feat(traefik): route *.falcon.pivoine.art to apps on falcon over Tailscale

Falcon (home machine) stays off the public internet; the VPS Traefik
terminates TLS/ACME as usual and forwards to falcon's tailnet IP.
This commit is contained in:
2026-08-16 16:32:21 +02:00
parent 4951492f4c
commit 184200299d
+38
View File
@@ -0,0 +1,38 @@
# Routes for apps running on the local machine "falcon", reached over the
# Tailscale/Headscale mesh (falcon's tailnet IP: 100.64.0.1). DNS for
# *.falcon.pivoine.art points here (the VPS), which terminates TLS and
# forwards over the tunnel — falcon itself is never exposed directly.
#
# To add another app: duplicate the <name>-web / <name>-web-secure routers
# and the service block below, swap the hostname and backend port.
http:
middlewares:
triggershell-redirect-web-secure:
redirectScheme:
scheme: https
routers:
triggershell-web:
rule: "Host(`triggershell.falcon.pivoine.art`)"
entrypoints:
- web
middlewares:
- triggershell-redirect-web-secure
service: triggershell
triggershell-web-secure:
rule: "Host(`triggershell.falcon.pivoine.art`)"
entrypoints:
- web-secure
tls:
certResolver: resolver
middlewares:
- security-headers@file
service: triggershell
services:
triggershell:
loadBalancer:
servers:
- url: "http://100.64.0.1:4173"