What is true
stacks/media runs on smaug since 2026-09-19 (#522) and has no secrets file. Jellyfin's admin credential lives in the operator's password manager and nowhere the estate can see. secrets/ holds lab, observability, sensitive and soc entries; .sops.yaml has a path_regex rule for each of those and none for media. Every other tier got a per-stack recipient under ADR-0020's rule; this one did not, because it was deployed by hand under TrueNAS's Docker rather than by make deploy.
Named as the one residual of #138 with no tracker, in that issue's 2026-09-19 comment.
What to decide
Done when
The credential is in the repository's custody path or the exception is recorded in docs/security.md beside the other tiers, and successor-handover.md says where the media admin lives.
Refs #138, #140, #141.
What is true
stacks/mediaruns onsmaugsince 2026-09-19 (#522) and has no secrets file. Jellyfin'sadmincredential lives in the operator's password manager and nowhere the estate can see.secrets/holdslab,observability,sensitiveandsocentries;.sops.yamlhas apath_regexrule for each of those and none formedia. Every other tier got a per-stack recipient under ADR-0020's rule; this one did not, because it was deployed by hand under TrueNAS's Docker rather than bymake deploy.Named as the one residual of #138 with no tracker, in that issue's 2026-09-19 comment.
What to decide
secrets/media.sops.yamland a.sops.yamlrule like the others, or whether a stack that holds one admin password and is deployed from TrueNAS's UI is the exception — written down either way.make renderwrites an env file no TrueNAS app reads; the answer is probably the same hand-deploy path feat(nas): the drives are in, erebor exists, the stack runs and the scrape is on #522 used, documented instacks/media/README.md.Done when
The credential is in the repository's custody path or the exception is recorded in
docs/security.mdbeside the other tiers, andsuccessor-handover.mdsays where the media admin lives.Refs #138, #140, #141.