blumeops/pulumi/tailscale
Erich Blume 12b2786ca2
All checks were successful
Deploy Fly.io Proxy / deploy (push) Successful in 1m59s
Route Fly proxy through Caddy on indri for direct WireGuard peering
Tailscale Ingress pods in k8s can't establish direct WireGuard
connections (stuck behind pod-network NAT → DERP relay → 20s latency).
Indri's host-level Tailscale CAN peer directly with Fly.

Change all nginx upstreams to route through Caddy on indri instead of
per-service Tailscale Ingress endpoints. Tag indri as flyio-target in
the Tailscale ACL so the Fly proxy can reach it.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-18 09:40:20 -07:00
..
.gitignore Add Fly.io public reverse proxy for docs.eblu.me (#120) 2026-02-08 02:36:19 -08:00
__main__.py Route Fly proxy through Caddy on indri for direct WireGuard peering 2026-04-18 09:40:20 -07:00
policy.hujson Route Fly proxy through Caddy on indri for direct WireGuard peering 2026-04-18 09:40:20 -07:00
Pulumi.tail8d86e.yaml Add Gandi DNS management via Pulumi (#54) 2026-01-25 08:15:46 -08:00
Pulumi.yaml Add Gandi DNS management via Pulumi (#54) 2026-01-25 08:15:46 -08:00
pyproject.toml Add Gandi DNS management via Pulumi (#54) 2026-01-25 08:15:46 -08:00
uv.lock Add Fly.io public reverse proxy for docs.eblu.me (#120) 2026-02-08 02:36:19 -08:00