docs(tailscale): add exit node HA to netinfra-02 for full 01/02 parity
netinfra-02 now advertises exit node routes (0.0.0.0/0, ::/0) in addition to the subnet route, matching netinfra-01's configuration. Both nodes are now fully redundant subnet routers + exit nodes. Subnet route (192.168.0.0/22) is approved and active. Exit node routes (0.0.0.0/0, ::/0) require separate approval in the Tailscale admin console. [#377]
This commit is contained in:
@@ -101,24 +101,26 @@ tailscale up --accept-dns=false
|
|||||||
|
|
||||||
> **Redmine:** [#377](https://projects.knownelement.com/issues/377)
|
> **Redmine:** [#377](https://projects.knownelement.com/issues/377)
|
||||||
|
|
||||||
Both DNS nodes advertise the LAN subnet as Tailscale subnet routes,
|
Both DNS nodes advertise the LAN subnet as Tailscale subnet routes AND
|
||||||
providing automatic failover for remote monitoring (Uptime Kuma on the
|
serve as exit nodes, providing full HA for remote monitoring (Uptime Kuma
|
||||||
Cloudron VPS) and off-site access:
|
on the Cloudron VPS), off-site access, and internet egress:
|
||||||
|
|
||||||
| Node | Tailscale IP | Advertised route | Role |
|
| Node | Tailscale IP | Advertised routes | Role |
|
||||||
|------|-------------|-----------------|------|
|
|------|-------------|-------------------|------|
|
||||||
| pfv-netinfra-01 | 100.70.181.72 | 192.168.0.0/22 | Primary subnet router + exit node |
|
| pfv-netinfra-01 | 100.70.181.72 | 192.168.0.0/22, 0.0.0.0/0, ::/0 | Primary subnet router + exit node |
|
||||||
| pfv-netinfra-02 | 100.71.171.20 | 192.168.0.0/22 | Secondary subnet router (failover) |
|
| pfv-netinfra-02 | 100.71.171.20 | 192.168.0.0/22, 0.0.0.0/0, ::/0 | Secondary subnet router + exit node (failover) |
|
||||||
|
|
||||||
To configure on a node:
|
To configure on a node (both flags together):
|
||||||
```bash
|
```bash
|
||||||
sudo tailscale set --advertise-routes=192.168.0.0/22
|
sudo tailscale set --advertise-routes=192.168.0.0/22 --advertise-exit-node
|
||||||
```
|
```
|
||||||
|
|
||||||
**Both routes must be approved** in the Tailscale admin console
|
**All routes must be approved** in the Tailscale admin console
|
||||||
(https://login.tailscale.com/admin/machines) for failover to activate.
|
(https://login.tailscale.com/admin/machines) for failover to activate.
|
||||||
Tailscale uses the primary router by default and fails over to the
|
This includes the subnet route (`192.168.0.0/22`) AND the exit node routes
|
||||||
secondary if the primary's tunnel drops.
|
(`0.0.0.0/0`, `::/0`) — they appear as separate approvals on each machine.
|
||||||
|
Tailscale uses the primary by default and fails over to the secondary if
|
||||||
|
the primary's tunnel drops.
|
||||||
|
|
||||||
### Known instability factors (2026-08-06, [#377])
|
### Known instability factors (2026-08-06, [#377])
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user