Weekly Review

Weekly review for Sunday planning. Audit carryover, review ideas, track certifications, verify PeopleSoft.

CRITICAL - Certification Deadlines

URGENT — Performance Review Deadline (June 1, 2026)

Certification Provider Deadline Status Impact

CISSP

ISC² — Certified Information Systems Security Professional

June 1, 2026

ACTIVE — Phase 0 (Project)

Required for performance review

RHCSA 9

Red Hat Certified System Administrator

June 1, 2026

ACTIVE — 21-phase curriculum (Project)

Required for performance review

53 days remaining until June 1st deadline.
These are PERFORMANCE REVIEW requirements. Missing deadline = career impact.

PeopleSoft Time Entry

Are you behind on time entry? Submit biweekly.

Active Projects

Project Code Combo Activity Budget (hrs)

Recognition Kiosk (Poppulo) - IS Labor

000018166

000018623

20

12

Spectrum TV/GetWell iPad Refresh

000016444

000018551

20

Azure Legacy Migration

000018100

000018619

20

Cisco Secure Endpoint Replacement

000017633

000018546

Windows 11 Device Hardening

000017706

000018549

MSCHAPv2 to EAP-TLS Migration

ISE 3.4 Migration

QRadar → Sentinel Migration

Standard Administrative Codes

Field Value Notes

Account

605010

InfoSec Engineering

Fund Code

1010

Department

8492000

PC Unit

PC100

Carryover Audit

Review items carried over too long. Either DO them or REMOVE them.

Carryover Backlog (CRITICAL)

Task Details Origin Days Status

k3s NAT verification

NAT rule 170 for 10.42.0.0/16 pod network - test internet connectivity

2026-03-09

31

P0 - BLOCKING

Wazuh indexer recovery

Restart pod after NAT confirmed working - SIEM visibility blocked

2026-03-09

31

P0 - Blocked by k3s

Strongline Gateway VLAN fix

8 devices in wrong identity group (David Rukiza assigned)

2026-03-16

24

P0 - TODO

Monad Pipeline Evaluation

Test pipeline creation, input sources, transforms (LEAD ROLE)

2026-03-11

29

P1 - TODO

Vocera EAP-TLS Supplicant Fix

~10 phones failing 802.1X, missing supplicant config

2026-03-12

28

P1 - TODO

ISE MnT Messaging Service

Enable "Use ISE Messaging Service for UDP syslogs delivery"

2026-03-12

28

P2 - TODO

ISE Patch 9 upgrade

ISE 3.2 Patch 9 addresses known replication issues

2026-03-12

28

P2 - TODO

BLOCKERS — Fix Immediately

Task Details Origin Days Impact

Z Fold 7 Termux

gopass and SSH not working

2026-03-10

30

BLOCKER — Cannot access passwords on mobile

gopass v3 organization

Inconsistent structure, poor key-value usage

2026-03-20

20

Inefficient password management, no aggregation

Ideas Backlog

Review weekly - promote to active or archive.

Ideas — Infrastructure

Idea Context Category Captured

Vault HA runbook

3-node Vault cluster on kvm-02

infra

2026-03-22

k3s HA runbook

3-node control plane

infra

2026-03-22

BIND secondary DNS

bind-02 for HA (currently SPOF)

infra

2026-03-22

ipa-02 replica

FreeIPA HA (currently SPOF)

infra

2026-03-22

Borg backup dashboard

Visualize backup status across hosts

infra

2026-03-22

Vault backup to S3

Automated Vault snapshots to MinIO

infra

2026-03-22


Ideas — Development & Tools

Idea Context Category Captured

netapi vyos commands

Add VyOS API integration (replaced pfSense)

netapi

2026-03-22

netapi bind commands

Add BIND nsupdate/rndc integration (DNS management)

netapi

2026-03-22

netapi k3s commands

kubectl wrapper with common patterns

netapi

2026-03-22

netapi batch operations

Cross-vendor batch commands (e.g., backup all)

netapi

2026-03-22

adoc improvements

Add --watch flag, live reload

tooling

2026-03-22

tmux sessionizer

Project-based tmux sessions (like ThePrimeagen)

tooling

2026-03-22

fzf git integrations

Interactive branch switching, log searching

tooling

2026-03-22

gopass v3 restructure

Use gopass-personal-docs templates (bills, storage, subscriptions)

