Tailscale
Tailscale is the only access path into the system — for management, HTTP services, git-over-SSH, and DNS.
Tailnet membership (deliberately minimal)
| Machine | Why joined |
|---|---|
| «HOSTNAME» (PVE host) | Management: Proxmox UI + SSH, never via public IP |
caddy (LXC 100) | Service ingress — all HTTP services proxy through it |
technitiumdns (LXC 101) | Split-horizon DNS target for «MYDOMAIN» |
gitea (LXC 104) | git-over-SSH (Caddy only proxies HTTP) |
Everything else stays off the tailnet and is reached through caddy’s internal proxying.
Policy
- Join a machine only when it must be reached directly — e.g. a non-HTTP protocol like SSH. HTTP services never get joined.
- No subnet routing. Don’t advertise
10.0.1.0/24; join specific machines instead. (Subnet routing was the alternative for gitea SSH — rejected in favor of joining the gitea container itself. See decisions.)
Machine-specific notes
- On
caddy:tailscale set --accept-dns=false— required so Caddy can resolve public DNS for the ACME DNS-01 challenges. giteauses its own embedded SSH server on port 22; the tailnet namegitea.«TAILNET_DOMAIN»is the SSH host in git remotes (see gitea).
Sharing with other users
Other users get their own Tailscale accounts; the caddy and
technitiumdns devices are shared into their tailnets, and they set up
Split DNS on their side. Full detail in dns.