Files
management/STATUS.md
T
Thore Cimbal f3417a4b24 docs: capture session knowledge not yet in the repo
Externalises what this session held that the migrated repo did not:

- vision/threadnet.md: the three capabilities that justify the forks beyond
  rebranding (AV scanning into encrypted rooms, call-quality defaults with a
  client-side-only privacy line, expiring guest access via @concierge).
- issue 0043 (M5): case-insensitive uniqueness in the matrix-invitation prompt
  stage — the open residual of ADR-0011.
- issue 0044 (M5): auto-restart consumers on SOPS values-secret change — the
  footgun behind the on_conflict fix sitting inactive until a manual restart.
- issue 0045 (M1): report_event.admin_message_md unset — content reports
  dead-end with no contact path (verified still open against live config).
- sources/protokolle: the raw apo-call diagnosis history, including the four
  ruled-out hypotheses and the harmful DB write, as the source behind the AAR.

STATUS.md regenerated (M5 appears for the first time). validate, gen_status
--check, upstream_drift and pruefe_prosa all green in the CI image.
2026-08-11 12:00:00 +00:00

8.9 KiB

STATUS

Issues (39 open, 0 closed)

Verteilung: M1 10 · M2 25 · M4 2 · M5 2

Issue Status Meilenstein Priorität Title
0001 open M2 low MATRIX-03: www.matrix.axion1337.de ist überflüssig
0002 waiting M1 medium GAME-01: Host von CFGMON aus nicht erreichbar, 2 Prometheus-Targets down
0003 open M2 low GAME-02: www.game.axion1337.de ist überflüssig
0004 waiting M1 low OVERMIND-02: e1000e-NIC-Hang — Beobachtung nach EEE-Fix + Firmware-Update
0005 open M2 low ZONE-01: IONOS-Default-Records bereinigen (www-Paare, tote Mail-Sätze)
0006 open M1 low ZONE-02: Apex-DMARC ist p=none und schützt nichts
0007 next M1 high CFGMON-01: Zertifikatserneuerung braucht offene Ports — zeitkritisch ab 2026-09-28
0008 waiting M1 medium CFGMON-03: Prometheus-Remote-Write und Loki öffentlich ohne Auth — Weg A, nachgelagerte Prüfung
0009 open M2 low CFGMON-04: Grafana-Admin-Credentials aus .env gelten nicht für die HTTP-API
0010 open M1 medium CFGMON-09: Gitea-Backups off-host (Borg/Storage Box) — Backup-Cron ist DEAKTIVIERT
0014 waiting M2 low CFGMON-14: Root-Zugang über die docker-Gruppe umgeht sudo und hinterlässt keine Spur
0015 next M2 medium CFGMON-15: Token-Hygiene — Einmal-Tokens der LABNET-02-Nacht widerrufen
0018 open M2 low DOC-01: Wiki-Rollout abschließen — CI-Freigaben, Zeitplan, Dokploy-Stack, wiki.lab
0019 open M2 low DOC-02: Veralteten wiki-Branch im gitops-Repo entfernen?
0020 next M2 medium DOC-03: Wiki-Oberfläche entscheiden — Docusaurus oder BookStack
0021 waiting M2 medium OVERMIND-03: Windows-Build-VM verschwindet — CI kann sie nur starten, nicht anlegen
0022 open M4 low BUILD-01: macOS-Client reproduzierbar bauen — aktuell nur manuell auf sorbs Mac
0023 open M2 low DOC-04: Navbar-Logo im Docusaurus-Wiki wird ausgeliefert, ist aber nicht sichtbar
0024 open M2 low Wiki-Hostname klären: wiki.lab oder axionwiki.lab?
0025 waiting M1 medium Deploy-Übergabe: CVE-Alarme aggregiert + Receiver-Robustheit (gitops#51, ff87cb2)
0027 waiting M2 medium AUDIT-01: Acht Widersprüche aus dem LABNET-02-Nachlauf (Selbst-Audit CFGMON-Session)
0028 open M2 low MIRROR-01: Ein Ausfall der Push-Mirrors bleibt unbemerkt — Produktion friert still ein
0029 open M4 medium UI harmonisieren: gleiche Farben und Formen über alle Oberflächen
0030 open M1 medium Der Restore ist nie geprobt — Sicherungen sind bisher eine Vermutung
0031 open M1 low Stillstandsprüfung: GITEA_TOKEN und Authentik-Teil nachziehen
0032 open M2 medium gameserver hat keinen Push-Mirror — und auf Gitea liegt ein anderer Stand
0033 open M2 low OVERMIND-01 — element-desktop-build von rohana in die Lab-Registry umziehen
0034 open M2 medium CFGMON-11 — Gitea-CI-Rückbau abschließen (sicher rückbaubare Schritte)
0035 open M2 medium Rollout Gruppenregeln-Pointer: axion1337.chat-gitops
0036 open M2 medium Rollout Gruppenregeln-Pointer: ThreadNet-Web
0037 open M2 medium Rollout Gruppenregeln-Pointer: threadnet-call
0038 open M2 medium Rollout Gruppenregeln-Pointer: thread-net-git
0039 open M2 medium Rollout Gruppenregeln-Pointer: threadnet-operating
0040 open M2 low neckbeard-Rückmeldungen aus dem Feldtest einreichen
0041 open M2 low wartegrund der 7 importierten waiting-Issues präzisieren
0042 open M2 high Migration in Betrieb nehmen: Push, erster Spiegel-Lauf, CI-Schedule
0043 open M5 medium Invitation-Flow: case-insensitive Eindeutigkeitsprüfung im Prompt-Stage
0044 open M5 low SOPS-Values-Secret-Änderung startet den konsumierenden Dienst nicht neu
0045 open M1 low Inhalts-Meldung führt ins Leere: kein Kontaktweg für Melder

Active design docs (0)

none active

ADRs (13)

ADR Status Title
0001 accepted 0001 — git.lab ist kanonisch, Gitea wird per Push-Mirror beliefert
0002 accepted 0002 — Issues und Management-Repo ziehen ins Lab („das Lab ist die Quelle der Wahrheit")
0003 accepted 0003 — CVE-Meldeweg: aggregierte Alarme, eigener Security-Raum, gleicher Bot
0004 accepted 0004 — Site-to-Site-VPN Hetzner-Projektnetz ↔ Lab, schaltbar über die UDM
0005 accepted 0005 — Projektmanagement: Kanban-Rückgrat mit leichten Scrum-Elementen
0006 accepted 0006 — Wikis ins Lab konsolidieren, Docusaurus als gemeinsame Lesefläche
0007 proposed 0007 — Wiki-Oberfläche: Docusaurus läuft, BookStack als Gegenentwurf
0008 accepted 0008 — Agenten-Sessions auf CFGMON laufen root-äquivalent über die docker-Gruppe
0009 accepted 0009 — Commit-Konventionen und rückwirkende Anonymisierung der Historie
0010 accepted 0010 — Härtung ist ein eigener Meilenstein (M5); M1 misst nur Kaputtes
0011 accepted 0011 — Provisionierung verweigert Localpart-Kollisionen, statt an bestehende Konten zu verknüpfen
0012 accepted ADR-0012: Issues leben im Repo; GitLab wird deterministisch bespiegelt
0013 accepted ADR-0013: Gruppenregeln kanonisch im management-Repo, Komponenten zeigen und werden geprüft

Open AARs (2)