Obsidian consolidation COMPLETE — vault out of iCloud, legacy vaults retired, secrets quarantined
Completed the remaining Obsidian work: retired 9 legacy vaults, recovered 4,364 unique notes that were about to be lost, quarantined 143 credential-bearing files out of a vault that syncs to a hosted service, and moved MasterVault out of the iCloud container — the structural fix for the stuck sync.
Host: rdmbair15m5 · Window: 2026-08-23 11:12 → 11:24 EDT · Operator: claude@rdmbair15m5
Final state
| MasterVault | ~/Obsidian/MasterVault — outside
iCloud |
| notes / files / size | 38,638 / 45,845 / 5.3 GB |
| root loose files | 0 |
| Obsidian Sync | bound and live — master-vault-fleet-primary-sync
survived the move |
| iCloud obsidian container | 20 KB (was 20 GB) |
vaults remaining in ~/Documents |
0 |
What was done
- Verified legacy vaults before touching them.
SHA-256 against MasterVault found 171 unique files in
the 7 iCloud vaults — they were NOT fully redundant. Preserved to
~/Backups/legacy-vault-unique-20260823/(0700/0600) before any archive. - Archived 7 iCloud legacy vaults (14 GB) →
~/Backups/legacy-vaults-archive-20260823/. Moved, not deleted. ~/Documents/obsidian-vaults/defaultwas NOT redundant — 4,506 unique files including real notes (personal/,infra/,reference/,clients/,projects/). Archiving it blind would have destroyed them.- Split-merged it. 4,364 clean notes →
MasterVault/30-Ingestion/Legacy-Vault-Merge/. 142 credential-bearing files held OUT →~/Backups/SENSITIVE-not-for-sync-20260823/(0700/0600, manifest, contents never opened). - Archived the last two
~/Documentsvaults after preserving 91 more unique files. - Moved MasterVault out of the iCloud container to
~/Obsidian/MasterVault, preserving the vault idmaster-vault-fleet-primaryso Obsidian Sync stayed bound. Verified: vault opens at the new path, 799 live sync refs, no competing sync plugins.
SECURITY FINDING — needs Rich's attention
Credential material was sitting in Obsidian vaults inside iCloud, and 4,506 of those files were one command away from being merged into a vault that now syncs to Obsidian's hosted service.
Three independent gates caught them (_sensitive/ folder
name, filename pattern, body content scan). Held back, by category:
_sensitive/folder — 89 files- A TOTP secret in the filename itself:
otpauthtotpIntuit…secret=TJYKIUXSMU457XFI2VFZWZXO34 - Work 2FA backup codes:
[email protected]_google_backup_codes_032823.md, and[email protected]_backup_codes_032823_*(3 copies across 3 vaults) infra/linux/V3 Passwords.md,infra/linux/Remote IP (temporary) credentials.md_sensitive/Unify UISP password.md,_sensitive/Nintendo Backup codes (122119).md- A Cisco type-7 password in a filename:
no username user1 password 7 1511021F07257A767B.md - A hashed password in a filename:
username rich privilege 15 secret 5 $1$FQjn$O6CFzNICM - 5
.ovpnfiles (normally embed private keys)
Contents were never opened. These predate this
session and were already in iCloud. The arista.com work 2FA
backup codes in particular should be regenerated — treat them as
exposed.
Reversibility
- Archived vaults:
~/Backups/legacy-vaults-archive-20260823/(25 GB, 10 vaults, moved not deleted) - Unique-file preserves:
~/Backups/legacy-vault-unique-20260823/+ MANIFEST.json - Secrets:
~/Backups/SENSITIVE-not-for-sync-20260823/+ HELD-MANIFEST.json obsidian.jsonbackup:~/Backups/obsidian.json.bak-20260823-1118- To undo the move: quit Obsidian,
mv ~/Obsidian/MasterVaultback, restore obsidian.json.
Outstanding
- Regenerate the Arista work 2FA backup codes — treat as exposed.
- Decide disposition of
~/Backups/legacy-vaults-archive-20260823(25 GB) — offload or delete once satisfied nothing else is needed. - Obsidian Sync Plus exact caps still unread from the app.
- Apple Notes reimport still pending (Rich: notes are mostly redundant to Apple Notes).
- Other fleet hosts still have their own legacy vaults in iCloud — this cleanup was rdmbair15m5 only.