Weekly Review
Weekly review for Sunday planning. Audit carryover, review ideas, track certifications, verify PeopleSoft.
CRITICAL - Certification Deadlines
URGENT — Performance Review Deadline (June 1, 2026)
| Certification | Provider | Deadline | Status | Impact |
|---|---|---|---|---|
CISSP |
ISC² — Certified Information Systems Security Professional |
June 1, 2026 |
ACTIVE — Phase 0 (Project) |
Required for performance review |
RHCSA 9 |
Red Hat Certified System Administrator |
June 1, 2026 |
ACTIVE — 21-phase curriculum (Project) |
Required for performance review |
| 53 days remaining until June 1st deadline. |
| These are PERFORMANCE REVIEW requirements. Missing deadline = career impact. |
PeopleSoft Time Entry
| Are you behind on time entry? Submit biweekly. |
Active Projects
| Project | Code | Combo | Activity | Budget (hrs) |
|---|---|---|---|---|
Recognition Kiosk (Poppulo) - IS Labor |
000018166 |
000018623 |
20 |
12 |
Spectrum TV/GetWell iPad Refresh |
000016444 |
000018551 |
20 |
|
Azure Legacy Migration |
000018100 |
000018619 |
20 |
|
Cisco Secure Endpoint Replacement |
000017633 |
000018546 |
||
Windows 11 Device Hardening |
000017706 |
000018549 |
||
MSCHAPv2 to EAP-TLS Migration |
||||
ISE 3.4 Migration |
||||
QRadar → Sentinel Migration |
Standard Administrative Codes
| Field | Value | Notes |
|---|---|---|
Account |
605010 |
InfoSec Engineering |
Fund Code |
1010 |
|
Department |
8492000 |
|
PC Unit |
PC100 |
Carryover Audit
Review items carried over too long. Either DO them or REMOVE them.
Carryover Backlog (CRITICAL)
| Task | Details | Origin | Days | Status |
|---|---|---|---|---|
k3s NAT verification |
NAT rule 170 for 10.42.0.0/16 pod network - test internet connectivity |
2026-03-09 |
31 |
P0 - BLOCKING |
Wazuh indexer recovery |
Restart pod after NAT confirmed working - SIEM visibility blocked |
2026-03-09 |
31 |
P0 - Blocked by k3s |
Strongline Gateway VLAN fix |
8 devices in wrong identity group (David Rukiza assigned) |
2026-03-16 |
24 |
P0 - TODO |
Monad Pipeline Evaluation |
Test pipeline creation, input sources, transforms (LEAD ROLE) |
2026-03-11 |
29 |
P1 - TODO |
Vocera EAP-TLS Supplicant Fix |
~10 phones failing 802.1X, missing supplicant config |
2026-03-12 |
28 |
P1 - TODO |
ISE MnT Messaging Service |
Enable "Use ISE Messaging Service for UDP syslogs delivery" |
2026-03-12 |
28 |
P2 - TODO |
ISE Patch 9 upgrade |
ISE 3.2 Patch 9 addresses known replication issues |
2026-03-12 |
28 |
P2 - TODO |
BLOCKERS — Fix Immediately
| Task | Details | Origin | Days | Impact |
|---|---|---|---|---|
Z Fold 7 Termux |
gopass and SSH not working |
2026-03-10 |
30 |
BLOCKER — Cannot access passwords on mobile |
gopass v3 organization |
Inconsistent structure, poor key-value usage |
2026-03-20 |
20 |
Inefficient password management, no aggregation |
Ideas Backlog
Review weekly - promote to active or archive.
Ideas — Infrastructure
| Idea | Context | Category | Captured |
|---|---|---|---|
Vault HA runbook |
3-node Vault cluster on kvm-02 |
infra |
2026-03-22 |
k3s HA runbook |
3-node control plane |
infra |
2026-03-22 |
BIND secondary DNS |
bind-02 for HA (currently SPOF) |
infra |
2026-03-22 |
ipa-02 replica |
FreeIPA HA (currently SPOF) |
infra |
2026-03-22 |
Borg backup dashboard |
Visualize backup status across hosts |
infra |
2026-03-22 |
Vault backup to S3 |
Automated Vault snapshots to MinIO |
infra |
2026-03-22 |
Ideas — Development & Tools
| Idea | Context | Category | Captured |
|---|---|---|---|
netapi vyos commands |
Add VyOS API integration (replaced pfSense) |
netapi |
2026-03-22 |
netapi bind commands |
Add BIND nsupdate/rndc integration (DNS management) |
netapi |
2026-03-22 |
netapi k3s commands |
kubectl wrapper with common patterns |
netapi |
2026-03-22 |
netapi batch operations |
Cross-vendor batch commands (e.g., backup all) |
netapi |
2026-03-22 |
adoc improvements |
Add --watch flag, live reload |
tooling |
2026-03-22 |
tmux sessionizer |
Project-based tmux sessions (like ThePrimeagen) |
tooling |
2026-03-22 |
fzf git integrations |
Interactive branch switching, log searching |
tooling |
2026-03-22 |
gopass v3 restructure |
Use gopass-personal-docs templates (bills, storage, subscriptions) |
tooling |
2026-03-22 |
gopass-query enhancements |
