feat(traefik,headscale): restrict falcon.pivoine.art to Tailscale mesh only

Add a Traefik IP allowlist so *.falcon.pivoine.art rejects any source
outside the Tailscale/Headscale CIDR ranges, even though DNS still
resolves publicly. Pair it with a headscale MagicDNS override so
tailnet clients resolve the hostname straight to the VPS's tailscale
IP and route correctly.

Requires Docker's userland-proxy disabled on the VPS host
(/etc/docker/daemon.json) so Traefik sees real client source IPs
instead of the docker bridge gateway — done manually, not tracked
in this repo.
This commit is contained in:
2026-08-16 16:51:53 +02:00
parent 184200299d
commit 6e96e33875
2 changed files with 19 additions and 0 deletions
+8
View File
@@ -57,6 +57,14 @@ dns:
- 1.1.1.1 - 1.1.1.1
- 1.0.0.1 - 1.0.0.1
search_domains: [] search_domains: []
# Served only to tailnet clients via MagicDNS: overrides falcon.pivoine.art
# app hostnames to resolve to the VPS's tailscale IP instead of its public
# one, so VPN-connected clients route straight over the tunnel and satisfy
# Traefik's falcon-vpn-only IP allowlist.
extra_records:
- name: "triggershell.falcon.pivoine.art"
type: "A"
value: "100.64.0.3"
# TLS is terminated by Traefik; headscale itself serves plain HTTP internally. # TLS is terminated by Traefik; headscale itself serves plain HTTP internally.
tls_letsencrypt_hostname: "" tls_letsencrypt_hostname: ""
+11
View File
@@ -11,6 +11,15 @@ http:
triggershell-redirect-web-secure: triggershell-redirect-web-secure:
redirectScheme: redirectScheme:
scheme: https scheme: https
# Only let traffic through whose source IP is inside the Tailscale/Headscale
# mesh (100.64.0.0/10, fd7a:115c:a1e0::/48). Public DNS still resolves these
# hostnames, but anyone reaching them over the open internet gets a 403 —
# this range is only reachable by actually being a peer on the tailnet.
falcon-vpn-only:
ipAllowList:
sourceRange:
- "100.64.0.0/10"
- "fd7a:115c:a1e0::/48"
routers: routers:
triggershell-web: triggershell-web:
@@ -18,6 +27,7 @@ http:
entrypoints: entrypoints:
- web - web
middlewares: middlewares:
- falcon-vpn-only
- triggershell-redirect-web-secure - triggershell-redirect-web-secure
service: triggershell service: triggershell
@@ -28,6 +38,7 @@ http:
tls: tls:
certResolver: resolver certResolver: resolver
middlewares: middlewares:
- falcon-vpn-only
- security-headers@file - security-headers@file
service: triggershell service: triggershell