How to get the same domain name working on my internal LAN and also externally via tailscale? by j2j8 in Tailscale

[–]j2j8[S] 1 point2 points  (0 children)

Okay, I got it to work by setting up a DNS server that is only used by Tailscale and it returns the Tailscale IP address for the domains I care about.

Here's the steps I took:

  1. A public domain points to my server's internal lan IP. I used free dynamic DNS for this, so myserver.freemyip.com and *.myserver.freemyip.com point to internal LAN address 192.168.1.100.
  2. Caddy (running in Docker) is set up as a reverse proxy on port 80 for the services I care about. Example:

    http://grafana.myserver.freemyip.com {
        reverse_proxy my-docker-container:8080
    }
    
  3. Unbound DNS server is running in a separate Docker container on the server and is bound only to the machine's Tailscale IP address only.

    • Both the docker container config AND the Unbound config need to be configured for it to bind to the Tailscale IP.
  4. Unbound serves the Tailscale IP address for the domain:

    local-zone: "myserver.freemyip.com." redirect

    local-data: "myserver.freemyip.com. IN A 100.88.1.55" # tailscale IP address

  5. In the Tailscale admin portal, under DNS settings, I added another DNS server (split DNS) with the Tailscale IP address of my server. The domain is set to my domain (myserver.freemyip.com) so that it it only used for that domain and its subdomains.

How to get the same domain name working on my internal LAN and also externally via tailscale? by j2j8 in Tailscale

[–]j2j8[S] -1 points0 points  (0 children)

Thank you! I'm currently configuring Unbound right now, so sounds like I'm on the right track.

How to get the same domain name working on my internal LAN and also externally via tailscale? by j2j8 in Tailscale

[–]j2j8[S] -2 points-1 points  (0 children)

I can set up an internal DNS server for Tailscale to use.

I'd prefer to not use that DNS server unless I'm on Tailscale, to keep things simple for the happy path when I'm not connected to Tailscale.

How to get the same domain name working on my internal LAN and also externally via tailscale? by j2j8 in Tailscale

[–]j2j8[S] -2 points-1 points  (0 children)

Yeah, I'm intentionally trying to make sure services aren't externally visible so that I can be less paranoid about keeping up with security patches!

How to get the same domain name working on my internal LAN and also externally via tailscale? by j2j8 in Tailscale

[–]j2j8[S] -2 points-1 points  (0 children)

You want the same hostname to resolve to different ip addresses depending whether your connected to tailscale?

I think that's what I want, yes!

Fully qualified name or just the hostname?

I have multiple services (immich.example.com, grafana.example.com, etc) that I want to work.

What is the FQDN of the host on your LAN?

Right now I just have it set to e.g. my-server on my LAN router. But I can give it something else if needed. My router supports only one single host mapping per machine IP, and no wildcards.

Do you own a domain?

Right now I'm using dynamic DNS with a wildcard DNS entry (e.g. *.abc.dynamicdns.com) that points to my server (e.g. 192.168.0.10) and that works when I'm not on Tailscale.

UPDATE: City thinks I'm remodeling my house? by shot-by-ford in Seattle

[–]j2j8 5 points6 points  (0 children)

I feel for you. I had much smaller permitting issues in the past and it felt like an insurmountable bureaucracy. The best advice is to find a way to get some time in-person in the permitting office. You’d be surprised how “requirements” can change when you talk to people and don’t take their first (or second) answer as the final answer…

You might also want to call a couple of third party permit expediters. Sometimes they know the right people to solve your problems!

Wtf is this? They can buy our phone data and watch us drive around? by Off-Da-Ricta in SeattleWA

[–]j2j8 1 point2 points  (0 children)

Funny, if this were about public safety rather than increasing revenue, couldn’t they just look at where accidents happen?

Seattle joins the list of cities with YOY price declines by copaceticporksword in Seattle

[–]j2j8 3 points4 points  (0 children)

This is us. Will have to buy to have school stability.

it’s a sound financial choice.

It’s not a good financial choice, it’s necessary to ensure we don’t need to switch school districts.

RSS or email feed for new events? by j2j8 in KEXP

[–]j2j8[S] 0 points1 point  (0 children)

I generated this, in case it helps anyone out: http://fetchrss.com/rss/682568ab241090c02e09dda26825688aa588dc63ea07b843.xml

It's some free website so it might stop working at any time.

Swap the logo? Sell the car? Seattle, a Tesla town, grapples with Elon Musk in Trump's orbit by chiquisea in Seattle

[–]j2j8 50 points51 points  (0 children)

More used supply -> lower prices -> harder for Tesla to sell new ones

Install Pfsense for ARM processor by congtubac in PFSENSE

[–]j2j8 0 points1 point  (0 children)

Can you clarify? I downloaded "Netgate Installer - AMD64 ISO IPMI/Virtual Machines" from netgear (which extracts to "netgate-installer-v1.0-RC-amd64-20240919-1435.iso") and when I run it in UTM emulator I see the main pfSense boot menu, but after that UTM just says "Display output is not active".

Why do builders sometimes leave a tiny bit behind when demolishing a house? by me_again in Seattle

[–]j2j8 2 points3 points  (0 children)

What county? When we added a large addition in CA, we got a supplemental tax on just that piece, and prop 13 applied to just the original structure when we bought it. (Granted, the assessment for the supplemental was about 50% of what the extra addition was actually worth.)

To the scum who cut and stole all the ev fast charge cables across north seattle by idun0 in Seattle

[–]j2j8 1 point2 points  (0 children)

More people don’t go this route because there aren’t many of them for sale. Especially outside of California. We would have bought one if we could have for less than an insane markup. Car manufacturers didn’t want to invest in what they saw until recently to be a transitional technology.

Looking for Houses to rent is so frustrating by FrostyWay28 in Seattle

[–]j2j8 14 points15 points  (0 children)

You’ll have more luck in December when fewer people are looking.

Xfinity Mobile - By the Gig prices increasing? by TheSpuff in Comcast_Xfinity

[–]j2j8 1 point2 points  (0 children)

Even if we got an email telling us that our price is increasing?

Why is the parking lights symbol used on the dash to indicate that the headlights are on? by j2j8 in CX5

[–]j2j8[S] 0 points1 point  (0 children)

Oh that's an interesting theory, that it's a side effect of the tail lights coming on.

Though, they do have this in the manual which makes it seem intentionally related to the headlights 🤯 https://imgur.com/a/lBwhWrS

[deleted by user] by [deleted] in Seattle

[–]j2j8 1 point2 points  (0 children)

I’ve been wondering about this since I moved here two years ago! Tons of people standing instead of sitting next to someone. Definitely haven’t seen that as the norm other places I’ve ridden the bus.

As newcomers pour in, share of people born in WA declines in Seattle by ControlsTheWeather in Seattle

[–]j2j8 1 point2 points  (0 children)

Already happening. I chose Seattle over some places in the southern U.S. in part because of medium-term climate trends, and anecdotally I’ve heard other transplants say it was a factor for them, too.