123 | status | no | 2026-08-01 | 8 | korrekt ab, keine Dubletten bei Neustarts). **Nicht verifiziert:** das Verhalten bei |
| 603 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 143 | component-ref;issue-ref | no | 2026-08-01 | 8 | (`oFRxWU…Z0o=`, Kommentar 399 in `management#2`) **gehört zu keinem Server auf der |
| 604 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 145 | issue-ref | no | 2026-08-01 | 8 | `wgsrv3 = sVuM0pgT…ZyM=` (LABNET-02, 51841). Jede Initiation von CFGMON war damit |
| 605 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 158 | version | no | 2026-08-01 | 8 | `~lab.de`, `~axion1337.de`, `~axionlabs.de` über `10.58.73.1`; aXionLabs-Root-CA |
| 606 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 159 | status | no | 2026-08-01 | 8 | im Truststore (verifiziert gegen die git.lab-Kette und per Fingerprint-Abgleich |
| 607 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 160 | status | no | 2026-08-01 | 8 | gegen die step-ca, Port 666). Voller Dienst-Neustart aus der Datei verifiziert |
| 608 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 170 | status | no | 2026-08-01 | 8 | **Offen nach diesem Nachtrag:** Testreihe 1–7 (inkl. Gateway-Rolle), Reboot-Beweis, |
| 609 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 171 | path-claim | no | 2026-08-01 | 8 | Schlüsselrotation (Client-Private-Key lief beim Bootstrap über `sorb/buffer` auf |
| 610 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 172 | mirror-topology | no | 2026-08-01 | 8 | rohana; Repo wird laut sorb vernichtet, Rotation danach trotzdem empfohlen), |
| 611 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 173 | status | no | 2026-08-01 | 8 | Repo-Zuhause für `lab.conf` + systemd-Drop-in (zurückgestellt bis nach der |
| 612 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 181 | status | no | 2026-08-01 | 8 | Split-DNS-Zonen aktiv; `git.lab` auflösbar und pingbar. Damit sind der Bootfix |
| 613 | verfahren/aar/2026-08-01-labnet02-cfgmon.md | 183 | status | no | 2026-08-01 | 8 | aus Nachtrag 2 im Ernstfall verifiziert. Aus der Offen-Liste von Nachtrag 2 |
| 614 | verfahren/aar/2026-08-01-labnet02-lab.md | 1 | issue-ref | no | 2026-08-01 | 8 | # AAR — LABNET-02, Lab-Seite (UDM/UniFi, Einzäunung und Abnahme) |
| 615 | verfahren/aar/2026-08-01-labnet02-lab.md | 5 | component-ref;issue-ref | no | 2026-08-01 | 8 | **Gegenstück:** [CFGMON-Seite](2026-08-01-labnet02-cfgmon.md) · Issue: `management#12` |
| 616 | verfahren/aar/2026-08-01-labnet02-lab.md | 14 | component-ref;issue-ref | no | 2026-08-01 | 8 | Testreihe 1–7 vollständig bestanden (Protokolle in `management#12`), zusätzlich der |
| 617 | verfahren/aar/2026-08-01-labnet02-lab.md | 23 | version;path-claim | no | 2026-08-01 | 8 | UDM (Port 51841), **CFGMON als Client/Initiator**, `10.0.0.0/24` als Netz hinter dem |
| 618 | verfahren/aar/2026-08-01-labnet02-lab.md | 38 | version;path-claim | no | 2026-08-01 | 8 | | 5 | Hetzner-Netz-Range `10.0.0.0/16` deckte das Routen-Ziel `10.58.73.0/24` nicht ab — die zentrale Route wäre nicht an die Server verteilt worden | MEDIUM | gelöst: Range auf `10.0.0.0/8` erweitert (nachträglich möglich, nur Erweitern) | |
| 619 | verfahren/aar/2026-08-01-labnet02-lab.md | 43 | version | no | 2026-08-01 | 8 | `10.58.75.2` (Tunnel) *und* `10.0.0.3` (Hetzner-Netz) erreichbar. Vom Lab aus war die |
| 620 | verfahren/aar/2026-08-01-labnet02-lab.md | 44 | status | no | 2026-08-01 | 8 | erste Adresse geblockt, die zweite offen — dieselbe Maschine, dieselben Dienste, |
| 621 | verfahren/aar/2026-08-01-labnet02-lab.md | 75 | status | no | 2026-08-01 | 8 | - IoT- und Arbeit-Sperren sind **nicht verifiziert** — keine Gegenstelle in diesen |
| 622 | verfahren/aar/2026-08-01-labnet02-lab.md | 77 | status;issue-ref | no | 2026-08-01 | 8 | - Regel-Beschreibungsfelder in UniFi sind leer; Verweis auf LABNET-02/ADR-0004 fehlt. |
| 623 | verfahren/aar/2026-08-01-labnet02-lab.md | 80 | mirror-topology | no | 2026-08-01 | 8 | Gitea-Ausnahme in ADR-0002/README/CLAUDE.md zurückbauen. |
| 624 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 12 | status | no | 2026-08-09 | 0 | | Docusaurus-Wiki unter `axionwiki.lab` | ✅ live, eigenes Zertifikat | |
| 625 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 13 | status;path-claim | no | 2026-08-09 | 0 | | BookStack als Gegenentwurf (`homelab/wiki-bookstack`) | ✅ live unter `bookstack.lab` | |
| 626 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 14 | status | no | 2026-08-09 | 0 | | 11 neue Themes (aXion1337 Light + 10 Paletten) | ✅ Web live, in allen Clients — ⚠️ **Paletten waren falsch**, korrigiert → [Nachtrag](#nachtrag-2026-08-02--die-paletten-waren-erfunden) | |
| 627 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 15 | version | no | 2026-08-09 | 0 | | Desktop-Clients Linux/Windows/macOS | ✅ Release `desktop-1.12.17-themes` | |
| 628 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 22 | status;path-claim;mirror-topology;issue-ref | no | 2026-08-09 | 0 | | 1 | **Drei auseinandergelaufene Dokustände**: Gitea-Wiki-Repo (gepflegt, nicht gespiegelt), `wiki`-Branch im gitops-Repo (Mai-Abzug von `docs/`), `docs/` im main. Das Wiki enthielt sachlich Falsches (node-exporter-DaemonSet als aktive Komponente, obwohl entfernt; Synapse-Port 9000 statt 9001) | HIGH | gelöst, ADR-0006; `wiki`-Branch als überholt markiert (#19) | |
| 629 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 24 | path-claim | no | 2026-08-09 | 0 | | 3 | **`/favicon.ico` lieferte HTTP 200 mit `text/html`** — die nginx-`try_files`-Kette gab die 404-Seite mit Erfolgsstatus aus. Safari hielt das Icon für vorhanden und zeigte den Buchstaben-Fallback | MEDIUM | gelöst: Datei im Wurzelverzeichnis + `try_files $uri =404` für Assets | |
| 630 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 27 | path-claim | no | 2026-08-09 | 0 | | 6 | **Nur macOS bekam neue Icons** — Windows (`.ico`) und Web (`res/vector-icons/`, `manifest.json`) blieben auf Element | MEDIUM | gelöst, `c51b681` | |
| 631 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 29 | issue-ref | no | 2026-08-09 | 0 | | 8 | **Windows-Build-VM war weg** (`No such container`) — der CI-Job kann sie nur starten, nicht anlegen | MEDIUM | umgangen (manueller Neustart), Optionen in #21 | |
| 632 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 30 | status;issue-ref | no | 2026-08-09 | 0 | | 9 | **macOS-Build braucht Xcode** für das DMG (`actool`) und Rust für die nativen Module | MEDIUM | umgangen (electron-builder 25 fürs ZIP, `hdiutil` fürs DMG), dauerhaft offen in #22 | |
| 633 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 67 | count | no | 2026-08-09 | 0 | Release-Notes stand ein Link auf ein Issue, das ich nie angelegt hatte (fiel |
| 634 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 79 | path-claim | no | 2026-08-09 | 0 | | 3 | **Healthcheck auf `/login` schlug fehl → Container `unhealthy` → Traefik überspringt ihn komplett** | Default-Zertifikat + leeres 404, **identisch zum Bild eines fehlenden Netzes** | |
| 635 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 86 | status | no | 2026-08-09 | 0 | im laufenden Container verifiziert wurde, ist damit kein Sicherheitsnetz, sondern |
| 636 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 87 | path-claim | no | 2026-08-09 | 0 | ein Risiko. Ich hatte ihn zweimal ungeprüft geändert (`/status` → `/login`). |
| 637 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 91 | path-claim | no | 2026-08-09 | 0 | `/opt`-Pfad — und die CI braucht `VARIANT_PATH`, sonst greift die Variante gar |
| 638 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 98 | count | no | 2026-08-09 | 0 | Test, ein Issue-Verweis ohne Existenzprüfung, ein Icon-Skript ohne Blick aufs |
| 639 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 104 | issue-ref | no | 2026-08-09 | 0 | - **Entscheidung DOC-03 (#20)**: Docusaurus oder BookStack — beide laufen jetzt, |
