snapshot: preserve central wiki state 2026-08-15 (7 modified + 1 new file)
This commit is contained in:
@@ -0,0 +1,72 @@
|
||||
---
|
||||
title: Tailscale
|
||||
type: infrastructure
|
||||
status: active
|
||||
created: 2026-07-26
|
||||
updated: 2026-07-27
|
||||
verified_on: 2026-07-27
|
||||
confidence: high
|
||||
tags: [tailscale, vpn, networking, infrastructure]
|
||||
---
|
||||
|
||||
# Tailscale
|
||||
|
||||
## Purpose
|
||||
WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve.
|
||||
|
||||
## Domain
|
||||
- **Tailnet:** `kangaroo-eel.ts.net`
|
||||
- **Primary node:** CT460 (`hermes.kangaroo-eel.ts.net`)
|
||||
- **Runtipi node:** CT201 (`runtipi.kangaroo-eel.ts.net`)
|
||||
|
||||
## CT460 Serve Routes
|
||||
| Path | Target | Notes |
|
||||
|---|---|---|
|
||||
| `/` | `http://127.0.0.1:9119` | Hermes WebUI |
|
||||
| `/jobs` | `http://127.0.0.1:9099` | Jobs Dashboard |
|
||||
| `/desktop` | `http://127.0.0.1:6081` | CUA noVNC |
|
||||
| `/vnc-camofox` | `http://127.0.0.1:6080` | Camofox VNC |
|
||||
|
||||
## CT460 Funnel Routes
|
||||
| Port | Target | Notes |
|
||||
|---|---|---|
|
||||
| `:8443/webhook` | `http://127.0.0.1:8085/webhook` | Public webhook Funnel |
|
||||
|
||||
## CT201 Serve Routes
|
||||
| Path | Target | Notes |
|
||||
|---|---|---|
|
||||
| `:8443` | `http://localhost:8082` | Homepage dashboard |
|
||||
| `/steel` | `http://127.0.0.1:5173` | Steel Browser UI |
|
||||
| `/steel-api` | `http://127.0.0.1:3000` | Steel Browser API (path prefix not stripped — use direct IP for API calls) |
|
||||
|
||||
## Atomic Restore Script
|
||||
`/home/hermes/.hermes/scripts/tailscale-serve-apply.sh` — Rebuilds the complete CT460 route table, including tailnet Serve on `:443` and public Funnel on `:8443`.
|
||||
|
||||
`tailscale serve reset` clears Funnel state as well as Serve state. The atomic script therefore restores `/webhook` after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery.
|
||||
|
||||
## Key Commands
|
||||
```bash
|
||||
# Check routes
|
||||
tailscale serve status
|
||||
|
||||
# Rebuild routes (CT460)
|
||||
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run
|
||||
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh
|
||||
|
||||
# Add route
|
||||
tailscale serve --set-path /jobs http://127.0.0.1:9099
|
||||
|
||||
# Remove route
|
||||
tailscale serve --set-path /jobs off
|
||||
```
|
||||
|
||||
## Notes
|
||||
- Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there
|
||||
- CT460 has no conflict — Tailscale uses 443 directly
|
||||
- Routes must be re-added in order (restore script handles this)
|
||||
- After every rebuild, verify that `tailscale serve status` contains both the `:443` Serve routes and the `:8443/webhook` Funnel route.
|
||||
|
||||
## Related
|
||||
- [[infrastructure/domains-and-tunnels]] — Full DNS and tunnel inventory
|
||||
- [[systems/homepage-dashboard]] — Homepage on CT201 via Tailscale
|
||||
- [[runbooks/job-radar]] — Dashboard incident and route verification
|
||||
Reference in New Issue
Block a user