blumeops/fly
Erich Blume 12b2786ca2
All checks were successful
Deploy Fly.io Proxy / deploy (push) Successful in 1m59s
Route Fly proxy through Caddy on indri for direct WireGuard peering
Tailscale Ingress pods in k8s can't establish direct WireGuard
connections (stuck behind pod-network NAT → DERP relay → 20s latency).
Indri's host-level Tailscale CAN peer directly with Fly.

Change all nginx upstreams to route through Caddy on indri instead of
per-service Tailscale Ingress endpoints. Tag indri as flyio-target in
the Tailscale ACL so the Fly proxy can reach it.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-18 09:40:20 -07:00
..
fail2ban Expose Forgejo publicly at forge.eblu.me (#278) 2026-03-03 08:40:41 -08:00
alloy.river Add Forgejo metrics + upstream latency histogram to Fly proxy dashboard 2026-04-17 15:05:59 -07:00
Dockerfile Pin Fly.io Tailscale to v1.94.1 to fix MagicDNS regression in v1.96.5 2026-04-10 19:32:38 -07:00
error.html Serve friendly error page when Fly.io proxy upstreams are unreachable (#133) 2026-02-09 12:01:24 -08:00
fly.toml Expose Tailscale WireGuard UDP port on Fly proxy 2026-04-18 09:17:03 -07:00
nginx.conf Route Fly proxy through Caddy on indri for direct WireGuard peering 2026-04-18 09:40:20 -07:00
start.sh Expose Tailscale WireGuard UDP port on Fly proxy 2026-04-18 09:17:03 -07:00