# TB-005 — Obsidian / CouchDB hardening **Status:** done — deployed 2026-06-10 **Your call:** **Do it** — LAN/tailnet only via `internal_only` --- ## Talk first > **Stop.** Don't read Reference until we've talked. > In chat, say **"let's do TB-005"** or **"obsidian / couchdb hardening"**. **In one sentence:** Your whole PKM vault syncs over a public URL — let's decide how exposed you're okay with. **Why it came up:** obsidian.ginnoir.com has no LAN-only or SSO gate; LiveSync needs remote access from phones. ### Questions 1. Do you sync Obsidian from your phone without Tailscale always on? 2. Would 'Tailscale only' work, or do you need public access? 3. Authentik login in front — okay if we test LiveSync still works? ### Your options | Option | Meaning | |--------|---------| | **Do it** | We're doing this — I'll implement or walk you through it | | **Later** | Keep on the list, not now | | **Drop** | Remove from plan — totally fine | | **Tweak** | Change scope; tell me how | ### What we decided | | | |---|---| | **Decision** | Do it — `internal_only` (LAN + tailnet); no public access | | **Notes** | `import internal_only` on obsidian.ginnoir.com. All LiveSync clients on tailnet; Authentik not needed. CouchDB password rotation deferred. | | **Date** | 2026-06-10 (decided + deployed) | ---
Reference (only open if we're doing it) ### Stack / files Caddyfile, stacks/notes/ ### If we do it — rough steps 1. Pick model: Tailscale-only, Authentik, or hybrid 2. Implement + test sync from each device 3. Rotate CouchDB password ### Done when - [x] You can still sync where you need to (tailnet) - [x] Admin/_utils not wide open (`internal_only` — LAN + 100.64.0.0/10 only)