<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Infra on Alwaldend</title>
		<link>https://www-staging.alwaldend.com/categories/infra/</link>
		<description>Recent content in Infra on Alwaldend</description>
		<generator>Hugo</generator>
		<language>en</language>
		
		
		
		
			<atom:link href="https://www-staging.alwaldend.com/categories/infra/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Infra</title>
				<link>https://www-staging.alwaldend.com/docs/infra/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/</guid>
				<description>&lt;p&gt;This tree contains&#xA;&lt;a href=&#34;https://en.wikipedia.org/wiki/Infrastructure_as_code&#34;&gt;infrastructure as code&lt;/a&gt;.&#xA;Tracked source follows the repository&amp;rsquo;s public-source policy. Infrastructure&#xA;facts are not confidential merely because they are operational, generated, or&#xA;live. Reports may include them unless they contain credentials, other secrets,&#xA;or personal information. Inspect raw state, plans, inventories, and decrypted&#xA;configuration because those artifacts can contain prohibited content; do not&#xA;track the artifacts themselves.&lt;/p&gt;&#xA;&lt;p&gt;Each infrastructure project owns its specifications and maintained changes&#xA;in &lt;code&gt;&amp;lt;project&amp;gt;/openspec/&lt;/code&gt;. Use the &lt;a href=&#34;../tools/openspec/README.md&#34;&gt;pinned OpenSpec workflow&lt;/a&gt;&#xA;with that project selected. These specifications describe checked-in definitions;&#xA;they do not establish deployed state or authorize infrastructure operations.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/arch/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/arch/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-architecture-specification&#34;&gt;Infrastructure architecture Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-architecture-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the maintained infrastructure diagrams owned by &lt;code&gt;infra/arch&lt;/code&gt;.&#xA;The baseline is checked-in source at revision&#xA;&lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;, observed on 2026-09-08.&#xA;These diagrams describe their source document; they do not establish live&#xA;inventory, deployment, or health.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-canonical-multi-page-architecture-source&#34;&gt;Requirement: Canonical multi-page architecture source&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-canonical-multi-page-architecture-source&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The project SHALL use &lt;code&gt;arch.drawio&lt;/code&gt; as the canonical source for its maintained&#xA;SVG diagrams and SHALL expose the source through the &lt;code&gt;//infra/arch&lt;/code&gt; editor&#xA;target. The named render mapping SHALL preserve all 15 source pages, including&#xA;the five pages classified as archives.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/ceph/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ceph/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;ceph-infrastructure-specification&#34;&gt;Ceph infrastructure specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#ceph-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the single-host Ceph CRUSH map maintained by &lt;code&gt;infra/ceph&lt;/code&gt; and its&#xA;documented operator workflow. This owner contains a map and documentation;&#xA;its BUILD file exposes documentation, not a Ceph deployment target. The&#xA;baseline describes checked-in source, not an observed running cluster.&lt;/p&gt;&#xA;&lt;p&gt;Baseline revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observed: 2026-09-08. Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/&#34;&gt;owner README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;BUILD&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../crush_map.txt&#34;&gt;CRUSH map&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-single-host-crush-topology&#34;&gt;Requirement: Single-host CRUSH topology&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-single-host-crush-topology&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The maintained CRUSH map SHALL place four HDD devices, &lt;code&gt;osd.0&lt;/code&gt; through&#xA;&lt;code&gt;osd.3&lt;/code&gt;, in the &lt;code&gt;host1&lt;/code&gt; bucket beneath the &lt;code&gt;default&lt;/code&gt; root, using the declared&#xA;device weights and &lt;code&gt;straw2&lt;/code&gt; bucket algorithm.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/dns/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/dns/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-dns&#34;&gt;Infrastructure DNS&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-dns&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe owner-local Terraform DNS declarations and runtime source-ownership&#xA;validation for global and dc1 records. This contract describes checked-in&#xA;source; it does not establish live adoption or authorize infrastructure writes.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/&#34;&gt;component documentation&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;target definitions&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../cmd/lint/main.go&#34;&gt;runtime linter&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../tf/dns.tf&#34;&gt;Terraform root&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-aggregate-records-from-their-owning-components&#34;&gt;Requirement: Aggregate records from their owning components&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-aggregate-records-from-their-owning-components&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;DNS declarations SHALL remain in their owners&amp;rsquo; &lt;code&gt;dnsconfig.json&lt;/code&gt; files. Runtime&#xA;inventory SHALL discover all canonical files, including nested modules and&#xA;empty declarations, without a checked-in ownership registry. The inventory&#xA;SHALL print a deterministic table of files, DNS names, types and views.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/openspec/specs/infra-flux/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/openspec/specs/infra-flux/spec/</guid>
				<description>&lt;h1 id=&#34;flux-infrastructure-specification&#34;&gt;Flux infrastructure specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#flux-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the Flux management cluster&amp;rsquo;s VM definition, K3s configuration,&#xA;and Git reconciliation entry points owned by &lt;code&gt;infra/flux&lt;/code&gt;. The &lt;code&gt;tf_setup&lt;/code&gt;,&#xA;&lt;code&gt;ansible&lt;/code&gt;, and &lt;code&gt;cl&lt;/code&gt; packages implement stages of this owner. This is a&#xA;checked-in source baseline; no cluster health or successful deployment was&#xA;observed for this specification.&lt;/p&gt;&#xA;&lt;p&gt;Baseline revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observed: 2026-09-08. Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/flux/&#34;&gt;owner README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;BUILD&lt;/a&gt;, and the implementation links below.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-dedicated-k3s-management-host&#34;&gt;Requirement: Dedicated K3s management host&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-dedicated-k3s-management-host&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Terraform setup SHALL declare a Proxmox VM in the &lt;code&gt;src_infra_flux&lt;/code&gt; pool with&#xA;two cores, 4096 MiB memory, and separate 20 GiB boot, K3s data, and K3s&#xA;storage disks. The deployment playbook SHALL apply the shared host and K3s&#xA;roles, and the K3s configuration SHALL enable secrets encryption and disable&#xA;the bundled Traefik component.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Flux DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before adoption and SHALL remain enabled&#xA;by default after authorized adoption. Adoption SHALL bind existing provider records&#xA;to the owner&amp;rsquo;s state without adding, changing, replacing, or deleting DNS records.&#xA;Subsequent reconciliation of unchanged declarations SHALL preserve owned and&#xA;unrelated records.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/openspec/specs/infra-forgejo/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/openspec/specs/infra-forgejo/spec/</guid>
				<description>&lt;h1 id=&#34;forgejo-infrastructure-specification&#34;&gt;Forgejo infrastructure specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#forgejo-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the Forgejo service owned by &lt;code&gt;infra/forgejo&lt;/code&gt;, including Xen&#xA;Orchestra provisioning, Ansible service configuration, and Terraform account&#xA;and repository management. The &lt;code&gt;tf_setup&lt;/code&gt;, &lt;code&gt;ansible&lt;/code&gt;, and &lt;code&gt;tf&lt;/code&gt; packages are&#xA;implementation stages of this owner. This baseline records source guarantees&#xA;and prerequisites; it does not verify live service health or restore earlier&#xA;Forgejo data.&lt;/p&gt;&#xA;&lt;p&gt;Baseline revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observed: 2026-09-08. Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/forgejo/&#34;&gt;owner README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;BUILD&lt;/a&gt;, and the implementation links below.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-scoped-xen-orchestra-provisioning-and-disk-checks&#34;&gt;Requirement: Scoped Xen Orchestra provisioning and disk checks&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-scoped-xen-orchestra-provisioning-and-disk-checks&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Setup SHALL provision Forgejo through Xen Orchestra in the&#xA;&lt;code&gt;src_infra_dc1_forgejo1&lt;/code&gt; resource set using the owner&amp;rsquo;s Vault AppRole and&#xA;packaged XO OIDC login flow. The VM SHALL declare 20 GiB boot, 40 GiB&#xA;Forgejo, and 5 GiB Traefik disks. Ansible SHALL verify the expected sizes&#xA;of &lt;code&gt;xvdb&lt;/code&gt; and &lt;code&gt;xvdc&lt;/code&gt; before applying the service roles that use them.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Forgejo DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before adoption and SHALL remain enabled&#xA;by default after authorized adoption. Adoption SHALL bind existing provider records&#xA;to the owner&amp;rsquo;s state without adding, changing, replacing, or deleting DNS records.&#xA;Subsequent reconciliation of unchanged declarations SHALL preserve owned and&#xA;unrelated records.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/openspec/specs/infra-forgejo-runner/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/openspec/specs/infra-forgejo-runner/spec/</guid>
				<description>&lt;h1 id=&#34;forgejo-runner-infrastructure-specification&#34;&gt;Forgejo runner infrastructure specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#forgejo-runner-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the Forgejo Actions runner VM and deployment scaffold owned by&#xA;&lt;code&gt;infra/forgejo_runner&lt;/code&gt;. Its &lt;code&gt;tf_setup&lt;/code&gt; and &lt;code&gt;ansible&lt;/code&gt; packages are stages of&#xA;this owner. The runner role is commented out in the baseline playbook;&#xA;the checked-in configuration therefore does not establish a deployed or&#xA;registered Actions worker. No live runner state was observed.&lt;/p&gt;&#xA;&lt;p&gt;Baseline revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observed: 2026-09-08. Sources:&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/forgejo_runner/&#34;&gt;owner README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;BUILD&lt;/a&gt;, and the implementation&#xA;links below.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Forgejo Actions runner DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped execution, adoption of existing records,&#xA;and offline source checks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before adoption and SHALL remain enabled&#xA;by default after authorized adoption. Adoption SHALL bind existing provider records&#xA;to the owner&amp;rsquo;s state without adding, changing, replacing, or deleting DNS records.&#xA;Subsequent reconciliation of unchanged declarations SHALL preserve owned and&#xA;unrelated records.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/github/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/github/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-github&#34;&gt;Infrastructure GitHub&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-github&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe Terraform ownership of the catalog-defined GitHub organization,&#xA;repositories, member access, default-branch restrictions, and Pages settings.&#xA;These requirements describe source guarantees; they do not assert that a plan&#xA;has been applied or that published sites are healthy.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/&#34;&gt;component documentation&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/README.md&#34;&gt;Terraform workflow&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../../repos/README.md&#34;&gt;shared catalog&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/BUILD.bazel&#34;&gt;packaged inputs&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/repositories.tf&#34;&gt;repository resources&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/organization.tf&#34;&gt;organization access&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/branch_rules.tf&#34;&gt;branch rules&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../tf/provider.tf&#34;&gt;provider configuration&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-consume-the-shared-organization-and-repository-catalog&#34;&gt;Requirement: Consume the shared organization and repository catalog&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-consume-the-shared-organization-and-repository-catalog&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The package SHALL consume organization identity, administrator and developer&#xA;lists, repository identity, default branches, repository settings, and Pages&#xA;configuration through &lt;code&gt;infra/repos/tf&lt;/code&gt;. It SHALL NOT generate a second inventory&#xA;from the build-project registry. Its provider instance SHALL require exactly&#xA;one configured GitHub organization.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/openspec/specs/infra-harbor/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/openspec/specs/infra-harbor/spec/</guid>
				<description>&lt;h1 id=&#34;harbor-infrastructure-specification&#34;&gt;Harbor infrastructure specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#harbor-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the Harbor registry infrastructure owned by &lt;code&gt;infra/harbor&lt;/code&gt;, spanning&#xA;Proxmox setup, K3s host configuration, Flux-managed chart declarations, and&#xA;Harbor service Terraform. The &lt;code&gt;tf_setup&lt;/code&gt;, &lt;code&gt;ansible&lt;/code&gt;, &lt;code&gt;cl&lt;/code&gt;, and &lt;code&gt;tf&lt;/code&gt; packages&#xA;are implementation stages of this owner. This is a checked-in source&#xA;baseline, without an observation of live registry availability or deployment&#xA;success.&lt;/p&gt;&#xA;&lt;p&gt;Baseline revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observed: 2026-09-08. Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/harbor/&#34;&gt;owner README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;BUILD&lt;/a&gt;, and the implementation links below.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-dedicated-k3s-registry-host&#34;&gt;Requirement: Dedicated K3s registry host&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-dedicated-k3s-registry-host&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Setup SHALL declare a Proxmox VM in the &lt;code&gt;src_infra_harbor&lt;/code&gt; pool with two&#xA;cores, 4096 MiB memory, and 20 GiB boot, 20 GiB K3s data, and 40 GiB K3s&#xA;storage disks. Ansible SHALL apply the shared host and K3s roles with K3s&#xA;secrets encryption enabled. Its firewall variables SHALL scope API port&#xA;6443 access to the declared Flux host address.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Harbor DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before adoption and SHALL default to&#xA;enabled in the reviewed adoption revision and after adoption. Adoption SHALL&#xA;import the exact existing provider records and require a scoped no-change import plan before saved-plan&#xA;apply. Subsequent reconciliation with unchanged root inputs SHALL preserve&#xA;adopted records, unrelated DNS records, and non-DNS resources in the root.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/ingress/openspec/specs/infra-ingress/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ingress/openspec/specs/infra-ingress/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-ingress&#34;&gt;Infrastructure ingress&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-ingress&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe Yandex Cloud ingress provisioning, the RouterOS WireGuard connection,&#xA;and the Ansible-managed Traefik configuration. The baseline covers checked-in&#xA;desired state, not a live routing or availability observation.&lt;/p&gt;&#xA;&lt;p&gt;Baseline source revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/ingress/&#34;&gt;component contract&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/vms.tf&#34;&gt;VM resources&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/wireguard.tf&#34;&gt;WireGuard resources&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../ansible/playbook_deploy.yaml&#34;&gt;deployment playbook&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../ansible/files/traefik.toml&#34;&gt;Traefik entry points&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../ansible/files/traefik_dynamic.toml&#34;&gt;Traefik routes&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-provision-ingress-hosts-from-the-declared-host-map&#34;&gt;Requirement: Provision ingress hosts from the declared host map&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-provision-ingress-hosts-from-the-declared-host-map&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Terraform SHALL create addresses, encrypted boot disks, and instances for the&#xA;active &lt;code&gt;local.vpc&lt;/code&gt; entries, using the shared cloud-init source. The baseline&#xA;active map SHALL contain &lt;code&gt;host1&lt;/code&gt; in &lt;code&gt;ru-central1-d&lt;/code&gt;; the commented &lt;code&gt;host2&lt;/code&gt; entry&#xA;SHALL NOT be treated as an enabled resource declaration.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/ingress/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ingress/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define retained ingress DNS ownership through the owner&amp;rsquo;s &lt;code&gt;tf&lt;/code&gt; root,&#xA;including canonical declarations, scoped execution, and offline source checks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/mikrotik/openspec/specs/infra-mikrotik/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/mikrotik/openspec/specs/infra-mikrotik/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-mikrotik&#34;&gt;Infrastructure MikroTik&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-mikrotik&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the checked-in RouterOS export snapshots and site DNS declarations for&#xA;the dc1 routers. This package is a documentation and record-input owner: its&#xA;BUILD file declares no router deployment executable. Export contents are&#xA;historical source evidence, not a verification of current device configuration.&lt;/p&gt;&#xA;&lt;p&gt;Baseline source revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/mikrotik/&#34;&gt;export workflow&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;package targets&lt;/a&gt;,&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/mikrotik/router1.rsc&#34;&gt;router1 snapshot&lt;/a&gt;,&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/mikrotik/router2.rsc&#34;&gt;router2 snapshot&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../dnsconfig.json&#34;&gt;DNS declarations&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/mikrotik/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/mikrotik/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define MikroTik router DNS management through the owner&amp;rsquo;s &lt;code&gt;tf&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/mikrotik/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/mikrotik/tf/</guid>
