--- title: Tailscale type: infrastructure status: active created: 2026-07-26 updated: 2026-07-27 verified_on: 2026-07-27 confidence: high tags: [tailscale, vpn, networking, infrastructure] --- # Tailscale ## Purpose WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve. ## Domain - **Tailnet:** `kangaroo-eel.ts.net` - **Primary node:** CT460 (`hermes.kangaroo-eel.ts.net`) - **Runtipi node:** CT201 (`runtipi.kangaroo-eel.ts.net`) ## CT460 Serve Routes | Path | Target | Notes | |---|---|---| | `/` | `http://127.0.0.1:9119` | Hermes WebUI | | `/jobs` | `http://127.0.0.1:9099` | Jobs Dashboard | | `/desktop` | `http://127.0.0.1:6081` | CUA noVNC | | `/vnc-camofox` | `http://127.0.0.1:6080` | Camofox VNC | ## CT460 Funnel Routes | Port | Target | Notes | |---|---|---| | `:8443/webhook` | `http://127.0.0.1:8085/webhook` | Public webhook Funnel | ## CT201 Serve Routes | Path | Target | Notes | |---|---|---| | `:8443` | `http://localhost:8082` | Homepage dashboard | | `/steel` | `http://127.0.0.1:5173` | Steel Browser UI | | `/steel-api` | `http://127.0.0.1:3000` | Steel Browser API (path prefix not stripped — use direct IP for API calls) | ## Atomic Restore Script `/home/hermes/.hermes/scripts/tailscale-serve-apply.sh` — Rebuilds the complete CT460 route table, including tailnet Serve on `:443` and public Funnel on `:8443`. `tailscale serve reset` clears Funnel state as well as Serve state. The atomic script therefore restores `/webhook` after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery. ## Key Commands ```bash # Check routes tailscale serve status # Rebuild routes (CT460) /home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run /home/hermes/.hermes/scripts/tailscale-serve-apply.sh # Add route tailscale serve --set-path /jobs http://127.0.0.1:9099 # Remove route tailscale serve --set-path /jobs off ``` ## Notes - Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there - CT460 has no conflict — Tailscale uses 443 directly - Routes must be re-added in order (restore script handles this) - After every rebuild, verify that `tailscale serve status` contains both the `:443` Serve routes and the `:8443/webhook` Funnel route. ## Related - [[infrastructure/domains-and-tunnels]] — Full DNS and tunnel inventory - [[systems/homepage-dashboard]] — Homepage on CT201 via Tailscale - [[runbooks/job-radar]] — Dashboard incident and route verification