Files
agent-estate-wiki/infrastructure/tailscale.md
T

3.0 KiB

title, type, status, created, updated, verified_on, confidence, tags
title type status created updated verified_on confidence tags
Tailscale infrastructure active 2026-07-26 2026-09-10 2026-09-10 high
tailscale
vpn
networking
infrastructure

Tailscale

Purpose

WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve.

Domain

  • Tailnet: kangaroo-eel.ts.net
  • Primary node: CT460 (hermes.kangaroo-eel.ts.net)
  • Runtipi node: CT201 (runtipi.kangaroo-eel.ts.net)

CT460 Serve Routes

Path Target Notes
/ http://127.0.0.1:9119 Hermes WebUI
/ui http://127.0.0.1:5175/ Hermes UI (Vite)
/jobs http://127.0.0.1:9099 Jobs Dashboard
/webui http://127.0.0.1:8787/ Hermes WebUI (Standalone)
/desktop http://127.0.0.1:6081 CUA noVNC
/vnc-camofox http://127.0.0.1:6080 Camofox VNC
/agent-estate http://127.0.0.1:8769/agent-estate-role-dashboard.html Role dashboard
/synergy-prep http://127.0.0.1:9123/ Synergy prep
/evening-grid.html http://127.0.0.1:9099/evening-grid.html Evening grid
/wiki http://100.118.5.51:9120 Agent Estate Wiki (Quartz)
/gitea http://100.82.100.128:3000 Gitea
/ignis http://127.0.0.1:8080 Ignis (browser-native Obsidian)

CT460 Funnel Routes

Port Target Notes
:8443/webhook http://127.0.0.1:8085/webhook Public webhook Funnel

CT201 Serve Routes

Path Target Notes
:8443 http://localhost:8082 Homepage dashboard
/steel http://127.0.0.1:5173 Steel Browser UI
/steel-api http://127.0.0.1:3000 Steel Browser API (path prefix not stripped — use direct IP for API calls)

Atomic Restore Script

/home/hermes/.hermes/scripts/tailscale-serve-apply.sh — Rebuilds the complete CT460 route table, including tailnet Serve on :443 and public Funnel on :8443.

tailscale serve reset clears Funnel state as well as Serve state. The atomic script therefore restores /webhook after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery.

Key Commands

# Check routes
tailscale serve status

# Rebuild routes (CT460)
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh

# Add route
tailscale serve --set-path /jobs http://127.0.0.1:9099

# Remove route
tailscale serve --set-path /jobs off

Notes

  • Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there
  • CT460 has no conflict — Tailscale uses 443 directly
  • Routes must be re-added in order (restore script handles this)
  • After every rebuild, verify that tailscale serve status contains both the :443 Serve routes and the :8443/webhook Funnel route.