				<description>&lt;h1 id=&#34;dns-terraform&#34;&gt;DNS Terraform&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#dns-terraform&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;p&gt;This root packages the owner&amp;rsquo;s canonical &lt;a href=&#34;../dnsconfig.json&#34;&gt;DNS declaration&lt;/a&gt;&#xA;through the shared DNS module and keeps state in the owner AppRole&amp;rsquo;s Vault HTTP&#xA;backend. The root contains DNS resources only. &lt;code&gt;dns_enabled&lt;/code&gt; defaults to &lt;code&gt;true&lt;/code&gt;&#xA;after verified adoption. Keep it enabled to retain existing records; disabling&#xA;it would propose deletion.&lt;/p&gt;&#xA;&lt;p&gt;Use the normal &lt;code&gt;//infra/mikrotik/tf:tf.&amp;lt;operation&amp;gt;&lt;/code&gt; wrappers for this DNS-only&#xA;root. The &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;DNS migration procedure&lt;/a&gt; owns credential&#xA;provisioning, reconciliation, and recovery. The&#xA;&lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption record&lt;/a&gt;&#xA;contains the import and inventory-preservation evidence. The package exposes&#xA;&lt;code&gt;//infra/mikrotik/tf:tf_tests.fmt_test&lt;/code&gt; for offline formatting checks.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/nas/openspec/specs/infra-nas/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/nas/openspec/specs/infra-nas/spec/</guid>
				<description>&lt;h1 id=&#34;nas-infrastructure-specification&#34;&gt;NAS infrastructure Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#nas-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the TrueNAS-related configuration surface currently owned by&#xA;&lt;code&gt;infra/nas&lt;/code&gt;. The baseline is checked-in source at revision&#xA;&lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;, observed on 2026-09-08.&#xA;The directory contains an AL configuration, DNS declarations, Vault wrappers,&#xA;and brief documentation. It does not contain a TrueNAS provisioning playbook&#xA;or Terraform configuration, and this baseline makes no claim about live NAS&#xA;configuration or availability.&lt;/p&gt;&#xA;&lt;p&gt;Source baseline limitation: the owning BUILD file restricts the AL target&amp;rsquo;s&#xA;visibility to &lt;code&gt;//infra/harvester:__subpackages__&lt;/code&gt;, although &lt;code&gt;infra/harvester&lt;/code&gt;&#xA;does not exist in this revision. This declaration does not establish a working&#xA;consumer integration.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/nas/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/nas/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define NAS DNS management through the owner&amp;rsquo;s &lt;code&gt;tf&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/nas/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/nas/tf/</guid>
				<description>&lt;h1 id=&#34;dns-terraform&#34;&gt;DNS Terraform&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#dns-terraform&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;p&gt;This root packages the owner&amp;rsquo;s canonical &lt;a href=&#34;../dnsconfig.json&#34;&gt;DNS declarations&lt;/a&gt;&#xA;through the shared DNS module and keeps state in the owner AppRole&amp;rsquo;s Vault HTTP&#xA;backend. The root contains DNS resources only. &lt;code&gt;dns_enabled&lt;/code&gt; defaults to &lt;code&gt;true&lt;/code&gt;&#xA;after verified adoption. Keep it enabled to retain existing records; disabling&#xA;it would propose deletion.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;DNS migration procedure&lt;/a&gt; owns credential provisioning,&#xA;reconciliation, and recovery. The &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption record&lt;/a&gt;&#xA;contains import and verification evidence. Use the &lt;code&gt;//infra/nas/tf:tf&lt;/code&gt; wrappers&#xA;for operational commands and &lt;code&gt;//infra/nas/tf:tf_tests.fmt_test&lt;/code&gt; for offline&#xA;source validation.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/openhands/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/openhands/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define OpenHands DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before adoption and SHALL default to&#xA;enabled in the reviewed adoption revision. Adoption SHALL bind existing records&#xA;to their exact provider identities and SHALL preserve their declared attributes.&#xA;Existing-record adoption SHALL contain no DNS record additions, changes,&#xA;replacements, or deletions. Verified missing declarations MAY be provisioned&#xA;through an exact additions-only DNS plan that preserves every existing record&#xA;and excludes non-DNS managed-resource changes. After deployment, default DNS&#xA;reconciliation SHALL retain the bindings and preserve unrelated provider records.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/pve/openspec/specs/infra-pve/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/pve/openspec/specs/infra-pve/spec/</guid>
				<description>&lt;h1 id=&#34;proxmox-infrastructure-specification&#34;&gt;Proxmox infrastructure Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#proxmox-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Specify the Proxmox cluster configuration, resource pools, and bootstrap test&#xA;VM owned by &lt;code&gt;infra/pve&lt;/code&gt;. The baseline is checked-in source at revision&#xA;&lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;, observed on 2026-09-08.&#xA;It describes declared infrastructure and packaged operator entry points;&#xA;deployment and cluster health have not been observed for this baseline.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-approle-resource-pools&#34;&gt;Requirement: AppRole resource pools&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-approle-resource-pools&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The Terraform configuration SHALL resolve the members of Vault&amp;rsquo;s &lt;code&gt;approles&lt;/code&gt;&#xA;identity group and declare one Proxmox pool per resolved entity, keyed and&#xA;named by that entity&amp;rsquo;s name. It SHALL also declare a separate &lt;code&gt;templates&lt;/code&gt; pool.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/pve/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/pve/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Proxmox cluster DNS management through the owner&amp;rsquo;s &lt;code&gt;tf&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/repos/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/repos/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;repository-catalog-specification&#34;&gt;repository-catalog Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#repository-catalog-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define shared organization, repository identity, naming, and named access&#xA;configuration for the GitHub, GitLab, and Forgejo infrastructure consumers.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-authoritative-organization-and-repository-inventory&#34;&gt;Requirement: Authoritative organization and repository inventory&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-authoritative-organization-and-repository-inventory&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The repository catalog SHALL store shared defaults and schema version at its&#xA;root, one configuration file per organization, and one configuration file per&#xA;repository beneath its organization. Those records SHALL own the configured&#xA;organizations, repositories, named administrators, and named developers.&#xA;Each forge consumer SHALL use&#xA;that catalog for its selected repositories and named roles, preserving&#xA;forge-specific settings without maintaining another copy of the inventory.&#xA;Authentication and service-specific grants SHALL remain with their existing&#xA;owners.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/src/openspec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/src/openspec/</guid>
				<description>&lt;h1 id=&#34;repository-evolution&#34;&gt;Repository evolution&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#repository-evolution&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;p&gt;This OpenSpec workspace describes evolution of the alwaldend/src repository&#xA;itself: its shared structure, build system and development workflows.&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/src/openspec/specs/repository/spec/&#34;&gt;&lt;code&gt;specs/repository/spec.md&lt;/code&gt;&lt;/a&gt; records that contract;&#xA;&lt;code&gt;changes/&lt;/code&gt; records proposed and completed changes to it.&lt;/p&gt;&#xA;&lt;p&gt;Each component owns a separate OpenSpec workspace beside its source:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;projects/&amp;lt;project&amp;gt;/openspec/&lt;/code&gt; holds that project&amp;rsquo;s specs and changes.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;tools/&amp;lt;project&amp;gt;/openspec/&lt;/code&gt; holds that tool project&amp;rsquo;s specs and changes.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;infra/&amp;lt;project&amp;gt;/openspec/&lt;/code&gt; holds that infrastructure project&amp;rsquo;s specs and changes.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;infra/src/openspec/&lt;/code&gt; holds the repository&amp;rsquo;s own specs and changes.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Select the narrowest owner of the requested behavior. A project change belongs&#xA;in that project&amp;rsquo;s workspace, including when it has a standalone Bazel module.&#xA;Changes to shared repository structure belong here. Work spanning owners&#xA;keeps each affected contract with its owner and links related changes.&#xA;Component READMEs and build declarations retain their existing authority.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/src/openspec/migration/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/src/openspec/migration/</guid>
				<description>&lt;h1 id=&#34;goal-migration-to-openspec&#34;&gt;Goal migration to OpenSpec&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#goal-migration-to-openspec&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;p&gt;On 2026-09-08, all nine tracked maintained project goal records at source commit &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt; were migrated into native OpenSpec changes. Each change now lives in its owning project’s &lt;code&gt;openspec/&lt;/code&gt; workspace. Eight completed records are imported as archived history. The Reimu Fumo change remains open with blocked execution and no accepted candidate.&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;migration.json&#34;&gt;machine-readable inventory&lt;/a&gt; maps all 222 tracked source files (834,320 bytes) to byte-identical provenance snapshots. Test fixtures and ignored task scratch are outside the maintained-record inventory.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/src/openspec/specs/go-mod-version/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/src/openspec/specs/go-mod-version/spec/</guid>
				<description>&lt;h1 id=&#34;go-mod-version-specification&#34;&gt;go-mod-version Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#go-mod-version-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Keep tracked &lt;code&gt;go.mod&lt;/code&gt; files on the Go version configured for&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/tools/go_mod/&#34;&gt;&lt;code&gt;tools/go_mod&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/tools/go_mod/&#34;&gt;tool README&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../../../tools/go_mod/cmd/go_mod/BUILD.bazel&#34;&gt;tool BUILD&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../changes/archive/2026-09-12-add-go-mod-version-tool/proposal.md&#34;&gt;archive&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-configured-gomod-version&#34;&gt;Requirement: Configured go.mod version&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-configured-gomod-version&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The repository SHALL provide a &lt;code&gt;tools/go_mod&lt;/code&gt; command that discovers every&#xA;tracked &lt;code&gt;go.mod&lt;/code&gt; file and sets its &lt;code&gt;go&lt;/code&gt; directive to the version configured in&#xA;the tool&amp;rsquo;s BUILD file. The command MUST offer an update mode and a check mode.&lt;/p&gt;&#xA;&lt;h4 id=&#34;scenario-update-module-files&#34;&gt;Scenario: Update module files&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scenario-update-module-files&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;WHEN&lt;/strong&gt; a user runs the update target&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;THEN&lt;/strong&gt; every tracked &lt;code&gt;go.mod&lt;/code&gt; file whose &lt;code&gt;go&lt;/code&gt; directive differs from the&#xA;configured version is rewritten to that version&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;AND&lt;/strong&gt; files already on the configured version remain unchanged&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h4 id=&#34;scenario-check-module-files&#34;&gt;Scenario: Check module files&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#scenario-check-module-files&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h4&gt;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;WHEN&lt;/strong&gt; the check test runs&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;THEN&lt;/strong&gt; it fails if any tracked &lt;code&gt;go.mod&lt;/code&gt; file has a &lt;code&gt;go&lt;/code&gt; directive&#xA;different from the configured version&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;AND&lt;/strong&gt; it passes when every tracked &lt;code&gt;go.mod&lt;/code&gt; file matches&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;requirement-repository-quality-integration&#34;&gt;Requirement: Repository quality integration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-repository-quality-integration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The go.mod version check MUST run as part of &lt;code&gt;//:repo_quality_test&lt;/code&gt; so a&#xA;version mismatch fails repository quality.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/src/openspec/specs/repository/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/src/openspec/specs/repository/spec/</guid>