Add |
tooling |
2026-03-22 |
gopass v3 → ADMINISTRATIO migration |
Script to move remaining entries from old structure |
tooling |
2026-03-22 |
Ideas — Education & Training
| Idea | Context | Category | Captured |
|---|---|---|---|
AWK curriculum |
Like regex curriculum — 10 modules, drills |
education |
2026-03-22 |
sed curriculum |
Pattern-based editing mastery |
education |
2026-03-22 |
Lua/Neovim curriculum |
Plugin development, lazy.nvim patterns |
education |
2026-03-22 |
Go CLI curriculum |
Learn Go via CLI tool development |
education |
2026-03-22 |
Anki deck from Don Quijote |
Extract vocabulary to spaced repetition |
language |
2026-03-22 |
DELE C1 mock exams |
Practice test structure |
language |
2026-03-22 |
Ideas — Documentation
| Idea | Context | Category | Captured |
|---|---|---|---|
Antora search fix |
Lunr index too large — explore alternatives |
docs |
2026-03-22 |
domus-* cross-reference audit |
Find and fix broken xrefs across all repos |
docs |
2026-03-22 |
Runbook template standardization |
Consistent format across all runbooks |
docs |
2026-03-22 |
Ideas — Personal & Creative
| Idea | Context | Category | Captured |
|---|---|---|---|
LilyPond → PDF pipeline |
Automate music notation compilation |
music |
2026-03-22 |
age encryption workflow doc |
Document full workflow for cold storage |
security |
2026-03-22 |
Certification Progress
Renewal Required
| Certification | Provider | Expiry | Status | Dependency |
|---|---|---|---|---|
LPIC-1 |
Linux Professional Institute |
Check expiry |
RENEW |
Blocks LPIC-2 pursuit |
Planned (After Urgent)
| Certification | Provider | Target | Status |
|---|---|---|---|
Claude Code Certification |
Anthropic |
Q2 2026 |
IN PROGRESS |
LPIC-2 |
Linux Professional Institute |
After LPIC-1 renewal |
Blocked |
DevNet Associate |
Cisco Developer Network |
Q3 2026 |
Draft (Project) |
CyberOps Associate |
Cisco Security Operations |
Q4 2026 |
Draft (Project) |
Language Certifications (Personal Development)
| Certification | Provider | Target | Status | Notes |
|---|---|---|---|---|
SIELE C1 |
Instituto Cervantes |
Q2 2026 |
ACTIVE |
Computer-based, take FIRST |
DELE C1 |
Instituto Cervantes |
Q3/Q4 2026 |
PLANNED |
After SIELE validates readiness |
Skill Focus: Comprensión auditiva (WEAK), Subjuntivo avanzado, Formal register
Full DELE Study Plan | include::partial$trackers/education/language-certifications.adoc[tag=skills-matrix] available
Weekly Checklist
-
PeopleSoft time submitted for pay period
-
Carryover items reviewed (>7 days = action required)
-
Certifications: Did I study this week?
-
Ideas: Promote 1-2 to active or archive stale
-
Blockers: Any progress? Escalation needed?
Infrastructure Status
HA Deployment Status
| System | Description | Status | Notes |
|---|---|---|---|
VyOS HA |
vyos-01 (kvm-01) + vyos-02 (kvm-02) with VRRP VIP |
✅ COMPLETE |
2026-03-07 - pfSense decommissioned |
BIND DNS HA |
bind-01 (kvm-01) + bind-02 (kvm-02) with AXFR |
✅ COMPLETE |
Zone transfer operational |
Vault HA |
Raft cluster (vault-01/02/03) |
✅ COMPLETE |
Integrated with PKI |
Keycloak Rebuild |
keycloak-01 corrupted, rebuild from scratch |
🔄 NEXT |
Priority P3 - SSO broken |
FreeIPA HA |
ipa-02 replica planned |
📋 PLANNED |
Linux auth redundancy |
AD DC HA |
home-dc02 replication |
📋 PLANNED |
Windows auth redundancy |
iPSK Manager HA |
ipsk-mgr-02 with MySQL replication |
📋 PLANNED |
PSK portal redundancy |
ISE HA |
PAN HA (ise-01 reconfigure) |
⏳ DEFERRED |
Wait until ise-02 stable |
ISE 3.5 Migration |
Upgrade path: 3.2p9 → 3.4 (P1) → 3.5 (target) |
📋 PLANNED |
After 3.4 Migration completes (Q2 2026) |
Single Points of Failure (CRITICAL)
| These systems have NO redundancy - outage impacts production. |
| System | Impact if Down | Mitigation |
|---|---|---|
ISE (ise-02) |
All 802.1X stops - wired and wireless auth fails |
ise-01 reconfiguration deferred until ise-02 stable |
Keycloak (keycloak-01) |
SAML/OIDC SSO broken (ISE admin, Grafana, etc.) |
NEXT PRIORITY - Rebuild runbook |
FreeIPA (ipa-01) |
Linux auth, sudo rules, HBAC fails |
ipa-02 replica planned |
AD DC (home-dc01) |
Windows auth, Kerberos, GPO fails |
home-dc02 replica planned |
iPSK Manager |
Self-service PSK portal unavailable |
ipsk-mgr-02 with MySQL replication planned |