Files
agent-estate-wiki/infrastructure/tailscale.md
T
Tony0410 20a3164dca maintain: general wiki freshness mechanism + restore tailscale routes page
Replace the skills-only regeneration script with a general wiki-maintain.sh that:
- regenerates skills-index from live skill tree (330 skills / 26 categories)
- audits EVERY page for staleness vs its updated date (>21d flagged)
- rebuilds + redeploys the Quartz site
- writes a dated freshness report to raw/stocktake/

Also fix the tailscale.md page (it had drifted to only 4 routes; reality now has
11 CT460 routes incl /webui, /agent-estate, /synergy-prep, /evening-grid, /wiki
and the /wiki proxy was also missing from the atomic apply script — added there).

Cron wiki-stocktake-maintenance (1a8e90ea2271) now runs this daily 03:00 and
commits+pushes so the wiki cannot silently drift again.
2026-08-16 00:16:48 +08:00

79 lines
2.9 KiB
Markdown

---
title: Tailscale
type: infrastructure
status: active
created: 2026-07-26
updated: 2026-08-16
verified_on: 2026-08-16
confidence: high
tags: [tailscale, vpn, networking, infrastructure]
---
# Tailscale
## Purpose
WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve.
## Domain
- **Tailnet:** `kangaroo-eel.ts.net`
- **Primary node:** CT460 (`hermes.kangaroo-eel.ts.net`)
- **Runtipi node:** CT201 (`runtipi.kangaroo-eel.ts.net`)
## CT460 Serve Routes
|| Path | Target | Notes |
||---|---|---|---|
|| `/` | `http://127.0.0.1:9119` | Hermes WebUI |
|| `/ui` | `http://127.0.0.1:5175/` | Hermes UI (Vite) |
|| `/jobs` | `http://127.0.0.1:9099` | Jobs Dashboard |
|| `/webui` | `http://127.0.0.1:8787/` | Hermes WebUI (Standalone) |
|| `/desktop` | `http://127.0.0.1:6081` | CUA noVNC |
|| `/vnc-camofox` | `http://127.0.0.1:6080` | Camofox VNC |
|| `/agent-estate` | `http://127.0.0.1:8769/agent-estate-role-dashboard.html` | Role dashboard |
|| `/synergy-prep` | `http://127.0.0.1:9123/` | Synergy prep |
|| `/evening-grid.html` | `http://127.0.0.1:9099/evening-grid.html` | Evening grid |
|| `/wiki` | `http://100.118.5.51:9120` | Agent Estate Wiki (Quartz) |
## CT460 Funnel Routes
| Port | Target | Notes |
|---|---|---|
| `:8443/webhook` | `http://127.0.0.1:8085/webhook` | Public webhook Funnel |
## CT201 Serve Routes
| Path | Target | Notes |
|---|---|---|
| `:8443` | `http://localhost:8082` | Homepage dashboard |
| `/steel` | `http://127.0.0.1:5173` | Steel Browser UI |
| `/steel-api` | `http://127.0.0.1:3000` | Steel Browser API (path prefix not stripped — use direct IP for API calls) |
## Atomic Restore Script
`/home/hermes/.hermes/scripts/tailscale-serve-apply.sh` — Rebuilds the complete CT460 route table, including tailnet Serve on `:443` and public Funnel on `:8443`.
`tailscale serve reset` clears Funnel state as well as Serve state. The atomic script therefore restores `/webhook` after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery.
## Key Commands
```bash
# Check routes
tailscale serve status
# Rebuild routes (CT460)
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh
# Add route
tailscale serve --set-path /jobs http://127.0.0.1:9099
# Remove route
tailscale serve --set-path /jobs off
```
## Notes
- Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there
- CT460 has no conflict — Tailscale uses 443 directly
- Routes must be re-added in order (restore script handles this)
- After every rebuild, verify that `tailscale serve status` contains both the `:443` Serve routes and the `:8443/webhook` Funnel route.
## Related
- [[infrastructure/domains-and-tunnels]] — Full DNS and tunnel inventory
- [[systems/homepage-dashboard]] — Homepage on CT201 via Tailscale
- [[runbooks/job-radar]] — Dashboard incident and route verification