				<description>&lt;h1 id=&#34;repository-evolution-specification&#34;&gt;Repository Evolution Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#repository-evolution-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define how the alwaldend/src monorepo evolves its shared structure, build&#xA;system and development workflows. Component behavior is specified in each&#xA;owner&amp;rsquo;s local OpenSpec workspace. This baseline was inspected at source revision&#xA;&lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt; on 2026-09-08 and incorporates the&#xA;OpenSpec migration delivered with this specification. Changes in &lt;code&gt;infra/src&lt;/code&gt;&#xA;record repository evolution; they do not collect unrelated component work or claim&#xA;runtime health or deployed infrastructure.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/&#34;&gt;repository map&lt;/a&gt;, &lt;a href=&#34;../../../../../AGENTS.md&#34;&gt;agent policy&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../../../BUILD.bazel&#34;&gt;root build&lt;/a&gt;, &lt;a href=&#34;https://www-staging.alwaldend.com/docs/projects/&#34;&gt;project boundary&lt;/a&gt;,&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/&#34;&gt;infrastructure boundary&lt;/a&gt;,&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/tools/&#34;&gt;tool boundary&lt;/a&gt;, and &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/src/openspec/&#34;&gt;OpenSpec workflow&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/openspec/specs/infra-threexui/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/openspec/specs/infra-threexui/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-3x-ui&#34;&gt;Infrastructure 3x-ui&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-3x-ui&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe 3x-ui provisioning, host deployment, node routing configuration, and&#xA;the subscription URL transformer. This baseline describes checked-in source,&#xA;not verified live node access. The advertised host-only subscription command&#xA;has a source limitation: &lt;code&gt;sub/main.go&lt;/code&gt; also attempts to read &lt;code&gt;sub_file&lt;/code&gt; when it&#xA;is empty, so successful host-only operation is not a baseline guarantee.&lt;/p&gt;&#xA;&lt;p&gt;Baseline source revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define retained 3x-ui DNS ownership through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped execution, and offline source checks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled before the adoption revision and SHALL&#xA;retain enabled ownership after authorized adoption into the owner&amp;rsquo;s state.&#xA;Reconciliation against adopted state and unchanged declarations SHALL propose&#xA;no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/openspec/specs/infra-vault/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/openspec/specs/infra-vault/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-vault&#34;&gt;Infrastructure Vault&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-vault&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe the Vault host configuration, authentication and certificate services,&#xA;and packaged recovery entry points. This baseline concerns checked-in desired&#xA;state and supported wrapper structure; it does not establish live unsealed&#xA;state, successful backups, quorum, or certificate freshness.&lt;/p&gt;&#xA;&lt;p&gt;Baseline source revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/vault/&#34;&gt;operator documentation&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../BUILD.bazel&#34;&gt;operational wrappers&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../ansible/BUILD.bazel&#34;&gt;Ansible entry points&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../ansible/files/vault.hcl&#34;&gt;Vault host template&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/auth.tf&#34;&gt;authentication backends&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/mounts.tf&#34;&gt;storage engines&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/pki_servers.tf&#34;&gt;server PKI&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../tf/pki_clients.tf&#34;&gt;client PKI&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../tf/outputs.tf&#34;&gt;public CA outputs&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define Vault service DNS management through the owner&amp;rsquo;s &lt;code&gt;tf_setup&lt;/code&gt; root,&#xA;including canonical declarations, scoped credentials, and offline source checks&#xA;before adopting live records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf_setup&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/xcp_ng/openspec/specs/infra-xcp-ng/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/xcp_ng/openspec/specs/infra-xcp-ng/spec/</guid>
				<description>&lt;h1 id=&#34;xcp-ng-infrastructure-specification&#34;&gt;XCP-ng infrastructure Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#xcp-ng-infrastructure-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Specify Xen Orchestra resource delegation, scoped authentication, and&#xA;certificate deployment owned by &lt;code&gt;infra/xcp_ng&lt;/code&gt;. The baseline is checked-in&#xA;source at revision &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;, observed on&#xA;2026-09-08. Existing operational observations in project documentation are&#xA;historical context; this baseline does not verify current deployment, edition,&#xA;identity synchronization, or service health.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-approle-resource-sets-with-named-inventory&#34;&gt;Requirement: AppRole resource sets with named inventory&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-approle-resource-sets-with-named-inventory&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;Terraform SHALL declare one Xen Orchestra resource set per entity in Vault&amp;rsquo;s&#xA;&lt;code&gt;approles&lt;/code&gt; group. Each set SHALL contain its explicitly assigned template,&#xA;storage repository, and network resolved by names within the selected pool;&#xA;unassigned sets SHALL contain no inventory objects. Each set SHALL have a&#xA;positive integer CPU quota, defaulting to 32. These resource sets SHALL&#xA;represent delegation groups rather than new physical host pools.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/xcp_ng/openspec/specs/owned-dns/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/xcp_ng/openspec/specs/owned-dns/spec/</guid>
				<description>&lt;h1 id=&#34;owned-dns-specification&#34;&gt;owned-dns Specification&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#owned-dns-specification&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Define XCP-ng infrastructure DNS management through the owner&amp;rsquo;s &lt;code&gt;tf&lt;/code&gt; root,&#xA;including canonical declarations, scoped execution, and offline source checks&#xA;through preparation, adoption, and ongoing reconciliation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;requirements&#34;&gt;Requirements&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirements&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;requirement-owner-local-dns-configuration&#34;&gt;Requirement: Owner-local DNS configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#requirement-owner-local-dns-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;p&gt;The &lt;code&gt;tf&lt;/code&gt; root SHALL consume this owner&amp;rsquo;s canonical &lt;code&gt;dnsconfig.json&lt;/code&gt; through&#xA;the shared DNS Terraform module, preserving declared record identities and views.&#xA;DNS resources SHALL default to disabled until the authorized adoption revision&#xA;and SHALL retain enabled ownership after existing records are imported into the&#xA;owner&amp;rsquo;s state. Reconciliation against unchanged declarations and adopted state&#xA;SHALL propose no record additions, changes, replacements, or deletions.&lt;/p&gt;</description>
			</item>
			<item>
				<title></title>
				<link>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/openspec/spec/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/openspec/spec/</guid>
				<description>&lt;h1 id=&#34;infrastructure-yandex-cloud&#34;&gt;Infrastructure Yandex Cloud&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#infrastructure-yandex-cloud&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h1&gt;&lt;h2 id=&#34;purpose&#34;&gt;Purpose&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#purpose&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Describe organization-level Yandex Cloud folder provisioning derived from Vault&#xA;AppRole identities. The direct &lt;code&gt;infra/yandex_cloud&lt;/code&gt; owner currently contains one&#xA;concrete organization package, &lt;code&gt;org1&lt;/code&gt;, covered here. This baseline does not&#xA;assert that the cloud organization or its folders were inspected live.&lt;/p&gt;&#xA;&lt;p&gt;Baseline source revision: &lt;code&gt;550d7e79b1f5fdbc2b6017b75178471d6914082f&lt;/code&gt;.&#xA;Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.&lt;/p&gt;&#xA;&lt;p&gt;Sources: &lt;a href=&#34;https://www-staging.alwaldend.com/docs/&#34;&gt;top-level documentation&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../org1/README.md&#34;&gt;organization package&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../org1/BUILD.bazel&#34;&gt;organization targets&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../org1/tf/BUILD.bazel&#34;&gt;Terraform packaging&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../org1/tf/folders.tf&#34;&gt;folder derivation&lt;/a&gt;,&#xA;&lt;a href=&#34;../../../org1/tf/provider.tf&#34;&gt;provider configuration&lt;/a&gt;, and&#xA;&lt;a href=&#34;../../../org1/al.lua&#34;&gt;credential injection&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/ingress/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ingress/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/openhands/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/openhands/ansible/</guid>
				<description>&lt;p&gt;Deploys the OpenHands components. The inventory has three hosts in three&#xA;groups, and the playbook applies one component role per group:&lt;/p&gt;&#xA;&lt;table&gt;&#xA;&#x9;&lt;thead&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Group&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Host&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Component&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/thead&gt;&#xA;&#x9;&lt;tbody&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;openhands_canvas&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;host1.canvas.openhands.alwaldend.com&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Agent Canvas&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;openhands_server_secure&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;host1.server.openhands.alwaldend.com&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Agent server (secured)&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;openhands_automation&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;&lt;code&gt;host1.automation.openhands.alwaldend.com&lt;/code&gt;&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Automation server&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;The three XCP-ng VMs exist only for the secured agent server and for the&#xA;components that must not share a trust boundary with host-bot. The secured&#xA;group sets &lt;code&gt;openhands_server_session_api_key&lt;/code&gt; and hands the same value to the&#xA;automation server so the automation dispatcher can authenticate its&#xA;dispatched conversations.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/pve/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/pve/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Ansible</title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/ansible/</guid>
				<description></description>
			</item>
			<item>
				<title>Architecture</title>
				<link>https://www-staging.alwaldend.com/docs/infra/arch/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/arch/</guid>
				<description>&lt;p&gt;These diagrams render every page of the checked-in &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/arch.drawio&#34;&gt;Drawio source&lt;/a&gt;.&#xA;They describe the source document, not a live inventory or health check. Pages&#xA;marked &lt;strong&gt;Archive&lt;/strong&gt; retain the source&amp;rsquo;s historical classification.&#xA;Open an image for its full-size SVG.&lt;/p&gt;&#xA;&lt;h2 id=&#34;dc1&#34;&gt;DC1&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#dc1&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/dc1.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/dc1.svg&#34; alt=&#34;DC1 infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;vault&#34;&gt;Vault&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#vault&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/vault.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/vault.svg&#34; alt=&#34;Vault infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;flux&#34;&gt;Flux&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#flux&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/flux.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/flux.svg&#34; alt=&#34;Flux infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;forgejo&#34;&gt;Forgejo&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#forgejo&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/forgejo.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/forgejo.svg&#34; alt=&#34;Forgejo infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;www&#34;&gt;www&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#www&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/www.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/www.svg&#34; alt=&#34;www infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;threexui&#34;&gt;Threexui&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#threexui&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/threexui.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/threexui.svg&#34; alt=&#34;Threexui infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;dns&#34;&gt;DNS&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#dns&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/dns.svg&#34;&gt;&lt;img src=&#34;https://www-staging.alwaldend.com/docs/infra/arch/assets/dns.svg&#34; alt=&#34;DNS infrastructure diagram&#34; loading=&#34;lazy&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
			</item>
			<item>
				<title>Ceph</title>
				<link>https://www-staging.alwaldend.com/docs/infra/ceph/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ceph/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Proxmox docs: &lt;a href=&#34;https://pve.proxmox.com/wiki/Deploy_Hyper-Converged_Ceph_Cluster&#34;&gt;https://pve.proxmox.com/wiki/Deploy_Hyper-Converged_Ceph_Cluster&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Single node crushmap: &lt;a href=&#34;https://imanudin.net/2025/05/12/proxmox-ceph-single-node-installation-for-test-lab-or-home-setup/&#34;&gt;https://imanudin.net/2025/05/12/proxmox-ceph-single-node-installation-for-test-lab-or-home-setup/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;see-current-crush-map&#34;&gt;See current crush map&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#see-current-crush-map&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Go to Nodes -&amp;gt; Host -&amp;gt; Ceph -&amp;gt; Configuration&lt;/p&gt;&#xA;&lt;h2 id=&#34;crush-map-update&#34;&gt;Crush map update&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#crush-map-update&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Ssh to the PVE host and update the map:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo ceph osd getcrushmap -o crushmap.cm&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo crushtool --decompile crushmap.cm -o crushmap.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo vim crushmap.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo crushtool --compile crushmap.txt -o new_crushmap.cm&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo ceph osd setcrushmap -i new_crushmap.cm&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;sudo ceph -s&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description>
			</item>
			<item>
				<title>cl</title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/cl/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/cl/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Cert manager charts: &lt;a href=&#34;https://artifacthub.io/packages/helm/cert-manager/cert-manager&#34;&gt;https://artifacthub.io/packages/helm/cert-manager/cert-manager&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>cl</title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/cl/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/cl/</guid>
				<description></description>
			</item>
			<item>
				<title>Cloud-init</title>
				<link>https://www-staging.alwaldend.com/docs/infra/cloud_init/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/cloud_init/</guid>
				<description>&lt;p&gt;&lt;code&gt;assets/cloud_init.yaml&lt;/code&gt; is the canonical configuration moved from PVE. PVE&#xA;and Yandex Cloud consume it directly. It owns the Ansible sudo user, SSH keys,&#xA;local TLS root CA, and common bootstrap policy. The Ansible SSH CA is selected by its certificate-authority principal options;&#xA;user and key ordering do not affect the Xen configuration. Missing or duplicate&#xA;Ansible users or CA keys fail template rendering.&#xA;&lt;code&gt;assets/cloud_init_min.yaml&lt;/code&gt; is the existing minimal PVE configuration with&#xA;QEMU guest tools. Both original PVE files retain their contents.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Cloudflare DNS</title>
				<link>https://www-staging.alwaldend.com/docs/infra/dns/cloudflare_dns/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/dns/cloudflare_dns/</guid>
