Mark homelab quick wins complete in plan briefs and task menu.

Close TB-002–004 and TB-033 with done-when checkboxes and update PLAN-BRIEF priority to the next themes.
This commit is contained in:
ginnoir
2026-06-11 03:00:45 -05:00
parent 67be0d6aff
commit 792305e5fa
5 changed files with 18 additions and 18 deletions
+8 -8
View File
@@ -18,9 +18,9 @@ Before any phase or task, we should answer:
| | | | | |
|---|---| |---|---|
| **Priority theme** | Backups + Obsidian hardening done (TB-001, TB-005 complete) | | **Priority theme** | Quick wins complete (TB-001005, TB-002004, TB-033) — next: TB-006 auth, cleanup, or finish-started |
| **Explicitly dropped** | _(none yet)_ | | **Explicitly dropped** | _(none yet)_ |
| **Notes** | _(conversation notes go here)_ | | **Notes** | Quick wins shipped 2026-06-11 (`51acb44` + follow-ups). Recyclarr `@daily`; infra pinned; jd + LAN lockdown on minio/homarr/docs. |
--- ---
@@ -28,15 +28,15 @@ Before any phase or task, we should answer:
Each link opens an **interview-first** task brief. The conversation is the task. Each link opens an **interview-first** task brief. The conversation is the task.
### Safety & quick wins ### Safety & quick wins — **complete** (2026-06-11)
| Say this… | About | | Say this… | About |
|-----------|--------| |-----------|--------|
| [TB-001](tasks/TB-001-backup-stack.md) | Automated backups — **done** (Kopia + B2) | | [TB-001](tasks/TB-001-backup-stack.md) | Automated backups — **done** (Kopia + B2) |
| [TB-033](tasks/TB-033-public-surface-audit.md) | What's actually public on the internet? | | [TB-033](tasks/TB-033-public-surface-audit.md) | Public surface audit — **done** |
| [TB-003](tasks/TB-003-recyclarr.md) | Sync *arr quality settings automatically | | [TB-003](tasks/TB-003-recyclarr.md) | Recyclarr — **done** (`@daily` sync) |
| [TB-004](tasks/TB-004-pin-infra-tags.md) | Stop `:latest` from breaking databases | | [TB-004](tasks/TB-004-pin-infra-tags.md) | Infra image pins — **done** |
| [TB-002](tasks/TB-002-jd-caddy-block.md) | JDownloader web UI on jd.ginnoir.com | | [TB-002](tasks/TB-002-jd-caddy-block.md) | jd.ginnoir.com — **done** |
### Security & cleanup ### Security & cleanup
@@ -91,7 +91,7 @@ Each link opens an **interview-first** task brief. The conversation is the task.
<details> <details>
<summary>Background (optional — skip if overwhelming)</summary> <summary>Background (optional — skip if overwhelming)</summary>
Homelab is ~50 containers, 15 stacks, Caddy ingress, git-push deploys. Main gaps from analysis: Authentik barely used, romhacks pipeline half-done, public-surface audit still open (TB-033). Homelab is ~50 containers, 15 stacks, Caddy ingress, git-push deploys. **Quick wins (TB-001005, TB-002004, TB-033) done 2026-06-11.** Main gaps: TB-006 Authentik rollout, romhacks handoff (TB-007), cleanup items.
Repo conventions: `stack.env` secrets, `edge` network, `internal_only` for LAN admin UIs, `./scripts/gen-bookmarks.ps1` after Caddy changes. Repo conventions: `stack.env` secrets, `edge` network, `internal_only` for LAN admin UIs, `./scripts/gen-bookmarks.ps1` after Caddy changes.
