Deployed 00663fbb to development with ProperDocs 1.6.7 and mike 2.2.0

This commit is contained in:
github-actions
2026-09-28 19:42:58 +00:00
parent 1bf4e15370
commit 455a773839
5 changed files with 6 additions and 6 deletions
+1 -1
View File
@@ -9,7 +9,7 @@
</span><span id=__span-1-4><a id=__codelineno-1-4 name=__codelineno-1-4 href=#__codelineno-1-4></a><span class=w> </span><span class=nt>ipv4</span><span class=p>:</span><span class=w> </span><span class="l l-Scalar l-Scalar-Plain">198.51.100.1</span>
</span><span id=__span-1-5><a id=__codelineno-1-5 name=__codelineno-1-5 href=#__codelineno-1-5></a><span class=w> </span><span class=nt>ipv6</span><span class=p>:</span><span class=w> </span><span class="l l-Scalar l-Scalar-Plain">2001:db8::1</span>
</span><span id=__span-1-6><a id=__codelineno-1-6 name=__codelineno-1-6 href=#__codelineno-1-6></a><span class=hll><span class=w> </span><span class=nt>urls</span><span class=p>:</span><span class=w> </span><span class="p p-Indicator">[]</span>
</span></span></code></pre></div> <div class="admonition warning"> <p class=admonition-title>Single point of failure</p> <p>Removing Tailscale's DERP servers means that there is now just a single DERP server available for clients. This is a single point of failure and could hamper connectivity.</p> <p><a href=#check-derp-server-connectivity>Check DERP server connectivity</a> with your embedded DERP server before removing Tailscale's DERP servers.</p> </div> <h3 id=customize-derp-map>Customize DERP map<a class=headerlink href=#customize-derp-map title="Permanent link">&para;</a></h3> <p>The DERP map offered to clients can be customized with a <a href=https://github.com/juanfont/headscale/blob/main/derp-example.yaml>dedicated YAML-configuration file</a>. This allows to modify previously loaded DERP maps fetched via URL or to offer your own, custom DERP servers to nodes.</p> <div class="tabbed-set tabbed-alternate" data-tabs=1:2><input checked=checked id=__tabbed_1_1 name=__tabbed_1 type=radio><input id=__tabbed_1_2 name=__tabbed_1 type=radio><div class=tabbed-labels><label for=__tabbed_1_1>Remove specific DERP regions</label><label for=__tabbed_1_2>Provide custom DERP servers</label></div> <div class=tabbed-content> <div class=tabbed-block> <p>The free-to-use <a href=https://tailscale.com/docs/reference/derp-servers>DERP servers</a> are organized into regions via a region ID. You can explicitly disable a specific region by setting its region ID to <code>null</code>. The following sample <code>derp.yaml</code> disables the New York DERP region (which has the region ID 1):</p> <div class="language-yaml highlight"><span class=filename>derp.yaml</span><pre><span></span><code><span id=__span-2-1><a id=__codelineno-2-1 name=__codelineno-2-1 href=#__codelineno-2-1></a><span class=nt>regions</span><span class=p>:</span>
</span></span></code></pre></div> <div class="admonition warning"> <p class=admonition-title>Single point of failure</p> <p>Removing Tailscale's DERP servers means that there is now just a single DERP server available for clients. This is a single point of failure and could hamper connectivity.</p> <p><a href=#check-derp-server-connectivity>Check DERP server connectivity</a> with your embedded DERP server before removing Tailscale's DERP servers.</p> </div> <h3 id=customize-derp-map>Customize DERP map<a class=headerlink href=#customize-derp-map title="Permanent link">&para;</a></h3> <p>The DERP map offered to clients can be customized with a <a href=https://github.com/juanfont/headscale/blob/main/derp-example.yaml>dedicated YAML-configuration file</a>. The file extension picks the format: <code>.yaml</code> or <code>.yml</code>, or the JSON format Tailscale serves DERP maps in as <code>.json</code> or <code>.hujson</code>. This allows to modify previously loaded DERP maps fetched via URL or to offer your own, custom DERP servers to nodes.</p> <div class="tabbed-set tabbed-alternate" data-tabs=1:2><input checked=checked id=__tabbed_1_1 name=__tabbed_1 type=radio><input id=__tabbed_1_2 name=__tabbed_1 type=radio><div class=tabbed-labels><label for=__tabbed_1_1>Remove specific DERP regions</label><label for=__tabbed_1_2>Provide custom DERP servers</label></div> <div class=tabbed-content> <div class=tabbed-block> <p>The free-to-use <a href=https://tailscale.com/docs/reference/derp-servers>DERP servers</a> are organized into regions via a region ID. You can explicitly disable a specific region by setting its region ID to <code>null</code>. The following sample <code>derp.yaml</code> disables the New York DERP region (which has the region ID 1):</p> <div class="language-yaml highlight"><span class=filename>derp.yaml</span><pre><span></span><code><span id=__span-2-1><a id=__codelineno-2-1 name=__codelineno-2-1 href=#__codelineno-2-1></a><span class=nt>regions</span><span class=p>:</span>