				<description>&lt;p&gt;Every record this repository declares for the public zone, which Cloudflare serves.&lt;/p&gt;&#xA;&lt;p&gt;This page is generated from the declarations; run &lt;code&gt;bazel run //infra/dns/cmd/dump -- --write&lt;/code&gt; after changing them. The authoritative source is each owner&amp;rsquo;s &lt;code&gt;dnsconfig.json&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;table&gt;&#xA;&#x9;&lt;thead&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Domain&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Type&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;TTL&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Value&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Declaration&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/thead&gt;&#xA;&#x9;&lt;tbody&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.108.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.109.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.110.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.111.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8000::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8001::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8002::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8003::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mail.protonmail.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;20 mailsec.protonmail.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_globalsign-domain-verification=0QBJgVV_uwcFLTi1Rot3bb1LyJ5uW1WD0ygvIS4OM5&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail-verification=bdcd133d3f472fa17f66328950d02fbeae1bef75&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 include:_spf.protonmail.ch ~all&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_dmarc&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DMARC1; p=quarantine; adkim=s&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_dmarc.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;canvas.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;cloud&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.automation.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.92&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.canvas.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.90&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.cloud&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.209&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.server.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.91&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.t3code.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim02._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim02._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim03._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim03._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;forgejo&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;git&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.ingress&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;81.26.185.118&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/ingress/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;81.26.185.118&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/ingress/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;int.forgejo&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.40&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;int.vault&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.218&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;mail._domainkey.yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DKIM1; k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCcYzFVgkeDOhaIIkWM8gNQjxVsv0/aXfU+ax5urB5y6hA6lSjRnjRo6tm0bXbkOJf41GmiwMNgdXpwRtzgzAlX1i2aJbtEr4b9jzibEGLQ7Cvqs44bOYES9f/K3ueQpnvdTOJmFqlRReFL7ZrUyDFCoQ7f4+7h4i8s01cCcRrt5wIDAQAB&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;njalla1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;45.142.141.133&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;njalla1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2a0a:3840:8078:141:0:2d8e:8d85:1337&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;pages&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.108.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;projects/alwaldend.com/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;pages&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8000::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;projects/alwaldend.com/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail2._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail2.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail3._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail3.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mx1.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;20 mx2.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;sl-verification=bxfzzfjiggzsxyzxhhmkmjqkaskjgy&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 include:simplelogin.co ~all&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;t3code.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;vault&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;www&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;www-staging&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;alwaldend.github.io.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;21600&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mx.yandex.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 redirect=_spf.yandex.net&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex-verification: b83672f59b3dbe16&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;NS&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ns1.yandexcloud.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;NS&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ns2.yandexcloud.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.nodes.yc.threexui.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/tbody&gt;&#xA;&lt;/table&gt;</description>
			</item>
			<item>
				<title>Dns</title>
				<link>https://www-staging.alwaldend.com/docs/infra/dns/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/dns/</guid>
				<description>&lt;p&gt;DNS records live in each owner&amp;rsquo;s &lt;code&gt;dnsconfig.json&lt;/code&gt;. Each owner manages its records&#xA;through the reusable &lt;a href=&#34;https://www-staging.alwaldend.com/docs/projects/tf_modules/dns_records/&#34;&gt;Terraform DNS module&lt;/a&gt;&#xA;from its designated &lt;code&gt;tf_setup&lt;/code&gt; or &lt;code&gt;tf&lt;/code&gt; root. This component&amp;rsquo;s&#xA;&lt;a href=&#34;dnsconfig.json&#34;&gt;dnsconfig.json&lt;/a&gt; owns shared apex and mail records.&lt;/p&gt;&#xA;&lt;h2 id=&#34;declaration-pages&#34;&gt;Declaration pages&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#declaration-pages&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/cloudflare_dns/&#34;&gt;Cloudflare DNS&lt;/a&gt; and &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/mikrotik_dns/&#34;&gt;Mikrotik DNS&lt;/a&gt; list the&#xA;records this repository declares for each destination view, with the owning&#xA;declaration for every record. They are generated from &lt;code&gt;dnsconfig.json&lt;/code&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel_agent bazel run //infra/dns/cmd/dump -- --write&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;//infra/dns:config_test&lt;/code&gt; fails when a checked-in page is out of date, so the&#xA;pages cannot drift from the declarations they project.&lt;/p&gt;</description>
			</item>
			<item>
				<title>flux</title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Site: &lt;a href=&#34;https://fluxcd.io/&#34;&gt;https://fluxcd.io/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;set-up-port-forwarding&#34;&gt;Set up port forwarding&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#set-up-port-forwarding&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;ssh -L 6443:127.0.0.1:6443 -N flux.alwaldend.com&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;run-flux-cli&#34;&gt;Run flux CLI&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#run-flux-cli&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:flux&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;show-flux-status&#34;&gt;Show flux status&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#show-flux-status&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run infra/flux/cl:flux -- get all -A&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;run-bootstrap&#34;&gt;Run bootstrap&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#run-bootstrap&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:flux.bootstrap&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;run-flux-operator&#34;&gt;Run flux operator&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#run-flux-operator&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:op&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;show-oidc-info&#34;&gt;Show oidc info&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#show-oidc-info&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:oidc&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;renew-certificate&#34;&gt;Renew certificate&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#renew-certificate&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:cmctl -- renew traefik-gateway-websecure-tls -n traefik&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;update-secrets&#34;&gt;Update secrets&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#update-secrets&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Generate secret id and the token:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;SECRET_ID&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;$(&lt;/span&gt;bazel run //infra/flux/cl:vault.secret_id | jq -r .data.secret_id&lt;span style=&#34;color:#66d9ef&#34;&gt;)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;TOKEN&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;$(&lt;/span&gt;echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;SECRET_ID&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt; | bazel run //infra/flux/cl:vault.ops_token | jq -r .auth.client_token&lt;span style=&#34;color:#66d9ef&#34;&gt;)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Secret id: &lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;SECRET_ID&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;, Token: &lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;TOKEN&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;li&gt;Patch secret-id in &lt;a href=&#34;https://github.com/alwaldend/src/blob/master/infra/flux/cl/cert-manager/issuer-approle.yaml&#34;&gt;./cl/cert-manager/issuer-approle.yaml&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Patch token in &lt;a href=&#34;https://github.com/alwaldend/src/blob/master/projects/kustomization/flux-repo/flux-sops-secret.yaml&#34;&gt;projects/kustomization/flux-repo/flux-sops-secret.yaml&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Encrypt:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:sops.encrypt infra/flux/cl/cert-manager/issuer-approle.yaml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:sops.encrypt projects/kustomization/flux-repo/flux-sops-secret.yaml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:sops.encrypt projects/kustomization/flux-repo/flux-git-src-secret.yaml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>forgejo</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Docs: &lt;a href=&#34;https://forgejo.org/docs/latest/admin/installation/binary/&#34;&gt;https://forgejo.org/docs/latest/admin/installation/binary/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Config reference: &lt;a href=&#34;https://forgejo.org/docs/latest/admin/config-cheat-sheet/&#34;&gt;https://forgejo.org/docs/latest/admin/config-cheat-sheet/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;repository-configuration&#34;&gt;Repository configuration&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#repository-configuration&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Service Terraform consumes the shared &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;repository catalog&lt;/a&gt;&#xA;for organization-owned repositories and named administrator/developer roles.&#xA;Vault continues to own OIDC login identities and service-specific access.&#xA;See &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/forgejo/tf/&#34;&gt;service Terraform&lt;/a&gt; for identity validation, state adoption,&#xA;and the preserved automation grants.&lt;/p&gt;&#xA;&lt;h2 id=&#34;deployment&#34;&gt;Deployment&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#deployment&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Forgejo is recreated on XCP-ng through Xen Orchestra, using the&#xA;&lt;code&gt;src_infra_dc1_forgejo1&lt;/code&gt; resource set provisioned by &lt;code&gt;infra/xcp_ng&lt;/code&gt;.&#xA;VM provisioning authenticates to XO through Vault OIDC as Forgejo&amp;rsquo;s own&#xA;AppRole. Its exact synchronized user receives the resource-set membership&#xA;and an explicit administration ACL on the existing Forgejo VM; it does not&#xA;use the shared infrastructure administrator token. These bindings must be&#xA;applied by &lt;code&gt;infra/xcp_ng/tf&lt;/code&gt; before Forgejo&amp;rsquo;s setup Terraform runs.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Forgejo runner</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/</guid>
				<description>&lt;h2 id=&#34;deploy-vms&#34;&gt;Deploy VMs&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#deploy-vms&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/forgejo_runner/tf_setup &lt;span style=&#34;color:#75715e&#34;&gt;# Create VMs&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/forgejo_runner/ansible &lt;span style=&#34;color:#75715e&#34;&gt;# Configure VMs&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description>
			</item>
			<item>
				<title>GitHub</title>
				<link>https://www-staging.alwaldend.com/docs/infra/github/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/github/</guid>
				<description>&lt;p&gt;This project manages the GitHub organization and repositories declared by the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;shared repository catalog&lt;/a&gt;, including existing forks,&#xA;project landing sites, organization membership, and developer access.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/github/tf/&#34;&gt;Service Terraform&lt;/a&gt; adopts existing resources and preserves their&#xA;identities. It also manages repository default-branch rules and existing Pages&#xA;configuration. Site content is published through the owning project deployment&#xA;targets; this infrastructure package does not publish it.&lt;/p&gt;</description>
			</item>
			<item>
				<title>GitHub Terraform</title>
				<link>https://www-staging.alwaldend.com/docs/infra/github/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/github/tf/</guid>
				<description>&lt;p&gt;This package consumes the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;shared repository catalog&lt;/a&gt;&#xA;through its provider-free Terraform module. The catalog supplies the GitHub&#xA;owner, repositories, default branches, repository settings, organization&#xA;administrators, and developers. This root supports one GitHub organization per&#xA;provider instance and rejects multiple configured owners.&lt;/p&gt;&#xA;&lt;p&gt;Existing repositories are imported, including forks. The apex site repository&#xA;keeps its Pages configuration and custom domain. Published repository names and&#xA;Pages domains come directly from the catalog; they are not regenerated from the&#xA;current build-project registry.&lt;/p&gt;</description>
			</item>
			<item>
				<title>GitLab</title>
				<link>https://www-staging.alwaldend.com/docs/infra/gitlab/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/gitlab/</guid>
				<description>&lt;p&gt;This project owns GitLab groups, memberships, repository imports, and forks&#xA;through the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/gitlab/tf/&#34;&gt;Terraform module&lt;/a&gt;. Organization membership and&#xA;repository definitions come from the shared &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;repository catalog&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>GitLab Terraform</title>
				<link>https://www-staging.alwaldend.com/docs/infra/gitlab/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/gitlab/tf/</guid>
				<description>&lt;p&gt;This module manages the GitLab groups, memberships, repository imports, and&#xA;forks declared in the shared &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;repository catalog&lt;/a&gt;.&#xA;Its &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/tf/&#34;&gt;catalog module&lt;/a&gt; supplies names, source URLs,&#xA;and repository settings. Provider versions and checksums are recorded in the shared&#xA;&lt;a href=&#34;../../../third_party/terraform/include.MODULE.bazel&#34;&gt;provider declarations&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Catalog administrators receive the Owner role; catalog users receive the&#xA;Developer role. Group defaults permit Maintainers and Owners to push and&#xA;merge into default branches, with force pushes and developer initial pushes&#xA;disabled. Developers can read repositories, create feature branches, and&#xA;open merge requests. Existing higher direct or inherited grants must be&#xA;reviewed separately because GitLab retains a user&amp;rsquo;s highest access level.&lt;/p&gt;</description>
			</item>
			<item>
				<title>harbor</title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Site: &lt;a href=&#34;https://goharbor.io/&#34;&gt;https://goharbor.io/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Releases: &lt;a href=&#34;https://github.com/goharbor/harbor/releases&#34;&gt;https://github.com/goharbor/harbor/releases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;ce-login&#34;&gt;CE Login&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#ce-login&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Go to User Profile, copy CLI secret&lt;/li&gt;&#xA;&lt;li&gt;Run:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;podman login harbor.alwaldend.com&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;update-secrets&#34;&gt;Update secrets&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#update-secrets&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Generate approle secret id:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;SECRET_ID&lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;$(&lt;/span&gt;bazel run //infra/harbor/cl:vault.secret_id | jq -r .data.secret_id&lt;span style=&#34;color:#66d9ef&#34;&gt;)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;echo &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Secret id: &lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;SECRET_ID&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;li&gt;Patch secret-id in &lt;a href=&#34;https://github.com/alwaldend/src/blob/master/infra/harbor/cl/cert-manager/issuer-approle.yaml&#34;&gt;./cl/cert-manager/issuer-approle.yaml&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Encrypt:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/flux/cl:sops.encrypt infra/harbor/cl/cert-manager/issuer-approle.yaml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>ingress</title>
				<link>https://www-staging.alwaldend.com/docs/infra/ingress/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ingress/</guid>
