Skip to content

stacks/media has no secrets file: Jellyfin's admin credential lives only in a password manager #528

Description

@Gerrrt

What is true

stacks/media runs on smaug since 2026-09-19 (#522) and has no secrets file. Jellyfin's admin credential lives in the operator's password manager and nowhere the estate can see. secrets/ holds lab, observability, sensitive and soc entries; .sops.yaml has a path_regex rule for each of those and none for media. Every other tier got a per-stack recipient under ADR-0020's rule; this one did not, because it was deployed by hand under TrueNAS's Docker rather than by make deploy.

Named as the one residual of #138 with no tracker, in that issue's 2026-09-19 comment.

What to decide

Done when

The credential is in the repository's custody path or the exception is recorded in docs/security.md beside the other tiers, and successor-handover.md says where the media admin lives.

Refs #138, #140, #141.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    mediastacks/media on smaug (VLAN 40)securityseq/1Step 1 within its milestone; same number = can run in parallel

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions