Skip to content

feat: retire Tailscale in favor of Cloudflare Tunnel + LAN - #50

Merged
danielroberts20 merged 4 commits into
mainfrom
tailscale-migration
Sep 29, 2026
Merged

danielroberts20 merged 4 commits into
mainfrom
tailscale-migration

Conversation

@danielroberts20

Copy link
Copy Markdown
Owner

Summary

Phase 1 of the Tailscale-removal migration:

  • Retire the monthly tailscale cert renewal cron job and its scp-to-Watchdog companion — nothing verifies against the Tailscale-issued cert anymore (Watchdog's CERT_PATH now points at api.travelnet.dev.crt)
  • Add _RETIRED_PATTERNS so old crontab lines from retired jobs actually get stripped on the next run, instead of lingering forever
  • Retarget api.travelnet.dev.crt scp destination and graceful_reboot.sh's maintenance-mode curl from Watchdog's Tailscale hostname to its LAN IP
  • Retire the Tailscale nginx server block; publish the dashboard port for Cloudflare Tunnel instead

Test plan

  • Confirm cert scp and maintenance-mode callback reach Watchdog over LAN
  • Confirm dashboard is reachable via Cloudflare Tunnel
  • Confirm old Tailscale crontab lines are stripped on next scheduled run

🤖 Generated with Claude Code

danielroberts20 and others added 4 commits September 22, 2026 08:35
…ck to LAN

Retired the monthly `tailscale cert` renewal job and its scp-to-Watchdog
companion together — nothing verifies against the Tailscale-issued cert
anymore (Watchdog's CERT_PATH now points at api.travelnet.dev.crt), so
renewing and distributing it served no purpose. Added _RETIRED_PATTERNS so
the old crontab lines for both actually get stripped on the next run,
rather than staying stuck forever (the existing filter only matched
patterns from *current* jobs).

Retargeted the api.travelnet.dev.crt scp destination, and
graceful_reboot.sh's maintenance-mode curl, from the Watchdog's Tailscale
hostname to its LAN IP (192.168.0.63).

Part of the Tailscale-removal migration, phase 1.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…r Cloudflare Tunnel

Dashboard is now fronted by admin.travelnet.dev via Cloudflare Tunnel +
Access instead of the Tailscale hostname. Removed the
travelnet.tail186ff8.ts.net server block from nginx.conf (its cert had
6 days left and no remaining renewal path, per this morning's watchdog
cron retirement). Published the dashboard container's port to the host
as 127.0.0.1:5000 only, loopback-scoped, so cloudflared can reach it
directly without widening exposure to the LAN.

Verified: old Tailscale hostname no longer serves the Dashboard,
admin.travelnet.dev correctly challenges through Cloudflare Access, and
the untouched api.travelnet.dev / Constellation server blocks still work.

Part of the Tailscale-removal migration, phase 2.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Exposes latest and historical location as randomly-jittered coordinates
(never raw) for Constellation's "how far apart are we" stat. Jitter
distance/bearing is randomised per call so repeated requests can't be
averaged out to recover the real point. History is downsampled using
the existing LOCATION_CHANGE_RADIUS_M movement threshold so genuine
movement survives while dense stationary points collapse.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…oint

feat(public): add fuzzed /public/location endpoint for Constellation
@danielroberts20
danielroberts20 merged commit 420a46d into main Sep 29, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant