| Priority | Issue | Details |
|---|---|---|
| High | AWX project does not auto-sync | The lab templates run from AWX project 10 (crc-awx-labops), which has update revision on launch disabled. Merging a fix to main has no effect until the project is synced manually. |
| Medium | LabOps AI open items | PBS protection for VMID 100 (drcc-labops-01) is not configured; the read-only AWX service token svc-drcc-labops-ai-ro has not been issued; non-owner/student denial and Refuse-in-Direct-Chat are unproven on production. All five write switches are false. See LabOps AI. |
| High | Student invite email delivery undecided | The DigitalRCC intake flow is intentionally in mock mode: the Supabase project has no custom SMTP and the built-in sender is rate-limited and restricted to project members. Choose custom SMTP or SES before the 9/6 cohort import, or students receive no portal invites. |
| Medium | Guacamole PODXX-GW tiles hidden |
The 20 gateway tiles were created with protocol http, which guacd does not implement, so they failed and looped. Students' READ permission was removed; restoring them requires a real protocol (or leaving firewall access in the browser). |
| High | Windows licensing gaps | POD07-SRV and POD11-SRV are unlicensed — their supplied keys are rejected with 0xC004C008 (activation count exhausted) and replacements have been requested; neither server may be issued to a student until activated. DC02-P01 still runs Datacenter Evaluation, expiring October 2, 2026. |
| Medium | IA M3-L2 is domain-wide | The lab uses the Default Domain Password Policy on the shared acs-p01.local domain, so it cannot be per-pod work — and a non-admin student cannot change it at all. The hardened policy is now applied centrally and the lab is verify-only / auto-credited for this cohort. The durable fix is a per-pod fine-grained password policy on the member servers (plus the matching IA guide section). |
| Medium | Waivers still enabled after the member-server move | IA M2-L1 (storing a scheduled-task credential) and MP M1-L1/M1-L2 (mounting VHDX media) are performable on PODXX-SRV, where the student is a local administrator. ia_m2l1_task_step_waived and the MP waiver stay true until the Pod01/Pod03 pilots prove both from a real RDP session; each is then retired with its guide and verifier change. |
| Medium | Seed templates overwrite student work | AC, IA, SI and SC seed playbooks have no "already seeded" guard (only MP/PE check .families/<F>.seeded). Never launch a seed template while a class is in progress — use the reset templates. |
| Low | MP seeding drive letters | MP attaches VHDX media and drive-letter assignment is machine-global. Now that MP seeds per member server the pods no longer contend with each other, but two MP jobs must not target the same host at once. |
| Task | Status | Notes |
|---|---|---|
Merge crc-awx-labops PR #41 |
Pending | pod_member_server provisioning role, member-server seed/verify/reset retargeting and the migration runbooks |
| Push the final guide-update branch | Blocked | The revised AC/IA/SI/SC/MP/PE guides are committed locally on devin/1787417238-guide-updates; every push to the tcecure remote returns HTTP 403 through the git proxy (fetch works). Reported to Cognition. |
| Interactive Pod01 / Pod03 member-server pilots | Pending | Real Guacamole + RDP sign-in: local-admin boundary, ADUC/AD PowerShell against the DCs, stored-credential scheduled task, evidence write, cross-pod denial. Gate for the batch rollout |
| Retire student logon on DC01/DC02 | Pending | Remove studentXX from DC01 Remote Desktop Users and their grants on the PODXX-DC tiles, then re-test DNS, LDAP/LDAPS, Kerberos, GC, SYSVOL/NETLOGON and replication |
| Decide Supabase SMTP vs SES for invites | Pending | Must be settled before the 9/6 cohort import |
| Replacement Datacenter keys for POD07 / POD11 | Pending | Supplier contacted; the other 18 member servers are activated. Retiring student sessions on DC01 also removes the RDS grace-period exposure |
| Per-pod fine-grained password policy for IA M3-L2 | Pending | Removes the last cross-pod dependency. The member-server move does not fix this one — the Default Domain Password Policy is domain-wide; requires seed/reset/verify changes and an IA guide update |
| Publish student guides as wiki pages | Done | See Lab Guides |
| Confirm snapshot rollback reset logic | Pending | Verify that rolling back student workstation snapshots correctly resets lab state |
| Re-disable password auth on PVE1 | Pending | Currently enabled for convenience; should be key-only |
| Disable rpcbind on PVE1 and PVE2 | Pending | Security hardening |
| Dreamwall firewall rules cleanup | Pending | Remove stale rules, document active rules |
| Git-based deploy on VM 105 | Pending | Set up automated deployment for CyberLab Portal |
| Remove workstation hosts from AWX inventory | Pending | ws01-p01 … ws01-p10 entries in CRC-LabPods are placeholders superseded by crc_pod_servers |
| DC02 licensing fix | Pending | Need full Windows Server license or reinstall before Oct 2, 2026 |
Retire the ia_m2l1_task_step_waived and MP media waivers |
Pending | After the pilots, one commit each with the matching guide and verifier change |
| Task | Date | Notes |
|---|---|---|
