| Time | Type | Actor | Services | Targets | Outcome | Summary | Link |
|---|---|---|---|---|---|---|---|
| 2026-03-23 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, NetBox, ntopng, Portainer, Proxmox UI, step-ca, Uptime Kuma | host:proxmox_florin, guest:docker-build-lv3 | success | Verified the ADR 0082 remote build execution gateway against the real docker-build-lv3 route, updated the build-server contract to use the Proxmox host jump path, and backfilled rsync into the build guest baseline. | Source |
| 2026-03-23 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | host:proxmox_florin, guest:docker-runtime-lv3 | success | Applied Compose runtime secret injection via OpenBao Agent on docker-runtime-lv3 for Windmill, Keycloak, Mattermost, Open WebUI, NetBox, the platform-context API, and the mail-platform gateway, and verified that each migrated stack now consumes `/run/lv3-secrets/<service>/runtime.env` instead of legacy compose-directory `.env` files. | Source |
| 2026-03-23 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | host:proxmox_florin, guest:docker-runtime-lv3 | success | Applied the private platform-context API and Qdrant runtime on docker-runtime-lv3, exposed it through the Proxmox host Tailscale proxy on port 8010, and rebuilt the live retrieval corpus with normalized repo-path citations. | Source |
| 2026-03-23 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | host:proxmox_florin, guest:docker-runtime-lv3, guest:monitoring-lv3, guest:postgres-lv3 | success | Applied ADR 0066 live on current main by validating host-side mutation audit sinks on proxmox_florin and docker-runtime-lv3, seeding and exercising the Windmill mutation-audit helper, shipping both the structured host file and OpenBao native audit file through the ADR 0052 Alloy-to-Loki path, and repairing current-main execution-gate regressions that blocked the verified monitoring and Windmill converges. | Source |
| 2026-03-23 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, step-ca, Uptime Kuma, Windmill | guest:postgres-lv3, guest:docker-runtime-lv3 | success | Applied the first low-risk ADR 0065 live rotation for `windmill_database_password`, repaired the live play path for separate worktrees and OpenBao metadata writes, and restored Windmill on docker-runtime-lv3 with verified OpenBao metadata and controller-local secret mirroring. | Source |
| 2026-03-22 | live-apply | codex agent | Proxmox Backup Server, Deployment History Portal, Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | host:proxmox_florin, guest_group:lv3_guests | success | Applied explicit default-deny guest network policy on the Proxmox host and every managed Debian guest, with matched Proxmox VM firewall rules plus guest nftables enforcement. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the private Open WebUI operator workbench live on docker-runtime-lv3, published it through the Proxmox host Tailscale proxy, and verified repo-managed bootstrap auth plus the restricted initial feature posture. | Source |
| 2026-03-22 | live-apply | codex agent | Grafana, Mattermost, NGINX Edge, ntopng, Platform Context API, Proxmox UI, step-ca | host:proxmox_florin, service_endpoint:ntopng-ui | success | Applied ntopng live on the Proxmox host with direct bridge capture on vmbr10 and vmbr0 plus an operator-only Tailscale proxy on port 3001. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, monitoring-lv3, postgres-lv3 | success | Applied the private Mattermost ChatOps surface live on docker-runtime-lv3, provisioned its PostgreSQL backend on postgres-lv3, published it through the Proxmox host Tailscale proxy, and verified channel bootstrap, webhook artifacts, and Grafana alert routing end to end. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, monitoring-lv3, nginx-lv3, postgres-lv3 | success | Applied the shared Keycloak SSO broker live on docker-runtime-lv3, provisioned its PostgreSQL backend on postgres-lv3, published it at sso.lv3.org, wired Grafana through OIDC, and verified the approved agent client-credentials path. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the private Portainer runtime live on docker-runtime-lv3, published it through the Proxmox host Tailscale proxy, persisted controller-local bootstrap artifacts, and verified the governed wrapper for inspection, logs, and bounded restarts. | Source |
| 2026-03-22 | live-apply | codex agent | Proxmox Backup Server, Deployment History Portal, Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, postgres-lv3 | success | Applied the private NetBox runtime live on docker-runtime-lv3, provisioned its PostgreSQL backend on postgres-lv3, published operator and agent access through the Proxmox host Tailscale proxy, and synchronized the canonical repository topology and IPAM inventory into the NetBox API. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, Open WebUI, OpenBao, Platform Context API, Portainer, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, monitoring-lv3 | success | Applied ADR 0053 live from main by converging the monitoring VM tracing stack and the mail gateway runtime so Tempo search, service-graph metrics, and span metrics are all verified for the first traced internal API surface. | Source |
| 2026-03-22 | live-apply | codex agent | Proxmox Backup Server, Deployment History Portal, Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Operations Portal, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, monitoring-lv3, nginx-lv3 | success | Applied ADR 0052 live by adding Loki to the monitoring plane and converging Alloy-based host and guest log shipping, while also completing the live rollout of the corrected ADR 0053 tracing stack on monitoring-lv3. | Source |
| 2026-03-22 | live-apply | codex agent | Proxmox Backup Server, Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | backup-lv3, docker-runtime-lv3 | success | Applied the control-plane recovery workflow live by enforcing the backup-store SSH path from docker-runtime-lv3 to backup-lv3, confirming the managed runtime backup timer and artifact set, mirroring the controller recovery bundle, and rerunning the restore drill against the latest archived control-plane state. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied notification profiles on the live mail platform by provisioning dedicated operator, platform, and agent sender identities, binding each to a scoped mail-gateway API key, and verifying per-profile delivery through the managed gateway. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Runtime VM, ntopng, Proxmox UI, step-ca, Windmill | controller:proxmox_florin_server-main, host:proxmox_florin | success | Applied the command catalog and approval gates live by validating the catalog on main and confirming a representative host mutation contract and approval gate before recording them as the steady-state execution path. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the short-lived credential and internal mTLS policy live by verifying step-ca-issued SSH certificates for routine operator access and enforcing step-ca-backed client-certificate authentication on the private OpenBao API. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the identity taxonomy live by re-reviewing the current human, service, agent, and break-glass principals against the running Proxmox and mail-platform surfaces. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the control-plane lane policy live by verifying the governed SSH, API, message, and event surfaces currently in use on the Proxmox host and docker-runtime-lv3. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, postgres-lv3 | success | Applied the private Windmill runtime live on docker-runtime-lv3, provisioned its PostgreSQL backend on postgres-lv3, published it through the Proxmox host Tailscale proxy, and verified workspace bootstrap and job execution end to end. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, Open WebUI, OpenBao, Platform Context API, Portainer, PostgreSQL, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3, postgres-lv3 | success | Applied the private OpenBao runtime live on docker-runtime-lv3, configured its PostgreSQL dynamic credential backend on postgres-lv3, seeded scoped controller and mail secrets, and verified Transit and database credential issuance end to end. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the private step-ca runtime live on docker-runtime-lv3, published it through the Proxmox host Tailscale path, and verified SSH and internal X.509 issuance end to end. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the Dockerized mail platform live on docker-runtime-lv3, published the mail DNS and ingress surfaces, and verified end-to-end inbound and outbound delivery with server@lv3.org. | Source |
| 2026-03-22 | live-apply | codex agent | Docker Build VM, Docker Runtime VM, Grafana, Keycloak, Mail Platform, Mattermost, NetBox, ntopng, Open WebUI, OpenBao, Platform Context API, Portainer, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied Docker runtime container telemetry live for docker-runtime-lv3 and verified the container metrics in InfluxDB and the expanded Grafana detail dashboard. | Source |
| 2026-03-22 | live-apply | codex agent | Proxmox Backup Server, Deployment History Portal, Platform Context API, Proxmox UI, step-ca | backup-lv3 | success | Applied the dedicated backup VM live, created the PBS datastore, and verified the host backup target and nightly job. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Docker Build VM, Docker Runtime VM, Grafana, Portainer, step-ca, Uptime Kuma | docker-build-lv3 | success | Applied Docker build count and duration telemetry live for docker-build-lv3 and verified the metrics in InfluxDB and Grafana. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, NGINX Edge, Open WebUI, OpenBao, Platform Context API, Portainer, Proxmox UI, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied Uptime Kuma live on docker-runtime-lv3, published it at uptime.lv3.org, and bootstrapped repo-managed local auth state. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Mattermost, PostgreSQL, Proxmox UI, step-ca | postgres-lv3 | success | Applied the dedicated PostgreSQL VM baseline live and verified the private tailnet publication path. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Docker Build VM, Docker Runtime VM, Keycloak, Mail Platform, Mattermost, NetBox, Open WebUI, OpenBao, Platform Context API, Portainer, step-ca, Uptime Kuma, Windmill | docker-runtime-lv3 | success | Applied the Docker runtime baseline live on docker-runtime-lv3 and verified Docker Engine, Compose, and daemon configuration. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Grafana, Mattermost, NGINX Edge, ntopng, Platform Operations Portal, Proxmox UI, step-ca | nginx-lv3 | success | Applied public hostname publication at the NGINX edge and verified the managed subdomain responses. | Source |
| 2026-03-22 | live-apply | codex agent | Deployment History Portal, Grafana, Proxmox UI, Uptime Kuma | monitoring-lv3 | success | Applied the monitoring VM stack live and verified Grafana, InfluxDB, and Proxmox metric ingestion. | Source |