Protects /config, selective labdata, and nightly DB dumps; documents homelab improvement plan briefs.
1.4 KiB
1.4 KiB
TB-005 — Obsidian / CouchDB hardening
Status: not started
Your call: (unset — talk first)
Talk first
Stop. Don't read Reference until we've talked. In chat, say "let's do TB-005" or "obsidian / couchdb hardening".
In one sentence: Your whole PKM vault syncs over a public URL — let's decide how exposed you're okay with.
Why it came up: obsidian.ginnoir.com has no LAN-only or SSO gate; LiveSync needs remote access from phones.
Questions
- Do you sync Obsidian from your phone without Tailscale always on?
- Would 'Tailscale only' work, or do you need public access?
- Authentik login in front — okay if we test LiveSync still works?
Your options
| Option | Meaning |
|---|---|
| Do it | We're doing this — I'll implement or walk you through it |
| Later | Keep on the list, not now |
| Drop | Remove from plan — totally fine |
| Tweak | Change scope; tell me how |
What we decided
| Decision | |
| Notes | |
| Date |
Reference (only open if we're doing it)
Stack / files
Caddyfile, stacks/notes/
If we do it — rough steps
- Pick model: Tailscale-only, Authentik, or hybrid
- Implement + test sync from each device
- Rotate CouchDB password
Done when
- You can still sync where you need to
- Admin/_utils not wide open