Files
homelabstack/plans/homelab-improvements/tasks/TB-005-obsidian-hardening.md
T
ginnoir 1253825541 Mark TB-005 Obsidian hardening complete.
Record deployed internal_only gate and update plan brief gaps.
2026-06-10 22:47:02 -05:00

1.7 KiB

TB-005 — Obsidian / CouchDB hardening

Status: done — deployed 2026-06-10
Your call: Do it — LAN/tailnet only via internal_only


Talk first

Stop. Don't read Reference until we've talked. In chat, say "let's do TB-005" or "obsidian / couchdb hardening".

In one sentence: Your whole PKM vault syncs over a public URL — let's decide how exposed you're okay with.

Why it came up: obsidian.ginnoir.com has no LAN-only or SSO gate; LiveSync needs remote access from phones.

Questions

  1. Do you sync Obsidian from your phone without Tailscale always on?
  2. Would 'Tailscale only' work, or do you need public access?
  3. Authentik login in front — okay if we test LiveSync still works?

Your options

Option Meaning
Do it We're doing this — I'll implement or walk you through it
Later Keep on the list, not now
Drop Remove from plan — totally fine
Tweak Change scope; tell me how

What we decided

Decision Do it — internal_only (LAN + tailnet); no public access
Notes import internal_only on obsidian.ginnoir.com. All LiveSync clients on tailnet; Authentik not needed. CouchDB password rotation deferred.
Date 2026-06-10 (decided + deployed)

Reference (only open if we're doing it)

Stack / files

Caddyfile, stacks/notes/

If we do it — rough steps

  1. Pick model: Tailscale-only, Authentik, or hybrid
  2. Implement + test sync from each device
  3. Rotate CouchDB password

Done when

  • You can still sync where you need to (tailnet)
  • Admin/_utils not wide open (internal_only — LAN + 100.64.0.0/10 only)