WRKLOG-2026-03-18

Summary

Tuesday. Regex training priority at 5:30am. DMV walk-in for REAL ID. Finalize Z Fold 7 Termux incident. Monad evaluation critically behind.

URGENT - All Domains

Carryover Backlog (CRITICAL)

Task Details Origin Days Status

k3s NAT verification

NAT rule 170 for 10.42.0.0/16 pod network - test internet connectivity

2026-03-09

29

P0 - BLOCKING

Wazuh indexer recovery

Restart pod after NAT confirmed working - SIEM visibility blocked

2026-03-09

29

P0 - Blocked by k3s

Strongline Gateway VLAN fix

8 devices in wrong identity group (David Rukiza assigned)

2026-03-16

22

P0 - TODO

Monad Pipeline Evaluation

Test pipeline creation, input sources, transforms (LEAD ROLE)

2026-03-11

27

P1 - TODO

Vocera EAP-TLS Supplicant Fix

~10 phones failing 802.1X, missing supplicant config

2026-03-12

26

P1 - TODO

ISE MnT Messaging Service

Enable "Use ISE Messaging Service for UDP syslogs delivery"

2026-03-12

26

P2 - TODO

ISE Patch 9 upgrade

ISE 3.2 Patch 9 addresses known replication issues

2026-03-12

26

P2 - TODO

Professional backlog is at critical levels. Monad evaluation 7+ days carried.

BLOCKERS — Fix Immediately

Task Details Origin Days Impact

Z Fold 7 Termux

gopass and SSH not working

2026-03-10

25

BLOCKER — Cannot access passwords on mobile

gopass v3 organization

Inconsistent structure, poor key-value usage

2026-03-20

15

Inefficient password management, no aggregation

URGENT - Requires Immediate Action

Item Details Deadline Status Impact

Housing Search

Granada Hills area - apartments/rooms

TBD

In Progress

Quality of life, commute

URGENT — Performance Review Deadline (June 1, 2026)

Certification Provider Deadline Status Impact

CISSP

ISC² — Certified Information Systems Security Professional

June 1, 2026

ACTIVE — Phase 0 (Project)

Required for performance review

RHCSA 9

Red Hat Certified System Administrator

June 1, 2026

ACTIVE — 21-phase curriculum (Project)

Required for performance review

55 days remaining until June 1st deadline.

Early Morning - 5:30am

Regex Training (PRIORITY)

  • Session 3 - Character classes, word boundaries

  • Practice drills from regex-mastery curriculum

  • Goal: 1 hour focused practice before day starts


Life Admin

DMV - REAL ID (COMPLETED ✓)

  • Walk-in completed - 2026-03-18

  • License was expired: 48 days (Jan 29, 2026)

  • Status: REAL ID obtained, valid for TSA/domestic flights

Storage - Extra Space (COMPLETED)

Item Details

Unit

8 x 11 climate-controlled

Monthly

$227.00

Insurance

$14.20/mo

Total

$241.20/mo

Status

Move-in complete

  • Move remaining items (books, containers)

Housing Search - Granada Hills

  • Search apartments/rooms in Granada Hills area

  • Budget: TBD

  • Timeline: TBD


Work (CHLA)

CHARGE TIME IN PEOPLESOFT - CRITICAL. Do this NOW before anything else.

Critical (P0)

Project Description Owner Status Due Blocker

Linux Research (Xianming Ding)

EAP-TLS for Linux workstations, dACL, UFW

Evan

BEHIND

02-24

Certificate "password required" - nmcli fix documented

iPSK Manager

Pre-shared key automation

Ben Castillo

BEHIND

 — 

DB replication issues

MSCHAPv2 Migration

Legacy auth deprecation

Evan

BEHIND

 — 

No progress on planning

Research Segmentation

All endpoints to Untrusted VLAN

Evan

BLOCKED

 — 

CISO decision pending

High Priority (P1)

Project Description Owner Status Target

ISE 3.4 Migration

Upgrade from 3.2p9

Evan

Blocked

Q1 2026

Switch Upgrades

IOS-XE fleet update (C9300, 3560CX)

