Files
agent-estate-wiki/infrastructure/tailscale.md
T

73 lines
2.5 KiB
Markdown

---
title: Tailscale
type: infrastructure
status: active
created: 2026-07-26
updated: 2026-07-27
verified_on: 2026-07-27
confidence: high
tags: [tailscale, vpn, networking, infrastructure]
---
# Tailscale
## Purpose
WireGuard-based mesh VPN connecting all homelab hosts and providing HTTPS access via Tailscale Serve.
## Domain
- **Tailnet:** `kangaroo-eel.ts.net`
- **Primary node:** CT460 (`hermes.kangaroo-eel.ts.net`)
- **Runtipi node:** CT201 (`runtipi.kangaroo-eel.ts.net`)
## CT460 Serve Routes
| Path | Target | Notes |
|---|---|---|
| `/` | `http://127.0.0.1:9119` | Hermes WebUI |
| `/jobs` | `http://127.0.0.1:9099` | Jobs Dashboard |
| `/desktop` | `http://127.0.0.1:6081` | CUA noVNC |
| `/vnc-camofox` | `http://127.0.0.1:6080` | Camofox VNC |
## CT460 Funnel Routes
| Port | Target | Notes |
|---|---|---|
| `:8443/webhook` | `http://127.0.0.1:8085/webhook` | Public webhook Funnel |
## CT201 Serve Routes
| Path | Target | Notes |
|---|---|---|
| `:8443` | `http://localhost:8082` | Homepage dashboard |
| `/steel` | `http://127.0.0.1:5173` | Steel Browser UI |
| `/steel-api` | `http://127.0.0.1:3000` | Steel Browser API (path prefix not stripped — use direct IP for API calls) |
## Atomic Restore Script
`/home/hermes/.hermes/scripts/tailscale-serve-apply.sh` — Rebuilds the complete CT460 route table, including tailnet Serve on `:443` and public Funnel on `:8443`.
`tailscale serve reset` clears Funnel state as well as Serve state. The atomic script therefore restores `/webhook` after rebuilding the 443 routes. Do not use the older Serve-only restore path for complete recovery.
## Key Commands
```bash
# Check routes
tailscale serve status
# Rebuild routes (CT460)
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh --dry-run
/home/hermes/.hermes/scripts/tailscale-serve-apply.sh
# Add route
tailscale serve --set-path /jobs http://127.0.0.1:9099
# Remove route
tailscale serve --set-path /jobs off
```
## Notes
- Port 443 occupied by Traefik on CT201 — Tailscale uses port 8443 there
- CT460 has no conflict — Tailscale uses 443 directly
- Routes must be re-added in order (restore script handles this)
- After every rebuild, verify that `tailscale serve status` contains both the `:443` Serve routes and the `:8443/webhook` Funnel route.
## Related
- [[infrastructure/domains-and-tunnels]] — Full DNS and tunnel inventory
- [[systems/homepage-dashboard]] — Homepage on CT201 via Tailscale
- [[runbooks/job-radar]] — Dashboard incident and route verification