| All 20 pod member servers built, hardened and mapped | Sep 2026 | POD01-SRV–POD20-SRV (VMs 401–420) domain-joined in OU=PodServers, matching studentXX as the only local admin / RDP user, patched, Defender on, no cached credentials or build artifacts |
Seed / verify / reset retargeted to crc_pod_servers |
Sep 2026 | All five families verified fleet-wide with crc_publish_tracker: false; crc_shared_dcs kept as the rollback path |
Guacamole PODXX-SRV connections issued |
Sep 2026 | 20 connections at 10.50.XX.20, granted only to the matching student, no stored passwords; legacy PODXX-DC tiles retained for rollback |
| Portal issues the member server as the session host | Sep 2026 | drcc-lab-companion PR #7 — PODXX-SRV / 10.50.XX.20 for the session host, DC01-P01 / DC02-P01 as directory controllers only |
| Cohort 1 evidence archived on DC01 | Sep 2026 | C:\CohortArchive\COHORT1-20260902 — 3,675 files, SHA-256 manifest, per-pod counts, restore notes |
Merged crc-awx-labops PRs #39 and #40 and synced AWX project 10 |
Sep 2026 | SC M3-L1 duplicates scoped per interface, M3-L3 reports NoHTTPSRuleTo10.51.XX.100, and the M4-L3 logging check names the offending block rules |
Merged drcc-lab-companion PR #5 |
Sep 2026 | Phase 2 LabOps AI app half and Direct Chat on main |
| LabOps AI Direct Chat | Aug 2026 | /admin/labops/chat — owner-only conversation with no support ticket, on the existing isolated runtime; migration applied to production, write switches untouched |
| LabOps AI Phase 2 security controls | Aug 2026 | Gateway/agent secret split, per-investigation workspace, default-deny egress, model-proxy-only provider key, cross-run denial, restart recovery — verified on drcc-labops-01 |
Merged crc-awx-labops PRs #26, #27, #29–#37 and synced AWX project 10 |
Aug 2026 | Waivers, guide corrections, SC firewall routing, tolerant grading and the anti-lockout baseline are live (project synced to 8e62ba2) |
| Wiki refreshed for the current cohort's fixes | Aug 2026 | Quick start, pods, network/firewall, tracker, lab guides updated; Current Cohort Lab Notices, Lab Health Monitoring and Portal Integration added |
| Read-only Proxmox health monitoring | Aug 2026 | drcc-monitor@pve + lab-status token (audit-only), lab-status-poller on pve1 publishing outbound every 45s — port 8006 stays unexposed |
| Authenticated per-pod progress API | Aug 2026 | GET /api/v1/pods/<NN>/progress live on the tracker host, consumed server-side by my.digitalrcc.com |
| Pod firewall reachable from the lab desktop | Aug 2026 | 11 wedged gateway VMs restarted (all 20 pfSense UIs return 200) and a boot-persistent pod-routing.service added on the gateway host, isolation preserved |
| Hardened domain password policy applied | Aug 2026 | 12 chars, all four character classes, lockout 10, history 24, max age 90 — IA M3-L2 now passes for every pod |
| IA M2-L1 task visibility fixed on all 20 pods | Aug 2026 | The PodNN ACS Nightly Backup tasks existed but their security descriptors excluded students; verified as a real student |
| MP media contents published for all 20 pods | Aug 2026 | PXX-FCI-USB-Contents.txt / PXX-Employee-Handbook-Contents.txt so classification is still real work without mounting |
| Non-elevated ADUC launch path | Aug 2026 | Desktop shortcut plus the RunAsInvoker command; Server Manager and admin PowerShell removed from all guides and quick starts |
| Guides and all 20 quick starts re-rendered | Aug 2026 | Print-stylesheet PDFs (intact table columns, real checkboxes, no page-splitting), AC CMMC mapping corrected to 3.1.1/3.1.2 |
| Wiki refreshed for six-family launch | Aug 2026 | Home, overview, lab families, pods, AWX, tracker, backlog updated; student quick start and lab guide pages added |
| All six families seeded + verified on pods 1–20 | Aug 2026 | AC, IA, SI, SC, MP, PE (57 labs) reset, seeded and verified into a clean FAIL state |
| Auto-verify + auto-advance schedules live | Aug 2026 | Schedules 7–13, every 30 min, advance_enabled and certificates_enabled on |
| Student completion guides for all six families | Aug 2026 | Markdown + DOCX + PDF in docs/ (PR #17) |
| MP and PE families added to AWX | Aug 2026 | Templates 27–29 (MP) and 30–32 (PE) |
| SC family automation | Aug 2026 | Templates 21–23, per-pod pfSense seeding over SSH |
| Training Tracker extended to all six families | Aug 2026 | MCP v2.5 on 192.168.1.61 queries verify templates 13, 16, 19, 22, 28, 31 |
| Completion certificate automation | Aug 2026 | Templates 36 (generate) and 37 (setup) |
| Remove WS01 connections from Guacamole | June 2026 | Deleted 20 PODXX-WS01 connections; each pod now shows DC only |
| DC02 ADWS service fix | June 2026 | ADWS running with Automatic start type |
| CDW zone fully operational | May 2026 | VMs 300-306 on PVE2 vmbr50 (192.168.50.0/24) |
| Wazuh SIEM deployed (CDW) | May 2026 | Docker-based Wazuh 4.9.2 on crc-cdw-monitor-01 |
| SI family AWX automation (seed/verify/reset) | June 2026 | Templates 18, 19, 20 |
| Expand from 10 to 20 pods | April 2026 | OU structure, users, groups, delegation for Pod11-Pod20 |
| Create per-pod MMC shortcuts | April 2026 | 20 pods x 3 files each |
| Deploy GPO logon scripts | April 2026 | 20 GPOs linked to pod OUs |
| Stand up Wiki.js | April 2026 | VM 106, Docker, PostgreSQL |