Files
stacks/headscale/config.yaml
T
valknar bed01b4fdf streamline traefik dashboard routing: docker labels instead of file provider
Switches traefik.pivoine.art routing from a standalone file-provider
router (dynamic/dashboard.yaml) to docker-compose labels on traefik's
own service - the same pattern every other stack already uses for its
own routing, rather than a one-off exception. Traefik discovers itself
just like any other container on falcon_network. Both routers point
at the built-in api@internal service via .service= instead of a
loadbalancer target, since there's no backend container port to route
to. Also dropped the (PathPrefix(`/api`) || PathPrefix(`/dashboard`))
condition - the whole traefik.pivoine.art host is dedicated to this,
so a bare Host() match is simpler and no less correct.

Also fixes why VPN access still failed: traefik.pivoine.art was never
added to Headscale's MagicDNS extra_records, so even a tailnet-
connected browser resolved it via public DNS and hit vpn-only from a
non-tailnet source IP - same root cause as the earlier
pulsenode.pivoine.art fix, just missed for this hostname.
2026-08-17 19:05:08 +02:00

80 lines
2.0 KiB
YAML

# Base Headscale config. Host-specific values (server_url, listen addrs) are
# overridden via HEADSCALE_* environment variables in compose.yml, following
# headscale's viper env-binding (HEADSCALE_SERVER_URL overrides server_url, etc).
# Full reference: https://github.com/juanfont/headscale/blob/main/config-example.yaml
server_url: https://headscale.example.com
listen_addr: 0.0.0.0:8080
metrics_listen_addr: 127.0.0.1:9090
grpc_listen_addr: 127.0.0.1:50443
grpc_allow_insecure: false
noise:
private_key_path: /var/lib/headscale/noise_private.key
prefixes:
v4: 100.64.0.0/10
v6: fd7a:115c:a1e0::/48
allocation: sequential
derp:
server:
enabled: false
urls:
- https://controlplane.tailscale.com/derpmap/default
paths: []
auto_update_enabled: true
update_frequency: 24h
disable_check_updates: false
node:
ephemeral:
inactivity_timeout: 30m
database:
type: sqlite
sqlite:
path: /var/lib/headscale/db.sqlite
write_ahead_log: true
unix_socket: /var/run/headscale/headscale.sock
unix_socket_permission: "0770"
log:
format: text
level: info
policy:
mode: file
path: ""
dns:
magic_dns: true
base_domain: hs.internal
nameservers:
global:
- 1.1.1.1
- 1.0.0.1
search_domains: []
# Served only to tailnet clients via MagicDNS: overrides these hostnames to
# resolve to the VPS's own tailscale IP (100.64.0.3) instead of its public
# one, so VPN-connected clients route straight over the tunnel and satisfy
# Traefik's vpn-only IP allowlist. Anyone not on the tailnet still gets the
# normal public DNS record and hits the same allowlist from outside it.
extra_records:
- name: "triggershell.falcon.pivoine.art"
type: "A"
value: "100.64.0.3"
- name: "pulsenode.pivoine.art"
type: "A"
value: "100.64.0.3"
- name: "traefik.pivoine.art"
type: "A"
value: "100.64.0.3"
# TLS is terminated by Traefik; headscale itself serves plain HTTP internally.
tls_letsencrypt_hostname: ""
tls_cert_path: ""
tls_key_path: ""