STATUS: 2026-09-09 state — 2FA done, admin levers live, queue refreshed

https://projects.knownelement.com/issues/942
This commit is contained in:
2026-09-09 13:12:52 -05:00
parent e99db2e553
commit dfaf8fe12f
+19 -23
View File
@@ -1,7 +1,7 @@
# STATUS.md — COO C2 lane
> Maintained by the COO-line agent (COO command-and-control chat).
> Last updated: 2026-09-07
> Last updated: 2026-09-09
## Scope (ruled by reachableceo 2026-09-07, corrected same day)
@@ -13,29 +13,25 @@
- **DEFERRED:** TCTC structure — reachableceo rules the week of 2026-09-14.
Interface to SVP TCTC is in scope now; the division's internals are not.
## Queue — gated on the vault/box incident
## Active tickets
Vault `pwvault` authed `/api/sync` hangs (started ~20:00 CT 09-07); same box
(152.53.37.179) hosts gitea (receive-pack 500, #937) and the my. vhost
(MySQL root@localhost leak, #939). Another chat is fixing the cloudron box.
1. File Redmine ticket for the 2026-09-07 org rulings; comment carries
commit URLs: TSYSGroupAIOS `8eb3867` (branch ic-builder/retire-creds-
pattern, symlink-live) + org-buildout `4669d24`.
2. Update #937 — corrected diagnosis notes.
3. Update #939 — correct attribution (public-box MySQL root leak is on
152.53.37.179, not the cloudron box); note fix-in-flight by another chat.
4. Push blocked commits: TSYSGroupAIOS (ssh 22/29418 filtered from this
host), org-buildout (receive-pack 500). Also create + push the new
KNELPDF repo (local at /data2/TSGCOO/projects/COO/KNELPDF, image
knelpdf:v2 = full doc-production pipeline, no Node.js) as KNEL/KNELPDF
on gitea, with its Redmine ticket + Discourse doc cross-links at birth.
5. coo identity stand-up — reachableceo-side asks open: gitea token mint
(coo-api), Redmine + Discourse account creation, glpi admin TOTP into
vault. Then ALL system actions switch to coo (reachableceo directive).
6. Route TechOps staff provisioning (techops-director, techops-manager)
to the owning lane as a ticket — this chat does not execute below SVP.
| ticket | state | item |
|---|---|---|
| #942 | 🔄 | identity lifecycle: 2FA 32/32 DONE; vptechops admin in all 4 systems; next = SSO first-logins + API keys batch |
| #946 | ⏳ | house rules PR #4 open (founder to merge) + release house-rules-v2026.09.0 |
| #826 | ✅ | all COO-chat perf asks done (gitea grant, org row, vpperf 2FA, knelperf project 94, Discourse Performance cat 77) |
| #940 | ⏳ | org-buildout moved to TSYSGroupCorporate; pushes work via vptechops |
| #944 | ✅ | SSH approval recorded (2026-09-09, app containers only) |
## Inbox
- (empty)
- Wazuh `--change-all` rotation: QUEUED — needs GLPI CR first (house rule);
GLPI REST token auth debug half-done (apiclients + api_token/personal_token
set for vptechops id 9, both still 401 — GLPI 11 token auth to dig).
- UI resets for stale pairs (phpipam/technitium/grafana/beszel/rancher):
queued behind Wazuh in the rotation waves.
- SSO + API keys batch (32 identities × 4 systems): mechanism proven
(oidc-login script + admin levers); batch run next.
- smcli setfield 400 bug (Vaultwarden "Data missing"): upstream fix pending;
scripts carry the recreate workaround. Junk `ztest_zz` fields on ~9 items
to clean when setfield is fixed.