				<description>&lt;h2 id=&#34;run-ansible&#34;&gt;Run ansible&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#run-ansible&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/ingress/ansible&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Services in &lt;code&gt;traefik_services&lt;/code&gt; must use a backend &lt;code&gt;target&lt;/code&gt; that resolves from&#xA;the ingress hosts without resolving back to ingress. Define a dedicated&#xA;site-local address, conventionally prefixed with &lt;code&gt;dc1.&lt;/code&gt;, in the owning&#xA;service&amp;rsquo;s DNS configuration and use that address as the target.&lt;/p&gt;&#xA;&lt;h2 id=&#34;apply-terraform&#34;&gt;Apply terraform&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#apply-terraform&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/ingress/tf&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;update-signed-image-url&#34;&gt;Update signed image url&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#update-signed-image-url&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Create a signed url: &lt;a href=&#34;https://yandex.cloud/ru/docs/storage/operations/objects/link-for-download&#34;&gt;https://yandex.cloud/ru/docs/storage/operations/objects/link-for-download&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Update the secret: &lt;code&gt;alwaldend.com/vault1/approles/src_infra_ingress/image&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;recreate-vms&#34;&gt;Recreate VMs&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#recreate-vms&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run infra/ingress/tf -- -replace &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;yandex_compute_disk.vpc[&amp;#34;*&amp;#34;]&amp;#39;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;regenerate-wireguard-keys&#34;&gt;Regenerate wireguard keys&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#regenerate-wireguard-keys&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Regenerate private and public keys:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;wg genkey | tee host1.privatekey.txt | wg pubkey &amp;gt;host1.publickey.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;wg genkey | tee host2.privatekey.txt | wg pubkey &amp;gt;host2.publickey.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;wg genkey | tee router.privatekey.txt | wg pubkey &amp;gt;router.publickey.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;cat - &amp;gt;data.json &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;lt;&amp;lt;EOF&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;{&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  &amp;#34;wg_public_keys&amp;#34;: {&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host1&amp;#34;: &amp;#34;$(cat host1.publickey.txt)&amp;#34;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host2&amp;#34;: &amp;#34;$(cat host2.publickey.txt)&amp;#34;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;router&amp;#34;: &amp;#34;$(cat router.publickey.txt)&amp;#34;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  },&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  &amp;#34;wg_private_keys&amp;#34;: {&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host1&amp;#34;: &amp;#34;$(cat host1.privatekey.txt)&amp;#34;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host2&amp;#34;: &amp;#34;$(cat host2.privatekey.txt)&amp;#34;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;router&amp;#34;: &amp;#34;$(cat router.privatekey.txt)&amp;#34;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  },&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  &amp;#34;wg_preshared_keys&amp;#34;: {&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host1&amp;#34;: &amp;#34;$(openssl rand 32 | base64)&amp;#34;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;    &amp;#34;host2&amp;#34;: &amp;#34;$(openssl rand 32 | base64)&amp;#34;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;  }&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;}&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;EOF&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run infra/ingress:vault.kv_put -- -format json alwaldend.com/vault1/approles/src_infra_ingress/wireguard &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;@&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;PWD&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;/data.json&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;rm data.json *.privatekey.txt *.publickey.txt&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Mikrotik</title>
				<link>https://www-staging.alwaldend.com/docs/infra/mikrotik/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/mikrotik/</guid>
				<description>&lt;p&gt;The &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/mikrotik/tf/&#34;&gt;Terraform package&lt;/a&gt; prepares owner-local DNS management.&#xA;Router exports remain documentation inputs and are not applied by that package.&lt;/p&gt;&#xA;&lt;h2 id=&#34;deployment&#34;&gt;Deployment&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#deployment&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Open &lt;a href=&#34;https://help.mikrotik.com/docs/spaces/ROS/pages/328129/WinBox&#34;&gt;Winbox&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Open new terminal&lt;/li&gt;&#xA;&lt;li&gt;Run &lt;code&gt;/export&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;Copy output&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Website: &lt;a href=&#34;https://mikrotik.com&#34;&gt;https://mikrotik.com&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Docs: &lt;a href=&#34;https://help.mikrotik.com/docs/spaces/ROS/pages/328155/Configuration&amp;#43;Management&#34;&gt;https://help.mikrotik.com/docs/spaces/ROS/pages/328155/Configuration+Management&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;exports&#34;&gt;Exports&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#exports&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;h3 id=&#34;router1&#34;&gt;Router1&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#router1&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code class=&#34;language-rsc&#34; data-lang=&#34;rsc&#34;&gt;/interface bridge&#xA;add admin-mac=78:9A:18:38:6C:CA auto-mac=no comment=&amp;#34;bridge1 (wired)&amp;#34; name=bridge1&#xA;add comment=&amp;#34;bridge2 (wireless)&amp;#34; name=bridge2&#xA;/interface wifi&#xA;set [ find default-name=wifi1 ] channel.frequency=5000-5400 .skip-dfs-channels=10min-cac comment=&amp;#34;wifi1 (5GHz)&amp;#34; configuration.country=Russia .mode=ap .ssid=divinity-5GHz datapath.client-isolation=yes disabled=no security.authentication-types=wpa2-psk,wpa3-psk .connect-priority=0 .ft=yes .ft-over-ds=yes&#xA;set [ find default-name=wifi2 ] channel.skip-dfs-channels=10min-cac comment=&amp;#34;wifi2 (2GHz)&amp;#34; configuration.country=Russia .mode=ap .ssid=divinity-2GHz datapath.client-isolation=yes disabled=no security.authentication-types=wpa2-psk,wpa3-psk .connect-priority=0 .ft=yes .ft-over-ds=yes&#xA;/interface ethernet&#xA;set [ find default-name=ether1 ] comment=ether1 l2mtu=1500 mac-address=F4:28:53:7F:A4:59&#xA;set [ find default-name=ether2 ] comment=ether2&#xA;set [ find default-name=ether3 ] comment=ether3&#xA;set [ find default-name=ether4 ] comment=ether4&#xA;set [ find default-name=ether5 ] comment=ether5&#xA;/interface wireguard&#xA;add comment=&amp;#34;tf[users/simeonwarren/hermes/tf_setup]&amp;#34; disabled=yes listen-port=13232 mtu=1420 name=hermes-vpc&#xA;add comment=&amp;#34;tf[infra/ingress/tf]&amp;#34; listen-port=13231 mtu=1420 name=ingress-vpc&#xA;/interface ethernet switch&#xA;set switch1 cpu-flow-control=yes&#xA;/interface list&#xA;add comment=defconf name=WAN&#xA;add comment=defconf name=LAN&#xA;add name=accept-forward-WAN&#xA;add name=accept-input-DNS&#xA;add name=accept-input-DHCP-server&#xA;add name=accept-input-ICMP&#xA;add name=accept-input-winbox&#xA;add name=accept-input-web-ui&#xA;add name=accept-input-mikrotik-neighbor-discovery&#xA;add name=accept-forward-LAN&#xA;add name=accept-output-LAN&#xA;add name=accept-input-NTP&#xA;add name=accept-input-API&#xA;/ip pool&#xA;add comment=bridge1 name=bridge1 ranges=192.168.1.10-192.168.1.254&#xA;add comment=bridge2 name=bridge2 ranges=192.168.2.10-192.168.2.254&#xA;/ip dhcp-server&#xA;add address-pool=bridge1 comment=bridge1 interface=bridge1 lease-time=10m name=bridge1&#xA;add address-pool=bridge2 interface=bridge2 name=bridge2&#xA;/ipv6 pool&#xA;add name=dc01 prefix=fd2e:546d:5738::/48 prefix-length=64&#xA;/user group&#xA;add comment=src_infra_dns name=src_infra_dns policy=read,write,api,rest-api,!local,!telnet,!ssh,!ftp,!reboot,!policy,!test,!winbox,!password,!web,!sniff,!sensitive,!romon&#xA;add comment=src_infra_ingress name=src_infra_ingress policy=read,write,api,rest-api,!local,!telnet,!ssh,!ftp,!reboot,!policy,!test,!winbox,!password,!web,!sniff,!sensitive,!romon&#xA;add comment=users_simeonwarren name=users_simeonwarren policy=read,write,api,rest-api,!local,!telnet,!ssh,!ftp,!reboot,!policy,!test,!winbox,!password,!web,!sniff,!sensitive,!romon&#xA;/interface bridge port&#xA;add bridge=bridge1 comment=bridge1-ether2 interface=ether2&#xA;add bridge=bridge1 comment=bridge1-ether3 interface=ether3&#xA;add bridge=bridge1 comment=bridge1-ether4 interface=ether4&#xA;add bridge=bridge1 comment=bridge1-ether5 interface=ether5&#xA;add bridge=bridge2 comment=bridge2-wifi1 interface=wifi1&#xA;add bridge=bridge2 comment=bridge2-wifi2 interface=wifi2&#xA;/ip neighbor discovery-settings&#xA;set discover-interface-list=LAN&#xA;/interface detect-internet&#xA;set detect-interface-list=WAN&#xA;/interface list member&#xA;add interface=bridge1 list=LAN&#xA;add interface=ether1 list=WAN&#xA;add interface=bridge2 list=LAN&#xA;add interface=bridge2 list=accept-forward-WAN&#xA;add interface=bridge1 list=accept-forward-WAN&#xA;add interface=bridge1 list=accept-input-DNS&#xA;add interface=bridge2 list=accept-input-DNS&#xA;add interface=bridge1 list=accept-input-DHCP-server&#xA;add interface=bridge2 list=accept-input-DHCP-server&#xA;add interface=bridge1 list=accept-input-ICMP&#xA;add interface=bridge2 list=accept-input-ICMP&#xA;add interface=bridge1 list=accept-input-winbox&#xA;add interface=bridge1 list=accept-input-web-ui&#xA;add interface=bridge1 list=accept-input-mikrotik-neighbor-discovery&#xA;add interface=bridge1 list=accept-forward-LAN&#xA;add interface=bridge1 list=accept-output-LAN&#xA;add interface=bridge1 list=accept-input-NTP&#xA;add interface=bridge1 list=accept-input-API&#xA;add comment=&amp;#34;tf[infra/ingress/tf]&amp;#34; interface=ingress-vpc list=accept-input-ICMP&#xA;add comment=&amp;#34;tf[infra/ingress/tf]&amp;#34; interface=ingress-vpc list=LAN&#xA;add comment=&amp;#34;tf[infra/ingress/tf]&amp;#34; interface=ingress-vpc list=accept-forward-LAN&#xA;add comment=&amp;#34;tf[users/simeonwarren/hermes/tf_setup]&amp;#34; interface=hermes-vpc list=accept-forward-LAN&#xA;add comment=&amp;#34;tf[users/simeonwarren/hermes/tf_setup]&amp;#34; interface=hermes-vpc list=accept-input-ICMP&#xA;add comment=&amp;#34;tf[users/simeonwarren/hermes/tf_setup]&amp;#34; interface=hermes-vpc list=LAN&#xA;/interface ovpn-server server&#xA;add mac-address=FE:B3:B4:C4:A4:48 name=ovpn-server1&#xA;/interface wireguard peers&#xA;add allowed-address=10.10.0.2/24 comment=host2 endpoint-address=103.76.53.6 endpoint-port=51820 interface=ingress-vpc name=ingress-vpc-host2 persistent-keepalive=5s public-key=&amp;#34;Z2JamOjZYOGaf4tPZzchyHjLw/XlOtUtQObyROEQ9DM=&amp;#34;&#xA;add allowed-address=10.10.0.1/24 comment=host1 endpoint-address=158.160.196.128 endpoint-port=51820 interface=ingress-vpc name=ingress-vpc-host1 persistent-keepalive=5s public-key=&amp;#34;xmyl+frvngmzRB9z5yEURxQj4vTw47tKQV7EZrTAREw=&amp;#34;&#xA;add allowed-address=10.20.0.1/24 comment=host1 endpoint-address=158.160.220.223 endpoint-port=51820 interface=hermes-vpc name=hermes-vpc-host1 persistent-keepalive=5s public-key=&amp;#34;oA4ZpsmrclIOIWh3ECsb4ZFKH1hQMDtuW3xNXat3IyQ=&amp;#34;&#xA;/ip settings&#xA;set send-redirects=no&#xA;/ip address&#xA;add address=192.168.1.1/24 comment=&amp;#34;bridge1 (LAN)&amp;#34; interface=bridge1 network=192.168.1.0&#xA;add address=192.168.2.1/24 comment=&amp;#34;bridge2 (Wireless)&amp;#34; interface=bridge2 network=192.168.2.0&#xA;add address=192.168.10.1/24 comment=host1.pve1.dc1.alwaldend.com interface=bridge1 network=192.168.10.0&#xA;add address=10.10.0.0/24 comment=&amp;#34;tf[infra/ingress/tf]&amp;#34; interface=ingress-vpc network=10.10.0.0&#xA;add address=10.20.0.0/24 comment=&amp;#34;tf[users/simeonwarren/hermes/tf_setup]&amp;#34; interface=hermes-vpc network=10.20.0.0&#xA;/ip dhcp-client&#xA;add comment=defconf interface=ether1 name=ether1 use-peer-dns=no&#xA;/ip dhcp-server lease&#xA;add address=192.168.1.250 client-id=1:2c:cf:67:67:b5:13 mac-address=2C:CF:67:67:B5:13 server=bridge1&#xA;add address=192.168.1.218 client-id=1:e0:be:3:2b:9a:1a mac-address=E0:BE:03:2B:9A:1A server=bridge1&#xA;add address=192.168.1.216 client-id=ff:60:8:6d:aa:0:1:0:1:31:93:31:1a:34:5a:60:8:6d:aa mac-address=34:5A:60:08:6D:AA server=bridge1&#xA;/ip dhcp-server network&#xA;add address=192.168.1.0/24 comment=defconf dns-server=192.168.1.1 gateway=192.168.1.1&#xA;add address=192.168.2.0/24 dns-server=192.168.2.1 gateway=192.168.2.1&#xA;/ip dns&#xA;set allow-remote-requests=yes servers=1.1.1.2,1.0.0.2 use-doh-server=https://odoh.cloudflare-dns.com/dns-query verify-doh-cert=yes&#xA;/ip dns static&#xA;add address=185.199.108.153 name=alwaldend.com ttl=5m type=A&#xA;add address=185.199.109.153 name=alwaldend.com ttl=5m type=A&#xA;add address=185.199.110.153 name=alwaldend.com ttl=5m type=A&#xA;add address=185.199.111.153 name=alwaldend.com ttl=5m type=A&#xA;add address=2606:50c0:8000::153 name=alwaldend.com ttl=5m type=AAAA&#xA;add address=2606:50c0:8001::153 name=alwaldend.com ttl=5m type=AAAA&#xA;add address=2606:50c0:8002::153 name=alwaldend.com ttl=5m type=AAAA&#xA;add address=2606:50c0:8003::153 name=alwaldend.com ttl=5m type=AAAA&#xA;add mx-exchange=mail.protonmail.ch mx-preference=10 name=alwaldend.com ttl=5m type=MX&#xA;add mx-exchange=mailsec.protonmail.ch mx-preference=20 name=alwaldend.com ttl=5m type=MX&#xA;add name=alwaldend.com text=&amp;#34;_globalsign-domain-verification=0QBJgVV_uwcFLTi1Rot3bb1LyJ5uW1WD0ygvIS4OM5&amp;#34; ttl=5m type=TXT&#xA;add name=alwaldend.com text=&amp;#34;protonmail-verification=bdcd133d3f472fa17f66328950d02fbeae1bef75&amp;#34; ttl=5m type=TXT&#xA;add name=alwaldend.com text=&amp;#34;v=spf1 include:_spf.protonmail.ch ~all&amp;#34; ttl=5m type=TXT&#xA;add name=_dmarc.alwaldend.com text=&amp;#34;v=DMARC1; p=quarantine; adkim=s&amp;#34; ttl=5m type=TXT&#xA;add cname=protonmail.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch name=protonmail._domainkey.alwaldend.com ttl=5m type=CNAME&#xA;add cname=protonmail2.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch name=protonmail2._domainkey.alwaldend.com ttl=5m type=CNAME&#xA;add cname=protonmail3.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch name=protonmail3._domainkey.alwaldend.com ttl=5m type=CNAME&#xA;add address=192.168.1.222 name=bm1.dc1.alwaldend.com ttl=5m type=A&#xA;add address=192.168.1.216 name=bm2.dc1.alwaldend.com ttl=5m type=A&#xA;add address=fd2e:546d:5738:0:365a:60ff:fe08:6daa name=bm2.dc1.alwaldend.com ttl=10m type=AAAA&#xA;add address=192.168.1.218 name=bm3.dc1.alwaldend.com ttl=5m type=A&#xA;add address=fd2e:546d:5738:0:e2be:3ff:fe2b:9a1a name=bm3.dc1.alwaldend.com ttl=10m type=AAAA&#xA;add cname=bm2.dc1.alwaldend.com name=host1.pve1.dc1.alwaldend.com ttl=10m type=CNAME&#xA;add address=192.168.10.10 name=cloudinit-test.vm.pve1.dc1.alwaldend.com ttl=5m type=A&#xA;add address=192.168.1.1 name=router1.dc1.alwaldend.com ttl=5m type=A&#xA;add address=fd2e:546d:5738::1 name=router1.dc1.alwaldend.com ttl=10m type=AAAA&#xA;add address=192.168.1.254 name=switch1.dc1.alwaldend.com ttl=5m type=A&#xA;add address=192.168.1.218 name=vault.dc1.alwaldend.com ttl=5m type=A&#xA;add mx-exchange=mx1.simplelogin.co mx-preference=10 name=simplelogin.alwaldend.com ttl=3h type=MX&#xA;add mx-exchange=mx2.simplelogin.co mx-preference=20 name=simplelogin.alwaldend.com ttl=3h type=MX&#xA;add name=simplelogin.alwaldend.com text=&amp;#34;sl-verification=bxfzzfjiggzsxyzxhhmkmjqkaskjgy&amp;#34; ttl=3h type=TXT&#xA;add name=simplelogin.alwaldend.com text=&amp;#34;v=spf1 include:simplelogin.co ~all&amp;#34; ttl=3h type=TXT&#xA;add name=_dmarc.simplelogin.alwaldend.com text=&amp;#34;v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s&amp;#34; ttl=3h type=TXT&#xA;add cname=dkim._domainkey.simplelogin.co name=dkim._domainkey.simplelogin.alwaldend.com ttl=3h type=CNAME&#xA;add cname=dkim02._domainkey.simplelogin.co name=dkim02._domainkey.simplelogin.alwaldend.com ttl=3h type=CNAME&#xA;add cname=dkim03._domainkey.simplelogin.co name=dkim03._domainkey.simplelogin.alwaldend.com ttl=3h type=CNAME&#xA;add cname=alwaldend.com name=www.alwaldend.com ttl=5m type=CNAME&#xA;add mx-exchange=mx.yandex.net mx-preference=10 name=yandex.alwaldend.com ttl=6h type=MX&#xA;add name=yandex.alwaldend.com text=&amp;#34;v=spf1 redirect=_spf.yandex.net&amp;#34; ttl=5m type=TXT&#xA;add name=yandex.alwaldend.com text=&amp;#34;yandex-verification: b83672f59b3dbe16&amp;#34; ttl=5m type=TXT&#xA;add name=mail._domainkey.yandex.alwaldend.com text=&amp;#34;v=DKIM1; k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCcYzFVgkeDOhaIIkWM8gNQjxVsv0/aXfU+ax5urB5y6hA6lSjRnjRo6tm0bXbkOJf41GmiwMNgdXpwRtzgzAlX1i2aJbtEr4b9jzibEGLQ7Cvqs44bOYES9f/K3ueQpnvdTOJmFqlRReFL7ZrUyDFCoQ7f4+7h4i8s01cCcRrt5wIDAQAB&amp;#34; ttl=5m type=TXT&#xA;add address=192.168.1.218 name=host1.vault.dc1.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.60 name=flux.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.60 name=host1.flux.alwaldend.com ttl=5m type=A&#xA;add cname=flux.alwaldend.com name=openid.flux.alwaldend.com ttl=10m type=CNAME&#xA;add cname=flux.alwaldend.com name=operator.flux.alwaldend.com ttl=10m type=CNAME&#xA;add address=192.168.10.40 name=forgejo.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.40 name=host1.forgejo.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.50 name=harbor.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.50 name=host1.harbor.alwaldend.com ttl=5m type=A&#xA;add address=192.168.1.216 name=pve.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.80 name=threexui.alwaldend.com ttl=5m type=A&#xA;add address=192.168.10.80 name=host1.threexui.alwaldend.com ttl=5m type=A&#xA;add address=45.142.141.133 name=njalla1.nodes.threexui.alwaldend.com ttl=5m type=A&#xA;add address=2a0a:3840:8078:141:0:2d8e:8d85:1337 name=njalla1.nodes.threexui.alwaldend.com ttl=10m type=AAAA&#xA;add address=192.168.1.218 name=vault.alwaldend.com ttl=5m type=A&#xA;add address=103.76.53.6 name=ingress.alwaldend.com ttl=5m type=A&#xA;add address=158.160.196.128 name=ingress.alwaldend.com ttl=5m type=A&#xA;add address=158.160.196.128 name=host1.ingress.alwaldend.com ttl=5m type=A&#xA;add address=103.76.53.6 name=host2.ingress.alwaldend.com ttl=5m type=A&#xA;add name=yc.threexui.alwaldend.com ns=ns1.yandexcloud.net ttl=5m type=NS&#xA;add name=yc.threexui.alwaldend.com ns=ns2.yandexcloud.net ttl=5m type=NS&#xA;add cname=host1.nodes.yc.threexui.alwaldend.com name=yc1.nodes.threexui.alwaldend.com ttl=10m type=CNAME&#xA;add address=192.168.10.100 name=runner1.forgejo-runner.alwaldend.com ttl=5m type=A&#xA;add cname=host1.yc.hermes.simeonwarren.users.alwaldend.com name=hermes.simeonwarren.users.alwaldend.com ttl=10m type=CNAME&#xA;add cname=host1.yc.hermes.simeonwarren.users.alwaldend.com name=host1.hermes.simeonwarren.users.alwaldend.com ttl=10m type=CNAME&#xA;add name=yc.hermes.simeonwarren.users.alwaldend.com ns=ns1.yandexcloud.net ttl=5m type=NS&#xA;add name=yc.hermes.simeonwarren.users.alwaldend.com ns=ns2.yandexcloud.net ttl=5m type=NS&#xA;/ip firewall filter&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept established,related,untracked&amp;#34; connection-state=established,related,untracked&#xA;add action=drop chain=input comment=&amp;#34;defconf: drop invalid&amp;#34; connection-state=invalid log-prefix=drop-invalid&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept ICMP&amp;#34; in-interface-list=accept-input-ICMP protocol=icmp&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept to local loopback (for CAPsMAN)&amp;#34; dst-address=127.0.0.1&#xA;add action=drop chain=input comment=&amp;#34;defconf: drop all not coming from LAN&amp;#34; in-interface-list=!LAN log-prefix=drop-not-coming-from-lan&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept in ipsec policy&amp;#34; ipsec-policy=in,ipsec&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept out ipsec policy&amp;#34; ipsec-policy=out,ipsec&#xA;add action=fasttrack-connection chain=forward comment=&amp;#34;defconf: fasttrack&amp;#34; connection-state=established,related&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept established,related, untracked&amp;#34; connection-state=established,related,untracked&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop invalid&amp;#34; connection-state=invalid log-prefix=drop-invalid&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop all from WAN not DSTNATed&amp;#34; connection-nat-state=!dstnat connection-state=new in-interface-list=WAN log-prefix=drop-from-wan-not-dstnated&#xA;add action=accept chain=input in-interface-list=WAN protocol=gre&#xA;add action=accept chain=forward comment=&amp;#34;accept forward WAN&amp;#34; in-interface-list=accept-forward-WAN out-interface-list=WAN&#xA;add action=accept chain=forward comment=&amp;#34;accept forward LAN&amp;#34; in-interface-list=accept-forward-LAN out-interface-list=LAN&#xA;add action=accept chain=input comment=&amp;#34;accept input DNS (udp)&amp;#34; dst-port=53 in-interface-list=accept-input-DNS protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input DNS (tcp)&amp;#34; dst-port=53 in-interface-list=accept-input-DNS protocol=tcp&#xA;add action=accept chain=input comment=accept-input-NTP dst-port=123 in-interface-list=accept-input-NTP protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input DHCP-server&amp;#34; dst-port=67 in-interface-list=accept-input-DHCP-server log-prefix=accept-DHCP protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input winbox (tcp)&amp;#34; dst-port=8291 in-interface-list=accept-input-winbox protocol=tcp&#xA;add action=accept chain=input comment=&amp;#34;accept input winbox (udp)&amp;#34; dst-port=20561 in-interface-list=accept-input-winbox protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input web ui&amp;#34; dst-port=80,443 in-interface-list=accept-input-web-ui protocol=tcp&#xA;add action=accept chain=input comment=&amp;#34;accept input mikrotik neighbor discovery&amp;#34; dst-port=5678 in-interface-list=accept-input-mikrotik-neighbor-discovery protocol=udp&#xA;add action=drop chain=forward comment=&amp;#34;drop forward&amp;#34; log=yes log-prefix=drop-forward&#xA;add action=drop chain=input comment=&amp;#34;drop input&amp;#34; log=yes log-prefix=drop-input&#xA;add action=accept chain=output comment=accept-output-LAN out-interface-list=LAN&#xA;/ip firewall nat&#xA;add action=masquerade chain=srcnat comment=&amp;#34;defconf: masquerade&amp;#34; ipsec-policy=out,none out-interface-list=WAN&#xA;/ip ipsec profile&#xA;set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5&#xA;/ip service&#xA;set www-ssl certificate=alwaldend.com_acme disabled=no&#xA;set reverse-proxy certificate=alwaldend.com_acme&#xA;set api-ssl certificate=alwaldend.com_acme&#xA;/ipv6 address&#xA;add address=::1 from-pool=dc01 interface=bridge1&#xA;add address=::1:0:0:0:1 from-pool=dc01 interface=bridge2&#xA;/ipv6 firewall address-list&#xA;add address=::/128 comment=&amp;#34;defconf: unspecified address&amp;#34; list=bad_ipv6&#xA;add address=::1/128 comment=&amp;#34;defconf: lo&amp;#34; list=bad_ipv6&#xA;add address=fec0::/10 comment=&amp;#34;defconf: site-local&amp;#34; list=bad_ipv6&#xA;add address=::ffff:0.0.0.0/96 comment=&amp;#34;defconf: ipv4-mapped&amp;#34; list=bad_ipv6&#xA;add address=::/96 comment=&amp;#34;defconf: ipv4 compat&amp;#34; list=bad_ipv6&#xA;add address=100::/64 comment=&amp;#34;defconf: discard only &amp;#34; list=bad_ipv6&#xA;add address=2001:db8::/32 comment=&amp;#34;defconf: documentation&amp;#34; list=bad_ipv6&#xA;add address=2001:10::/28 comment=&amp;#34;defconf: ORCHID&amp;#34; list=bad_ipv6&#xA;add address=3ffe::/16 comment=&amp;#34;defconf: 6bone&amp;#34; list=bad_ipv6&#xA;/ipv6 firewall filter&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept established,related,untracked&amp;#34; connection-state=established,related,untracked&#xA;add action=drop chain=input comment=&amp;#34;defconf: drop invalid&amp;#34; connection-state=invalid&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept ICMPv6&amp;#34; in-interface-list=accept-input-ICMP protocol=icmpv6&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept UDP traceroute&amp;#34; dst-port=33434-33534 protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept DHCPv6-Client prefix delegation.&amp;#34; dst-port=546 protocol=udp src-address=fe80::/10&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept IKE&amp;#34; dst-port=500,4500 protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept ipsec AH&amp;#34; protocol=ipsec-ah&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept ipsec ESP&amp;#34; protocol=ipsec-esp&#xA;add action=accept chain=input comment=&amp;#34;defconf: accept all that matches ipsec policy&amp;#34; ipsec-policy=in,ipsec&#xA;add action=drop chain=input comment=&amp;#34;defconf: drop everything else not coming from LAN&amp;#34; in-interface-list=!LAN&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept established,related,untracked&amp;#34; connection-state=established,related,untracked&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop invalid&amp;#34; connection-state=invalid&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop packets with bad src ipv6&amp;#34; src-address-list=bad_ipv6&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop packets with bad dst ipv6&amp;#34; dst-address-list=bad_ipv6&#xA;add action=drop chain=forward comment=&amp;#34;defconf: rfc4890 drop hop-limit=1&amp;#34; hop-limit=equal:1 protocol=icmpv6&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept ICMPv6&amp;#34; in-interface-list=accept-input-ICMP protocol=icmpv6&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept HIP&amp;#34; protocol=139&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept IKE&amp;#34; dst-port=500,4500 protocol=udp&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept ipsec AH&amp;#34; protocol=ipsec-ah&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept ipsec ESP&amp;#34; protocol=ipsec-esp&#xA;add action=accept chain=forward comment=&amp;#34;defconf: accept all that matches ipsec policy&amp;#34; ipsec-policy=in,ipsec&#xA;add action=drop chain=forward comment=&amp;#34;defconf: drop everything else not coming from LAN&amp;#34; in-interface-list=!LAN&#xA;add action=accept chain=forward comment=&amp;#34;accept forward WAN&amp;#34; in-interface-list=accept-forward-WAN out-interface-list=WAN&#xA;add action=accept chain=forward comment=&amp;#34;accept forward LAN&amp;#34; in-interface-list=accept-forward-LAN out-interface-list=LAN&#xA;add action=accept chain=input comment=&amp;#34;accept input DNS (udp)&amp;#34; dst-port=53 in-interface-list=accept-input-DNS protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input DNS (tcp)&amp;#34; dst-port=53 in-interface-list=accept-input-DNS protocol=tcp&#xA;add action=accept chain=input comment=accept-input-NTP dst-port=123 in-interface-list=accept-input-NTP protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input winbox (tcp)&amp;#34; dst-port=8291 in-interface-list=accept-input-winbox protocol=tcp&#xA;add action=accept chain=input comment=&amp;#34;accept input winbox (udp)&amp;#34; dst-port=20561 in-interface-list=accept-input-winbox protocol=udp&#xA;add action=accept chain=input comment=&amp;#34;accept input web ui&amp;#34; dst-port=80,443 in-interface-list=accept-input-web-ui protocol=tcp&#xA;add action=accept chain=input comment=&amp;#34;accept input mikrotik neighbor discovery&amp;#34; dst-port=5678 in-interface-list=accept-input-mikrotik-neighbor-discovery protocol=udp&#xA;add action=drop chain=forward comment=&amp;#34;drop forward&amp;#34; log=yes log-prefix=drop-forward-ipv6&#xA;add action=drop chain=input comment=&amp;#34;drop input&amp;#34; log=yes log-prefix=drop-input-ipv6&#xA;add action=accept chain=output comment=accept-output-LAN out-interface-list=LAN&#xA;/ipv6 nd&#xA;set [ find default=yes ] advertise-dns=yes interface=bridge1&#xA;add advertise-dns=yes interface=bridge2&#xA;/system clock&#xA;set time-zone-name=Europe/Moscow&#xA;/system identity&#xA;set name=router1.dc1.alwaldend.com&#xA;/system ntp server&#xA;set enabled=yes&#xA;/system routerboard settings&#xA;set auto-upgrade=yes&#xA;/tool mac-server&#xA;set allowed-interface-list=LAN&#xA;/tool mac-server mac-winbox&#xA;set allowed-interface-list=LAN&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;h3 id=&#34;router2&#34;&gt;Router2&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#router2&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code class=&#34;language-rsc&#34; data-lang=&#34;rsc&#34;&gt;# 2025-09-07 11:04:01 by RouterOS 7.19.4&#xA;# model = L009UiGS-2HaxD&#xA;/interface bridge&#xA;add name=bridge01&#xA;/port&#xA;set 0 name=serial0&#xA;/interface bridge port&#xA;add bridge=bridge01 interface=ether2&#xA;add bridge=bridge01 interface=ether3&#xA;add bridge=bridge01 interface=ether4&#xA;add bridge=bridge01 interface=ether5&#xA;add bridge=bridge01 interface=ether6&#xA;add bridge=bridge01 interface=ether7&#xA;add bridge=bridge01 interface=ether8&#xA;add bridge=bridge01 interface=ether1&#xA;/ip neighbor discovery-settings&#xA;set discover-interface-list=!dynamic&#xA;/ipv6 settings&#xA;set accept-router-advertisements=yes&#xA;/ip dhcp-client&#xA;add interface=bridge01&#xA;/system clock&#xA;set time-zone-name=Europe/Moscow&#xA;/system identity&#xA;set name=router02.dc01.alwaldend.com&#xA;/system routerboard settings&#xA;set enter-setup-on=delete-key&#xA;&lt;/code&gt;&lt;/pre&gt;</description>
			</item>
			<item>
				<title>Mikrotik DNS</title>
				<link>https://www-staging.alwaldend.com/docs/infra/dns/mikrotik_dns/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/dns/mikrotik_dns/</guid>
				<description>&lt;p&gt;Every record this repository declares for the internal &lt;code&gt;dc1&lt;/code&gt; view, which RouterOS serves for that network.&lt;/p&gt;&#xA;&lt;p&gt;This page is generated from the declarations; run &lt;code&gt;bazel run //infra/dns/cmd/dump -- --write&lt;/code&gt; after changing them. The authoritative source is each owner&amp;rsquo;s &lt;code&gt;dnsconfig.json&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;table&gt;&#xA;&#x9;&lt;thead&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Domain&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Type&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;TTL&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Value&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Declaration&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/thead&gt;&#xA;&#x9;&lt;tbody&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.108.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.109.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.110.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;185.199.111.153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8000::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8001::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8002::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2606:50c0:8003::153&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mail.protonmail.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;20 mailsec.protonmail.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_globalsign-domain-verification=0QBJgVV_uwcFLTi1Rot3bb1LyJ5uW1WD0ygvIS4OM5&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail-verification=bdcd133d3f472fa17f66328950d02fbeae1bef75&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;@&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 include:_spf.protonmail.ch ~all&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_dmarc&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DMARC1; p=quarantine; adkim=s&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;_dmarc.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;automation.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.92&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.222&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/mikrotik/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm2.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.216&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/pve/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm2.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;fd2e:546d:5738:0:365a:60ff:fe08:6daa&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/pve/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm3.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.218&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm3.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;fd2e:546d:5738:0:e2be:3ff:fe2b:9a1a&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;canvas.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.90&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;cloud&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;nas.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;cloudinit-test.vm.pve1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.10&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/pve/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.automation.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.92&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.canvas.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.90&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.cloud&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.209&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.server.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.91&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dc1.t3code.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim02._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim02._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim03._domainkey.simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;dkim03._domainkey.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;flux&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.60&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/flux/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;forgejo&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.40&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;git&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.40&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;harbor&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.50&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/harbor/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.automation.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.92&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.canvas.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.90&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.cloud&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.nas.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.flux&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.60&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/flux/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.forgejo&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.40&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.harbor&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.50&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/harbor/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.ingress&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;81.26.185.118&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/ingress/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.nas&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.209&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.pve1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;bm2.dc1.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/pve/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.server.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.91&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.80&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.vault.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.218&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.xcp-ng&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.213&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/xcp_ng/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.xoa.xcp-ng&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.206&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/xcp_ng/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ingress&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;81.26.185.118&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/ingress/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;mail._domainkey.yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=DKIM1; k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCcYzFVgkeDOhaIIkWM8gNQjxVsv0/aXfU+ax5urB5y6hA6lSjRnjRo6tm0bXbkOJf41GmiwMNgdXpwRtzgzAlX1i2aJbtEr4b9jzibEGLQ7Cvqs44bOYES9f/K3ueQpnvdTOJmFqlRReFL7ZrUyDFCoQ7f4+7h4i8s01cCcRrt5wIDAQAB&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;nas&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.209&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/nas/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;njalla1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;45.142.141.133&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;njalla1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;2a0a:3840:8078:141:0:2d8e:8d85:1337&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;openid.flux&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;flux.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/flux/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;operator.flux&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;flux.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/flux/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail2._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail2.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail3._domainkey&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;protonmail3.domainkey.djgwfzcu5fgjtpoijqqomgifmqj6zeiuwdd4mzim4hrxab3zsgwkq.domains.proton.ch.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;pve&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.216&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/pve/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;router1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/mikrotik/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;router1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;AAAA&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;fd2e:546d:5738::1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/mikrotik/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;runner1.forgejo-runner&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.100&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/forgejo_runner/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;server.openhands&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.91&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/openhands/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mx1.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;20 mx2.simplelogin.co.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;sl-verification=bxfzzfjiggzsxyzxhhmkmjqkaskjgy&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;simplelogin&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10800&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 include:simplelogin.co ~all&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;switch1.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.254&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/mikrotik/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;t3code.host-bot.simeonwarren.users&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.210&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;users/simeonwarren/host_bot/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.10.80&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;vault&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.218&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;vault.dc1&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.218&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/vault/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;www&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;www-staging&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;alwaldend.github.io.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;xcp-ng&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.213&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/xcp_ng/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;xoa.xcp-ng&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;A&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;192.168.1.206&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/xcp_ng/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;MX&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;21600&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;10 mx.yandex.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;v=spf1 redirect=_spf.yandex.net&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;TXT&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;300&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yandex-verification: b83672f59b3dbe16&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/dns/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;NS&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ns1.yandexcloud.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;NS&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;ns2.yandexcloud.net.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;yc1.nodes.threexui&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;CNAME&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;default&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;host1.nodes.yc.threexui.alwaldend.com.&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;infra/threexui/dnsconfig.json&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/tbody&gt;&#xA;&lt;/table&gt;</description>
			</item>
			<item>
				<title>Nas</title>
				<link>https://www-staging.alwaldend.com/docs/infra/nas/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/nas/</guid>
				<description>&lt;p&gt;The &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/nas/tf/&#34;&gt;Terraform package&lt;/a&gt; prepares this owner&amp;rsquo;s DNS records through&#xA;its dedicated Vault AppRole. NAS service provisioning remains outside that root.&lt;/p&gt;&#xA;&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Docs: &lt;a href=&#34;https://www.truenas.com/&#34;&gt;https://www.truenas.com/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>OpenHands</title>
				<link>https://www-staging.alwaldend.com/docs/infra/openhands/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/openhands/</guid>
				<description>&lt;p&gt;OpenHands deploys as separate components because each owns a distinct&#xA;responsibility and trust boundary:&lt;/p&gt;&#xA;&lt;table&gt;&#xA;&#x9;&lt;thead&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Component&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;th&gt;Responsibility&lt;/th&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/thead&gt;&#xA;&#x9;&lt;tbody&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Agent Canvas&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Browser client for conversations, files, settings, backends, automations&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Agent Server&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Runs conversations, agents, tools, and workspace operations&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&#x9;&#x9;&lt;tr&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Automation Server&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&#x9;&#x9;&lt;td&gt;Stores schedules and triggers, tracks runs, dispatches conversations&lt;/td&gt;&#xA;&#x9;&#x9;&#x9;&lt;/tr&gt;&#xA;&#x9;&lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;The agent server runs directly on the host with the service account&amp;rsquo;s&#xA;permissions. Its workspace is a working directory; operating-system account&#xA;permissions define its access to the host. Treat the agent server host as&#xA;trusted infrastructure.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Org1</title>
				<link>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/org1/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/org1/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Site: &lt;a href=&#34;https://yandex.cloud&#34;&gt;https://yandex.cloud&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Output</title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/tf/output/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/tf/output/</guid>
				<description></description>
			</item>
			<item>
				<title>Pve</title>
				<link>https://www-staging.alwaldend.com/docs/infra/pve/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/pve/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Docs: &lt;a href=&#34;https://www.proxmox.com/en/products/proxmox-virtual-environment/overview&#34;&gt;https://www.proxmox.com/en/products/proxmox-virtual-environment/overview&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;deployment&#34;&gt;Deployment&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#deployment&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/pve/ansible &lt;span style=&#34;color:#75715e&#34;&gt;# host setup&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/pve/tf/tf.apply &lt;span style=&#34;color:#75715e&#34;&gt;# tf setup&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;recreate-the-test-vm&#34;&gt;Recreate the test VM&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#recreate-the-test-vm&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/pve/tf:tf.apply -- --replace module.vm_cloudinit_test.proxmox_vm_qemu.vm&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;cloud-init-snippet-update&#34;&gt;Cloud-init snippet update&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#cloud-init-snippet-update&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/pve/ansible -- --tags pve_snippets&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;update-acme-account&#34;&gt;Update ACME account&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#update-acme-account&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Create an EAB:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/dc1/vault -- write -f pki/ica_servers/roles/src_infra_dc1_pve1_pki_server/acme/new-eab&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;li&gt;Login as &lt;code&gt;root@pam&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;Go to Datacenter -&amp;gt; ACME&lt;/li&gt;&#xA;&lt;li&gt;Create a new account with the EAB and a directory:&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;https://vault.dc1.alwaldend.com:8200/v1/pki/ica_servers/roles/src_infra_dc1_pve1_pki_server/acme/directory&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;pve-token&#34;&gt;Pve token&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#pve-token&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Create a token with Privilege Separation&lt;/li&gt;&#xA;&lt;li&gt;Grant it required roles&lt;/li&gt;&#xA;&lt;li&gt;Create json:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-json&#34; data-lang=&#34;json&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#f92672&#34;&gt;&amp;#34;token_id&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&amp;#34;&lt;/span&gt;,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#f92672&#34;&gt;&amp;#34;token_secret&amp;#34;&lt;/span&gt;: &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;li&gt;Write the data:&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/pve:vault.kv_put alwaldend.com/vault1/approles/src_infra_dc1_pve1/pve_token @&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;${&lt;/span&gt;PWD&lt;span style=&#34;color:#e6db74&#34;&gt;}&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;/data.json&amp;#34;&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
			<item>
				<title>Repositories</title>
				<link>https://www-staging.alwaldend.com/docs/infra/repos/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/repos/</guid>
				<description>&lt;p&gt;This project owns the organization and repository catalog consumed by&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/github/tf/&#34;&gt;GitHub&lt;/a&gt;, &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/gitlab/tf/&#34;&gt;GitLab&lt;/a&gt;, and&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/forgejo/tf/&#34;&gt;Forgejo&lt;/a&gt;. Named organization administrators and&#xA;developers belong in this catalog. &lt;a href=&#34;config.json&#34;&gt;Root configuration&lt;/a&gt; owns&#xA;the schema version and defaults. Each organization owns&#xA;&lt;code&gt;orgs/&amp;lt;organization&amp;gt;/org.json&lt;/code&gt; and one&#xA;&lt;code&gt;orgs/&amp;lt;organization&amp;gt;/repos/&amp;lt;repository&amp;gt;.json&lt;/code&gt; file per repository. Vault&#xA;continues to own Forgejo login identities and service-specific access.&lt;/p&gt;&#xA;&lt;p&gt;First-party means owned by us, regardless of forge. Our repositories retain&#xA;their chosen names across GitHub, GitLab, and Forgejo: &lt;code&gt;alwaldend/src&lt;/code&gt; stays&#xA;&lt;code&gt;alwaldend/src&lt;/code&gt;, including when copied or synchronized between those forges.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Repository catalog module</title>
				<link>https://www-staging.alwaldend.com/docs/infra/repos/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/repos/tf/</guid>
				<description>&lt;p&gt;This provider-free Terraform module reads the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;catalog files&lt;/a&gt;, merges&#xA;forge defaults, and projects organization-owned repository names and settings&#xA;for each consumer. It creates no resources and uses no credentials.&lt;/p&gt;&#xA;&lt;p&gt;Fork and mirror names follow the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;catalog naming contract&lt;/a&gt;.&#xA;Output keys retain the organization and catalog key, independently of the&#xA;derived destination name. The consumers retain their existing state addresses&#xA;where resources were already managed.&lt;/p&gt;&#xA;&lt;p&gt;The catalog test runs without network access or provider initialization:&lt;/p&gt;</description>
			</item>
			<item>
				<title>Shared DNS Terraform</title>
				<link>https://www-staging.alwaldend.com/docs/infra/dns/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/dns/tf/</guid>
				<description>&lt;p&gt;This root consumes &lt;a href=&#34;../dnsconfig.json&#34;&gt;the canonical common declarations&lt;/a&gt;&#xA;through the reusable DNS module. It uses the &lt;code&gt;src_infra_dns&lt;/code&gt; AppRole and its&#xA;existing Vault-backed HTTP state. Both Cloudflare and RouterOS credentials&#xA;are injected through the &lt;code&gt;tf=1&lt;/code&gt; stage label.&lt;/p&gt;&#xA;&lt;p&gt;Shared apex and mail records were adopted on 2026-09-13. &lt;code&gt;dns_enabled&lt;/code&gt; now&#xA;defaults to &lt;code&gt;true&lt;/code&gt;; reconciliation against the adopted state and unchanged&#xA;declarations must propose no record changes. The &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption evidence&lt;/a&gt;&#xA;records 60 imports and preservation of both complete provider inventories.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Source repository</title>
				<link>https://www-staging.alwaldend.com/docs/infra/src/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/src/</guid>
				<description>&lt;p&gt;This project owns the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/src/openspec/&#34;&gt;OpenSpec workspace&lt;/a&gt; describing&#xA;evolution of the alwaldend/src monorepo: its shared structure, build system&#xA;and development workflows. It also retains the index of the goal-to-OpenSpec&#xA;migration. Individual projects own their own specifications and change history.&lt;/p&gt;&#xA;&lt;p&gt;The repository root remains the Bazel workspace and owns shared executable&#xA;configuration. This directory owns repository development specifications;&#xA;adding or changing them does not provision infrastructure.&lt;/p&gt;&#xA;&lt;p&gt;Run the &lt;a href=&#34;../../tools/openspec/README.md&#34;&gt;pinned CLI&lt;/a&gt; from the repository root.&#xA;It selects this project by default:&lt;/p&gt;</description>
			</item>
			<item>
				<title>sub</title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/sub/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/sub/</guid>
				<description></description>
			</item>
			<item>
				<title>Terraform</title>
				<link>https://www-staging.alwaldend.com/docs/infra/xcp_ng/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/xcp_ng/tf/</guid>
				<description>&lt;p&gt;This configuration manages one Xen Orchestra resource set per Vault AppRole&#xA;and configures the installed XO OIDC plugin through a packaged JSON-RPC helper.&#xA;See the &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/xcp_ng/&#34;&gt;project documentation&lt;/a&gt; for requirements and checks.&lt;/p&gt;&#xA;&lt;p&gt;Resource-set subjects reference exact synchronized OIDC users whose OIDC&#xA;subject identifiers match Vault AppRole entity UUIDs. AppRole groups can include other&#xA;service entities, so using those groups would grant access across deployments.&#xA;Bootstrap XO&amp;rsquo;s OIDC configuration first, then log in through OIDC as each&#xA;AppRole and run the full Terraform apply. Identity discovery runs at plan&#xA;time and never creates users. AppRoles that have not logged in are listed in&#xA;&lt;code&gt;approles_pending_oidc_login&lt;/code&gt;; their sets remain without subjects until the&#xA;next apply after login. Groups remain responsible for login entitlement and&#xA;administrative access, separately from these per-AppRole grants.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Terraform setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo_runner/tf_setup/</guid>
				<description>&lt;p&gt;Use this package&amp;rsquo;s &lt;code&gt;dns.plan&lt;/code&gt;, &lt;code&gt;dns.show&lt;/code&gt;, and &lt;code&gt;dns.apply&lt;/code&gt; targets for the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;scoped DNS adoption workflow&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;These targets select &lt;code&gt;dns=1&lt;/code&gt; and target &lt;code&gt;module.dns&lt;/code&gt; with the existing&#xA;&lt;code&gt;src_infra_forgejo_runner&lt;/code&gt; AppRole and setup backend. Plan declared imports,&#xA;inspect the saved plan with &lt;code&gt;dns.show&lt;/code&gt;, and apply only the reviewed file with&#xA;&lt;code&gt;dns.apply&lt;/code&gt;. Ordinary setup commands retain their &lt;code&gt;tf=setup&lt;/code&gt; flow.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;dns_enabled&lt;/code&gt; defaults to &lt;code&gt;true&lt;/code&gt; after verified adoption. Keep it enabled to&#xA;retain existing records; disabling it would propose deletion. The&#xA;&lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption record&lt;/a&gt;&#xA;contains the import, follow-up plan, inventory, and DNS verification evidence.&#xA;The shared &lt;a href=&#34;../../dns/openspec/changes/archive/2026-09-13-migrate-project-dns-to-terraform/cutover.md#prepare-the-owner&#34;&gt;cutover procedure&lt;/a&gt;&#xA;owns prerequisites and recovery. Scoped DNS checks do not establish VM or runner&#xA;service health.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/tf/</guid>