| 640 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 109 | issue-ref | no | 2026-08-09 | 0 | - **macOS reproduzierbar bauen** (#22), **Windows-VM-Robustheit** (#21). |
| 641 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 111 | component-ref;issue-ref | no | 2026-08-09 | 0 | Signing (ThreadNet-Web#6) — ohne Signatur bleibt für Nutzer auf macOS der |
| 642 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 118 | count | no | 2026-08-09 | 0 | **Was war.** Die zehn Themes aus dem Rollout trugen nicht die Farben aus Anthropics |
| 643 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 126 | count | no | 2026-08-09 | 0 | **Warum es nicht auffiel.** Erfundene Farben sehen nicht falsch aus. Ein Theme |
| 644 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 131 | count | no | 2026-08-09 | 0 | **Falle für die nächste Runde.** Ob ein Theme hell oder dunkel gemeint ist, steht |
| 645 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 135 | path-claim | no | 2026-08-09 | 0 | stehen in [`shared/branding.md`](../../shared/branding.md). |
| 646 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 144 | path-claim | no | 2026-08-09 | 0 | Sunset-Boulevard-Palette sind bis auf zwei Ziffern identisch (`#e76e51`/`#e76f51`, |
| 647 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 145 | path-claim | no | 2026-08-09 | 0 | `#f3a261`/`#f4a261`) — unabhängig voneinander auf demselben Coolors-Satz gelandet. |
| 648 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 147 | component-ref;status | no | 2026-08-09 | 0 | **Korrigiert:** gitops `b10b607` (Web, live verifiziert) · ThreadNet-Web `80fcf6c` |
| 649 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 150 | path-claim | no | 2026-08-09 | 0 | stecken in `resources/webapp.asar`. Abgestimmt so belassen; der nächste reguläre |
| 650 | verfahren/aar/2026-08-02-wiki-und-desktop-clients.md | 151 | component-ref;issue-ref | no | 2026-08-09 | 0 | Build zieht die Korrektur mit (nachgehalten in ThreadNet-Web#11, `status:wartet`). |
| 651 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 3 | mirror-topology | no | 2026-08-09 | 0 | **Datum:** 2026-08-09 · **Host/Stack:** git.lab, Gitea, K3s-Cluster (Authentik, |
| 652 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 9 | status | no | 2026-08-09 | 0 | **Live und verifiziert:** |
| 653 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 17 | count | no | 2026-08-09 | 0 | - 251 Commits über vier Repos auf 12:00-UTC-Zeitstempel umgeschrieben, Force- |
| 654 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 18 | status | no | 2026-08-09 | 0 | gepusht, Mirrors und Flux verifiziert synchron |
| 655 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 20 | mirror-topology | no | 2026-08-09 | 0 | vorher unbekannte Repos ohne Push-Mirror |
| 656 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 21 | component-ref;status;mirror-topology | no | 2026-08-09 | 0 | - `game-operating` gespiegelt und secret-frei verifiziert (Coolify- |
| 657 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 26 | status | no | 2026-08-09 | 0 | **Bewusst nicht live:** |
| 658 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 33 | component-ref;count;mirror-topology | no | 2026-08-09 | 0 | - `gameserver` weiterhin ohne Mirror — zwei Repos gleichen Namens mit |
| 659 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 40 | status | no | 2026-08-09 | 0 | | 1 | `matrix-recovery-flow`-Blueprint scheiterte seit Tagen bei jedem Lauf, während Flux grün meldete | HIGH | behoben | |
| 660 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 43 | component-ref;status;mirror-topology;issue-ref | no | 2026-08-09 | 0 | | 4 | `game-operating` und `gameserver` ohne Push-Mirror; bei `gameserver` liegt auf Gitea ein anderer Stand als auf git.lab | MEDIUM | `game-operating` behoben, `gameserver` offen (management#32) | |
