vpn-only (the ipAllowList middleware pulsenode now uses) checks the connection's source IP, but being on the tailnet doesn't reroute traffic to a normal public DNS hostname through the tunnel - Tailscale only reroutes destinations it actually knows about. pulsenode.pivoine.art had no such record, so it always resolved publicly for everyone, tailnet or not, and Traefik never saw a tailnet-range source IP to allow. Same fix already in place for triggershell.falcon.pivoine.art: an extra_records override served only over MagicDNS, pointing to the VPS's own tailnet IP so tailnet clients' connections actually traverse the tunnel and satisfy the allowlist.
77 lines
1.9 KiB
YAML
77 lines
1.9 KiB
YAML
# Base Headscale config. Host-specific values (server_url, listen addrs) are
|
|
# overridden via HEADSCALE_* environment variables in compose.yml, following
|
|
# headscale's viper env-binding (HEADSCALE_SERVER_URL overrides server_url, etc).
|
|
# Full reference: https://github.com/juanfont/headscale/blob/main/config-example.yaml
|
|
|
|
server_url: https://headscale.example.com
|
|
listen_addr: 0.0.0.0:8080
|
|
metrics_listen_addr: 127.0.0.1:9090
|
|
grpc_listen_addr: 127.0.0.1:50443
|
|
grpc_allow_insecure: false
|
|
|
|
noise:
|
|
private_key_path: /var/lib/headscale/noise_private.key
|
|
|
|
prefixes:
|
|
v4: 100.64.0.0/10
|
|
v6: fd7a:115c:a1e0::/48
|
|
allocation: sequential
|
|
|
|
derp:
|
|
server:
|
|
enabled: false
|
|
urls:
|
|
- https://controlplane.tailscale.com/derpmap/default
|
|
paths: []
|
|
auto_update_enabled: true
|
|
update_frequency: 24h
|
|
|
|
disable_check_updates: false
|
|
|
|
node:
|
|
ephemeral:
|
|
inactivity_timeout: 30m
|
|
|
|
database:
|
|
type: sqlite
|
|
sqlite:
|
|
path: /var/lib/headscale/db.sqlite
|
|
write_ahead_log: true
|
|
|
|
unix_socket: /var/run/headscale/headscale.sock
|
|
unix_socket_permission: "0770"
|
|
|
|
log:
|
|
format: text
|
|
level: info
|
|
|
|
policy:
|
|
mode: file
|
|
path: ""
|
|
|
|
dns:
|
|
magic_dns: true
|
|
base_domain: hs.internal
|
|
nameservers:
|
|
global:
|
|
- 1.1.1.1
|
|
- 1.0.0.1
|
|
search_domains: []
|
|
# Served only to tailnet clients via MagicDNS: overrides these hostnames to
|
|
# resolve to the VPS's own tailscale IP (100.64.0.3) instead of its public
|
|
# one, so VPN-connected clients route straight over the tunnel and satisfy
|
|
# Traefik's vpn-only IP allowlist. Anyone not on the tailnet still gets the
|
|
# normal public DNS record and hits the same allowlist from outside it.
|
|
extra_records:
|
|
- name: "triggershell.falcon.pivoine.art"
|
|
type: "A"
|
|
value: "100.64.0.3"
|
|
- name: "pulsenode.pivoine.art"
|
|
type: "A"
|
|
value: "100.64.0.3"
|
|
|
|
# TLS is terminated by Traefik; headscale itself serves plain HTTP internally.
|
|
tls_letsencrypt_hostname: ""
|
|
tls_cert_path: ""
|
|
tls_key_path: ""
|