Problem
146 first-party markdown files. Nothing machine-checks them, so drift is silent.
The mechanical half is now fixed in #3398 (mermaid parse gate, whole-tree link
gate, the two broken diagrams, the one dead link, both wired into quality.yml).
This issue tracks what a script cannot do: the semantic drift — docs
asserting stack counts, port numbers, index names, route tables and env-var
defaults that the compose files, arcane/manifests/home-production.json and the
source have moved past. The oldest narrative docs have not been touched since
2026-07-26.
Method, per file
For each task below, compare the doc's claims against reality and correct the
doc — do not correct reality to match the doc, except where the doc is the
authoritative design record. A plan/record doc may legitimately describe intent
that is not shipped; mark it as such rather than rewriting its history.
Cheapest sources of truth, in order:
arcane/manifests/home-production.json — the stack inventory
arcane/home/*/compose.yml — services, ports, env, profiles
git ls-files arcane/home | cut -d/ -f3 | sort -u — the actual stack count
arcane/home/honeypot-dashboard/backend-service/src/main.rs — the route table
arcane/home/honeypot-init/ — ES templates, pipelines, ILM
grep -rn 'profiles:' --include='*.yml'
graphify query "..." / graphify explain "..." when a claim spans files
Rules:
A task is closed when the file was corrected or explicitly re-verified as
accurate . Record which, in the PR body. No silent skips.
Do not restyle prose that is not wrong. Minimal diffs.
Numbers, counts and identifiers must be checked, not eyeballed.
If a doc is genuinely obsolete, say so and propose deletion rather than
patching it to look current.
Task list, oldest doc first
Group A — the six oldest
Group B — analysis / ghidra
Group C — sandbox
Group D — core architecture / operations
chore(deps): bump actions/setup-go from 5 to 7 #23 docs/STACK-REBUILD.md (2026-08-16)
chore(deps): bump github/codeql-action from 3 to 4 #24 docs/GEOIP-THREAT-INTEL.md (2026-08-22)
chore(deps): bump python-dateutil from 2.9.0 to 2.9.0.post0 in /ml-worker #25 docs/RECOVERY.md (2026-08-23)
Align dashboard theme and modal rendering #26 docs/NETWORK.md (2026-08-27) — diagram
Document direct deployment paths #27 docs/TESTING.md (2026-08-27)
Fix home SSHFS mounts at boot #28 docs/persona-design.md (2026-08-27)
Add homeserver login health dashboard #29 docs/settings-operations.md (2026-08-27)
Fix empty sandbox analysis reports #30 docs/KEYCLOAK-OPERATIONS.md (2026-08-29)
Normalize legacy sandbox timeout reports #31 docs/ARCHITECTURE.md (2026-08-30) — diagram
Fix EveBox search stalls and resource limits #32 docs/ROCKY-10-MIGRATION.md (2026-08-31)
Coordinate ML and GPU implementation roadmap #33 docs/PIPELINES.md (2026-09-02) — diagram
Relay SSHFS events into EveBox #34 docs/gpu-docker-passthrough.md (2026-09-02) — diagram
Boot sandbox guests deterministically #35 docs/gpu-ml-worker-acceleration.md (2026-09-02)
feat(sandbox): expose result evidence differences #36 docs/knowledge-store-design.md (2026-09-02)
fix(dashboard): keep modal host out of app grid #37 docs/STORAGE.md (2026-09-03) — diagram
fix(dashboard): refresh corrected layout stylesheet #38 docs/DASHBOARD-CUTOVER.md (2026-09-04)
fix(sandbox): merge DNS evidence from both captures #39 docs/ES-CONSUME-PATTERNS.md (2026-09-04)
Add themed sandbox PDF reports #40 docs/KEYCLOAK-CUTOVER.md (2026-09-04)
Plan user settings and configuration system #41 docs/OPERATIONS.md (2026-09-04)
Keep PDF sections with their content #42 docs/canarytoken-live-fire-checklist.md (2026-09-04)
Verify dashboard roles with auth backend #43 docs/community-threat-intel-sharing.md (2026-09-04)
Coordinate auth and dashboard deployments #44 docs/container-writable-layer-audit-2026-09-03.md (2026-09-04)
Document system architecture and analysis flows #45 docs/dionaea-bistreams-retention.md (2026-09-04)
docs: plan dashboard profile action menu #46 docs/honeypot-network-isolation.md (2026-09-04)
Windows sandbox Phase 1: build the Windows 11 golden image #47 docs/ip-reporting-plan.md (2026-09-04) — diagram
Packer: fix the template so a Windows 11 build can start #48 docs/kvm-network-traffic-analysis.md (2026-09-04)
Obtain the Windows 11 evaluation ISO (operator action required) #49 docs/kvm-snapshot-vs-golden-image.md (2026-09-04)
Install Packer on the analysis host #50 docs/llm-inference-backend-comparison.md (2026-09-04)
Run the Packer build and produce win11-analysis.qcow2 #51 docs/ml-gpu-coordinated-roadmap.md (2026-09-04) — diagram
Define the libvirt domain and take the GOLDEN_READY snapshot #52 docs/security-fixes.md (2026-09-04)
End-to-end smoke test: dashboard submit to Windows sandbox report #53 README.md (2026-09-05) — diagram
10.8.0.1 (the WireGuard tunnel peer) is counted as an attacker source on /ips #54 docs/ROADMAP.md (2026-09-05)
Phase 4: author docker-compose.sandbox.yml (INetSim, mitmproxy, Zeek, Suricata on the isolated bridge) #55 docs/agent-intrusion-threat-model.md (2026-09-05)
Run-cycle step 13: orchestrate/generate_report.py is referenced but missing #56 docs/benchmarks/claim-pools/README.md (2026-09-05)
Gate 0: restore authorized management access and recover the home Compose stack #57 docs/dashboard-manual-ip-block-design.md (2026-09-05)
CSP cutover: thread a per-request nonce through every page data struct #58 docs/ml-worker-plan.md (2026-09-05) — diagram
Complete the modal inventory: event detail, payload preview, exports, destructive actions #59 docs/gpu-llm-analysis-worker.md (2026-09-07) — diagram
Dashboard regression tests and the dark/light visual acceptance matrix #60 docs/sandbox/README.md (2026-09-08) — diagram
ML worker v0.1: reconcile the scaffold against its plan and decide if it is runnable #61 docs/payload-analysis-workbench.md (2026-09-09) — diagram
ML worker v0.2: feature engineering and HBOS fast filtering #62 docs/BACKUP-ESSENTIALS.md (2026-09-10)
ML worker v0.3-v0.4: temporal and composite scoring with explainable output #63 docs/HOMESERVER-DISK-LAYOUT.md (2026-09-10)
ML worker v0.5-v0.7: deliver scores to the dashboard #64 docs/HOST-TUNING.md (2026-09-10)
ML worker v0.8-v1.0: retraining, versioning, drift detection and threshold controls #65 docs/analysis/ghidra/benchmarks/injection-gate-protocol.md (2026-09-10)
Guarded GPU LLM analysis worker, offline and dry-run only #66 docs/benchmarks/2026-08-30-injection-gate-recalibration.md (2026-09-10)
CUDA selection, GPU sharing budget, and embedding clustering #67 docs/benchmarks/plans/2026-09-05-1947-resume-plan.md (2026-09-10)
IP reporter Phase 1: file tailing, SQLite dedup, whitelist, dry-run by default #68 docs/benchmarks/plans/2026-09-06-round7-hermes-init.md (2026-09-10)
IP reporter Phase 2: Suricata and Blocklist.de validation with metrics #69 docs/benchmarks/plans/2026-09-06-round7-unsloth-train-requant-ollama.md (2026-09-10)
Reconcile the KVM and network-analysis guides against the implemented sandbox tooling #70 docs/DECEPTION-EXTENSIONS.md (2026-09-13)
Design a background-noise generator that cannot contaminate evidence #71 docs/SENSORS.md (2026-09-13)
Verify archive candidates and repair inbound links before moving any doc #72 docs/design-lab/README.md (2026-09-14)
Sync the upstream auto-generated YARA corpus from Xore/honeypot into the local scanner #73 docs/design-lab/design-notes.md (2026-09-14)
Manual, admin-only GitHub-analysis publisher with a dashboard button #74 docs/ml-worker-evaluation.md (2026-09-25)
Close the source-recovery gap on the VPS so fewer events land unattributed #75 docs/ARCANE-GIT-SYNC.md (2026-09-26)
Build the Ghidra request spool, then add the payload-page entry points #76 docs/CGNAT-DEPLOYMENT.md (2026-09-26) — diagram
Authenticated profile action menu, route settings, admin settings and logout #77 docs/CI-CD.md (2026-09-26) — diagram
Ghidra analysis pipeline phases 3-5: GhidrAssist, plugin selection, report generation #78 docs/README.md (2026-09-26)
Suricata eve.json grows unbounded on the VPS (4.4 GB and climbing) #79 docs/llm-worker/README.md (2026-09-26)
Triage the five open CodeQL alerts; three are new from the Phase 7 sandbox routing #80 docs/local-llm-model-evaluation.md (2026-09-26)
Verify the settings subsystem on the deployed stack: introspection token rollout and the 72-hour soak #81 docs/deploy-profiles/README.md (2026-09-27)
Deliberately out of scope
Vendored / decoy-fs copies — arcane/home/honeypot-cowrie/cowrie/honeyfs/**,
sandbox/ghosts/vendor/**. Someone else's README, inside a fake filesystem an
attacker is meant to explore.
Frozen records — docs/sandbox/windows/vm-detection-results/* (14 files),
docs/benchmarks/runs/*, docs/research/*, *-record.md,
approval-record.md, docs/sandbox/windows_kimi/*, dev/sensing-lab/. A
record's value is that it says what was true on the day; reconciling it
destroys it.
One-off working notes at the repo root — DIFF.md, EVIDENCE.md,
HANDOFF-3097.md. These look like they should just be deleted, but that is a
separate call, not a docs fix.
Acceptance
Problem
146 first-party markdown files. Nothing machine-checks them, so drift is silent.
The mechanical half is now fixed in #3398 (mermaid parse gate, whole-tree link
gate, the two broken diagrams, the one dead link, both wired into
quality.yml).This issue tracks what a script cannot do: the semantic drift — docs
asserting stack counts, port numbers, index names, route tables and env-var
defaults that the compose files,
arcane/manifests/home-production.jsonand thesource have moved past. The oldest narrative docs have not been touched since
2026-07-26.
Method, per file
For each task below, compare the doc's claims against reality and correct the
doc — do not correct reality to match the doc, except where the doc is the
authoritative design record. A plan/record doc may legitimately describe intent
that is not shipped; mark it as such rather than rewriting its history.
Cheapest sources of truth, in order:
arcane/manifests/home-production.json— the stack inventoryarcane/home/*/compose.yml— services, ports, env, profilesgit ls-files arcane/home | cut -d/ -f3 | sort -u— the actual stack countarcane/home/honeypot-dashboard/backend-service/src/main.rs— the route tablearcane/home/honeypot-init/— ES templates, pipelines, ILMgrep -rn 'profiles:' --include='*.yml'graphify query "..."/graphify explain "..."when a claim spans filesRules:
accurate. Record which, in the PR body. No silent skips.
patching it to look current.
Task list, oldest doc first
Group A — the six oldest
SECURITY.md(2026-07-26)docs/analysis/gpu-queue/README.md(2026-08-05)docs/personas/README.md(2026-08-05)docs/sandbox/windows/runner/README.md(2026-08-05)docs/sandbox/ghosts/README.md(2026-08-06)docs/analysis/ghidra/revdeck/README.md(2026-08-11)Group B — analysis / ghidra
docs/analysis/ghidra/DASHBOARD_INTEGRATION_PLAN.md(2026-08-06) — diagramdocs/analysis/ghidra/README.md(2026-08-10) — diagramdocs/analysis/ghidra/IMPLEMENTATION_PLAN.md(2026-08-27) — diagramdocs/analysis/README.md(2026-08-27) — diagramdocs/analysis/ghidra/benchmarks/README.md(2026-08-27)docs/analysis/ghidra/ghidrassist/README.md(2026-08-27)docs/analysis/yara/README.md(2026-08-27)docs/analysis/RECOVERY.md(2026-08-26)docs/analysis/ghidra/benchmarks/corpus/README.md(2026-08-30)docs/analysis/ghidra/models/README.md(2026-08-30)docs/analysis/ghidra/AI_TRIAGE.md(2026-08-31) — diagramGroup C — sandbox
docs/sandbox/windows/packer-golden-image-guide.md(2026-08-06) — diagramdocs/sandbox/windows-guest-risk-config-model.md(2026-08-12)docs/sandbox/ghosts/IMPLEMENTATION_PLAN.md(2026-08-27)docs/sandbox/cape/IMPLEMENTATION_PLAN.md(2026-08-28)docs/sandbox/windows/IMPLEMENTATION_PLAN.md(2026-08-29) — diagramGroup D — core architecture / operations