</span><span id=__span-2-2><a id=__codelineno-2-2 name=__codelineno-2-2 href=#__codelineno-2-2></a><span class=w> </span><span class=nt>1</span><span class=p>:</span><span class=w> </span><span class="l l-Scalar l-Scalar-Plain">null</span>
</span></code></pre></div> <p>Use the following configuration to serve the default DERP map (excluding New York) to nodes:</p> <div class="language-yaml highlight"><span class=filename>config.yaml</span><pre><span></span><code><span id=__span-3-1><a id=__codelineno-3-1 name=__codelineno-3-1 href=#__codelineno-3-1></a><span class=nt>derp</span><span class=p>:</span>
</span><span id=__span-3-2><a id=__codelineno-3-2 name=__codelineno-3-2 href=#__codelineno-3-2></a><span class=w> </span><span class=nt>server</span><span class=p>:</span>
+1 -1
View File
@@ -21,7 +21,7 @@
</span><span id=__span-1-10><a id=__codelineno-1-10 name=__codelineno-1-10 href=#__codelineno-1-10></a><span class=w> </span><span class=nt>"value"</span><span class=p>:</span><span class=w> </span><span class=s2>"100.64.0.3"</span>
</span><span id=__span-1-11><a id=__codelineno-1-11 name=__codelineno-1-11 href=#__codelineno-1-11></a><span class=w> </span><span class=p>}</span>
</span><span id=__span-1-12><a id=__codelineno-1-12 name=__codelineno-1-12 href=#__codelineno-1-12></a><span class=p>]</span>
</span></code></pre></div> <p>Headscale picks up changes to the above JSON file automatically.</p> <div class="admonition tip"> <p class=admonition-title>Good to know</p> <ul> <li>The <code>dns.extra_records_path</code> option in the <a href=../configuration/ >configuration file</a> needs to reference the JSON file containing extra DNS records.</li> <li>Be sure to "sort keys" and produce a stable output in case you generate the JSON file with a script. Headscale uses a checksum to detect changes to the file and a stable output avoids unnecessary processing.</li> </ul> </div> </div> </div> </div> </li> <li> <p>Verify that DNS records are properly set using the DNS querying tool of your choice:</p> <div class="tabbed-set tabbed-alternate" data-tabs=2:2><input checked=checked id=__tabbed_2_1 name=__tabbed_2 type=radio><input id=__tabbed_2_2 name=__tabbed_2 type=radio><div class=tabbed-labels><label for=__tabbed_2_1>Query with dig</label><label for=__tabbed_2_2>Query with drill</label></div> <div class=tabbed-content> <div class=tabbed-block> <div class="language-console highlight"><pre><span></span><code><span id=__span-2-1><a id=__codelineno-2-1 name=__codelineno-2-1 href=#__codelineno-2-1></a><span class=go>dig +short grafana.myvpn.example.com</span>
</span></code></pre></div> <p>Headscale picks up changes to the above JSON file automatically.</p> <div class="admonition tip"> <p class=admonition-title>Good to know</p> <ul> <li>The <code>dns.extra_records_path</code> option in the <a href=../configuration/ >configuration file</a> needs to reference the file containing extra DNS records. Its extension picks the format: <code>.json</code>, <code>.hujson</code>, <code>.yaml</code> or <code>.yml</code>.</li> <li>Be sure to "sort keys" and produce a stable output in case you generate the JSON file with a script. Headscale uses a checksum to detect changes to the file and a stable output avoids unnecessary processing.</li> </ul> </div> </div> </div> </div> </li> <li> <p>Verify that DNS records are properly set using the DNS querying tool of your choice:</p> <div class="tabbed-set tabbed-alternate" data-tabs=2:2><input checked=checked id=__tabbed_2_1 name=__tabbed_2 type=radio><input id=__tabbed_2_2 name=__tabbed_2 type=radio><div class=tabbed-labels><label for=__tabbed_2_1>Query with dig</label><label for=__tabbed_2_2>Query with drill</label></div> <div class=tabbed-content> <div class=tabbed-block> <div class="language-console highlight"><pre><span></span><code><span id=__span-2-1><a id=__codelineno-2-1 name=__codelineno-2-1 href=#__codelineno-2-1></a><span class=go>dig +short grafana.myvpn.example.com</span>
</span><span id=__span-2-2><a id=__codelineno-2-2 name=__codelineno-2-2 href=#__codelineno-2-2></a><span class=go>100.64.0.3</span>
</span></code></pre></div> </div> <div class=tabbed-block> <div class="language-console highlight"><pre><span></span><code><span id=__span-3-1><a id=__codelineno-3-1 name=__codelineno-3-1 href=#__codelineno-3-1></a><span class=go>drill -Q grafana.myvpn.example.com</span>
</span><span id=__span-3-2><a id=__codelineno-3-2 name=__codelineno-3-2 href=#__codelineno-3-2></a><span class=go>100.64.0.3</span>
+1 -1
View File
@@ -10,7 +10,7 @@
