The NixOS firewall was blocking pod-to-host TCP traffic because only tailscale0 was trusted. Pods could ping the host but not reach the API server (port 6443), breaking Tailscale Ingress TLS cert refresh and all ringtail services (authentik, frigate, ntfy, ollama). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| configuration.nix | ||
| disk-config.nix | ||
| flake.lock | ||
| flake.nix | ||
| hardware-configuration.nix | ||
| k3s-registries.yaml | ||