docs/STACK-REBUILD.md(2026-08-16)docs/GEOIP-THREAT-INTEL.md(2026-08-22)docs/RECOVERY.md(2026-08-23)docs/NETWORK.md(2026-08-27) — diagramdocs/TESTING.md(2026-08-27)docs/persona-design.md(2026-08-27)docs/settings-operations.md(2026-08-27)docs/KEYCLOAK-OPERATIONS.md(2026-08-29)docs/ARCHITECTURE.md(2026-08-30) — diagramdocs/ROCKY-10-MIGRATION.md(2026-08-31)docs/PIPELINES.md(2026-09-02) — diagramdocs/gpu-docker-passthrough.md(2026-09-02) — diagramdocs/gpu-ml-worker-acceleration.md(2026-09-02)docs/knowledge-store-design.md(2026-09-02)docs/STORAGE.md(2026-09-03) — diagramdocs/DASHBOARD-CUTOVER.md(2026-09-04)docs/ES-CONSUME-PATTERNS.md(2026-09-04)docs/KEYCLOAK-CUTOVER.md(2026-09-04)docs/OPERATIONS.md(2026-09-04)docs/canarytoken-live-fire-checklist.md(2026-09-04)docs/community-threat-intel-sharing.md(2026-09-04)docs/container-writable-layer-audit-2026-09-03.md(2026-09-04)docs/dionaea-bistreams-retention.md(2026-09-04)docs/honeypot-network-isolation.md(2026-09-04)docs/ip-reporting-plan.md(2026-09-04) — diagramdocs/kvm-network-traffic-analysis.md(2026-09-04)docs/kvm-snapshot-vs-golden-image.md(2026-09-04)docs/llm-inference-backend-comparison.md(2026-09-04)docs/ml-gpu-coordinated-roadmap.md(2026-09-04) — diagramdocs/security-fixes.md(2026-09-04)README.md(2026-09-05) — diagramdocs/ROADMAP.md(2026-09-05)docs/agent-intrusion-threat-model.md(2026-09-05)docs/benchmarks/claim-pools/README.md(2026-09-05)docs/dashboard-manual-ip-block-design.md(2026-09-05)docs/ml-worker-plan.md(2026-09-05) — diagramdocs/gpu-llm-analysis-worker.md(2026-09-07) — diagramdocs/sandbox/README.md(2026-09-08) — diagramdocs/payload-analysis-workbench.md(2026-09-09) — diagramdocs/BACKUP-ESSENTIALS.md(2026-09-10)docs/HOMESERVER-DISK-LAYOUT.md(2026-09-10)docs/HOST-TUNING.md(2026-09-10)docs/analysis/ghidra/benchmarks/injection-gate-protocol.md(2026-09-10)docs/benchmarks/2026-08-30-injection-gate-recalibration.md(2026-09-10)docs/benchmarks/plans/2026-09-05-1947-resume-plan.md(2026-09-10)docs/benchmarks/plans/2026-09-06-round7-hermes-init.md(2026-09-10)docs/benchmarks/plans/2026-09-06-round7-unsloth-train-requant-ollama.md(2026-09-10)docs/DECEPTION-EXTENSIONS.md(2026-09-13)docs/SENSORS.md(2026-09-13)docs/design-lab/README.md(2026-09-14)docs/design-lab/design-notes.md(2026-09-14)docs/ml-worker-evaluation.md(2026-09-25)docs/ARCANE-GIT-SYNC.md(2026-09-26)docs/CGNAT-DEPLOYMENT.md(2026-09-26) — diagramdocs/CI-CD.md(2026-09-26) — diagramdocs/README.md(2026-09-26)docs/llm-worker/README.md(2026-09-26)docs/local-llm-model-evaluation.md(2026-09-26)docs/deploy-profiles/README.md(2026-09-27)Deliberately out of scope
arcane/home/honeypot-cowrie/cowrie/honeyfs/**,sandbox/ghosts/vendor/**. Someone else's README, inside a fake filesystem anattacker is meant to explore.
docs/sandbox/windows/vm-detection-results/*(14 files),docs/benchmarks/runs/*,docs/research/*,*-record.md,approval-record.md,docs/sandbox/windows_kimi/*,dev/sensing-lab/. Arecord's value is that it says what was true on the day; reconciling it
destroys it.
DIFF.md,EVIDENCE.md,HANDOFF-3097.md. These look like they should just be deleted, but that is aseparate call, not a docs fix.
Acceptance
docs/README.md(Ghidra analysis pipeline phases 3-5: GhidrAssist, plugin selection, report generation #78) updated last, after the tree it indexes is accurate