1.7 KiB
1.7 KiB
TB-005 — Obsidian / CouchDB hardening
Status: done — deployed 2026-06-10
Your call: Do it — LAN/tailnet only via internal_only
Talk first
Stop. Don't read Reference until we've talked. In chat, say "let's do TB-005" or "obsidian / couchdb hardening".
In one sentence: Your whole PKM vault syncs over a public URL — let's decide how exposed you're okay with.
Why it came up: obsidian.ginnoir.com has no LAN-only or SSO gate; LiveSync needs remote access from phones.
Questions
- Do you sync Obsidian from your phone without Tailscale always on?
- Would 'Tailscale only' work, or do you need public access?
- Authentik login in front — okay if we test LiveSync still works?
Your options
| Option | Meaning |
|---|---|
| Do it | We're doing this — I'll implement or walk you through it |
| Later | Keep on the list, not now |
| Drop | Remove from plan — totally fine |
| Tweak | Change scope; tell me how |
What we decided
| Decision | Do it — internal_only (LAN + tailnet); no public access |
| Notes | import internal_only on obsidian.ginnoir.com. All LiveSync clients on tailnet; Authentik not needed. CouchDB password rotation deferred. |
| Date | 2026-06-10 (decided + deployed) |
Reference (only open if we're doing it)
Stack / files
Caddyfile, stacks/notes/
If we do it — rough steps
- Pick model: Tailscale-only, Authentik, or hybrid
- Implement + test sync from each device
- Rotate CouchDB password
Done when
- You can still sync where you need to (tailnet)
- Admin/_utils not wide open (
internal_only— LAN + 100.64.0.0/10 only)