## Summary - Add `ringtail` DeviceTags Pulumi resource with `tag:homelab` + `tag:blumeops` (matching indri/sifaka pattern) - Remove the bootstrap `ringtail_key` auth key — ringtail is already on the tailnet - Add SSH ACL rule allowing `tag:homelab` → `tag:homelab` SSH, unblocking cross-host management (e.g., ringtail running ansible against indri) ## Deployment and Testing - [ ] `mise run tailnet-preview` — dry run, confirm diff - [ ] `mise run tailnet-up` — apply - [ ] From ringtail: `ssh indri 'hostname'` — should succeed 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: https://forge.ops.eblu.me/eblume/blumeops/pulls/210 |
||
|---|---|---|
| .. | ||
| .gitkeep | ||
| feature-k3s-ringtail-runner.feature.md | ||
| feature-ntfy-container.infra.md | ||
| feature-ringtail-nixos.feature.md | ||
| feature-ringtail-nixos.infra.md | ||
| fix-frigate-detect-fps.bugfix.md | ||
| fix-tailscale-ssh-ringtail.infra.md | ||
| fix-zk-docs.bugfix.md | ||
| frigate-zmq-detector.infra.md | ||
| review-ntfy-v2.17.0.infra.md | ||
| update-external-secrets-helm-2.0.0.infra.md | ||
| upgrade-frigate-0.17.infra.md | ||