Contempo operations

Priority Queue

Evidence-backed work from the September 27, 2026 estate diagnostic. Public-safe by design: no credentials, private paths, access tokens, or recovery keys are published here.

Updated September 27, 2026 24 open tasks ยท 0 confirmed P0 outages

Core status: OpenClaw, Matrix, A2A, both web hosts, all three game nodes, and continuous offsite backup destinations are reachable. P1 items are active defects or exposed security/recovery risks; P2 items are the next maintenance cycle; P3 items are planned improvements or dependency-blocked work.

P1 โ€” Act first

Target: next controlled maintenance window.

  1. P1-01

    Remove obsolete Contempo certificate lineages from the Mission/SEN host.

    Five expired, moved-domain lineages make Certbot fail twice daily. Archive the renewal definitions, remove only the obsolete lineages, clear the failed unit, and pass a renewal dry run without disturbing live SEN certificates.

    Open
  2. P1-02

    Restore reliable offsite backups for three AMP instances.

    Dune 2000, Vanilla Minecraft, and Verdant repeatedly time out waiting for AMP backups. Diagnose each instance, produce a fresh archive, upload it offsite, verify its size/hash or archive traversal, and leave the daily job green.

    Open
  3. P1-03

    Patch and reboot the Mission/SEN web host.

    The host requires a reboot and has 72 pending packages. Take a fresh application/site backup, record rollback evidence, patch in a maintenance window, reboot, then prove Apache, database, certificates, and public sites.

    Open
  4. P1-04

    Restore Windows disk-encryption protection.

    The system volume is encrypted but protection is suspended, and the secondary volume is unencrypted. Preserve recovery material first, re-enable protection on the system volume, and make an explicit encrypt-or-exempt decision for the secondary volume.

    Open
  5. P1-05

    Rotate and stop logging the secure coin-flip administrator capability.

    The service journal contains administrator-capability material. Remove it from logging, rotate the capability, restart only that service, and verify normal public operation without exposing the replacement.

    Open

P2 โ€” Next maintenance cycle

Reliability, recovery, and configuration hygiene.

  1. P2-01

    Patch and reboot the primary Contempo host.

    The host is healthy but requires a reboot and has 16 pending packages. Use a fresh verified backup and rollback plan, then prove Nginx, database, Matrix, Node services, and certificate renewal after reboot.

    Open
  2. P2-02

    Apply the local Ubuntu/WSL package backlog.

    Twenty-seven upgrades are pending. Review held packages, update in a low-impact window, and rerun service, package, and reboot-required checks.

    Open
  3. P2-03

    Repair or intentionally retire the Grim Jr reverse tunnel.

    The user service is failed and its endpoint is unreachable. Confirm whether the remote device still exists; restore and prove the tunnel if needed, otherwise disable and document retirement.

    Decision
  4. P2-04

    Move the Matrix access token to a SecretRef.

    The OpenClaw doctor reports a plaintext Matrix token in configuration. Create a recoverable secret reference, validate configuration, restart once, and prove encrypted Matrix send/receive health.

    Open
  5. P2-05

    Reconcile abandoned OpenClaw update history.

    Three update records remain abandoned even though the installed release is current. Back up first, run the supported repair path, and verify current version, plugins, channels, and a clean update ledger.

    Open
  6. P2-06

    Pin external OpenClaw plugin install specifications.

    Codex, Discord, and Matrix are recorded with unpinned package specifications. Pin each to the currently proven exact version and validate plugin discovery, configuration, and runtime health.

    Open
  7. P2-07

    Resolve the permanent outbound dead-letter entry.

    One 15-day-old delivery remains in the failed queue. Confirm it is obsolete, archive enough metadata for traceability, clear it through the supported queue path, and prove the queue is green.

    Open
  8. P2-08

    Refresh and automate Grim/Vault recovery bundles.

    The latest verified Grim and Vault bundles are eight days old. Produce fresh verified copies to continuous offsite storage and WorkHorse, automate an appropriate cadence, and schedule a real restore drill separately from archive verification.

    Open
  9. P2-09

    Restore Matrix secure-backup trust.

    The duplicate one-time-key defect is repaired and should not remain on the queue, but the separate secure-backup trust state is still unresolved. Preserve the verified device, reconcile trust without resetting encryption state, and prove backup/key recovery status.

    Open
  10. P2-10

    Review high-impact tool authority in shared chat contexts.

    The security audit detects a personal-assistant trust model serving allowlisted groups while broad runtime/filesystem tools remain available. Confirm each room's authority, reduce unnecessary tool reach, and keep privileged/private lanes isolated.

    Review
  11. P2-11

    Replace the stale public SEN status snapshot with live telemetry.

    The public status page still presents an August snapshot and can disagree with current services. Publish a sanitized live feed from the existing node telemetry, include freshness, and avoid claiming game availability without current evidence.

    Open
  12. P2-12

    Verify network firewall coverage for both public hosts.

    Host UFW is inactive on both servers. Confirm and document provider-firewall rules against observed public listeners; if coverage is absent, stage host-firewall rules with console access and rollback before enabling them.

    Review

P3 โ€” Planned / dependency-blocked

Do after higher-risk defects are closed.

  1. P3-01

    Decide whether Discord guild traffic should be enabled.

    The connector is healthy, but the guild allowlist is empty, so guild messages are blocked. Add only the intended server/channel if needed; otherwise document Discord as intentionally direct/presence-only.

    Decision
  2. P3-02

    Refresh and smoke-test the cold OpenClaw standby.

    The standby is correctly inactive but behind the current release. Back it up, update without activating its connectors, and prove it can be started only under the single-gateway recovery procedure.

    Open
  3. P3-03

    Decide whether to restore Tailscale remote administration.

    The local Tailscale client is logged out. Re-enroll only if it remains part of the intended admin path; otherwise remove stale expectations and retain the current local-only posture.

    Decision
  4. P3-04

    Apply retention to non-runtime local storage growth.

    Review old system images, Codex history, SEN migration backups, plugin build captures, generated media, and caches. Preserve unique recovery data first, then archive or remove only verified redundant material.

    Open
  5. P3-05

    Improve secondary Windows-volume headroom.

    The secondary volume has about 59 GB free. Identify growth sources, set a warning threshold, and relocate or remove only recoverable/non-runtime data.

    Monitor
  6. P3-06

    Acquire and install the PowerEdge T330 storage controller path.

    The four 2.4 TB SAS disks need a compatible PERC/HBA, correct backplane cables, and cache-protection hardware. After funding, inventory parts, update firmware, health-test every disk, then create the selected RAID 10 and install Ubuntu Server.

    Funding
  7. P3-07

    Expand the T330 to a practical memory floor.

    The server currently has one working 16 GB DIMM. Validate supported matched memory, then target at least 32 GB before migrating production workloads; 64 GB is preferred if cost permits.

    Funding