Contempo operations
Priority Queue
Evidence-backed work from the September 27, 2026 estate diagnostic. Public-safe by design: no credentials, private paths, access tokens, or recovery keys are published here.
Core status: OpenClaw, Matrix, A2A, both web hosts, all three game nodes, and continuous offsite backup destinations are reachable. P1 items are active defects or exposed security/recovery risks; P2 items are the next maintenance cycle; P3 items are planned improvements or dependency-blocked work.
P1 โ Act first
Target: next controlled maintenance window.
- P1-01Open
Remove obsolete Contempo certificate lineages from the Mission/SEN host.
Five expired, moved-domain lineages make Certbot fail twice daily. Archive the renewal definitions, remove only the obsolete lineages, clear the failed unit, and pass a renewal dry run without disturbing live SEN certificates.
- P1-02Open
Restore reliable offsite backups for three AMP instances.
Dune 2000, Vanilla Minecraft, and Verdant repeatedly time out waiting for AMP backups. Diagnose each instance, produce a fresh archive, upload it offsite, verify its size/hash or archive traversal, and leave the daily job green.
- P1-03Open
Patch and reboot the Mission/SEN web host.
The host requires a reboot and has 72 pending packages. Take a fresh application/site backup, record rollback evidence, patch in a maintenance window, reboot, then prove Apache, database, certificates, and public sites.
- P1-04Open
Restore Windows disk-encryption protection.
The system volume is encrypted but protection is suspended, and the secondary volume is unencrypted. Preserve recovery material first, re-enable protection on the system volume, and make an explicit encrypt-or-exempt decision for the secondary volume.
- P1-05Open
Rotate and stop logging the secure coin-flip administrator capability.
The service journal contains administrator-capability material. Remove it from logging, rotate the capability, restart only that service, and verify normal public operation without exposing the replacement.
P2 โ Next maintenance cycle
Reliability, recovery, and configuration hygiene.
- P2-01Open
Patch and reboot the primary Contempo host.
The host is healthy but requires a reboot and has 16 pending packages. Use a fresh verified backup and rollback plan, then prove Nginx, database, Matrix, Node services, and certificate renewal after reboot.
- P2-02Open
Apply the local Ubuntu/WSL package backlog.
Twenty-seven upgrades are pending. Review held packages, update in a low-impact window, and rerun service, package, and reboot-required checks.
- P2-03Decision
Repair or intentionally retire the Grim Jr reverse tunnel.
The user service is failed and its endpoint is unreachable. Confirm whether the remote device still exists; restore and prove the tunnel if needed, otherwise disable and document retirement.
- P2-04Open
Move the Matrix access token to a SecretRef.
The OpenClaw doctor reports a plaintext Matrix token in configuration. Create a recoverable secret reference, validate configuration, restart once, and prove encrypted Matrix send/receive health.
- P2-05Open
Reconcile abandoned OpenClaw update history.
Three update records remain abandoned even though the installed release is current. Back up first, run the supported repair path, and verify current version, plugins, channels, and a clean update ledger.
- P2-06Open
Pin external OpenClaw plugin install specifications.
Codex, Discord, and Matrix are recorded with unpinned package specifications. Pin each to the currently proven exact version and validate plugin discovery, configuration, and runtime health.
- P2-07Open
Resolve the permanent outbound dead-letter entry.
One 15-day-old delivery remains in the failed queue. Confirm it is obsolete, archive enough metadata for traceability, clear it through the supported queue path, and prove the queue is green.
- P2-08Open
Refresh and automate Grim/Vault recovery bundles.
The latest verified Grim and Vault bundles are eight days old. Produce fresh verified copies to continuous offsite storage and WorkHorse, automate an appropriate cadence, and schedule a real restore drill separately from archive verification.
- P2-09Open
Restore Matrix secure-backup trust.
The duplicate one-time-key defect is repaired and should not remain on the queue, but the separate secure-backup trust state is still unresolved. Preserve the verified device, reconcile trust without resetting encryption state, and prove backup/key recovery status.
- P2-10Review
Review high-impact tool authority in shared chat contexts.
The security audit detects a personal-assistant trust model serving allowlisted groups while broad runtime/filesystem tools remain available. Confirm each room's authority, reduce unnecessary tool reach, and keep privileged/private lanes isolated.
- P2-11Open
Replace the stale public SEN status snapshot with live telemetry.
The public status page still presents an August snapshot and can disagree with current services. Publish a sanitized live feed from the existing node telemetry, include freshness, and avoid claiming game availability without current evidence.
- P2-12Review
Verify network firewall coverage for both public hosts.
Host UFW is inactive on both servers. Confirm and document provider-firewall rules against observed public listeners; if coverage is absent, stage host-firewall rules with console access and rollback before enabling them.
P3 โ Planned / dependency-blocked
Do after higher-risk defects are closed.
- P3-01Decision
Decide whether Discord guild traffic should be enabled.
The connector is healthy, but the guild allowlist is empty, so guild messages are blocked. Add only the intended server/channel if needed; otherwise document Discord as intentionally direct/presence-only.
- P3-02Open
Refresh and smoke-test the cold OpenClaw standby.
The standby is correctly inactive but behind the current release. Back it up, update without activating its connectors, and prove it can be started only under the single-gateway recovery procedure.
- P3-03Decision
Decide whether to restore Tailscale remote administration.
The local Tailscale client is logged out. Re-enroll only if it remains part of the intended admin path; otherwise remove stale expectations and retain the current local-only posture.
- P3-04Open
Apply retention to non-runtime local storage growth.
Review old system images, Codex history, SEN migration backups, plugin build captures, generated media, and caches. Preserve unique recovery data first, then archive or remove only verified redundant material.
- P3-05Monitor
Improve secondary Windows-volume headroom.
The secondary volume has about 59 GB free. Identify growth sources, set a warning threshold, and relocate or remove only recoverable/non-runtime data.
- P3-06Funding
Acquire and install the PowerEdge T330 storage controller path.
The four 2.4 TB SAS disks need a compatible PERC/HBA, correct backplane cables, and cache-protection hardware. After funding, inventory parts, update firmware, health-test every disk, then create the selected RAID 10 and install Ubuntu Server.
- P3-07Funding
Expand the T330 to a practical memory floor.
The server currently has one working 16 GB DIMM. Validate supported matched memory, then target at least 32 GB before migrating production workloads; 64 GB is preferred if cost permits.