mcp: session-notes — Tailscale .ts.net path-based routing — petal-dispatch over tailnet
This commit is contained in:
parent
09745b33bd
commit
d575bc5ba4
@ -0,0 +1,54 @@
|
|||||||
|
---
|
||||||
|
created: '2026-06-07'
|
||||||
|
path: Sources/Homelab
|
||||||
|
project: traefik-deployment
|
||||||
|
tags:
|
||||||
|
- tailscale
|
||||||
|
- traefik
|
||||||
|
- tls
|
||||||
|
- dispatch
|
||||||
|
- dns
|
||||||
|
type: session-notes
|
||||||
|
---
|
||||||
|
|
||||||
|
Addendum to `2026-06-07-tailscale-tsnet-traefik-access` — extending remote tailnet access from the Traefik dashboard to actual services (petal-dispatch).
|
||||||
|
|
||||||
|
## Outcome
|
||||||
|
|
||||||
|
petal-dispatch is now reachable remotely at `https://traefik.taila7f44e.ts.net/dispatch/` (path-based, reusing the single `.ts.net` box cert). Same `petal-dispatch` service backend as the LAN `dispatch.herbylab.dev` route — just a second router.
|
||||||
|
|
||||||
|
## Key Learnings
|
||||||
|
|
||||||
|
- **Tailscale issues certs only for actual node names.** `tailscale cert dispatch.taila7f44e.ts.net` fails: `invalid domain ...; must be one of ["traefik.taila7f44e.ts.net"]`. Per-service `.ts.net` hostnames are not possible without a node per service. All remote services must therefore share the one box cert and be distinguished by path, not subdomain.
|
||||||
|
- **Path-based routing on the shared cert is the pattern.** Add a router with `Host(`traefik.taila7f44e.ts.net`) && PathPrefix(`/<svc>`)` + a `stripPrefix` middleware, pointing at the existing service. No new cert, no new service block.
|
||||||
|
- **Duplicate top-level `http:` keys in one dynamic YAML file fail silently.** Appending a second `http:` block (rather than nesting routers under the existing one) means the last block wins and the earlier routers vanish — no parse error. Everything must live under a single `http:` key. This briefly clobbered the dashboard router too.
|
||||||
|
- **Subpath asset caveat (open):** path-based routing means the app runs under `/dispatch`, not root. If the web client builds asset URLs from `/`, the page loads but CSS/JS 404. Needs a base-href fix in the petal-dispatch web client.
|
||||||
|
|
||||||
|
## Config landed
|
||||||
|
|
||||||
|
`/opt/traefik/dynamic/tailscale.yml` — single `http:` block, both routers + stripPrefix middleware:
|
||||||
|
```yaml
|
||||||
|
http:
|
||||||
|
routers:
|
||||||
|
tailscale-dashboard:
|
||||||
|
rule: "Host(`traefik.taila7f44e.ts.net`)"
|
||||||
|
service: api@internal
|
||||||
|
tls: {}
|
||||||
|
entryPoints: [websecure]
|
||||||
|
tailscale-dispatch:
|
||||||
|
rule: "Host(`traefik.taila7f44e.ts.net`) && PathPrefix(`/dispatch`)"
|
||||||
|
service: petal-dispatch
|
||||||
|
middlewares: [dispatch-stripprefix]
|
||||||
|
tls: {}
|
||||||
|
entryPoints: [websecure]
|
||||||
|
middlewares:
|
||||||
|
dispatch-stripprefix:
|
||||||
|
stripPrefix:
|
||||||
|
prefixes: ["/dispatch"]
|
||||||
|
```
|
||||||
|
|
||||||
|
## Follow-ons
|
||||||
|
|
||||||
|
- [ ] Verify petal-dispatch renders correctly under `/dispatch` subpath — check browser console for asset 404s; set base-href in web client if needed.
|
||||||
|
- [ ] Add path-based routers for any other services wanted remotely (same pattern, append router under the single `http:` block).
|
||||||
|
- [ ] Carries forward from the parent note: static `.ts.net` cert renewal (no auto-renew), and the tailnet Global Nameserver decision.
|
||||||
Loading…
Reference in New Issue
Block a user