WRKLOG-2026-03-18
Summary
Tuesday. Regex training priority at 5:30am. DMV walk-in for REAL ID. Finalize Z Fold 7 Termux incident. Monad evaluation critically behind.
URGENT - All Domains
Carryover Backlog (CRITICAL)
| Task | Details | Origin | Days | Status |
|---|---|---|---|---|
k3s NAT verification |
NAT rule 170 for 10.42.0.0/16 pod network - test internet connectivity |
2026-03-09 |
29 |
P0 - BLOCKING |
Wazuh indexer recovery |
Restart pod after NAT confirmed working - SIEM visibility blocked |
2026-03-09 |
29 |
P0 - Blocked by k3s |
Strongline Gateway VLAN fix |
8 devices in wrong identity group (David Rukiza assigned) |
2026-03-16 |
22 |
P0 - TODO |
Monad Pipeline Evaluation |
Test pipeline creation, input sources, transforms (LEAD ROLE) |
2026-03-11 |
27 |
P1 - TODO |
Vocera EAP-TLS Supplicant Fix |
~10 phones failing 802.1X, missing supplicant config |
2026-03-12 |
26 |
P1 - TODO |
ISE MnT Messaging Service |
Enable "Use ISE Messaging Service for UDP syslogs delivery" |
2026-03-12 |
26 |
P2 - TODO |
ISE Patch 9 upgrade |
ISE 3.2 Patch 9 addresses known replication issues |
2026-03-12 |
26 |
P2 - TODO |
| Professional backlog is at critical levels. Monad evaluation 7+ days carried. |
BLOCKERS — Fix Immediately
| Task | Details | Origin | Days | Impact |
|---|---|---|---|---|
Z Fold 7 Termux |
gopass and SSH not working |
2026-03-10 |
25 |
BLOCKER — Cannot access passwords on mobile |
gopass v3 organization |
Inconsistent structure, poor key-value usage |
2026-03-20 |
15 |
Inefficient password management, no aggregation |
URGENT - Requires Immediate Action
| Item | Details | Deadline | Status | Impact |
|---|---|---|---|---|
Housing Search |
Granada Hills area - apartments/rooms |
TBD |
In Progress |
Quality of life, commute |
URGENT — Performance Review Deadline (June 1, 2026)
| Certification | Provider | Deadline | Status | Impact |
|---|---|---|---|---|
CISSP |
ISC² — Certified Information Systems Security Professional |
June 1, 2026 |
ACTIVE — Phase 0 (Project) |
Required for performance review |
RHCSA 9 |
Red Hat Certified System Administrator |
June 1, 2026 |
ACTIVE — 21-phase curriculum (Project) |
Required for performance review |
| 55 days remaining until June 1st deadline. |
Early Morning - 5:30am
Regex Training (PRIORITY)
-
Session 3 - Character classes, word boundaries
-
Practice drills from regex-mastery curriculum
-
Goal: 1 hour focused practice before day starts
Life Admin
DMV - REAL ID (COMPLETED ✓)
-
Walk-in completed - 2026-03-18
-
License was expired: 48 days (Jan 29, 2026)
-
Status: REAL ID obtained, valid for TSA/domestic flights
Storage - Extra Space (COMPLETED)
| Item | Details |
|---|---|
Unit |
8 x 11 climate-controlled |
Monthly |
$227.00 |
Insurance |
$14.20/mo |
Total |
$241.20/mo |
Status |
Move-in complete |
-
Move remaining items (books, containers)
Housing Search - Granada Hills
-
Search apartments/rooms in Granada Hills area
-
Budget: TBD
-
Timeline: TBD
Work (CHLA)
| CHARGE TIME IN PEOPLESOFT - CRITICAL. Do this NOW before anything else. |
Critical (P0)
| Project | Description | Owner | Status | Due | Blocker |
|---|---|---|---|---|---|
Linux Research (Xianming Ding) |
EAP-TLS for Linux workstations, dACL, UFW |
Evan |
BEHIND |
02-24 |
Certificate "password required" - nmcli fix documented |
iPSK Manager |
Pre-shared key automation |
Ben Castillo |
BEHIND |
— |
DB replication issues |
MSCHAPv2 Migration |
Legacy auth deprecation |
Evan |
BEHIND |
— |
No progress on planning |
Research Segmentation |
All endpoints to Untrusted VLAN |
Evan |
BLOCKED |
— |
CISO decision pending |
High Priority (P1)
| Project | Description | Owner | Status | Target |
|---|---|---|---|---|
ISE 3.4 Migration |
Upgrade from 3.2p9 |
Evan |
Blocked |
Q1 2026 |
Switch Upgrades |
IOS-XE fleet update (C9300, 3560CX) |
Evan |
Pending |
Q1 2026 |
Spikewell BYOD VPN |
dACL SQL, AD group integration |
Evan |
Active |
— |
Strongline Gateway |
MAC capture, Identity Group setup |
Evan |
Active |
— |
QRadar → Sentinel Migration |
Full SIEM platform transition, Monad evaluation |
Evan |
Active |
Q2 2026 |
Strategic (P2)
| Project | Description | Owner | Status |
|---|---|---|---|
HHS Regulatory Compliance |
New HHS security policies implementation |
TBD |
NOT STARTED |
InfoSec Reporting Dashboard |
PowerBI metrics for executives |
TBD |
NOT STARTED |
EDR Migration (AMP → Defender) |
Endpoint protection consolidation |
TBD |
NOT STARTED |
Azure Legacy Migration |
Modern landing zone |
Team |
In Progress |
ChromeOS EAP-TLS |
SCEP + Victor, Paul testing |
Victor |
In Progress |
Today’s Priorities
-
P0 - Strongline Gateway VLAN fix (blocking Arin)
-
P0 - k3s NAT verification (9 days carried - CRITICAL)
-
P1 - Monad Pipeline Evaluation (7 days - CRITICAL)
-
P1 - Wazuh indexer recovery (blocked by NAT)
Session Accomplishments (Claude Code)
gopass Tools Documentation
Added reference documentation for gopass management tools in domus-captures:
| File | Purpose |
|---|---|
|
gopass-audit - read-only consolidation analysis |
|
gopass-migrate - safe migration with backups |
|
gopass-personal-docs - 12-category entry generator |
Commits:
- d2e868a - docs(codex): Add gopass-audit and gopass-migrate reference documentation
- 04f8f2c - feat(cli): Add gopass-audit and gopass-migrate for entry consolidation (dotfiles-optimus)
Installation:
ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-audit ~/.local/bin/
ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-migrate ~/.local/bin/
ln -sf ~/atelier/_projects/personal/dotfiles-optimus/bin/gopass-personal-docs ~/.local/bin/
PeopleSoft Time Entry System
Created scalable time tracking system for PeopleSoft submissions:
Page: trackers/peoplesoft.adoc (Operations → Trackers → PeopleSoft Time Entry)
Partial: partials/trackers/work/peoplesoft-codes.adoc
Features: - Project codes table with budget tracking - Activity hour baselines (30+ activities across 8 categories) - Standard CHLA admin codes (Account 605010, Fund 1010, Dept 8492000) - Biweekly tracking template - Tagged sections for selective includes
Projects Added:
| Project | Code | Budget |
|---|---|---|
Recognition Kiosk (Poppulo) - IS Labor |
00018166 |
12 hrs |
Spectrum TV/GetWell iPad Refresh |
000016444 |
|
Cisco Secure Endpoint Replacement |
000017633 |
|
Windows 11 Device Hardening |
000017706 |
Commit: 7c300b9 - feat(trackers): Add scalable PeopleSoft time entry system
Principia Discovery
Located existing PeopleSoft structure in Principia:
-
Principia/02_Assets/TAB-CAPTURES/partials/peoplesoft-defaults.adoc -
Principia/02_Assets/TAB-CAPTURES/partials/activity-baselines.adoc
Activity baselines migrated to domus-captures for active use.