tooling

2026-03-22

gopass-query enhancements

Add gopass-query vehicles, gopass-query insurance, monthly totals

tooling

2026-03-22

gopass v3 → ADMINISTRATIO migration

Script to move remaining entries from old structure

tooling

2026-03-22


Ideas — Education & Training

Idea Context Category Captured

AWK curriculum

Like regex curriculum — 10 modules, drills

education

2026-03-22

sed curriculum

Pattern-based editing mastery

education

2026-03-22

Lua/Neovim curriculum

Plugin development, lazy.nvim patterns

education

2026-03-22

Go CLI curriculum

Learn Go via CLI tool development

education

2026-03-22

Anki deck from Don Quijote

Extract vocabulary to spaced repetition

language

2026-03-22

DELE C1 mock exams

Practice test structure

language

2026-03-22


Ideas — Documentation

Idea Context Category Captured

Antora search fix

Lunr index too large — explore alternatives

docs

2026-03-22

domus-* cross-reference audit

Find and fix broken xrefs across all repos

docs

2026-03-22

Runbook template standardization

Consistent format across all runbooks

docs

2026-03-22


Ideas — Personal & Creative

Idea Context Category Captured

LilyPond → PDF pipeline

Automate music notation compilation

music

2026-03-22

age encryption workflow doc

Document full workflow for cold storage

security

2026-03-22

Certification Progress

Renewal Required

Certification Provider Expiry Status Dependency

LPIC-1

Linux Professional Institute

Check expiry

RENEW

Blocks LPIC-2 pursuit

Planned (After Urgent)

Certification Provider Target Status

Claude Code Certification

Anthropic

Q2 2026

IN PROGRESS

LPIC-2

Linux Professional Institute

After LPIC-1 renewal

Blocked

DevNet Associate

Cisco Developer Network

Q3 2026

Draft (Project)

CyberOps Associate

Cisco Security Operations

Q4 2026

Draft (Project)

Language Certifications (Personal Development)

Certification Provider Target Status Notes

SIELE C1

Instituto Cervantes

Q2 2026

ACTIVE

Computer-based, take FIRST

DELE C1

Instituto Cervantes

Q3/Q4 2026

PLANNED

After SIELE validates readiness

Skill Focus: Comprensión auditiva (WEAK), Subjuntivo avanzado, Formal register

Full DELE Study Plan | include::partial$trackers/education/language-certifications.adoc[tag=skills-matrix] available

Weekly Checklist

  • PeopleSoft time submitted for pay period

  • Carryover items reviewed (>7 days = action required)

  • Certifications: Did I study this week?

  • Ideas: Promote 1-2 to active or archive stale

  • Blockers: Any progress? Escalation needed?

Infrastructure Status

HA Deployment Status

System Description Status Notes

VyOS HA

vyos-01 (kvm-01) + vyos-02 (kvm-02) with VRRP VIP

✅ COMPLETE

2026-03-07 - pfSense decommissioned

BIND DNS HA

bind-01 (kvm-01) + bind-02 (kvm-02) with AXFR

✅ COMPLETE

Zone transfer operational

Vault HA

Raft cluster (vault-01/02/03)

✅ COMPLETE

Integrated with PKI

Keycloak Rebuild

keycloak-01 corrupted, rebuild from scratch

🔄 NEXT

Priority P3 - SSO broken

FreeIPA HA

ipa-02 replica planned

📋 PLANNED

Linux auth redundancy

AD DC HA

home-dc02 replication

📋 PLANNED

Windows auth redundancy

iPSK Manager HA

ipsk-mgr-02 with MySQL replication

📋 PLANNED

PSK portal redundancy

ISE HA

PAN HA (ise-01 reconfigure)

⏳ DEFERRED

Wait until ise-02 stable

ISE 3.5 Migration

Upgrade path: 3.2p9 → 3.4 (P1) → 3.5 (target)

📋 PLANNED

After 3.4 Migration completes (Q2 2026)

Single Points of Failure (CRITICAL)

These systems have NO redundancy - outage impacts production.
System Impact if Down Mitigation

ISE (ise-02)

All 802.1X stops - wired and wireless auth fails

ise-01 reconfiguration deferred until ise-02 stable

Keycloak (keycloak-01)

SAML/OIDC SSO broken (ISE admin, Grafana, etc.)

NEXT PRIORITY - Rebuild runbook

FreeIPA (ipa-01)

Linux auth, sudo rules, HBAC fails

ipa-02 replica planned

AD DC (home-dc01)

Windows auth, Kerberos, GPO fails

home-dc02 replica planned

iPSK Manager

Self-service PSK portal unavailable

ipsk-mgr-02 with MySQL replication planned