vpn-only (the ipAllowList middleware pulsenode now uses) checks the
connection's source IP, but being on the tailnet doesn't reroute
traffic to a normal public DNS hostname through the tunnel - Tailscale
only reroutes destinations it actually knows about. pulsenode.pivoine.art
had no such record, so it always resolved publicly for everyone,
tailnet or not, and Traefik never saw a tailnet-range source IP to
allow. Same fix already in place for triggershell.falcon.pivoine.art:
an extra_records override served only over MagicDNS, pointing to the
VPS's own tailnet IP so tailnet clients' connections actually traverse
the tunnel and satisfy the allowlist.
Add a Traefik IP allowlist so *.falcon.pivoine.art rejects any source
outside the Tailscale/Headscale CIDR ranges, even though DNS still
resolves publicly. Pair it with a headscale MagicDNS override so
tailnet clients resolve the hostname straight to the VPS's tailscale
IP and route correctly.
Requires Docker's userland-proxy disabled on the VPS host
(/etc/docker/daemon.json) so Traefik sees real client source IPs
instead of the docker bridge gateway — done manually, not tracked
in this repo.