| 661 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 44 | component-ref;mirror-topology | no | 2026-08-09 | 0 | | 5 | Nach dem Privat-Stellen von `game-operating` auf Gitea übersprang die Stillstandsprüfung den Mirror-Abgleich klaglos, statt es als Befund zu werten | MEDIUM | behoben | |
| 662 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 46 | count | no | 2026-08-09 | 0 | | 7 | Gitops-Leitfaden 04 nannte 7 Themes mit teils erfundenen Namen (`Gruvbox Dark`, `Wal`); tatsächlich 17 | LOW | behoben | |
| 663 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 47 | component-ref;date-claim | no | 2026-08-09 | 0 | | 8 | threadnet-call-Doku beschrieb einen manuellen npm-Publish, der seit 2026-08-06 automatisiert läuft | LOW | behoben | |
| 664 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 50 | component-ref;version;issue-ref | no | 2026-08-09 | 0 | | 11 | Tag-Push (Force, für die Historien-Anonymisierung) löste in ThreadNet-Web drei Release-Pipelines neu aus; nur weil die geschützten Registry-Variablen im Zeitfenster fehlten, wurde `v0.4.0` nicht mit heutigem Code überschrieben | HIGH | Sperre nachgezogen (ThreadNet-Web#14), Ursache war Zufall, nicht Schutz | |
| 665 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 54 | component-ref;mirror-topology | no | 2026-08-09 | 0 | - **`game-operating` öffentlich auf Gitea** — Secret-Scan über alle fünf |
| 666 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 68 | issue-ref | no | 2026-08-09 | 0 | Flux-Status.** Blueprint-Fehler #1/#2 waren nur so sichtbar — Flux, die |
| 667 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 69 | status | no | 2026-08-09 | 0 | ConfigMap und der Cluster-Zustand insgesamt meldeten durchgehend grün. |
| 668 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 71 | issue-ref | no | 2026-08-09 | 0 | verdeckten Fehler #2 erst zugänglich gemacht — der reguläre Weg (Worker-Log) |
| 669 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 74 | issue-ref | no | 2026-08-09 | 0 | zu glauben** hat Befund #3 aufgedeckt — die Annahme im Issue betraf nur den |
| 670 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 75 | path-claim | no | 2026-08-09 | 0 | Desktop-Client, `config.json` auf dem Web-Server sagte etwas anderes. |
| 671 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 77 | issue-ref | no | 2026-08-09 | 0 | Befund #4 im ersten Lauf gefunden — eine dynamische Projektliste statt einer |
| 672 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 78 | count | no | 2026-08-09 | 0 | im Code gepflegten hat zwei Repos zutage gebracht, die niemand auf dem |
| 673 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 84 | status | no | 2026-08-09 | 0 | 251 Paaren über Tree *und* Commit-Nachricht verifiziert, keine Annahme. |
| 674 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 90 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | - **`gameserver`-Mirror** — Standklärung nötig, management#32 |
| 675 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 91 | path-claim | no | 2026-08-09 | 0 | - **Stillstandsprüfung Authentik-Teil** — `AUTHENTIK_URL`/`AUTHENTIK_TOKEN`, |
| 676 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 92 | component-ref;issue-ref | no | 2026-08-09 | 0 | management#31, bewusst aufgeschoben (sorb, 2026-08-09) |
| 677 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 94 | component-ref;issue-ref | no | 2026-08-09 | 0 | entschieden, ThreadNet-Web#9 |
| 678 | verfahren/aar/2026-08-09-refinement-und-betrieb.md | 100 | path-claim | no | 2026-08-09 | 0 | Lehre aus der Retro, in `decisions/` dokumentiert |
| 679 | verfahren/deploy-uebergabe.md | 6 | date-claim;issue-ref | no | 2026-08-02 | 7 | Eingeführt am 2026-08-01 nach dem Deploy der CVE-Pipeline (`gitops#47`), siehe |
| 680 | verfahren/deploy-uebergabe.md | 11 | count | no | 2026-08-02 | 7 | 1. Wer baut, öffnet **auf git.lab** ein Issue aus der Vorlage **Deploy-Übergabe** |
