Add a service
Checklist for adding a new HTTP service — preserves the system invariants (overview).
1. Create the guest
- Next free VMID (see inventory) and LAN IP
10.0.1.x. - Default is now manual-first:
pct create/qm create+ per-service bootstrap (+ compose if containers are wanted) — see decisions. Helper-script LXCs are no longer the default for new services; QEMU only when the workload needs a full kernel.
2. DNS
- Technitium zone: add
<name>.«MYDOMAIN»→ A → «CADDY_TAILNET_IP». Update the table in dns.
3. Caddy
- Add a site block to
/etc/caddy/Caddyfileon LXC 100:
<name>.«MYDOMAIN» {
reverse_proxy 10.0.1.<x>:<port>
tls {
dns cloudflare {env.CLOUDFLARE_API_TOKEN}
resolvers 1.1.1.1
propagation_timeout 10m
}
}
-
systemctl reload caddy(or restart). First request triggers the DNS-01 cert — allow a few minutes for propagation. - Refresh the snapshot in caddyfile.
4. Auth (optional)
- If it supports OIDC: register a client in Pocket-ID (backed by lldap).
5. Storage (optional)
- Needs bulk data? Mount the Storage Box — mechanism per guest type in storage.
6. Non-HTTP needs (rare)
- If the service needs direct non-HTTP access (SSH etc.), join the guest to the tailnet — do NOT enable subnet routing (decisions).