#0043: the case-insensitive username policy is live and verified end to end — present in the ConfigMap, mounted in the worker, applied by authentik on its own, and bound to the prompt stage. It reads only prompt_data, since the stage runs anonymously and that is exactly what the previous system policies died on. #0044 turns out to be largely solved already, which the issue could not know: the ESS chart hangs config and secret hashes on the pod template as labels, so MAS and the other chart components do roll out on change, and coturn has its own annotation bump driven by the rotation job. What remains are three services whose secrets change rarely and deliberately — recommending against adding a controller for that. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
7.0 KiB
7.0 KiB
STATUS
Issues (23 open, 24 closed)
Verteilung: M1 6 · M2 13 · M4 2 · M5 2
| Issue | Status | Meilenstein | Priorität | Title |
|---|---|---|---|---|
| 0002 | waiting | M1 | medium | GAME-01: Host von CFGMON aus nicht erreichbar, 2 Prometheus-Targets down |
| 0004 | waiting | M1 | low | OVERMIND-02: e1000e-NIC-Hang — Beobachtung nach EEE-Fix + Firmware-Update |
| 0008 | waiting | M1 | medium | CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung |
| 0009 | open | M2 | low | CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API |
| 0014 | open | M2 | low | CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur |
| 0015 | waiting | M2 | medium | CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen |
| 0018 | open | M2 | low | DOC-01: Wiki-Rollout abschließen — CI-Freigaben, Zeitplan, Dokploy-Stack, wiki.lab |
| 0019 | open | M2 | low | DOC-02: Veralteten wiki-Branch im gitops-Repo entfernen? |
| 0021 | waiting | M2 | medium | OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen |
| 0022 | open | M4 | low | BUILD-01: macOS-Client reproduzierbar bauen — aktuell nur manuell auf sorbs Mac |
| 0028 | open | M2 | low | MIRROR-01: Ein Ausfall der Push-Mirrors bleibt unbemerkt — Produktion friert still ein |
| 0029 | open | M4 | medium | UI harmonisieren: gleiche Farben und Formen über alle Oberflächen |
| 0030 | in-progress | M1 | medium | Der Restore ist nie geprobt — Sicherungen sind bisher eine Vermutung |
| 0031 | open | M1 | low | Stillstandsprüfung: GITEA_TOKEN und Authentik-Teil nachziehen |
| 0032 | open | M2 | medium | gameserver hat keinen Push-Mirror — und auf Gitea liegt ein anderer Stand |
| 0033 | open | M2 | low | OVERMIND-01 — element-desktop-build von rohana in die Lab-Registry umziehen |
| 0034 | open | M2 | medium | CFGMON-11 — Gitea-CI-Rückbau abschließen (sicher rückbaubare Schritte) |
| 0040 | open | M2 | low | neckbeard-Rückmeldungen aus dem Feldtest einreichen |
| 0042 | open | M2 | high | Migration in Betrieb nehmen: Push, erster Spiegel-Lauf, CI-Schedule |
| 0044 | open | M5 | low | SOPS-Values-Secret-Änderung startet den konsumierenden Dienst nicht neu |
| 0045 | open | M1 | low | Inhalts-Meldung führt ins Leere: kein Kontaktweg für Melder |
| 0051 | open | M5 | high | CVE-Remediation-Pass: Schwachstellen-Report abarbeiten |
| 0053 | open | M2 | low | Historien-Durchgang: acht nicht-kanonische Commits mitziehen |
Active design docs (0)
none active
ADRs (17)
| ADR | Status | Title |
|---|---|---|
| 0001 | accepted | 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert |
| 0002 | accepted | 0002 — Issues und Management-Repo ziehen ins Lab („das Lab ist die Quelle der Wahrheit") |
| 0003 | accepted | 0003 — CVE-Meldeweg: aggregierte Alarme, eigener Security-Raum, gleicher Bot |
| 0004 | accepted | 0004 — Site-to-Site-VPN Hetzner-Projektnetz ↔ Lab, schaltbar über die UDM |
| 0005 | accepted | 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen |
| 0006 | accepted | 0006 — Wikis ins Lab konsolidieren, Docusaurus als gemeinsame Lesefläche |
| 0007 | superseded | 0007 — Wiki-Oberfläche: Docusaurus läuft, BookStack als Gegenentwurf |
| 0008 | accepted | 0008 — Agenten-Sessions auf CFGMON laufen root-äquivalent über die docker-Gruppe |
| 0009 | accepted | 0009 — Commit-Konventionen und rückwirkende Anonymisierung der Historie |
| 0010 | accepted | 0010 — Härtung ist ein eigener Meilenstein (M5); M1 misst nur Kaputtes |
| 0011 | accepted | 0011 — Provisionierung verweigert Localpart-Kollisionen, statt an bestehende Konten zu verknüpfen |
| 0012 | accepted | ADR-0012: Issues leben im Repo; GitLab wird deterministisch bespiegelt |
| 0013 | accepted | ADR-0013: Gruppenregeln kanonisch im management-Repo, Komponenten zeigen und werden geprüft |
| 0014 | accepted | 0014 — Wiki.js löst Docusaurus ab: abgeschottete Betriebs-/Anwenderdoku, docs-as-code |
| 0015 | accepted | 0015 — Wiki.js Git-Storage: Inhalt fließt Cluster→Gitea→kanonisiert nach git.lab |
| 0016 | accepted | 0016 — Das Notfallhandbuch bleibt lab-intern und wird nicht gespiegelt |
| 0017 | accepted | 0017 — Split-DNS auf CFGMON: vier Zonen statt einer, je Zone begründet |