Z Fold 7 Termux - Final Fixes
Resolved remaining issues from INC-2026-03-16:
| Issue | Resolution |
|---|---|
SSH cert expired (8hr TTL) |
Manual re-sign with |
|
Script has |
Oh-my-posh crashes on ARM64 |
Replaced with Starship ( |
Clipboard not working (gopass -c) |
Installed Termux:API app from F-Droid |
Commits:
-
3f886f4- docs(incident): Add 2026-03-18 SSH cert expiry troubleshooting -
73cedbd- docs(incident): Add Phase 7 - Oh-My-Posh prompt setup for Termux -
b017ac1- docs(incident): Replace oh-my-posh with starship on Termux -
1da1f5b- docs(incident): Add Phase 8 - Termux:API for gopass clipboard
Personal
In Progress
| Project | Description | Status | Notes |
|---|---|---|---|
k3s Platform |
Production k3s cluster on kvm-01 |
Active |
Prometheus, Grafana, Wazuh deployed |
Wazuh Archives |
Enable archives indexing in Filebeat |
Active |
PVC fix pending |
kvm-02 Hardware |
Supermicro B deployment |
Active |
Hardware ready, RAM upgrade done |
Planned
| Project | Description | Target | Blocked By |
|---|---|---|---|
Vault HA (3-node) |
vault-02, vault-03 on kvm-02 |
Q1 2026 |
kvm-02 deployment |
k3s HA (3-node) |
Control plane HA |
Q1 2026 |
kvm-02 deployment |
ArgoCD GitOps |
k3s GitOps deployment |
After k3s stable |
— |
MinIO S3 |
Object storage for k3s |
After ArgoCD |
— |
Personal asset management (YAML + CLI + AsciiDoc) |
Q2 2026 |
Schema approved |
Active — Infrastructure
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
Wazuh agent deployment |
Deploy agents to all infrastructure hosts |
P2 |
Pending |
After archives fix |
k3s Platform |
Production k3s cluster on kvm-01 |
P1 |
In Progress |
— |
Wazuh Archives |
Enable archives indexing in Filebeat, PVC fix |
P1 |
In Progress |
— |
kvm-02 Hardware |
Supermicro B deployment, RAM upgrade done |
P1 |
In Progress |
— |
Active — Security & Encryption
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
Configure 4th YubiKey |
SSH FIDO2 keys |
P1 |
TODO |
— |
Cold storage M-DISC backup |
age-encrypted archives |
P1 |
TODO |
After YubiKey setup |
Active — Development & Tools
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
netapi Commercialization |
Go CLI rewrite with Cobra-style argument discovery, package for distribution |
P0 |
Active |
— |
Ollama API Service |
FastAPI (17 endpoints), productize — config audit, doc tools, runbook gen |
P0 |
Active |
— |
Shell functions (fe, fec, fef) |
File hunting helpers |
P3 |
TODO |
— |
Active — Documentation
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
D2 Catppuccin Mocha styling |
domus-* spoke repos (177 files total) |
P3 |
In Progress |
— |
Active — Financial
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
Amazon order history import |
Download CSV from Privacy Central → parse with awk → populate subscriptions tracker |
P1 |
Waiting |
Pending Amazon data export (requested 2026-04-04) |
Active — Education
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
No active education tasks — see education trackers |
Active — Personal & Life Admin
| Task | Details | Priority | Status | Due |
|---|---|---|---|---|
ThinkPad T16g Setup |
Arch install, stow dotfiles, Ollama stack, netapi dev env |
P0 |
Pending |
— |
P50 Arch to Ubuntu migration |
P2 |
In Progress |
— |
|
X1 Carbon Ubuntu installs |
2 laptops, LUKS encryption |
P2 |
In Progress |
— |
P50 Steam Test |
Test Flatpak Steam + apt cleanup of broken i386 packages |
P3 |
Pending |
— |
Documentation Sites
-
docs.domusdigitalis.dev - Private documentation hub
-
docs.architectus.dev - Public portfolio site
Z Fold 7 Termux - Finalization
Incident: INC-2026-03-16
Completed tasks:
-
Wrap Mason
ensure_installedfor Termux (commit19ae888in domus-nvim) -
Remove temporary password auth from workstation SSH config (lines 187-188 removed)
-
Final verification:
gopass show,ssh -T git@github.com -
Close incident
Mason now detects Termux via TERMUX_VERSION env or /data/data/com.termux path and skips ensure_installed.
