Skip to content

Add Stirling-PDF to the sensitive tier #143

Description

@Gerrrt

Beyond ADR-0008's nine. Pairs directly with Paperless-ngx (#133).

What and why

Stirling-PDF Apache-2.0 Docker/Javaawesome-selfhosted README.md:762.

Merge, split, rotate, convert, OCR, sign, compress — the operations that otherwise get done by uploading a document to whichever free PDF website ranks first that week.

That last point is the actual argument. This estate segments its network by trust and encrypts its secrets at rest, and none of it matters if a P60 or a passport scan goes through an anonymous web converter on the way to being emailed. This is a small service that closes a real gap between the household's habits and the design's intent.

Paperless (#133) is an archive and deliberately not an editor; Stirling is the editor and deliberately not an archive. Neither wants to be the other.

Placement

Sensitive tier, VLAN 99 — it handles the same documents Paperless holds, so it inherits the same classification. Processing is entirely local; nothing leaves the container.

What it needs

Which VLAN this touches

🔴 99 — Winterfell (management)

Security review

  • Does not weaken the default-deny posture between VLANs — reached from Hicks under the existing 50→99; no new rule
  • Any new credential goes in secrets/*.sops.yaml — if login is enabled
  • Any new device is added to docs/network.md with an OUI-truncated MAC — n/a

Depends on

#102 (the mini PC), #129 (Caddy). Pairs with #133.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions