3 ms·
I've been using it too and it works well, particularly with Caddy to do automatic certificates with ACME where possible Plus all my services go through Tailsca
by mojzu 5y ago
I've been using it too and it works well, particularly with Caddy to do automatic certificates with ACME where possible
Plus all my services go through Tailscale, so although I am leaking internal hostnames via DNS, all those records point to is 100.* addresses
- chrisweekly 5y agoI'm a fan of both Caddy and Tailscale; any chance you have any devnotes to share on your setup?
- mojzu 5y agoMy notes were pretty rough but I've tried putting them into a gist here: https://gist.github.com/mojzu/b093d79e73e7aa302dde8e335945b2cd https://gist.github.com/mojzu/b093d79e73e7aa302dde8e335945b2... Which covers using step-ca with Caddy to get TLS certs via ACME for subdomains, and protecting internal services using client certificates/mtls I then install Tailscale on the host which is running the docker containers, and configure the firewall so that only other 100.* IP addresses can connect to ports 80/443/444. The combination of VPN+MTLS mitigates most of my worries about exposing internal subdomains on public DNS
- chrisweekly 5y agoAwesome, thanks!
- Proven 5y ago
- dolmen 5y agoTailscale+TLS: isn't it two strong layers of encryption?
- mojzu 5y agoYeah, it's probably overkill but I think the multiple layers would help in cases I misconfigured something or if an account someone uses to log into Tailscale was compromised. For example when I ran the containers on a linux host I discovered later docker was bypassing the firewall rules and allowing all connections, but it probably wasn't a big deal because of the MTLS (and the server was behind a NAT router anyway so it was only addressable within the local network)