Commit Graph
19 Commits
Author SHA1 Message Date
ja 9494d1693b docs(tech): add firmware/BIOS update research for all workstation components
- Researched 7 component categories for available firmware updates
- NVMe SSD (PM9A1): update available GXA7401Q -> GXA7802Q
- Motherboard BIOS F53 is current (no update needed)
- SATA SSD 840 EVO, GPU GTX 1050 Ti: EOL, no updates
- NIC/CPU microcode: managed via kernel/firmware packages
- USB peripherals: no LVFS/fwupd support
- Recommend installing fwupd for future firmware management
2026-04-02 09:49:00 +02:00
ja 5a1ae7b0e2 docs(tech): add hardware inventory and document LLM model migration
- Created docs/tech/hardware-inventory.md with full system specs
- Documented LLM model move to /home/mw/models in manual-overrides.md
2026-04-02 09:38:02 +02:00
ja 6980d7369a docs(tech): add hardware inventory, fix DDR5->DDR4 error in health doc
- New docs/tech/hardware-inventory.md with full hardware specs:
  CPU (Ryzen 7 2700X), RAM (64GiB DDR4-2666, 4x16GiB), storage
  (512G NVMe PM9A1 + 500G SATA 840 EVO), GPU (GTX 1050 Ti),
  networking (Realtek 1Gbps + Tailscale), USB peripherals, chipset
- Fix workstation-health.md: DDR5-3200 was incorrect, actual DDR4-2666
- Note: primary disk at 93% usage (34G free)
2026-04-02 09:18:06 +02:00
jaandJunie ccdaf95f15 docs(security): add AppArmor, systemd sandboxing, Falco, YARA, cosign, OIDC, Ansible integration
Complete hardening workflow now covers all key technical concepts:
- AppArmor/SELinux status, systemd sandboxing audit
- Semgrep SAST, YARA malware patterns, Nuclei network scan
- Cosign artifact verification, SHA256 package verification
- Falco/eBPF runtime monitoring, Volatility 3 memory forensics
- OIDC/GAT token best practices
- Ansible integration per .clinerules/workstation.md

Co-authored-by: Junie <junie@jetbrains.com>
2026-03-24 04:35:50 +01:00
jaandJunie e0c2997ee4 docs(security): add workstation hardening workflow for Arch Linux
Daily/weekly/monthly security checks covering systemd health,
network C2 detection, package audit, SBOM scanning, Unicode IOC
sweep, kernel hardening, and firewall status. References
supply-chain-security-2026-03.md for detailed threat context.

Co-authored-by: Junie <junie@jetbrains.com>
2026-03-24 04:34:31 +01:00
jaandJunie 8670ecd787 docs(security): expand supply chain defense guide with deep research findings
Co-authored-by: Junie <junie@jetbrains.com>
2026-03-23 23:16:34 +01:00
ja 519142f0d7 docs: update workstation health with crashlog analysis 2026-03-17 23:27:53 +01:00
ja 9a5d81124c docs: update workstation health documentation with system check results 2026-03-17 23:25:22 +01:00
ja 54ab23dce9 docs(system): analysis reports and EOD workflows
- Created crash analysis for 2026-03-17 OOM event.
- Documented stability test results and memory tuning effects.
- Added PARA-structured workflows for EOD protocol.
- Updated workstation health report for current 16GB swap status.
2026-03-17 19:02:06 +01:00
ja 2bce647b31 docs: sync system health and cleanup deprecated software (2026-03-13) 2026-03-13 14:24:14 +01:00
ja 13dc8f71aa feat(ansible): enable WebGPU in Chrome via chrome-flags.conf and add docs 2026-03-11 22:58:28 +01:00
ja 3a74abc74a docs(health): update workstation health report for 2026-03-09 2026-03-09 12:41:48 +01:00
ja 91f4c8d283 docs: add manual-overrides.md as required by rules 2026-03-09 11:02:56 +01:00
ja 385a548859 docs: add next session tasks for 2026-03-09 2026-03-09 11:02:35 +01:00
ja 6dbe59e117 docs: align with satware AG best practices
- Delete deprecated CLAUDE.md
- Create root-level AGENTS.md for AI assistant guidance
- Create SDD constitution in .specify/memory/constitution.md
- Align documentation with PARA structure (docs/product/project-brief.md, docs/tech/stack.md, docs/plans/)
- Add standardized YAML frontmatter to all documentation files
- Update README.md with saTway branding and structure
2026-03-09 11:02:17 +01:00
ja 5a929898a1 docs: add workstation health report and spec baseline 2026-03-06 15:21:00 +01:00
ja 51b5afc8b4 feat(workstation): complete software cleanup and project organization
- Synchronized Ansible roles with removed redundant packages.
- Performed system audit (performance, boot, disk usage).
- Organized home directory by removing 22 clean remote repositories.
- Reclaimed ~21GB of disk space in ~/Projects.
- Retained dirty repositories and those without remote origins for safety.
- Updated documentation (performance tuning, software stack, setup).
- Created NEXT_STEPS.md and documented learnings.
2026-02-27 18:07:54 +01:00
ja dfd1b1c851 docs: add infrastructure baseline verification report 2026-02-27 16:30:42 +01:00
ja 264cd31ce6 feat: initial infrastructure baseline 2026-02-27 16:20:37 +01:00