Skip to content

Add Mealie to the sensitive tier #146

Description

@Gerrrt

Beyond ADR-0008's nine.

What and why

Mealie MIT Pythonawesome-selfhosted README.md:1804.

Recipe manager with meal planning, shopping lists and URL import, aimed explicitly at being usable by a whole household rather than by its administrator.

That is the reason it is on this list. Almost everything else here is infrastructure that the household benefits from without touching — segmentation, alerting, backups. This is one of the few services someone other than the operator will open on purpose, and a homelab that produces something the rest of the house actually likes is easier to justify continuing to spend money on. That is not a technical argument, and it is still a real one.

grocy (:1840, MIT, PHP/Docker) is the adjacent option — household ERP, stock tracking, chores, batteries, far more ambitious. It wants genuine day-to-day discipline to stay accurate, and an inaccurate stock database is worse than none. Mealie asks much less and is more likely to survive contact with real life.

Placement

Sensitive tier, VLAN 99, on the 50→99 rule that already exists. Recipes are not sensitive data — but placing it on 40 with the media services would mean it is reachable from the televisions and not from anything else, which is backwards for something used from a phone or a laptop in the kitchen.

Worth noting: this is the kind of low-consequence, human-facing service that would have made the strongest case for the dedicated services VLAN ADR-0008 rejected. It does not justify reopening that decision on its own, but it is a data point if others accumulate.

What it needs

Which VLAN this touches

🔴 99 — Winterfell (management)

Security review

  • Does not weaken the default-deny posture between VLANs — reached from Hicks under the existing 50→99; no new rule
  • Any new credential goes in secrets/*.sops.yaml
  • Any new device is added to docs/network.md with an OUI-truncated MAC — n/a

Depends on

#102 (the mini PC), #129 (Caddy).

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions