Officina · configuration inventory · read-only sweep

Nine lines reach every device. The biggest file reaches one.

Officina is one always-on Linux server; the laptop, the phone and any borrowed machine are terminals into it, stitched together by Tailscale. Its promise is warm recovery — anything can die and you are working again within two hours, from whatever device you are holding. Forty-one files configure that. This map draws each one as an area: size is the area, danger is the marking. They turn out to have almost nothing to do with each other.

Files mapped
41
Everything under officina/ that changes machine state.
Biggest file
412lines
Touches 1 device. A bad edit costs one rebuild.
Smallest fleet-wide file
9lines
Touches all 11. A bad edit lands everywhere at once.
Reach all 11 devices
6files
347 lines — 11.6% of the configuration.
Size vs reach
−0.09r
Line count predicts blast radius about as well as a coin.
Area = line count Marking = blast radius

A proportional map of 41 configuration files. Each cell's area is its line count. Each cell is marked with how far a mistake in it propagates: FLEET reaches all 11 devices, WIDE reaches 3 to 4, LOCAL reaches 1 or 2. The largest cells are all LOCAL. The four smallest cells drawn individually are all FLEET.

○ Local · 1 device ansible/roles/workstation/tasks/main.yml 412 lines · 1 of 11 devices
○ Local · 1 device agents/skills/officina-recovery/SKILL.md 296 lines · 1 of 11 devices
○ Local · 2 devices caddy/Caddyfile 289 lines · 2 of 11 devices
○ Local · 1 device backup/restic/exclude-rules.conf 207 lines · 1 of 11 devices
○ Local · 1 device systemd/user/[email protected] 143 lines · 1 of 11 devices
◆ Wide · 3 devices ansible/roles/base/tasks/hardening.yml 140 lines · 3 of 11 devices
▲ Fleet · 11 devices ansible/group_vars/all.yml 137 lines · 11 of 11 devices
○ Local · 2 devices caddy/snippets/tls-internal.caddy 118 lines · 2 of 11 devices
○ Local · 1 device systemd/system/officina-backup.service 116 lines · 1 of 11 devices
○ Local · 1 device agents/skills/deploy-check/SKILL.md 112 lines · 1 of 11 devices
○ Local · 1 backup/restic/prune-policy.env 106 lines · 1 of 11
▲ Fleet · 11 ansible/roles/tailscale/tasks/main.yml 104 lines · 11 of 11
○ Local · 1 systemd/system/officina-restore.target 101 lines · 1 of 11
◆ Wide · 4 caddy/sites/inbox.caddy 97 lines · 4 of 11
▲ Fleet · 11 systemd/user/[email protected] 44 lines · 11 of 11
▲ Fleet · 11 tailscale/dns-split.json 31 lines · 11 of 11
▲ Fleet · 11 tailscale/acl.hujson 22 lines · 11 of 11
▲ Fleet · 11 agents/policy/action-whitelist.txt 9 lines · 11 of 11
○ Local · 1–2 devices each 23 remaining files, drawn as one blocktimers, drop-ins, one-line env files, two more Caddy sites 496 lines · none reaches more than 2 of 11 devices
▲ Fleet — 11 of 11 devices — 6 files ◆ Wide — 3–4 devices — 2 files ○ Local — 1–2 devices — 33 files

Area is line count, honestly, down to about 95 lines. Below that a cell is drawn at a floor size so it can still carry its own filename and its own numbers — the four smallest cells are bigger on this map than they are in the repository. agents/policy/action-whitelist.txt is drawn roughly ten times its true share. At true scale it would be a two-pixel mark in the corner, and it would still reach all eleven devices. That is the whole finding: the thing your eye is drawn to and the thing that can hurt you are different things.

The six that reach everything

smallest first — which is also least-reviewed first

Ordered by line count ascending, because on this list that ordering is the argument. Small files invite a quicker read than large ones, and size tracks blast radius not at all. The first half of that is an assumption; this page measures line count and device reach, not review behaviour. None of these is misconfigured today. All six are places where a correct-looking three-character change arrives on every device you own.

agents/policy/action-whitelist.txt

Fleet · 9 lines · 11 devices

Nine allowed action names, one per line. Every agent process on every device reads it before it does anything. Adding a tenth line widens what an agent may do everywhere at once, and a nine-line file produces a one-line diff that no review habit is built to catch.

The project's own rule says it plainly: the action whitelist is a security boundary, not a UX choice. The rule is written down. The file is still the smallest thing that reaches every device.

tailscale/acl.hujson

Fleet · 22 lines · 11 devices

The tailnet grant table: which tags may reach which ports. A wrong tag changes who can reach the server, from where, on every device simultaneously — including the borrowed laptop that is only ever a terminal.

Warm recovery depends on this file being permissive enough to let a fresh device in, and safe enough that a fresh device is not a hole. Both properties live in twenty-two lines.

tailscale/dns-split.json

Fleet · 31 lines · 11 devices

MagicDNS split routes. Its failure mode is the bad one: a wrong entry does not break access, it silently resolves a name somewhere else. Nothing goes red.

The two-hour recovery clock only starts when someone notices. A file whose failure mode is a wrong answer rather than an outage does not start the clock at all.

systemd/user/[email protected]

Fleet · 44 lines · 11 devices

The paste-inbox unit, instantiated once per device. Its Environment= block fixes the inbox path and its mode. A change here lands on every terminal the next time the unit is re-templated, which is on the next converge, not on a deliberate rollout.

Forty-four lines, and one of them decides whether a directory that receives files from other machines is 0700 or 0755.

ansible/roles/tailscale/tasks/main.yml

Fleet · 104 lines · 11 devices

Brings tailscaled up and applies tags at join time. It runs against every host in the inventory, so it is fleet-wide by construction rather than by accident.

This one is at least the right size to look important, which is the only reason it gets read.

ansible/group_vars/all.yml

Fleet · 137 lines · 11 devices

The variables every play interpolates. Nothing executes here; everything is parameterised from here. Change a hostname and eleven machines converge on the new one.

The largest fleet-wide file on the map — and, by every account, the only fleet-wide file anyone reviews carefully. Size is buying attention it does not need, and denying it to the five files above.

What this is not

This is an inventory, not an incident. No file on this map is misconfigured, no credential is exposed, and nothing here was reachable that should not have been. Every one of the forty-one files is doing exactly what it was written to do.

The finding is about where attention goes. A review queue sorted by diff size, a habit of skimming short files, an eye that reads a big block as a big responsibility — all three point away from the six files that reach the whole fleet. The map is here because a sorted list would have been read as a ranking, and the point is not that one file is worse than another. The point is that the picture and the danger do not line up, and you can see that in two seconds but not in a table.

The cheapest correction is not a tool. It is putting the six paths above somewhere a change to them cannot be quiet — a required second pair of eyes, a converge that announces itself, a line in the recovery runbook. The whitelist rule already exists. It just needs to apply to the file, not only to the idea.

Full roster — 18 files drawn individually, plus the 23-file tail
Path Lines Devices Blast radius
ansible/roles/workstation/tasks/main.yml4121○ Local
agents/skills/officina-recovery/SKILL.md2961○ Local
caddy/Caddyfile2892○ Local
backup/restic/exclude-rules.conf2071○ Local
systemd/user/[email protected]1431○ Local
ansible/roles/base/tasks/hardening.yml1403◆ Wide
ansible/group_vars/all.yml13711▲ Fleet
caddy/snippets/tls-internal.caddy1182○ Local
systemd/system/officina-backup.service1161○ Local
agents/skills/deploy-check/SKILL.md1121○ Local
backup/restic/prune-policy.env1061○ Local
ansible/roles/tailscale/tasks/main.yml10411▲ Fleet
systemd/system/officina-restore.target1011○ Local
caddy/sites/inbox.caddy974◆ Wide
systemd/user/[email protected]4411▲ Fleet
tailscale/dns-split.json3111▲ Fleet
tailscale/acl.hujson2211▲ Fleet
agents/policy/action-whitelist.txt911▲ Fleet
23 remaining files (timers, drop-ins, env files, 2 Caddy sites)4961–2○ Local
41 files2,980—6 fleet · 2 wide · 33 local