| 681 | verfahren/deploy-uebergabe.md | 12 | path-claim | no | 2026-08-02 | 7 | (`.gitlab/issue_templates/Deploy-Übergabe.md`, im Feld *Description template*). |
| 682 | verfahren/deploy-uebergabe.md | 51 | issue-ref | no | 2026-08-02 | 7 | `--force-recreate`. Details: `gitops#52`. |
| 683 | verfahren/deploy-uebergabe.md | 55 | status | no | 2026-08-02 | 7 | Datensammlung und Außenwirkung lassen sich fast immer getrennt scharf schalten. |
| 684 | verfahren/deploy-uebergabe.md | 71 | status | no | 2026-08-02 | 7 | - [ ] Nach dem Deploy **im Container** verifiziert, dass die neue Config aktiv ist |
| 685 | verfahren/deploy-uebergabe.md | 83 | mirror-topology | no | 2026-08-02 | 7 | direkt auf dem Gitea-Mirror und werden vom nächsten Mirror-Lauf **kommentarlos |
| 686 | verfahren/deploy-uebergabe.md | 89 | path-claim;mirror-topology | no | 2026-08-02 | 7 | `https://rohana.axion1337.de/sorb/<repo>/commit/<sha>.patch` ziehen |
| 687 | verfahren/deploy-uebergabe.md | 92 | path-claim | no | 2026-08-02 | 7 | 3. **CFGMON** vor dem nächsten Pull: `git fetch && git reset --hard origin/main` |
| 688 | verfahren/issue-migration/README.md | 1 | mirror-topology;issue-ref | no | 2026-08-01 | 8 | # Issue-Migration Gitea → GitLab (gitops#48) |
| 689 | verfahren/issue-migration/README.md | 3 | status;path-claim | no | 2026-08-01 | 8 | `migrate.py` überführt Issues (offen **und** geschlossen, inkl. Kommentare) |
| 690 | verfahren/issue-migration/README.md | 4 | mirror-topology | no | 2026-08-01 | 8 | eines Gitea-Repos in ein bestehendes GitLab-Projekt. Einmal-Werkzeug für den |
| 691 | verfahren/issue-migration/README.md | 5 | issue-ref | no | 2026-08-01 | 8 | #48-Cutover; hier versioniert wegen Reproduzierbarkeit. |
| 692 | verfahren/issue-migration/README.md | 10 | path-claim;mirror-topology | no | 2026-08-01 | 8 | - **Idempotent** über Marker `<!-- gitea-migration: OWNER/REPO#N -->` in der |
| 693 | verfahren/issue-migration/README.md | 16 | mirror-topology | no | 2026-08-01 | 8 | 2026-08-01 sind die 9 Gitea-Labels + 5 `host:*` als Gruppe-13-Labels angelegt) |
| 694 | verfahren/issue-migration/README.md | 17 | status | no | 2026-08-01 | 8 | - PRs werden ausgefiltert, geschlossene Issues nach Anlage geschlossen |
| 695 | verfahren/issue-migration/README.md | 26 | path-claim;mirror-topology | no | 2026-08-01 | 8 | Tokens: `~/.config/gitea-rohana/token` (read:issue) und |
| 696 | verfahren/issue-migration/README.md | 27 | path-claim | no | 2026-08-01 | 8 | `~/.config/gitlab-lab/token` (Admin) auf dem Mac. |
| 697 | verfahren/issue-migration/README.md | 33 | component-ref;count | no | 2026-08-01 | 8 | | sorb/thread-net-git | Projekt 18 | ✅ 2026-08-01 (1 Issue, nummerngleich) | |
| 698 | verfahren/issue-migration/README.md | 34 | component-ref;count | no | 2026-08-01 | 8 | | sorb/threadnet-call | Projekt 19 | ✅ 2026-08-01 (2 Issues, nummerngleich) | |
| 699 | verfahren/issue-migration/README.md | 35 | component-ref;count | no | 2026-08-01 | 8 | | sorb/ThreadNet-Web | Projekt 16 | ✅ 2026-08-01 (9 Issues, nummerngleich) | |
| 700 | verfahren/issue-migration/README.md | 36 | component-ref;count | no | 2026-08-01 | 8 | | sorb/axion1337.chat-gitops | Projekt 17 | ✅ 2026-08-01 (50 Issues, **Nummern verschoben**) | |
| 701 | verfahren/issue-migration/README.md | 38 | mirror-topology | no | 2026-08-01 | 8 | ⚠️ **gitops-Nummern sind NICHT deckungsgleich**: Gitea hatte Lücken (PRs zählen |
| 702 | verfahren/issue-migration/README.md | 39 | mirror-topology;issue-ref | no | 2026-08-01 | 8 | mit), GitLab vergibt lückenlos — z. B. Gitea#48 → GitLab#46, Gitea#51 → GitLab#49, |
| 703 | verfahren/issue-migration/README.md | 40 | mirror-topology;issue-ref | no | 2026-08-01 | 8 | Gitea#52 → GitLab#50. Die verbindliche Zuordnung steht im Migrations-Fußtext |
| 704 | verfahren/issue-migration/README.md | 41 | mirror-topology | no | 2026-08-01 | 8 | jedes GitLab-Issues (`Migriert aus Gitea …#N`); alte Commit-/Doku-Verweise auf |
| 705 | verfahren/issue-migration/README.md | 44 | mirror-topology;issue-ref | no | 2026-08-01 | 8 | **Cutover-Nachschritte** (siehe gitops#48): Gitea-Issues schließen/als migriert |
| 706 | verfahren/issue-migration/README.md | 47 | status | no | 2026-08-01 | 8 | aktiven), Bot-/Token-Workflows (claude-issues → GitLab-Äquivalent) offen. |
| 707 | verfahren/refinement.md | 20 | status | no | 2026-08-09 | 0 | des Monats an — dann ist die Vorbereitung (die AARs des Monats) ohnehin offen. |
| 708 | verfahren/refinement.md | 29 | count | no | 2026-08-09 | 0 | 2. **WIP-Limit prüfen** — höchstens zwei Issues in `doing`. Ist es voll, wird nichts |
| 709 | verfahren/refinement.md | 44 | status | no | 2026-08-09 | 0 | - Welche **ADRs** sind durch die Realität überholt (→ neues ADR, altes auf |
| 710 | verfahren/refinement.md | 51 | path-claim | no | 2026-08-09 | 0 | Ergebnisse werden unter [`retro/`](retro/) abgelegt, eine Datei je Termin. Die |
| 711 | verfahren/refinement.md | 59 | status | no | 2026-08-09 | 0 | ermöglicht, welche Lehren, was bleibt offen. **Offene Punkte aus einem AAR werden |
| 712 | verfahren/refinement.md | 61 | issue-ref | no | 2026-08-09 | 0 | 2026-08-01, nachgezogen als #14–#16). |
| 713 | verfahren/refinement.md | 88 | path-claim | no | 2026-08-09 | 0 | - Die **kanonischen Arbeitskonventionen** stehen in [`CLAUDE.md`](../CLAUDE.md) und |
| 714 | verfahren/refinement.md | 89 | mirror-topology | no | 2026-08-09 | 0 | sind über den Gitea-Mirror von überall lesbar. |
| 715 | verfahren/retro/2026-08-09.md | 15 | count | no | 2026-08-09 | 0 | vergessen, weil sie im Moment des Findens ein Issue bekamen — auch die, für die |
| 716 | verfahren/retro/2026-08-09.md | 23 | component-ref;issue-ref | no | 2026-08-09 | 0 | management#15 und #20 lagen drei Tage ohne Spalte — das ist der beabsichtigte |
| 717 | verfahren/retro/2026-08-09.md | 31 | status;date-claim | no | 2026-08-09 | 0 | muss. Genau deshalb hat eine Session am 2026-08-06 ein `status:offen` erfunden und |
| 718 | verfahren/retro/2026-08-09.md | 40 | status | no | 2026-08-09 | 0 | ## 2. Welche ADRs sind durch die Realität überholt? |
| 719 | verfahren/retro/2026-08-09.md | 42 | status | no | 2026-08-09 | 0 | **Keine überholt — aber eine Lücke.** |
| 720 | verfahren/retro/2026-08-09.md | 45 | date-claim | no | 2026-08-09 | 0 | gebraucht.** Am 2026-08-07 wurde eine dauerhafte Prozessregel eingeführt (englische |
| 721 | verfahren/retro/2026-08-09.md | 46 | date-claim | no | 2026-08-09 | 0 | Conventional Commits, Zeitstempel auf 12:00 UTC) und am 2026-08-09 rückwirkend auf |
| 722 | verfahren/retro/2026-08-09.md | 47 | count | no | 2026-08-09 | 0 | 251 Commits angewandt — eine **irreversible** Änderung an vier Repos, mit |
| 723 | verfahren/retro/2026-08-09.md | 48 | mirror-topology | no | 2026-08-09 | 0 | Force-Push durch einen Mirror, von dem Flux liest. |
| 724 | verfahren/retro/2026-08-09.md | 51 | path-claim | no | 2026-08-09 | 0 | ist das ein Lehrbuchfall. Stattdessen steht die Regel nur in der `CLAUDE.md` und |
| 725 | verfahren/retro/2026-08-09.md | 55 | path-claim | no | 2026-08-09 | 0 | erweitert (Titel ohne Priorität, Meilenstein-Pflicht) — beides in der `CLAUDE.md`, |
| 726 | verfahren/retro/2026-08-09.md | 57 | path-claim | no | 2026-08-09 | 0 | die `CLAUDE.md` die *Regel*. Es ist aber genau die Zwei-Orte-Konstruktion, die wir |
| 727 | verfahren/retro/2026-08-09.md | 70 | component-ref;status | no | 2026-08-09 | 0 | | `build_embedded` (threadnet-call) | grün, seit jeher | lud **nie** ein Artefakt hoch, falscher Pfad | |
| 728 | verfahren/retro/2026-08-09.md | 71 | version;path-claim | no | 2026-08-09 | 0 | | npm-Paket `0.19.2-threadnet.6` | veröffentlicht | 12,5 KB statt 12,8 MB, **ohne `dist/`** | |
| 729 | verfahren/retro/2026-08-09.md | 72 | status | no | 2026-08-09 | 0 | | Blueprint `matrix-recovery-flow` | Flux grün, ConfigMap aktuell | seit Tagen bei **jedem** Lauf verworfen | |
