# TB-033 — Public surface audit **Status:** not started **Your call:** _(unset — talk first)_ --- ## Talk first > **Stop.** Don't read Reference until we've talked. > In chat, say **"let's do TB-033"** or **"public surface audit"**. **In one sentence:** A short conversation + checklist: what's reachable from the internet, and should it be? **Why it came up:** Some things are public on purpose (Foundry, famapp); some might surprise you (Obsidian). ### Questions 1. Want to walk through the list together in chat instead of reading a table? 2. Any service you *know* should be public that we'd flag as wrong? ### Your options | Option | Meaning | |--------|---------| | **Do it** | We're doing this — I'll implement or walk you through it | | **Later** | Keep on the list, not now | | **Drop** | Remove from plan — totally fine | | **Tweak** | Change scope; tell me how | ### What we decided | | | |---|---| | **Decision** | | | **Notes** | | | **Date** | | ---
Reference (only open if we're doing it) ### Stack / files Caddyfile review only ### If we do it — rough steps 1. Walk each public domain in conversation 2. Mark: keep public / lock down / drop 3. Save decisions here and in TB-005/TB-006 as needed ### Done when - [ ] Every public site has your yes/no - [ ] Action items linked to other TBs