Three more composes — compose.tailnet.yml, compose.tailnet.frontend.yml, compose.tailnet.backend.yml — mirror the funnel set exactly but mount serve.default/frontend/backend.tailnet.json, which drop AllowFunnel. The sidecar still registers and serves HTTPS with a tailnet certificate, but nothing is exposed publicly; Serve also needs no ACL change. Project names carry a -tailnet suffix so both sets can coexist, and the README explains that each set needs its own data directory (or host), plus how to switch a host between funnel and tailnet by starting the other file with the same .env. Verified: all six composes validate with docker compose config, and the six serve configs split cleanly into funnel (AllowFunnel present) and tailnet-only (absent).
17 lines
207 B
JSON
17 lines
207 B
JSON
{
|
|
"TCP": {
|
|
"8443": {
|
|
"HTTPS": true
|
|
}
|
|
},
|
|
"Web": {
|
|
"${TS_CERT_DOMAIN}:8443": {
|
|
"Handlers": {
|
|
"/": {
|
|
"Proxy": "http://127.0.0.1:80"
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|