system/tailscale: loosen firewall for tailnet

This commit is contained in:
Cilly Leang 2026-06-06 20:14:37 +10:00
parent 91abcbed19
commit ee3e0868a8
Signed by: cilly
GPG key ID: 6500251E087653C9

View file

@ -1,6 +1,7 @@
{ config, ... }: { { config, ... }: {
age.secrets.tailscale_auth.file = ../../secrets/tailscale_auth.age; age.secrets.tailscale_auth.file = ../../secrets/tailscale_auth.age;
me.binds."/var/lib/tailscale" = "tailscale"; me.binds."/var/lib/tailscale" = "tailscale";
networking.firewall.trustedInterfaces = [ "tailscale0" ];
services.tailscale = { services.tailscale = {
enable = true; enable = true;
authKeyFile = config.age.secrets.tailscale_auth.path; authKeyFile = config.age.secrets.tailscale_auth.path;