Tailscale

Tailscale is the only access path into the system — for management, HTTP services, git-over-SSH, and DNS.

Tailnet membership (deliberately minimal)

MachineWhy joined
«HOSTNAME» (PVE host)Management: Proxmox UI + SSH, never via public IP
caddy (LXC 100)Service ingress — all HTTP services proxy through it
technitiumdns (LXC 101)Split-horizon DNS target for «MYDOMAIN»
gitea (LXC 104)git-over-SSH (Caddy only proxies HTTP)

Everything else stays off the tailnet and is reached through caddy’s internal proxying.

Policy

  • Join a machine only when it must be reached directly — e.g. a non-HTTP protocol like SSH. HTTP services never get joined.
  • No subnet routing. Don’t advertise 10.0.1.0/24; join specific machines instead. (Subnet routing was the alternative for gitea SSH — rejected in favor of joining the gitea container itself. See decisions.)

Machine-specific notes

  • On caddy: tailscale set --accept-dns=false — required so Caddy can resolve public DNS for the ACME DNS-01 challenges.
  • gitea uses its own embedded SSH server on port 22; the tailnet name gitea.«TAILNET_DOMAIN» is the SSH host in git remotes (see gitea).

Sharing with other users

Other users get their own Tailscale accounts; the caddy and technitiumdns devices are shared into their tailnets, and they set up Split DNS on their side. Full detail in dns.