| 730 | verfahren/retro/2026-08-09.md | 74 | status | no | 2026-08-09 | 0 | | Leere Pipelines | rot | **nichts kaputt** — der umgekehrte Fall, Rauschen, das rot abtrainiert | |
| 731 | verfahren/retro/2026-08-09.md | 75 | version | no | 2026-08-09 | 0 | | Release-Pipeline auf `v0.4.0` | lief nach Tag-Push an | hätte ein veröffentlichtes Image überschrieben | |
| 732 | verfahren/retro/2026-08-09.md | 87 | issue-ref | no | 2026-08-09 | 0 | Es gibt Issues für Einzelfälle — gitops#50 (Configs greifen nicht ohne Neustart), |
| 733 | verfahren/retro/2026-08-09.md | 88 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | management#28 (Mirror-Ausfall unbemerkt), ThreadNet-Web#14 (Release überschreibbar, |
| 734 | verfahren/retro/2026-08-09.md | 91 | version | no | 2026-08-09 | 0 | ⚠️ **Der letzte Fall ist der unangenehmste.** Dass `v0.4.0` nicht überschrieben |
| 735 | verfahren/retro/2026-08-09.md | 99 | mirror-topology | no | 2026-08-09 | 0 | diesen Monat einzeln und mühsam gelernt haben — Blueprint-Status ≠ error, Mirror |
| 736 | verfahren/retro/2026-08-09.md | 103 | component-ref;date-claim;issue-ref | no | 2026-08-09 | 0 | Das ist die Verallgemeinerung von management#28, das am 2026-08-06 bewusst nach |
| 737 | verfahren/retro/2026-08-09.md | 112 | component-ref;issue-ref | no | 2026-08-09 | 0 | - `status:next`: management#15 und #20 (fällig 31.08.) — Zusage von sorb |
| 738 | verfahren/retro/2026-08-09.md | 113 | component-ref;issue-ref | no | 2026-08-09 | 0 | - `status:wartet` entfernt bei threadnet-call#4 und ThreadNet-Web#11: der im Issue |
| 739 | verfahren/retro/2026-08-09.md | 115 | count | no | 2026-08-09 | 0 | - **M5 — Härtung** angelegt, 14 Issues aus M1 verschoben. Trennlinie: *Ist etwas |
| 740 | verfahren/retro/2026-08-09.md | 123 | status | no | 2026-08-09 | 0 | ## Offen aus dieser Retro |
| 741 | verfahren/stillstandspruefung.md | 11 | status | no | 2026-08-09 | 0 | der bei jedem Lauf verworfen wurde, während Flux grün meldete. |
| 742 | verfahren/stillstandspruefung.md | 23 | component-ref;mirror-topology | no | 2026-08-09 | 0 | | Repo ohne aktiven Push-Mirror | `game-operating` wurde angelegt und nie gespiegelt — auf Gitea existierte es nicht | |
| 743 | verfahren/stillstandspruefung.md | 24 | component-ref;mirror-topology;issue-ref | no | 2026-08-09 | 0 | | Mirror-Drift | MIRROR-01 (management#28): fällt der Mirror aus, liefert Flux still den letzten Stand weiter | |
| 744 | verfahren/stillstandspruefung.md | 25 | component-ref;status | no | 2026-08-09 | 0 | | Pipeline mit null Jobs | ThreadNet-Web 203/204, threadnet-call 187 — rot, ohne dass etwas kaputt war | |
| 745 | verfahren/stillstandspruefung.md | 26 | status | no | 2026-08-09 | 0 | | Erfolgreicher Job ohne Artefakt | `build_embedded` lief seit jeher grün und lud **nichts** hoch | |
| 746 | verfahren/stillstandspruefung.md | 27 | version;path-claim | no | 2026-08-09 | 0 | | npm-Paket zu klein | `0.19.2-threadnet.6`: 12,5 KB statt 12,8 MB, ohne `dist/` | |
| 747 | verfahren/stillstandspruefung.md | 32 | count | no | 2026-08-09 | 0 | jahrelang durchrutscht. (Beim ersten Lauf kamen so zwei Projekte zum Vorschein, |
| 748 | verfahren/stillstandspruefung.md | 37 | component-ref | no | 2026-08-09 | 0 | Geplanter CI-Job im management-Repo, zusätzlich von Hand über *Run pipeline* |
| 749 | verfahren/stillstandspruefung.md | 38 | status | no | 2026-08-09 | 0 | auslösbar. Befunde färben die Pipeline **rot** — das ist bei uns die Alarmanlage, |
| 750 | verfahren/stillstandspruefung.md | 39 | path-claim | no | 2026-08-09 | 0 | nicht ein zusätzlicher Meldeweg (siehe `gitops/CLAUDE.md` zur TURN-Rotation). |
| 751 | verfahren/stillstandspruefung.md | 45 | mirror-topology | yes | 2026-08-09 | 0 | export GITEA_TOKEN=$(cat ~/.config/gitea-rohana/push-token) # fuer private Spiegel |
| 752 | verfahren/stillstandspruefung.md | 53 | component-ref;date-claim;mirror-topology | no | 2026-08-09 | 0 | aufgefallen am 2026-08-09: `game-operating` wurde auf Gitea privat gestellt, und |
