Replace the skills-only regeneration script with a general wiki-maintain.sh that: - regenerates skills-index from live skill tree (330 skills / 26 categories) - audits EVERY page for staleness vs its updated date (>21d flagged) - rebuilds + redeploys the Quartz site - writes a dated freshness report to raw/stocktake/ Also fix the tailscale.md page (it had drifted to only 4 routes; reality now has 11 CT460 routes incl /webui, /agent-estate, /synergy-prep, /evening-grid, /wiki and the /wiki proxy was also missing from the atomic apply script — added there). Cron wiki-stocktake-maintenance (1a8e90ea2271) now runs this daily 03:00 and commits+pushes so the wiki cannot silently drift again.
2.9 KiB
title, type, status, created, updated, verified_on, confidence, tags
| title | type | status | created | updated | verified_on | confidence | tags | ||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Tailscale | infrastructure | active | 2026-07-26 | 2026-08-16 | 2026-08-16 | high |
|
Tailscale
Purpose
WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve.
Domain
- Tailnet:
kangaroo-eel.ts.net - Primary node: CT460 (
hermes.kangaroo-eel.ts.net) - Runtipi node: CT201 (
runtipi.kangaroo-eel.ts.net)
CT460 Serve Routes
|| Path | Target | Notes |
||---|---|---|---|
|| / | http://127.0.0.1:9119 | Hermes WebUI |
|| /ui | http://127.0.0.1:5175/ | Hermes UI (Vite) |
|| /jobs | http://127.0.0.1:9099 | Jobs Dashboard |
|| /webui | http://127.0.0.1:8787/ | Hermes WebUI (Standalone) |
|| /desktop | http://127.0.0.1:6081 | CUA noVNC |
|| /vnc-camofox | http://127.0.0.1:6080 | Camofox VNC |
|| /agent-estate | http://127.0.0.1:8769/agent-estate-role-dashboard.html | Role dashboard |
|| /synergy-prep | http://127.0.0.1:9123/ | Synergy prep |
|| /evening-grid.html | http://127.0.0.1:9099/evening-grid.html | Evening grid |
|| /wiki | http://100.118.5.51:9120 | Agent Estate Wiki (Quartz) |
CT460 Funnel Routes
| Port | Target | Notes |
|---|---|---|
:8443/webhook |
http://127.0.0.1:8085/webhook |
Public webhook Funnel |
CT201 Serve Routes
| Path | Target | Notes |
|---|---|---|
:8443 |
http://localhost:8082 |
Homepage dashboard |
/steel |
http://127.0.0.1:5173 |
Steel Browser UI |
/steel-api |
http://127.0.0.1:3000 |
Steel Browser API (path prefix not stripped — use direct IP for API calls) |
Atomic Restore Script
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh — Rebuilds the complete CT460 route table, including tailnet Serve on :443 and public Funnel on :8443.
tailscale serve reset clears Funnel state as well as Serve state. The atomic script therefore restores /webhook after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery.
Key Commands
# Check routes
tailscale serve status
# Rebuild routes (CT460)
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh
# Add route
tailscale serve --set-path /jobs http://127.0.0.1:9099
# Remove route
tailscale serve --set-path /jobs off
Notes
- Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there
- CT460 has no conflict — Tailscale uses 443 directly
- Routes must be re-added in order (restore script handles this)
- After every rebuild, verify that
tailscale serve statuscontains both the:443Serve routes and the:8443/webhookFunnel route.
Related
- infrastructure/domains-and-tunnels — Full DNS and tunnel inventory
- systems/homepage-dashboard — Homepage on CT201 via Tailscale
- runbooks/job-radar — Dashboard incident and route verification