Evan

Pending

Q1 2026

Spikewell BYOD VPN

dACL SQL, AD group integration

Evan

Active

 — 

Strongline Gateway

MAC capture, Identity Group setup

Evan

Active

 — 

QRadar → Sentinel Migration

Full SIEM platform transition, Monad evaluation

Evan

Active

Q2 2026

Strategic (P2)

Project Description Owner Status

HHS Regulatory Compliance

New HHS security policies implementation

TBD

NOT STARTED

InfoSec Reporting Dashboard

PowerBI metrics for executives

TBD

NOT STARTED

EDR Migration (AMP → Defender)

Endpoint protection consolidation

TBD

NOT STARTED

Azure Legacy Migration

Modern landing zone

Team

In Progress

ChromeOS EAP-TLS

SCEP + Victor, Paul testing

Victor

In Progress

Today’s Priorities

  • P0 - Strongline Gateway VLAN fix (blocking Arin)

  • P0 - k3s NAT verification (9 days carried - CRITICAL)

  • P1 - Monad Pipeline Evaluation (7 days - CRITICAL)

  • P1 - Wazuh indexer recovery (blocked by NAT)

Notes

Day-specific work notes here.


Session Accomplishments (Claude Code)

gopass Tools Documentation

Added reference documentation for gopass management tools in domus-captures:

File Purpose

codex/gopass/audit.adoc

gopass-audit - read-only consolidation analysis

codex/gopass/migrate.adoc

gopass-migrate - safe migration with backups

codex/gopass/personal-docs.adoc

gopass-personal-docs - 12-category entry generator

Commits: - d2e868a - docs(codex): Add gopass-audit and gopass-migrate reference documentation - 04f8f2c - feat(cli): Add gopass-audit and gopass-migrate for entry consolidation (dotfiles-optimus)

Installation:

ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-audit ~/.local/bin/
ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-migrate ~/.local/bin/
ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-personal-docs ~/.local/bin/

PeopleSoft Time Entry System

Created scalable time tracking system for PeopleSoft submissions:

Page: trackers/peoplesoft.adoc (Operations → Trackers → PeopleSoft Time Entry)

Partial: partials/trackers/work/peoplesoft-codes.adoc

Features: - Project codes table with budget tracking - Activity hour baselines (30+ activities across 8 categories) - Standard CHLA admin codes (Account 605010, Fund 1010, Dept 8492000) - Biweekly tracking template - Tagged sections for selective includes

Projects Added:

Project Code Budget

Recognition Kiosk (Poppulo) - IS Labor

00018166

12 hrs

Spectrum TV/GetWell iPad Refresh

000016444

Cisco Secure Endpoint Replacement

000017633

Windows 11 Device Hardening

000017706

Commit: 7c300b9 - feat(trackers): Add scalable PeopleSoft time entry system

Principia Discovery

Located existing PeopleSoft structure in Principia:

  • Principia/02_Assets/TAB-CAPTURES/partials/peoplesoft-defaults.adoc

  • Principia/02_Assets/TAB-CAPTURES/partials/activity-baselines.adoc

Activity baselines migrated to domus-captures for active use.

Z Fold 7 Termux - Final Fixes

Resolved remaining issues from INC-2026-03-16:

Issue Resolution

SSH cert expired (8hr TTL)

Manual re-sign with valid_principals="evanusmodestus,u0_a385"

vault-ssh-sign wrong principals

Script has u0_a361, need to add u0_a385

Oh-my-posh crashes on ARM64

Replaced with Starship (starship preset tokyo-night)

Clipboard not working (gopass -c)

Installed Termux:API app from F-Droid

Commits:

  • 3f886f4 - docs(incident): Add 2026-03-18 SSH cert expiry troubleshooting

  • 73cedbd - docs(incident): Add Phase 7 - Oh-My-Posh prompt setup for Termux

  • b017ac1 - docs(incident): Replace oh-my-posh with starship on Termux

  • 1da1f5b - docs(incident): Add Phase 8 - Termux:API for gopass clipboard


Personal

In Progress

Project Description Status Notes

k3s Platform

Production k3s cluster on kvm-01

Active

Prometheus, Grafana, Wazuh deployed

Wazuh Archives

Enable archives indexing in Filebeat

Active

PVC fix pending

kvm-02 Hardware

Supermicro B deployment

Active

Hardware ready, RAM upgrade done

Planned

Project Description Target Blocked By

Vault HA (3-node)

vault-02, vault-03 on kvm-02

Q1 2026

kvm-02 deployment

k3s HA (3-node)