</span></code></pre></div> <p>Run <code>tailscale up</code> and provide at least one tag to login a tagged device:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-4-1><a id=__codelineno-4-1 name=__codelineno-4-1 href=#__codelineno-4-1></a><span class=go>tailscale up --login-server &lt;YOUR_HEADSCALE_URL&gt; --advertise-tags tag:&lt;TAG&gt;</span>
</span></code></pre></div> <p>Usually, a browser window with further instructions is opened. This page explains how to complete the registration on your Headscale server and it also prints the Auth ID required to approve the node:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-5-1><a id=__codelineno-5-1 name=__codelineno-5-1 href=#__codelineno-5-1></a><span class=go>headscale auth register --user &lt;USER&gt; --auth-id &lt;AUTH_ID&gt;</span>
</span></code></pre></div> <p>Headscale checks that <code>&lt;USER&gt;</code> is allowed to register a node with the specified tag(s) and then transfers ownership of the new node to the special user <code>tagged-devices</code>. The registration of a tagged node is complete and it should be listed as "online" in the output of <code>headscale nodes list</code>. The "User" column displays <code>tagged-devices</code> as the owner of the node. See the "Tags" column for the list of assigned tags.</p> </div> </div> </div> <h3 id=pre-authenticated-key>Pre authenticated key<a class=headerlink href=#pre-authenticated-key title="Permanent link">&para;</a></h3> <p>Registration with a pre authenticated key (or auth key) is a non-interactive way to register a new node. The Headscale administrator creates a preauthkey upfront and this preauthkey can then be used to register a node non-interactively. Its best suited for automation.</p> <div class="tabbed-set tabbed-alternate" data-tabs=2:2><input checked=checked id=__tabbed_2_1 name=__tabbed_2 type=radio><input id=__tabbed_2_2 name=__tabbed_2 type=radio><div class=tabbed-labels><label for=__tabbed_2_1>Personal devices</label><label for=__tabbed_2_2>Tagged devices</label></div> <div class=tabbed-content> <div class=tabbed-block> <p>A personal node is always assigned to a Headscale user. Use the <code>headscale users</code> command to create a new user<sup id=fnref2:1><a class=footnote-ref href=#fn:1>1</a></sup>:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-6-1><a id=__codelineno-6-1 name=__codelineno-6-1 href=#__codelineno-6-1></a><span class=go>headscale users create &lt;USER&gt;</span>
</span></code></pre></div> <p>Use the <code>headscale user list</code> command to learn its <code>&lt;USER_ID&gt;</code> and create a new pre authenticated key for your user:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-7-1><a id=__codelineno-7-1 name=__codelineno-7-1 href=#__codelineno-7-1></a><span class=go>headscale preauthkeys create --user &lt;USER_ID&gt;</span>
</span></code></pre></div> <p>Create a new pre authenticated key for your user, by name or by the <code>&lt;USER_ID&gt;</code> that <code>headscale user list</code> shows:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-7-1><a id=__codelineno-7-1 name=__codelineno-7-1 href=#__codelineno-7-1></a><span class=go>headscale preauthkeys create --user &lt;USER&gt;</span>
</span></code></pre></div> <p>The above prints a pre authenticated key with the default settings (can be used once and is valid for one hour). Use this auth key to register a node non-interactively:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-8-1><a id=__codelineno-8-1 name=__codelineno-8-1 href=#__codelineno-8-1></a><span class=go>tailscale up --login-server &lt;YOUR_HEADSCALE_URL&gt; --authkey &lt;YOUR_AUTH_KEY&gt;</span>
</span></code></pre></div> <p>Congrations, the registration of your personal node is complete and it should be listed as "online" in the output of <code>headscale nodes list</code>. The "User" column displays <code>&lt;USER&gt;</code> as the owner of the node.</p> </div> <div class=tabbed-block> <p>Create a new pre authenticated key and provide at least one tag:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-9-1><a id=__codelineno-9-1 name=__codelineno-9-1 href=#__codelineno-9-1></a><span class=go>headscale preauthkeys create --tags tag:&lt;TAG&gt;</span>
</span></code></pre></div> <p>The above prints a pre authenticated key with the default settings (can be used once and is valid for one hour). Use this auth key to register a node non-interactively. You don't need to provide the <code>--advertise-tags</code> parameter as the tags are automatically read from the pre authenticated key. Advertising a subset of the key's tags is accepted; any other tag is rejected:</p> <div class="language-console highlight"><pre><span></span><code><span id=__span-10-1><a id=__codelineno-10-1 name=__codelineno-10-1 href=#__codelineno-10-1></a><span class=go>tailscale up --login-server &lt;YOUR_HEADSCALE_URL&gt; --authkey &lt;YOUR_AUTH_KEY&gt;</span>
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long