fixig ailscaled routes

This commit is contained in:
juvdiaz 2026-07-02 13:04:11 -06:00
parent 7f851ccfa2
commit 6cf5abe8bd
4 changed files with 58 additions and 2 deletions

View File

@ -86,7 +86,7 @@ server {
limit_req zone=one burst=20 nodelay;
client_max_body_size 512m;
proxy_pass http://${gitea_backend_host}:${gitea_backend_port};
proxy_pass http://${gitea_backend_host}:${gitea_backend_port}/;
proxy_http_version 1.1;
proxy_request_buffering off;
proxy_read_timeout 300s;

View File

@ -594,6 +594,15 @@ Raspberry Pi when Docker is missing. Default is to fail.
: Allow the edge OpenTofu stack to install Docker on the OCI host when Docker is
missing. Default is to fail.
`LAB_EDGE_CONFIGURE_TAILSCALE_ROUTES`
: Configure the Raspberry Pi as the Tailscale subnet-route advertiser and set
the OCI edge host to accept routes before applying the edge stack. Defaults to
`true`.
`LAB_EDGE_TAILSCALE_SUBNET_ROUTE`
: Subnet route advertised by the Raspberry Pi for edge-to-LAN app traffic.
Defaults to `LAB_LAN_CIDR`, normally `192.168.100.0/24`.
`TF_VAR_haproxy_stats_password`
: HAProxy stats password for the edge stack. If unset, Jeannie loads it from
`LAB_EDGE_HAPROXY_STATS_CREDENTIALS_FILE`, recovers it from the live edge host's

View File

@ -72,7 +72,7 @@ OCI cannot reach `192.168.100.240:80`:
Refresh the edge stack from the repo:
```bash
tofu -chdir=bootstrap/edge apply
./jeannie edge
```
Restart edge containers only:

47
jeannie
View File

@ -482,6 +482,7 @@ run_tofu_stack() {
ensure_cluster_worker_var_file
fi
if [[ "${stack}" == "bootstrap/edge" ]]; then
ensure_edge_tailscale_routes
ensure_edge_haproxy_stats_password
fi
@ -4928,6 +4929,52 @@ edge_haproxy_stats_password_valid() {
[[ -n "${password}" ]] && ((${#password} >= 12)) && [[ "${password}" != "adminpassword" ]]
}
ensure_edge_tailscale_routes() {
local enabled="${LAB_EDGE_CONFIGURE_TAILSCALE_ROUTES:-true}"
local route="${LAB_EDGE_TAILSCALE_SUBNET_ROUTE:-${LAB_LAN_CIDR:-192.168.100.0/24}}"
local rpi_host="${LAB_RPI_HOST:-${LAB_RASPBERRY_HOST:-192.168.100.89}}"
local rpi_user="${LAB_RPI_USER:-${LAB_RASPBERRY_USER:-jv}}"
local rpi_key="${LAB_RPI_SSH_KEY_PATH:-${LAB_RASPBERRY_SSH_KEY_PATH:-/home/jv/.ssh/id_ed25519}}"
local edge_host="${TF_VAR_edge_host:-${LAB_EDGE_HOST:-}}"
local edge_user="${TF_VAR_edge_user:-${LAB_EDGE_USER:-ubuntu}}"
local edge_key="${TF_VAR_edge_ssh_key_path:-${LAB_EDGE_SSH_KEY_PATH:-/home/jv/.ssh/id_ed25519}}"
if disabled_value "${enabled}"; then
return 0
fi
if ! truthy "${enabled}"; then
echo "LAB_EDGE_CONFIGURE_TAILSCALE_ROUTES must be true or false." >&2
exit 1
fi
if ! validate_ipv4_cidr_or_host "${route}"; then
echo "Invalid LAB_EDGE_TAILSCALE_SUBNET_ROUTE '${route}'." >&2
exit 1
fi
if [[ -z "${edge_host}" ]]; then
echo "LAB_EDGE_HOST or TF_VAR_edge_host is required to configure edge Tailscale routes." >&2
exit 1
fi
echo "Ensuring RPi advertises ${route} and OCI edge accepts Tailscale routes..."
ssh -i "${rpi_key}" -o BatchMode=yes -o ConnectTimeout=10 -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new "${rpi_user}@${rpi_host}" "set -eu
if ! command -v tailscale >/dev/null 2>&1; then
echo 'tailscale is not installed on the RPi subnet router.' >&2
exit 1
fi
sudo mkdir -p /etc/sysctl.d
printf '%s\n' 'net.ipv4.ip_forward = 1' | sudo tee /etc/sysctl.d/99-homelab-tailscale-subnet-router.conf >/dev/null
sudo sysctl -w net.ipv4.ip_forward=1 >/dev/null
sudo tailscale set --advertise-routes='${route}'
"
ssh -i "${edge_key}" -o BatchMode=yes -o ConnectTimeout=10 -o IdentitiesOnly=yes -o StrictHostKeyChecking=accept-new "${edge_user}@${edge_host}" "set -eu
if ! command -v tailscale >/dev/null 2>&1; then
echo 'tailscale is not installed on the OCI edge host.' >&2
exit 1
fi
sudo tailscale set --accept-routes=true
"
}
edge_haproxy_stats_credentials_file() {
printf '%s\n' "${LAB_EDGE_HAPROXY_STATS_CREDENTIALS_FILE:-${HOME}/.config/homelab/edge-haproxy.env}"
}