Control plane HA

Q1 2026

kvm-02 deployment

ArgoCD GitOps

k3s GitOps deployment

After k3s stable

 — 

MinIO S3

Object storage for k3s

After ArgoCD

 — 

Domus Inventory

Personal asset management (YAML + CLI + AsciiDoc)

Q2 2026

Schema approved

Active — Infrastructure

Task Details Priority Status Due

Wazuh agent deployment

Deploy agents to all infrastructure hosts

P2

Pending

After archives fix

k3s Platform

Production k3s cluster on kvm-01

P1

In Progress

 — 

Wazuh Archives

Enable archives indexing in Filebeat, PVC fix

P1

In Progress

 — 

kvm-02 Hardware

Supermicro B deployment, RAM upgrade done

P1

In Progress

 — 


Active — Security & Encryption

Task Details Priority Status Due

Configure 4th YubiKey

SSH FIDO2 keys

P1

TODO

 — 

Cold storage M-DISC backup

age-encrypted archives

P1

TODO

After YubiKey setup


Active — Development & Tools

Task Details Priority Status Due

netapi Commercialization

Go CLI rewrite with Cobra-style argument discovery, package for distribution

P0

Active

 — 

Ollama API Service

FastAPI (17 endpoints), productize — config audit, doc tools, runbook gen

P0

Active

 — 

Shell functions (fe, fec, fef)

File hunting helpers

P3

TODO

 — 


Active — Documentation

Task Details Priority Status Due

D2 Catppuccin Mocha styling

domus-* spoke repos (177 files total)

P3

In Progress

 — 


Active — Financial

Task Details Priority Status Due

Amazon order history import

Download CSV from Privacy Central → parse with awk → populate subscriptions tracker

P1

Waiting

Pending Amazon data export (requested 2026-04-04)


Active — Education

Task Details Priority Status Due

No active education tasks — see education trackers


Active — Personal & Life Admin

Task Details Priority Status Due

ThinkPad T16g Setup

Arch install, stow dotfiles, Ollama stack, netapi dev env

P0

Pending

 — 

P50 Arch to Ubuntu migration

CR-2026-03-12

P2

In Progress

 — 

X1 Carbon Ubuntu installs

2 laptops, LUKS encryption

P2

In Progress

 — 

P50 Steam Test

Test Flatpak Steam + apt cleanup of broken i386 packages

P3

Pending

 — 

Documentation Sites

Z Fold 7 Termux - Finalization

Incident: INC-2026-03-16

Completed tasks:

  • Wrap Mason ensure_installed for Termux (commit 19ae888 in domus-nvim)

  • Remove temporary password auth from workstation SSH config (lines 187-188 removed)

  • Final verification: gopass show, ssh -T git@github.com

  • Close incident

Mason now detects Termux via TERMUX_VERSION env or /data/data/com.termux path and skips ensure_installed.

Notes

Day-specific personal notes here.


Education

Skills Mastery (Critical)

Certification Deadlines

  • CISSP - Before June 1, 2026 (performance review)

  • RHCSA 9 - Before June 1, 2026 (performance review)

  • LPIC-1 - Renewal required (blocks LPIC-2)

Spanish C1 Certification Goals

Certification Provider Target Status Strategy

SIELE C1

Instituto Cervantes / UNAM / Salamanca

Q2 2026

ACTIVE

Computer-based, faster results - take FIRST

DELE C1

Instituto Cervantes

Q3/Q4 2026

PLANNED

After SIELE success, harder exam

DELE C2

Instituto Cervantes

2027

FUTURE

Mastery level - requires extensive immersion

SIELE is computer-adaptive, results in 3 weeks. DELE is paper-based, results in 3-4 months. Do SIELE first to validate readiness.