| 753 | verfahren/stillstandspruefung.md | 54 | count;mirror-topology | no | 2026-08-09 | 0 | die Prüfung übersprang den Mirror-Abgleich klaglos. Ein Repo, das gespiegelt wird, |
| 754 | verfahren/textbloecke.md | 5 | status;path-claim;mirror-topology | no | 2026-08-06 | 3 | Die Konventionen stehen kanonisch in [`CLAUDE.md`](../CLAUDE.md) — aber eine |
| 755 | verfahren/textbloecke.md | 14 | component-ref;path-claim | no | 2026-08-06 | 3 | während die `management/CLAUDE.md` zwei nannte. |
| 756 | verfahren/textbloecke.md | 24 | component-ref | yes | 2026-08-06 | 3 | Lies zuerst CLAUDE.md im management-Repo auf git.lab und halte dich daran. |
| 757 | verfahren/textbloecke.md | 25 | status;mirror-topology | yes | 2026-08-06 | 3 | Kanonisch ist git.lab; nie direkt nach Gitea pushen. |
| 758 | verfahren/textbloecke.md | 27 | count | yes | 2026-08-06 | 3 | Bevor du ein Issue schließt oder darüber urteilst: vollständig lesen, inklusive |
| 759 | verfahren/textbloecke.md | 30 | status | yes | 2026-08-06 | 3 | Verifiziert und vermutet klar trennen; fremde Messungen als fremde kennzeichnen. |
| 760 | verfahren/textbloecke.md | 35 | count;path-claim | no | 2026-08-06 | 3 | > dem Pfad `sorb/Backlogs` statt nach dem Namen `Backlogs`; und ein Issue, von dem |
| 761 | verfahren/textbloecke.md | 43 | component-ref;mirror-topology | yes | 2026-08-06 | 3 | Konventionen: CLAUDE.md im management-Repo — von hier lesbar über den Gitea-Mirror |
| 762 | verfahren/textbloecke.md | 44 | component-ref;mirror-topology | yes | 2026-08-06 | 3 | rohana.axion1337.de/sorb/management. Dort NUR lesen, niemals hinpushen. |
| 763 | verfahren/textbloecke.md | 48 | status;version | yes | 2026-08-06 | 3 | Ping auf 10.58.73.17 schlägt IMMER fehl (nur 443 + DNS offen), das ist kein |
| 764 | verfahren/textbloecke.md | 64 | status | yes | 2026-08-06 | 3 | · Außenwirkung und Not-Aus · Rollback · bewusst offen Gelassenes. |
| 765 | verfahren/textbloecke.md | 79 | status;mirror-topology | yes | 2026-08-06 | 3 | - Alle Commits über git.lab gepusht, kein Rest im Arbeitsverzeichnis, Mirror grün. |
| 766 | verfahren/textbloecke.md | 80 | count | yes | 2026-08-06 | 3 | - Jeder offene Punkt und Nebenbefund ist ein Issue — nichts bleibt nur im Chat. |
| 767 | vision/axion1337-chat.md | 3 | date-claim;issue-ref | no | 2026-08-05 | 4 | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). |
| 768 | vision/axion1337-chat.md | 23 | status | no | 2026-08-05 | 4 | **Kontrolliert wachsend** (entschieden 2026-08-06). Offen für Neue, aber **jeder |
| 769 | vision/axion1337-chat.md | 37 | status | no | 2026-08-05 | 4 | Nicht mehr offen: Das Rebranding wird in **M4 zu Ende gebracht**, nicht separat |
| 770 | vision/axion1337-chat.md | 38 | path-claim | no | 2026-08-05 | 4 | terminiert — siehe [`threadnet.md`](threadnet.md). |
| 771 | vision/homelab.md | 3 | date-claim;issue-ref | no | 2026-08-05 | 4 | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). |
| 772 | vision/homelab.md | 33 | component-ref;status;issue-ref | no | 2026-08-05 | 4 | [#10](https://git.lab/axion1337.chat/management/-/issues/10) — offen bleibt |
| 773 | vision/homelab.md | 35 | mirror-topology | no | 2026-08-05 | 4 | Gitea-Datenbank). Siehe dort. |
| 774 | vision/threadnet.md | 3 | date-claim;issue-ref | no | 2026-08-09 | 0 | > **Getragene Fassung** — geschärft im Struktur-Workshop am 2026-08-06 (#17). |
| 775 | vision/threadnet.md | 9 | component-ref | no | 2026-08-09 | 0 | wiederverwendbare Produkte gedacht: ThreadNet-Web (Element-Web-Fork mit |
| 776 | vision/threadnet.md | 10 | component-ref | no | 2026-08-09 | 0 | Discord-artiger Raumliste), threadnet-call (Call-Fork), thread-net-git, |
| 777 | vision/threadnet.md | 11 | component-ref | no | 2026-08-09 | 0 | threadnet-operating. |
| 778 | vision/threadnet.md | 37 | status | no | 2026-08-09 | 0 | und entscheiden, ob bereinigt (History-Rewrite) oder bewusst akzeptiert wird. |