headscale: move the tailnet to orbit.sol, route all DNS through pihole
Three connected changes, all triggered by the same outage. base_domain leaves mgaction.town. That zone has a wildcard A+AAAA pointing at neptun, and DNS wildcards match multi-label names, so jupiter.hosts.mgaction.town resolved publicly to NEPTUN and Caddy proxied to itself -- a silent loop rather than a lookup failure. Nesting the tailnet inside the LAN domain as orbit.sol keeps the theme and resolves unambiguously, since tailscale matches routes by longest suffix. override_local_dns = true with pihole as the only global nameserver, so roaming devices get ad blocking and .sol names off-LAN. With it false, globalResolvers land in the netmap's FallbackResolvers, which a phone with carrier DNS never consults. No public fallback is listed on purpose: tailscale treats the list as a set, so a second entry would let queries slip past the filter whenever mercury is slow. The cost is that mercury is now a single point of failure for tailnet DNS. neptun and mercury opt out individually. mercury would otherwise resolve through itself. neptun must not depend on a Pi behind a domestic line to renew the certificates for the control server every other node needs -- and it is circular besides, since tailscaled has to resolve vpn.mgaction.town to connect at all. Instead neptun runs a dnsmasq stub forwarding just orbit.sol to MagicDNS on 100.100.100.100, which tailscaled answers whenever it is running regardless of --accept-dns. That resolves jupiter live, so the hardcoded /etc/hosts pin is gone. Also sets dns.nameservers.split explicitly: nixpkgs renders its own dns.split option one level too high, but headscale reads dns.nameservers.split (hscontrol/types/config.go:722) and so does headplane, whose DNS page dies on the missing key with "Cannot convert undefined or null to object". The module's option is dead as written. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
+51
-14
@@ -2,9 +2,10 @@
|
||||
|
||||
# Headscale — self-hosted control server for the tailnet. Every host's
|
||||
# services/vpn/tailscale.nix points --login-server at https://vpn.mgaction.town
|
||||
# (this host). MagicDNS base_domain "hosts.mgaction.town" matches the
|
||||
# "jupiter.hosts.mgaction.town" names used in this repo's Caddy vhosts
|
||||
# (e.g. hosts/neptun/configuration.nix) — don't change one without the other.
|
||||
# (this host). MagicDNS base_domain "orbit.sol" matches the
|
||||
# "jupiter.orbit.sol" names used in this repo's Caddy vhosts
|
||||
# (hosts/neptun/configuration.nix) — changing base_domain means changing
|
||||
# those too, and re-pointing neptun's dnsmasq stub at the new suffix.
|
||||
#
|
||||
# TLS terminates at Caddy (see the host's configuration.nix); headscale
|
||||
# itself only listens on localhost.
|
||||
@@ -17,18 +18,54 @@
|
||||
server_url = "https://vpn.mgaction.town";
|
||||
|
||||
dns = {
|
||||
base_domain = "hosts.mgaction.town";
|
||||
nameservers.global = [ "1.1.1.1" "9.9.9.9" ];
|
||||
# Deliberately OUTSIDE mgaction.town. That zone has a wildcard A+AAAA
|
||||
# pointing at neptun, and DNS wildcards match multi-label names — so
|
||||
# with base_domain = hosts.mgaction.town, `jupiter.hosts.mgaction.town`
|
||||
# resolved publicly to NEPTUN and Caddy proxied to itself: a silent
|
||||
# loop rather than a lookup failure.
|
||||
#
|
||||
# `.sol` is the LAN domain pihole serves, so this nests the tailnet
|
||||
# inside it: planets sit on the LAN as jupiter.sol, and reach each
|
||||
# other in orbit as jupiter.orbit.sol. Resolution is unambiguous
|
||||
# because tailscale matches routes by LONGEST suffix, so orbit.sol
|
||||
# goes to MagicDNS even when everything else funnels to pihole.
|
||||
#
|
||||
# Never give a LAN host the name `orbit`: pihole's
|
||||
# `address=/<host>.sol/<ip>` lines match a name AND everything under
|
||||
# it, so an `orbit` host would swallow this entire zone.
|
||||
base_domain = "orbit.sol";
|
||||
# pihole on mercury, over the tailnet — so every roaming device gets
|
||||
# ad blocking and .sol names wherever it is, not just on the LAN.
|
||||
# Deliberately NO public fallback: tailscale treats the list as a set,
|
||||
# so adding 9.9.9.9 here would let queries slip past the filter
|
||||
# whenever mercury is briefly slow. Strict blocking, at the cost of
|
||||
# mercury being a single point of failure for tailnet DNS.
|
||||
#
|
||||
# ⚠️ A hardcoded tailnet address, so it changes if mercury re-enrols
|
||||
# — check `headscale nodes list` if DNS dies tailnet-wide.
|
||||
nameservers.global = [ "100.64.0.7" ];
|
||||
|
||||
# Leave each client's own resolvers alone; only route base_domain to
|
||||
# MagicDNS. Upstream defaults this to true, which replaces resolv.conf
|
||||
# with 100.100.100.100 on every node — that silently breaks the LAN's
|
||||
# `.sol` names (pihole on mercury serves those, and the global
|
||||
# nameservers above return NXDOMAIN for them) and takes ad blocking
|
||||
# with it. It also makes a node's entire DNS depend on tailscaled
|
||||
# being up, which is what forced --accept-dns=false onto neptun and
|
||||
# mercury individually.
|
||||
override_local_dns = false;
|
||||
# Must be set, and must be HERE rather than via the module's
|
||||
# `dns.split` option. nixpkgs renders that option one level too high
|
||||
# (a sibling of `nameservers:`), but headscale reads
|
||||
# dns.nameservers.split (hscontrol/types/config.go:722) and so does
|
||||
# headplane. So the module's option is dead, and the missing key makes
|
||||
# headplane's DNS page die with
|
||||
# TypeError: Cannot convert undefined or null to object
|
||||
# from Object.keys(config.dns.nameservers.split).
|
||||
nameservers.split = { };
|
||||
|
||||
# Point every node's resolver at MagicDNS, which forwards on to the
|
||||
# global nameserver above. That is the only way to get pihole onto a
|
||||
# roaming device: with this false, globalResolvers land in the
|
||||
# netmap's FallbackResolvers (hscontrol/types/config.go:826-830) and a
|
||||
# phone with carrier DNS never consults them.
|
||||
#
|
||||
# The cost is that every node's DNS now depends on mercury and on the
|
||||
# home connection, so mercury going down costs name resolution
|
||||
# everywhere, not just `.sol`. neptun and mercury opt out of this
|
||||
# individually with --accept-dns=false — see their configuration.nix.
|
||||
override_local_dns = true;
|
||||
};
|
||||
|
||||
# Authentik as the login provider, so `tailscale up --login-server ...`
|
||||
|
||||
Reference in New Issue
Block a user