Today’s Study

  • Focus: Regex Mastery - Session 3

  • Time: Later today (morning derailed by Termux incident)

  • Progress: Deferred - must complete today

Regex training is falling behind. Prioritize after time entry.

Training Curriculum Development (Session Accomplishment)

Built complete training curricula matching regex pattern (Sessions → Drills progression):

Track Files Focus

jq

6 sessions, 6 drills

Fundamentals → Infrastructure patterns (ISE, k8s, Vault)

Python

6 sessions, 6 drills

Fundamentals → Infrastructure automation (subprocess, argparse)

Lua

5 sessions, 5 drills

Fundamentals → Neovim LSP (lazy.nvim, lspconfig)

ETL

5 sessions, 5 drills

Pipes → Infrastructure ETL (Monad-style routing)

Total: 22 session files + 22 drill files + 4 index pages + nav.adoc updated

Training philosophy: Sessions (curriculum) first, then Drills (practice) for repetition.


Infrastructure

Documentation Sites

Site URL Status Actions Needed

Domus Digitalis

docs.domusdigitalis.dev

Active

Validate, harden, improve

Architectus

docs.architectus.dev

Active

Public portfolio site - maintain

HA Deployment Status

System Description Status Notes

VyOS HA

vyos-01 (kvm-01) + vyos-02 (kvm-02) with VRRP VIP

✅ COMPLETE

2026-03-07 - pfSense decommissioned

BIND DNS HA

bind-01 (kvm-01) + bind-02 (kvm-02) with AXFR

✅ COMPLETE

Zone transfer operational

Vault HA

Raft cluster (vault-01/02/03)

✅ COMPLETE

Integrated with PKI

Keycloak Rebuild

keycloak-01 corrupted, rebuild from scratch

🔄 NEXT

Priority P3 - SSO broken

FreeIPA HA

ipa-02 replica planned

📋 PLANNED

Linux auth redundancy

AD DC HA

home-dc02 replication

📋 PLANNED

Windows auth redundancy

iPSK Manager HA

ipsk-mgr-02 with MySQL replication

📋 PLANNED

PSK portal redundancy

ISE HA

PAN HA (ise-01 reconfigure)

⏳ DEFERRED

Wait until ise-02 stable

ISE 3.5 Migration

Upgrade path: 3.2p9 → 3.4 (P1) → 3.5 (target)

📋 PLANNED

After 3.4 Migration completes (Q2 2026)

Single Points of Failure (CRITICAL)

These systems have NO redundancy - outage impacts production.
System Impact if Down Mitigation

ISE (ise-02)

All 802.1X stops - wired and wireless auth fails

ise-01 reconfiguration deferred until ise-02 stable

Keycloak (keycloak-01)

SAML/OIDC SSO broken (ISE admin, Grafana, etc.)

NEXT PRIORITY - Rebuild runbook

FreeIPA (ipa-01)

Linux auth, sudo rules, HBAC fails

ipa-02 replica planned

AD DC (home-dc01)

Windows auth, Kerberos, GPO fails

home-dc02 replica planned

iPSK Manager

Self-service PSK portal unavailable

ipsk-mgr-02 with MySQL replication planned

Validation Tasks

Task Details Status

docs.domusdigitalis.dev validation

Test all cross-references, search, rendering

TODO

docs.domusdigitalis.dev hardening

HTTPS, CSP headers, security review

TODO

docs.architectus.dev validation

Public site content review

TODO

Hub-spoke sync verification

All components building correctly

Ongoing


Quick Commands

Termux Finalization

# On phone - wrap Mason ensure_installed (edit lsp/init.lua)
nvim ~/.config/nvim/lua/domus/plugins/config/lsp/init.lua

# On workstation - remove temporary password auth
sed -i '/^Host fold7$/,/^Host [^*]/{/PasswordAuthentication yes/d; /PreferredAuthentications publickey,password/d}' ~/.ssh/config

Monad Quick Start

dsource d000 lab/app
netapi monad pipelines
netapi monad input-search cisco