|
Education
Active Tracks (Focus)
-
Don Quijote - Primera Parte
Skills Mastery (Critical)
-
Regex Mastery - 10-module curriculum
-
AsciiDoc Docs - Documentation format
-
Antora Docs - Documentation pipeline
Certification Deadlines
-
CISSP - Before June 1, 2026 (performance review)
-
RHCSA 9 - Before June 1, 2026 (performance review)
-
LPIC-1 - Renewal required (blocks LPIC-2)
Spanish C1 Certification Goals
| Certification | Provider | Target | Status | Strategy |
|---|---|---|---|---|
Instituto Cervantes / UNAM / Salamanca |
Q2 2026 |
ACTIVE |
Computer-based, faster results - take FIRST |
|
Q3/Q4 2026 |
PLANNED |
After SIELE success, harder exam |
||
2027 |
FUTURE |
Mastery level - requires extensive immersion |
| SIELE is computer-adaptive, results in 3 weeks. DELE is paper-based, results in 3-4 months. Do SIELE first to validate readiness. |
Today’s Study
-
Focus: Regex Mastery - Session 3
-
Time: Later today (morning derailed by Termux incident)
-
Progress: Deferred - must complete today
| Regex training is falling behind. Prioritize after time entry. |
Training Curriculum Development (Session Accomplishment)
Built complete training curricula matching regex pattern (Sessions → Drills progression):
| Track | Files | Focus |
|---|---|---|
jq |
6 sessions, 6 drills |
Fundamentals → Infrastructure patterns (ISE, k8s, Vault) |
Python |
6 sessions, 6 drills |
Fundamentals → Infrastructure automation (subprocess, argparse) |
Lua |
5 sessions, 5 drills |
Fundamentals → Neovim LSP (lazy.nvim, lspconfig) |
ETL |
5 sessions, 5 drills |
Pipes → Infrastructure ETL (Monad-style routing) |
Total: 22 session files + 22 drill files + 4 index pages + nav.adoc updated
Training philosophy: Sessions (curriculum) first, then Drills (practice) for repetition.
Infrastructure
Documentation Sites
| Site | URL | Status | Actions Needed |
|---|---|---|---|
Domus Digitalis |
Active |
Validate, harden, improve |
|
Architectus |
Active |
Public portfolio site - maintain |
HA Deployment Status
| System | Description | Status | Notes |
|---|---|---|---|
VyOS HA |
vyos-01 (kvm-01) + vyos-02 (kvm-02) with VRRP VIP |
✅ COMPLETE |
2026-03-07 - pfSense decommissioned |
BIND DNS HA |
bind-01 (kvm-01) + bind-02 (kvm-02) with AXFR |
✅ COMPLETE |
Zone transfer operational |
Vault HA |
Raft cluster (vault-01/02/03) |
✅ COMPLETE |
Integrated with PKI |
Keycloak Rebuild |
keycloak-01 corrupted, rebuild from scratch |
🔄 NEXT |
Priority P3 - SSO broken |
FreeIPA HA |
ipa-02 replica planned |
📋 PLANNED |
Linux auth redundancy |
AD DC HA |
home-dc02 replication |
📋 PLANNED |
Windows auth redundancy |
iPSK Manager HA |
ipsk-mgr-02 with MySQL replication |
📋 PLANNED |
PSK portal redundancy |
ISE HA |
PAN HA (ise-01 reconfigure) |
⏳ DEFERRED |
Wait until ise-02 stable |
ISE 3.5 Migration |
Upgrade path: 3.2p9 → 3.4 (P1) → 3.5 (target) |
📋 PLANNED |
After 3.4 Migration completes (Q2 2026) |
Single Points of Failure (CRITICAL)
| These systems have NO redundancy - outage impacts production. |
| System | Impact if Down | Mitigation |
|---|---|---|
ISE (ise-02) |
All 802.1X stops - wired and wireless auth fails |
ise-01 reconfiguration deferred until ise-02 stable |
Keycloak (keycloak-01) |
SAML/OIDC SSO broken (ISE admin, Grafana, etc.) |
NEXT PRIORITY - Rebuild runbook |
FreeIPA (ipa-01) |
Linux auth, sudo rules, HBAC fails |
ipa-02 replica planned |
AD DC (home-dc01) |
Windows auth, Kerberos, GPO fails |
home-dc02 replica planned |
iPSK Manager |
Self-service PSK portal unavailable |
ipsk-mgr-02 with MySQL replication planned |
Validation Tasks
| Task | Details | Status |
|---|---|---|
docs.domusdigitalis.dev validation |
Test all cross-references, search, rendering |
TODO |
docs.domusdigitalis.dev hardening |
HTTPS, CSP headers, security review |
TODO |
docs.architectus.dev validation |
Public site content review |
TODO |
Hub-spoke sync verification |
All components building correctly |
Ongoing |
Quick Commands
Termux Finalization
# On phone - wrap Mason ensure_installed (edit lsp/init.lua)
nvim ~/.config/nvim/lua/domus/plugins/config/lsp/init.lua
# On workstation - remove temporary password auth
sed -i '/^Host fold7$/,/^Host [^*]/{/PasswordAuthentication yes/d; /PreferredAuthentications publickey,password/d}' ~/.ssh/config
Monad Quick Start
dsource d000 lab/app
netapi monad pipelines
netapi monad input-search cisco