				<description>&lt;p&gt;This package configures Forgejo organizations, repositories, and access from&#xA;the shared &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/&#34;&gt;repository catalog&lt;/a&gt;. The catalog owns named&#xA;administrators, developers, repository identities, and destination names.&#xA;Its &lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/repos/tf/&#34;&gt;Terraform module&lt;/a&gt; supplies the consumer&amp;rsquo;s&#xA;repository projection. First-party names remain stable across forges;&#xA;external fork and mirror names retain their original upstream identity.&lt;/p&gt;&#xA;&lt;p&gt;Before applying, provision the Vault OIDC authentication source with Ansible and set&#xA;&lt;code&gt;TF_VAR_vault_oauth_source_id&lt;/code&gt; to its verified positive numeric ID. Obtain the&#xA;ID from &lt;code&gt;forgejo admin auth list&lt;/code&gt; on the instance using the service&amp;rsquo;s config&#xA;and work path; confirm that the &lt;code&gt;vault&lt;/code&gt; source is active and uses OpenID&#xA;Connect with the expected Vault issuer. Do not assume source IDs survive&#xA;instance recreation.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/tf/</guid>
				<description></description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/ingress/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/ingress/tf/</guid>
				<description>&lt;p&gt;Use this package&amp;rsquo;s &lt;code&gt;dns.plan&lt;/code&gt;, &lt;code&gt;dns.show&lt;/code&gt;, and &lt;code&gt;dns.apply&lt;/code&gt; targets for the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;scoped DNS adoption workflow&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;DNS ownership is enabled by default after the verified 2026-09-13 adoption.&#xA;The &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption evidence&lt;/a&gt;&#xA;records four imports, a no-change follow-up plan, and preserved provider inventories.&#xA;The DNS wrappers select &lt;code&gt;dns=1&lt;/code&gt; and &lt;code&gt;module.dns&lt;/code&gt; within this root and backend;&#xA;their validation covers DNS and its dependencies. Apply requires a reviewed&#xA;saved plan, and ordinary ingress service authentication remains separate.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/pve/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/pve/tf/</guid>
				<description>&lt;p&gt;Use this package&amp;rsquo;s &lt;code&gt;dns.plan&lt;/code&gt;, &lt;code&gt;dns.show&lt;/code&gt;, and &lt;code&gt;dns.apply&lt;/code&gt; targets for the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;scoped DNS adoption workflow&lt;/a&gt;.&#xA;They select &lt;code&gt;dns=1&lt;/code&gt; and target &lt;code&gt;module.dns&lt;/code&gt; in this root, retaining the&#xA;&lt;code&gt;src_infra_dc1_pve1&lt;/code&gt; AppRole and existing backend. Use the&#xA;&lt;a href=&#34;../../dns/openspec/changes/archive/2026-09-13-migrate-project-dns-to-terraform/cutover.md#prepare-the-owner&#34;&gt;owner preparation and import procedure&lt;/a&gt;&#xA;for declarative import maps and reviewed saved-plan apply.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;dns_enabled&lt;/code&gt; defaults to &lt;code&gt;true&lt;/code&gt; after the&#xA;&lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;completed adoption&lt;/a&gt;.&#xA;Reconciliation against adopted state and unchanged declarations produces no DNS&#xA;changes. DNS targeting covers DNS and its dependencies; it does not establish&#xA;PVE host, API, or service health. Ordinary Terraform commands retain their&#xA;existing Proxmox authentication.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/tf/</guid>
				<description></description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/tf/</guid>
				<description>&lt;h2 id=&#34;dns-identities&#34;&gt;DNS identities&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#dns-identities&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;a href=&#34;approles_dns.tf&#34;&gt;Missing DNS-owner AppRoles&lt;/a&gt; compose the existing reusable&#xA;AppRole module with an owner-specific DNS policy in &lt;code&gt;approles/&amp;lt;name&amp;gt;/&lt;/code&gt;.&#xA;&lt;a href=&#34;dns_access/main.tf&#34;&gt;DNS access&lt;/a&gt; grants read-only access to the existing&#xA;provider credentials for the owner&amp;rsquo;s views. Existing component identities&#xA;receive these policies through their existing module declarations.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;group_dns_approles.tf&#34;&gt;DNS-only group membership&lt;/a&gt; adds no policies. These&#xA;identities retain their own state and named shared-secret access without&#xA;joining the general infrastructure AppRole group or receiving cloud&#xA;provisioning, SSH, or PKI permissions.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf</title>
				<link>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/org1/tf/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/org1/tf/</guid>
				<description></description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/flux/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/flux/tf_setup/</guid>
				<description>&lt;p&gt;This root owns the &lt;a href=&#34;../dnsconfig.json&#34;&gt;Flux DNS declaration&lt;/a&gt;. DNS ownership&#xA;defaults to enabled after &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;verified adoption&lt;/a&gt;;&#xA;keep it enabled to retain the managed records.&lt;/p&gt;&#xA;&lt;p&gt;Use &lt;code&gt;//infra/flux/tf_setup:dns.plan&lt;/code&gt;, &lt;code&gt;:dns.show&lt;/code&gt;, and &lt;code&gt;:dns.apply&lt;/code&gt; for&#xA;&lt;a href=&#34;../../dns/openspec/changes/archive/2026-09-13-migrate-project-dns-to-terraform/cutover.md#prepare-the-owner&#34;&gt;scoped DNS reconciliation&lt;/a&gt;.&#xA;These targets retain the setup backend and &lt;code&gt;src_infra_flux&lt;/code&gt; AppRole, select&#xA;&lt;code&gt;dns=1&lt;/code&gt;, and target &lt;code&gt;module.dns&lt;/code&gt;. Apply requires a reviewed saved plan.&#xA;Reconciliation of unchanged declarations must produce no DNS changes.&lt;/p&gt;&#xA;&lt;p&gt;The ordinary setup targets retain their service authentication behavior.&#xA;DNS checks do not establish PVE VM or service health; current aggregate source&#xA;validation remains part of repository delivery.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/forgejo/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/forgejo/tf_setup/</guid>
				<description>&lt;p&gt;This package creates a Xen Orchestra VM in the &lt;code&gt;src_infra_dc1_forgejo1&lt;/code&gt;&#xA;resource set. &lt;code&gt;infra/forgejo/al.lua&lt;/code&gt; authenticates with Forgejo&amp;rsquo;s own Vault&#xA;AppRole and the packaged XO OIDC login plugin. The plugin supplies a temporary&#xA;XO token and revokes it on shutdown; no infrastructure administrator token&#xA;is loaded. The setup HTTP backend remains owned by the same Forgejo config.&lt;/p&gt;&#xA;&lt;p&gt;Before running this package, bootstrap the AppRole&amp;rsquo;s XO OIDC user and apply&#xA;its resource-set membership and existing VM ACL through &lt;code&gt;infra/xcp_ng/tf&lt;/code&gt;.&#xA;Subjects are matched by immutable Vault entity UUID under the configured&#xA;OIDC issuer, not by login name or AppRole group membership. See&#xA;&lt;a href=&#34;../../xcp_ng/cmd/xo_login/README.md&#34;&gt;XO authentication&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/harbor/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/harbor/tf_setup/</guid>
				<description>&lt;p&gt;This root owns the &lt;a href=&#34;../dnsconfig.json&#34;&gt;Harbor DNS declaration&lt;/a&gt;. DNS ownership&#xA;defaults to enabled after &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;verified adoption&lt;/a&gt;;&#xA;keep it enabled to retain the managed records.&lt;/p&gt;&#xA;&lt;p&gt;Use &lt;code&gt;//infra/harbor/tf_setup:dns.plan&lt;/code&gt;, &lt;code&gt;:dns.show&lt;/code&gt;, and &lt;code&gt;:dns.apply&lt;/code&gt; for&#xA;&lt;a href=&#34;../../dns/openspec/changes/archive/2026-09-13-migrate-project-dns-to-terraform/cutover.md#prepare-the-owner&#34;&gt;scoped DNS reconciliation&lt;/a&gt;.&#xA;These targets retain the setup backend and &lt;code&gt;src_infra_harbor&lt;/code&gt; AppRole, select&#xA;&lt;code&gt;dns=1&lt;/code&gt;, and target &lt;code&gt;module.dns&lt;/code&gt;. Apply requires a reviewed saved plan.&#xA;Reconciliation of unchanged declarations must produce no DNS changes.&lt;/p&gt;&#xA;&lt;p&gt;The ordinary setup targets retain their service authentication behavior.&#xA;DNS checks do not establish PVE VM or service health; current aggregate source&#xA;validation remains part of repository delivery.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/openhands/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/openhands/tf_setup/</guid>
				<description>&lt;p&gt;This package creates Xen Orchestra VMs in the &lt;code&gt;src_infra_openhands&lt;/code&gt; resource&#xA;set for the three OpenHands components that run off host-bot: Agent Canvas,&#xA;the agent server, and the automation server. &lt;code&gt;infra/openhands/al.lua&lt;/code&gt;&#xA;authenticates with OpenHands&amp;rsquo; own Vault AppRole and the packaged XO OIDC login&#xA;plugin. The plugin supplies a temporary XO token and revokes it on shutdown;&#xA;no infrastructure administrator token is loaded. The setup HTTP backend&#xA;remains owned by the same OpenHands config.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/tf_setup/</guid>
				<description>&lt;p&gt;Use this package&amp;rsquo;s &lt;code&gt;dns.plan&lt;/code&gt;, &lt;code&gt;dns.show&lt;/code&gt;, and &lt;code&gt;dns.apply&lt;/code&gt; targets for the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;scoped DNS adoption workflow&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;DNS ownership is enabled by default after the verified 2026-09-13 adoption.&#xA;The &lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption evidence&lt;/a&gt;&#xA;records 12 imports, a no-change follow-up plan, and preserved provider inventories.&#xA;The DNS wrappers select &lt;code&gt;dns=1&lt;/code&gt; and &lt;code&gt;module.dns&lt;/code&gt; within this setup root and&#xA;backend; their validation covers DNS and its dependencies. Apply requires a&#xA;reviewed saved plan, and ordinary service authentication remains separate.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Tf setup</title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/tf_setup/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/tf_setup/</guid>
				<description>&lt;p&gt;This root owns Vault&amp;rsquo;s canonical &lt;a href=&#34;../dnsconfig.json&#34;&gt;DNS declaration&lt;/a&gt; and&#xA;retains its existing &lt;code&gt;src_infra_dc1_vault&lt;/code&gt; AppRole and setup state backend.&#xA;Use &lt;code&gt;//infra/vault/tf_setup:dns.plan&lt;/code&gt;, &lt;code&gt;dns.show&lt;/code&gt;, and &lt;code&gt;dns.apply&lt;/code&gt; for the&#xA;&lt;a href=&#34;https://www-staging.alwaldend.com/docs/infra/dns/&#34;&gt;scoped DNS workflow&lt;/a&gt;. They select &lt;code&gt;dns=1&lt;/code&gt; and&#xA;&lt;code&gt;module.dns&lt;/code&gt;; apply requires a reviewed saved plan. Ordinary setup and service&#xA;wrappers retain their existing authentication flow.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;dns_enabled&lt;/code&gt; defaults to &lt;code&gt;true&lt;/code&gt; after verified adoption. Keep it enabled to&#xA;retain existing records; disabling it would propose deletion. The&#xA;&lt;a href=&#34;../openspec/changes/archive/2026-09-13-adopt-dns-records/design.md&#34;&gt;adoption record&lt;/a&gt;&#xA;contains the import and verification evidence. Targeted DNS checks do not&#xA;establish the health of other resources in the root.&lt;/p&gt;</description>
			</item>
			<item>
				<title>threexui</title>
				<link>https://www-staging.alwaldend.com/docs/infra/threexui/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/threexui/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Site: &lt;a href=&#34;https://docs.sanaei.dev/&#34;&gt;https://docs.sanaei.dev/&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Releases: &lt;a href=&#34;https://github.com/MHSanaei/3x-ui/releases&#34;&gt;https://github.com/MHSanaei/3x-ui/releases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;fetch-and-fix-subs-for-a-particular-subscription-id&#34;&gt;Fetch and fix subs for a particular subscription id&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#fetch-and-fix-subs-for-a-particular-subscription-id&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/threexui:fix_subs -- --hosts njalla1.nodes.threexui.alwaldend.com,yc1.nodes.threexui.alwaldend.com --sub_id subid&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;fix-subs-from-a-local-file&#34;&gt;Fix subs from a local file&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#fix-subs-from-a-local-file&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/threexui:fix_subs -- --sub_file path_to_file&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description>
			</item>
			<item>
				<title>Vault</title>
				<link>https://www-staging.alwaldend.com/docs/infra/vault/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/vault/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Intermediate CA: &lt;a href=&#34;https://developer.hashicorp.com/vault/tutorials/pki/pki-engine-external-ca&#34;&gt;https://developer.hashicorp.com/vault/tutorials/pki/pki-engine-external-ca&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;ACME: &lt;a href=&#34;https://developer.hashicorp.com/vault/docs/secrets/pki/acme&#34;&gt;https://developer.hashicorp.com/vault/docs/secrets/pki/acme&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;deployment&#34;&gt;Deployment&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#deployment&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/tf_setup:tf.apply &lt;span style=&#34;color:#75715e&#34;&gt;# Create VMs (requires an active Vault host)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/ansible &lt;span style=&#34;color:#75715e&#34;&gt;# Set up hosts (BM and VMs)&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/tf:tf.apply &lt;span style=&#34;color:#75715e&#34;&gt;# Configure vault&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;backup&#34;&gt;Backup&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#backup&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault:backup&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;unseal&#34;&gt;Unseal&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#unseal&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;With a working Vault:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault:unseal&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Without a working Vault:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault:unseal_standalone&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;fix-quorum&#34;&gt;Fix quorum&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#fix-quorum&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/ansible:fix_quorum&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;set-up-only-vms&#34;&gt;Set up only VMs&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#set-up-only-vms&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/ansible:ansible.vm &lt;span style=&#34;color:#75715e&#34;&gt;# Set up only VMs&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;set-up-only-bare-metal&#34;&gt;Set up only bare metal&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#set-up-only-bare-metal&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;bazel run //infra/vault/ansible:ansible.bm &lt;span style=&#34;color:#75715e&#34;&gt;# Set up only bare metal&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;tf&#34;&gt;Tf&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#tf&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Plan:&lt;/p&gt;</description>
			</item>
			<item>
				<title>XCP-ng</title>
				<link>https://www-staging.alwaldend.com/docs/infra/xcp_ng/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/xcp_ng/</guid>
				<description>&lt;p&gt;Terraform in &lt;code&gt;tf&lt;/code&gt; manages a Xen Orchestra resource set for every&#xA;entity in Vault&amp;rsquo;s &lt;code&gt;approles&lt;/code&gt; group, following &lt;code&gt;infra/pve/tf&lt;/code&gt;. Resource sets&#xA;are the XO grouping and delegation mechanism; XCP-ng host pools represent&#xA;physical clusters and are not created per AppRole.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;resource_set_inventory&lt;/code&gt; assigns a pool, template, storage repository and&#xA;network by name to each AppRole. Native provider lookups resolve their IDs&#xA;and reject ambiguous matches. Forgejo and OpenHands have assignments by default;&#xA;other sets remain empty. Subjects are the exact synchronized OIDC users&#xA;selected by Vault issuer and immutable AppRole entity UUID. Bootstrap has&#xA;synchronized the 18 AppRole users; new AppRoles need their first OIDC login&#xA;before Terraform can bind their sets. &lt;code&gt;resource_set_cpu_limit&lt;/code&gt; defaults to&#xA;32 CPUs per set. Creating a set does not allocate CPUs or storage.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Xen Orchestra certificates</title>
				<link>https://www-staging.alwaldend.com/docs/infra/xcp_ng/ansible/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/xcp_ng/ansible/</guid>
				<description>&lt;p&gt;This playbook installs Debian&amp;rsquo;s Certbot package and obtains a certificate for&#xA;&lt;code&gt;xoa.xcp-ng.alwaldend.com&lt;/code&gt; and &lt;code&gt;host1.xoa.xcp-ng.alwaldend.com&lt;/code&gt; from the Vault&#xA;&lt;code&gt;src_infra_xcp_ng_pki_server&lt;/code&gt; ACME role. The XCP-ng AppRole creates the&#xA;external account binding; its registration file is removed after issuance.&lt;/p&gt;&#xA;&lt;p&gt;The target injects &lt;code&gt;xoa_ssh_password&lt;/code&gt; from&#xA;&lt;code&gt;secrets/alwaldend.com/vault1/approles/src_infra_xcp_ng/xoa&lt;/code&gt; for the appliance&amp;rsquo;s&#xA;&lt;code&gt;xoa&lt;/code&gt; SSH account and sudo. Ansible uses its &lt;code&gt;sshpass&lt;/code&gt; password mechanism;&#xA;the controller must provide &lt;code&gt;sshpass&lt;/code&gt; and a verified SSH host key. Passwords&#xA;are runtime environment inputs and are not stored in inventory.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Yandex Cloud</title>
				<link>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
				<guid>https://www-staging.alwaldend.com/docs/infra/yandex_cloud/</guid>
				<description>&lt;h2 id=&#34;links&#34;&gt;Links&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#links&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;Site: &lt;a href=&#34;https://yandex.cloud&#34;&gt;https://yandex.cloud&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
			</item>
	</channel>
</rss>
