neptun: add Headscale + Headplane

Headscale is the tailnet control server every host's services/tailscale.nix
already points at (--login-server=https://vpn.mgaction.town). MagicDNS
base_domain "hosts.mgaction.town" matches the "jupiter.hosts.mgaction.town"
names already used in this repo's Caddy vhosts.

Headplane is its web UI, running as headscale's own user (native process
integration, no container). No OIDC wired up - log in with a headscale API
key generated on the box. Both proxied through Caddy; headscale's vhost
needs flush_interval -1 since its node-update endpoint is a long-poll.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-19 22:36:40 +02:00
co-authored by Claude Sonnet 5
parent ced2b56764
commit 5507dfac0a
5 changed files with 69 additions and 2 deletions
+20
View File
@@ -0,0 +1,20 @@
{ config, ... }:
# Headplane — web UI for headscale (services/headscale.nix; must be enabled
# first). Runs as headscale's own OS user via "native process integration",
# so it can restart headscale when settings change from the UI.
#
# No OIDC wired up — log in with a headscale API key instead
# (`headscale apikeys create` on the box, pasted into the Headplane login
# page). headscale.url/config_path/public_url all default correctly off of
# services.headscale's own options, so nothing to repeat here.
{
services.headplane = {
enable = true;
settings.server = {
cookie_secret_path = config.sops.secrets.headplane_cookie_secret.path;
cookie_secure = true; # served over HTTPS via Caddy
base_url = "https://headplane.mgaction.town";
};
};
}
+28
View File
@@ -0,0 +1,28 @@
{ ... }:
# Headscale — self-hosted control server for the tailnet. Every host's
# services/tailscale.nix points --login-server at https://vpn.mgaction.town
# (this host). MagicDNS base_domain "hosts.mgaction.town" matches the
# "jupiter.hosts.mgaction.town" style names already used throughout this
# repo's Caddy vhosts (e.g. hosts/neptun/configuration.nix) — don't change
# one without the other.
#
# TLS terminates at Caddy (see the host's configuration.nix for the vhost,
# proxying with `flush_interval -1` since headscale's node-update endpoint
# is a long-poll and needs unbuffered responses); headscale itself only
# listens on localhost.
{
services.headscale = {
enable = true;
port = 8082; # zitadel already sits on the usual 8080 on this host
settings = {
server_url = "https://vpn.mgaction.town";
dns = {
base_domain = "hosts.mgaction.town";
nameservers.global = [ "1.1.1.1" "9.9.9.9" ];
};
};
};
}