Tailnet-only (Serve, no Funnel) compose variants

Three more composes — compose.tailnet.yml, compose.tailnet.frontend.yml,
compose.tailnet.backend.yml — mirror the funnel set exactly but mount
serve.default/frontend/backend.tailnet.json, which drop AllowFunnel. The
sidecar still registers and serves HTTPS with a tailnet certificate, but
nothing is exposed publicly; Serve also needs no ACL change.

Project names carry a -tailnet suffix so both sets can coexist, and the
README explains that each set needs its own data directory (or host), plus
how to switch a host between funnel and tailnet by starting the other file
with the same .env.

Verified: all six composes validate with docker compose config, and the
six serve configs split cleanly into funnel (AllowFunnel present) and
tailnet-only (absent).
This commit is contained in:
2026-09-18 11:21:48 -05:00
parent ce016fb221
commit 30b1a1a4b0
8 changed files with 375 additions and 6 deletions
+6 -4
View File
@@ -34,10 +34,12 @@ Project constraints (do not regress):
- deploy/ is the deployment source of truth: J621-Frontend (SPA on static
nginx) and J621-Backend (gunicorn + whitenoise, ffmpeg, migrations on
start), three compose variants (both / frontend-only / backend-only) behind
a shared nginx proxy service, and a Tailscale sidecar per compose whose
serve configs only use funnel ports 443 / 8443 / 10000. Images are pushed
to the Gitea registry with deploy/push_*.sh (multi-arch, :latest + :sha,
GIT_HASH baked in for the version pill).
a shared nginx proxy service, and a Tailscale sidecar per compose.
serve.*.json are the public Funnel variants (only ports 443 / 8443 / 10000);
serve.*.tailnet.json + compose.tailnet*.yml are the same stacks without
AllowFunnel (tailnet-only, no public exposure). Images are pushed to the
Gitea registry with deploy/push_*.sh (multi-arch, :latest + :sha, GIT_HASH
baked in for the version pill).
- Security/permission tests live in backend/apps/core/tests and need a
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';