+4 -4
View File
@@ -35,9 +35,9 @@ Parent: [PLAN-BRIEF.md](../PLAN-BRIEF.md) · Template: [_TEMPLATE.md](_TEMPLATE.
| ID | One line | Brief | | ID | One line | Brief |
|----|----------|-------| |----|----------|-------|
| TB-001 | Automated backups ✓ | [](TB-001-backup-stack.md) | | TB-001 | Automated backups ✓ | [](TB-001-backup-stack.md) |
| TB-002 | jd.ginnoir.com | [](TB-002-jd-caddy-block.md) | | TB-002 | jd.ginnoir.com | [](TB-002-jd-caddy-block.md) |
| TB-003 | Recyclarr | [](TB-003-recyclarr.md) | | TB-003 | Recyclarr | [](TB-003-recyclarr.md) |
| TB-004 | Pin infra tags | [](TB-004-pin-infra-tags.md) | | TB-004 | Pin infra tags | [](TB-004-pin-infra-tags.md) |
| TB-005 | Obsidian hardening ✓ | [](TB-005-obsidian-hardening.md) | | TB-005 | Obsidian hardening ✓ | [](TB-005-obsidian-hardening.md) |
| TB-006 | Authentik admin login | [](TB-006-authentik-forward-auth.md) | | TB-006 | Authentik admin login | [](TB-006-authentik-forward-auth.md) |
| TB-007 | Romhacks handoff | [](TB-007-romhacks-handoff.md) | | TB-007 | Romhacks handoff | [](TB-007-romhacks-handoff.md) |
@@ -66,4 +66,4 @@ Parent: [PLAN-BRIEF.md](../PLAN-BRIEF.md) · Template: [_TEMPLATE.md](_TEMPLATE.
| TB-030 | AdGuard Home | [](TB-030-adguard-home.md) | | TB-030 | AdGuard Home | [](TB-030-adguard-home.md) |
| TB-031 | Pingvin Share | [](TB-031-pingvin-share.md) | | TB-031 | Pingvin Share | [](TB-031-pingvin-share.md) |
| TB-032 | Wiki.js | [](TB-032-wikijs.md) | | TB-032 | Wiki.js | [](TB-032-wikijs.md) |
| TB-033 | Public audit | [](TB-033-public-surface-audit.md) | | TB-033 | Public audit | [](TB-033-public-surface-audit.md) |
@@ -1,6 +1,6 @@
# TB-003 — Recyclarr # TB-003 — Recyclarr
**Status:** done — 2026-06-11 (deploy + first sync pending push) **Status:** done — 2026-06-11
**Your call:** Do it **Your call:** Do it
--- ---
@@ -33,7 +33,7 @@
| | | | | |
|---|---| |---|---|
| **Decision** | Do it — WEB-1080p (Sonarr) + HD Bluray+WEB (Radarr) | | **Decision** | Do it — WEB-1080p (Sonarr) + HD Bluray+WEB (Radarr) |
| **Notes** | Config in stacks/media/recyclarr/; run `docker exec recyclarr recyclarr sync` after deploy | | **Notes** | Config in `stacks/media/recyclarr/`; syncs `@daily` via container cron; manual: `docker exec recyclarr recyclarr sync` |
| **Date** | 2026-06-11 | | **Date** | 2026-06-11 |
--- ---
@@ -53,7 +53,7 @@ stacks/media/
### Done when ### Done when
- [ ] Recyclarr syncs without errors - [x] Recyclarr syncs without errors
- [ ] Profiles visible in Sonarr or Radarr - [x] Profiles visible in Sonarr or Radarr
</details> </details>
@@ -54,6 +54,6 @@ All compose files
### Done when ### Done when
- [x] No :latest on DB/Caddy/Vault/CouchDB/MinIO - [x] No :latest on DB/Caddy/Vault/CouchDB/MinIO
- [ ] Stacks still deploy clean (verify after push) - [x] Stacks still deploy clean (verified after push + Portainer git repair)
</details> </details>
@@ -33,7 +33,7 @@
| | | | | |
|---|---| |---|---|
| **Decision** | Do it — audit complete; fixes tracked below | | **Decision** | Do it — audit complete; fixes tracked below |
| **Notes** | Obsidian locked down in TB-005. Auth gaps → TB-006 (other session). | | **Notes** | Obsidian locked down in TB-005. minio/homarr/docs → `internal_only` (2026-06-11). Remaining auth gaps → TB-006. |
| **Date** | 2026-06-11 | | **Date** | 2026-06-11 |
--- ---