Close TB-002–004 and TB-033 with done-when checkboxes and update PLAN-BRIEF priority to the next themes.
3.5 KiB
3.5 KiB
TB-033 — Public surface audit
Status: done — audited 2026-06-11
Your call: Do it (walkthrough complete; action items below)
Talk first
Stop. Don't read Reference until we've talked. In chat, say "let's do TB-033" or "public surface audit".
In one sentence: A short conversation + checklist: what's reachable from the internet, and should it be?
Why it came up: Some things are public on purpose (Foundry, famapp); some might surprise you (Obsidian).
Questions
- Want to walk through the list together in chat instead of reading a table?
- Any service you know should be public that we'd flag as wrong?
Your options
| Option | Meaning |
|---|---|
| Do it | We're doing this — I'll implement or walk you through it |
| Later | Keep on the list, not now |
| Drop | Remove from plan — totally fine |
| Tweak | Change scope; tell me how |
What we decided
| Decision | Do it — audit complete; fixes tracked below |
| Notes | Obsidian locked down in TB-005. minio/homarr/docs → internal_only (2026-06-11). Remaining auth gaps → TB-006. |
| Date | 2026-06-11 |
Audit results (2026-06-11)
Sites without internal_only — reachable from the public internet (Cloudflare → Caddy):
Intentionally public ✓
| Site | Purpose |
|---|---|
| foundry.ginnoir.com, foundry2.ginnoir.com | Foundry VTT for players |
| 5etools.ginnoir.com, pf2e.ginnoir.com | Tabletop reference sites |
| files.ginnoir.com | ownCloud (Authentik on admin UI) |
| ffttsystems.ginnoir.com | Static site |
| requests.ginnoir.com | Overseerr for friends |
| ntfy.ginnoir.com | Push notifications (native auth) |
| freshrss.ginnoir.com | RSS reader (HTTP auth via Authentik) |
| resume.ginnoir.com, j-costa.com | Portfolio |
| storage.j-costa.com | Resume PDF/object storage (public by design) |
| fam.ginnoir.com | Family app (Authentik OIDC) |
| auth.ginnoir.com | Authentik |
| dev.ginnoir.com | External LAN host (192.168.1.74) — DNS public but host isn't on valhalla |
Public but gated (Authentik forward_auth or native OIDC) — OK for now
| Site | Gate |
|---|---|
| sonarr–stash, qbittorrent, deluge, … | internal_only + Authentik |
| uptime.ginnoir.com, backup.ginnoir.com | Authentik |
| code.ginnoir.com, registry-ui, dbx, vault, plane.ginnoir.com | Authentik |
| portainer.ginnoir.com | Authentik on UI; webhook POST bypass |
Flagged — review / fix
| Site | Issue | Action |
|---|---|---|
Fixed 2026-06-11 — internal_only |
||
Fixed 2026-06-11 — internal_only |
||
Fixed 2026-06-11 — internal_only |
||
| gitea.ginnoir.com | UI reachable; api/git bypass by design | OK if Gitea login is enough; optional Authentik — TB-006 |
Correctly internal-only ✓
obsidian, roms, romhacks, romhacks-files, registry.ginnoir.com, router.ginnoir.com, jd.ginnoir.com (added TB-002), all *arr admin UIs.
Reference (only open if we're doing it)
Stack / files
Caddyfile review only
If we do it — rough steps
- Walk each public domain in conversation
- Mark: keep public / lock down / drop
- Save decisions here and in TB-005/TB-006 as needed
Done when
- Every public site has your yes/no
- Action items linked to other TBs