Externalises what this session held that the migrated repo did not: - vision/threadnet.md: the three capabilities that justify the forks beyond rebranding (AV scanning into encrypted rooms, call-quality defaults with a client-side-only privacy line, expiring guest access via @concierge). - issue 0043 (M5): case-insensitive uniqueness in the matrix-invitation prompt stage — the open residual of ADR-0011. - issue 0044 (M5): auto-restart consumers on SOPS values-secret change — the footgun behind the on_conflict fix sitting inactive until a manual restart. - issue 0045 (M1): report_event.admin_message_md unset — content reports dead-end with no contact path (verified still open against live config). - sources/protokolle: the raw apo-call diagnosis history, including the four ruled-out hypotheses and the harmful DB write, as the source behind the AAR. STATUS.md regenerated (M5 appears for the first time). validate, gen_status --check, upstream_drift and pruefe_prosa all green in the CI image.
8.9 KiB
8.9 KiB
STATUS
Issues (39 open, 0 closed)
Verteilung: M1 10 · M2 25 · M4 2 · M5 2
| Issue | Status | Meilenstein | Priorität | Title |
|---|---|---|---|---|
| 0001 | open | M2 | low | MATRIX-03: www.matrix.axion1337.de ist überflüssig |
| 0002 | waiting | M1 | medium | GAME-01: Host von CFGMON aus nicht erreichbar, 2 Prometheus-Targets down |
| 0003 | open | M2 | low | GAME-02: www.game.axion1337.de ist überflüssig |
| 0004 | waiting | M1 | low | OVERMIND-02: e1000e-NIC-Hang — Beobachtung nach EEE-Fix + Firmware-Update |
| 0005 | open | M2 | low | ZONE-01: IONOS-Default-Records bereinigen (www-Paare, tote Mail-Sätze) |
| 0006 | open | M1 | low | ZONE-02: Apex-DMARC ist p=none und schützt nichts |
| 0007 | next | M1 | high | CFGMON-01: Zertifikatserneuerung braucht offene Ports — zeitkritisch ab 2026-09-28 |
| 0008 | waiting | M1 | medium | CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung |
| 0009 | open | M2 | low | CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API |
| 0010 | open | M1 | medium | CFGMON-09: Gitea-Backups off-host (Borg/Storage Box) — Backup-Cron ist DEAKTIVIERT |
| 0014 | waiting | M2 | low | CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur |
| 0015 | next | M2 | medium | CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen |
| 0018 | open | M2 | low | DOC-01: Wiki-Rollout abschließen — CI-Freigaben, Zeitplan, Dokploy-Stack, wiki.lab |
| 0019 | open | M2 | low | DOC-02: Veralteten wiki-Branch im gitops-Repo entfernen? |
| 0020 | next | M2 | medium | DOC-03: Wiki-Oberfläche entscheiden — Docusaurus oder BookStack |
| 0021 | waiting | M2 | medium | OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen |
| 0022 | open | M4 | low | BUILD-01: macOS-Client reproduzierbar bauen — aktuell nur manuell auf sorbs Mac |
| 0023 | open | M2 | low | DOC-04: Navbar-Logo im Docusaurus-Wiki wird ausgeliefert, ist aber nicht sichtbar |
| 0024 | open | M2 | low | Wiki-Hostname klären: wiki.lab oder axionwiki.lab? |
| 0025 | waiting | M1 | medium | Deploy-Übergabe: CVE-Alarme aggregiert + Receiver-Robustheit (gitops#51, ff87cb2) |
| 0027 | waiting | M2 | medium | AUDIT-01: Acht Widersprüche aus dem LABNET-02-Nachlauf (Selbst-Audit CFGMON-Session) |
| 0028 | open | M2 | low | MIRROR-01: Ein Ausfall der Push-Mirrors bleibt unbemerkt — Produktion friert still ein |
| 0029 | open | M4 | medium | UI harmonisieren: gleiche Farben und Formen über alle Oberflächen |
| 0030 | open | M1 | medium | Der Restore ist nie geprobt — Sicherungen sind bisher eine Vermutung |
| 0031 | open | M1 | low | Stillstandsprüfung: GITEA_TOKEN und Authentik-Teil nachziehen |
| 0032 | open | M2 | medium | gameserver hat keinen Push-Mirror — und auf Gitea liegt ein anderer Stand |
| 0033 | open | M2 | low | OVERMIND-01 — element-desktop-build von rohana in die Lab-Registry umziehen |
| 0034 | open | M2 | medium | CFGMON-11 — Gitea-CI-Rückbau abschließen (sicher rückbaubare Schritte) |
| 0035 | open | M2 | medium | Rollout Gruppenregeln-Pointer: axion1337.chat-gitops |
| 0036 | open | M2 | medium | Rollout Gruppenregeln-Pointer: ThreadNet-Web |
| 0037 | open | M2 | medium | Rollout Gruppenregeln-Pointer: threadnet-call |
| 0038 | open | M2 | medium | Rollout Gruppenregeln-Pointer: thread-net-git |
| 0039 | open | M2 | medium | Rollout Gruppenregeln-Pointer: threadnet-operating |
| 0040 | open | M2 | low | neckbeard-Rückmeldungen aus dem Feldtest einreichen |
| 0041 | open | M2 | low | wartegrund der 7 importierten waiting-Issues präzisieren |
| 0042 | open | M2 | high | Migration in Betrieb nehmen: Push, erster Spiegel-Lauf, CI-Schedule |
| 0043 | open | M5 | medium | Invitation-Flow: case-insensitive Eindeutigkeitsprüfung im Prompt-Stage |
| 0044 | open | M5 | low | SOPS-Values-Secret-Änderung startet den konsumierenden Dienst nicht neu |
| 0045 | open | M1 | low | Inhalts-Meldung führt ins Leere: kein Kontaktweg für Melder |
Active design docs (0)
none active
ADRs (13)
| ADR | Status | Title |
|---|---|---|
| 0001 | accepted | 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert |
| 0002 | accepted | 0002 — Issues und Management-Repo ziehen ins Lab („das Lab ist die Quelle der Wahrheit") |
| 0003 | accepted | 0003 — CVE-Meldeweg: aggregierte Alarme, eigener Security-Raum, gleicher Bot |
| 0004 | accepted | 0004 — Site-to-Site-VPN Hetzner-Projektnetz ↔ Lab, schaltbar über die UDM |
| 0005 | accepted | 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen |
| 0006 | accepted | 0006 — Wikis ins Lab konsolidieren, Docusaurus als gemeinsame Lesefläche |
| 0007 | proposed | 0007 — Wiki-Oberfläche: Docusaurus läuft, BookStack als Gegenentwurf |
| 0008 | accepted | 0008 — Agenten-Sessions auf CFGMON laufen root-äquivalent über die docker-Gruppe |
| 0009 | accepted | 0009 — Commit-Konventionen und rückwirkende Anonymisierung der Historie |
| 0010 | accepted | 0010 — Härtung ist ein eigener Meilenstein (M5); M1 misst nur Kaputtes |
| 0011 | accepted | 0011 — Provisionierung verweigert Localpart-Kollisionen, statt an bestehende Konten zu verknüpfen |
| 0012 | accepted | ADR-0012: Issues leben im Repo; GitLab wird deterministisch bespiegelt |
| 0013 | accepted | ADR-0013: Gruppenregeln kanonisch im management-Repo, Komponenten zeigen und werden geprüft |