From 533b00fc2610542106db9a921493ac4cb9577e07 Mon Sep 17 00:00:00 2001 From: peskyadmin Date: Sun, 2 Aug 2026 15:54:26 -0400 Subject: [PATCH] fix: correct serve config assignment and clean up README - serve.json: now uses ${TS_CERT_DOMAIN} with 443 (Tailscale default) - serve.headscale.json: uses hardcoded example domain (Headscale) - README: replace all {{service}} placeholders with vikunja - Update logo to selfh.st icon - Harden .gitignore --- .gitignore | 11 ++++--- README.md | 46 +++++++++++++-------------- tailscale/config/serve.headscale.json | 2 +- tailscale/config/serve.json | 15 ++++++++- 4 files changed, 45 insertions(+), 29 deletions(-) diff --git a/.gitignore b/.gitignore index 0e96c14..b7c0aa1 100644 --- a/.gitignore +++ b/.gitignore @@ -1,14 +1,17 @@ -# Environment and secrets +# Real environment files (never commit) .env -.env.* +.env.local +.env.*.local + +# Secrets and keys *.key tskey-* authkey* -# Tailscale state (never commit) +# Tailscale state tailscale/tailscale-data/ -# OS / editor files +# OS / editor .DS_Store *.swp *.swo diff --git a/README.md b/README.md index 43f2200..d897006 100644 --- a/README.md +++ b/README.md @@ -1,8 +1,8 @@ -# {{Service}} with Tailscale Integration +# Vikunja with Tailscale Integration -![{{Service}} with Tailscale](https://example.com/logo.svg "{{Service}}") +![Vikunja with Tailscale](https://selfh.st/vikunja/logo.png "Vikunja") -This project sets up a {{Service}} instance with Tailscale VPN integration using Docker Compose. It creates a secure, private network connection for your {{Service}} instance using Tailscale. +This project sets up a Vikunja instance with Tailscale VPN integration using Docker Compose. It creates a secure, private network connection for your Vikunja instance using Tailscale. ## Prerequisites @@ -12,21 +12,21 @@ This project sets up a {{Service}} instance with Tailscale VPN integration using ## Project Structure ``` -ts-{{service}}/ +ts-vikunja/ ├── docker-compose.yml ├── tailscale/ │ ├── tailscale-data/ # Persistent Tailscale state │ └── config/ # Tailscale configuration files -└── {{service}}/ - └── config/ # {{Service}} configuration files +└── vikunja/ + └── config/ # Vikunja configuration files ``` ## Setup Instructions 1. **Clone the Repository** ```bash - git clone https://gitea.example.com/org/ts-{{service}} - cd ts-{{service}} + git clone https://gitea.example.com/org/ts-vikunja + cd ts-vikunja ``` 2. Create Required Directories ```bash @@ -37,7 +37,7 @@ ts-{{service}}/ - Optionally, update the file in `tailscale/config/serve.json` if you need specific Tailscale serve configurations - CAUTION: Changing `"${TS_CERT_DOMAIN}:443": false` to `true` will expose the service to the internet -4. Configure {{Service}} +4. Configure Vikunja - See the [documentation]({{service_docs}}) for configuration options 5. Start the Services @@ -48,30 +48,30 @@ ts-{{service}}/ 6. Wait for Certificate to propagate [~2m] 7. Login - - After starting the services your service should be available via tailnet at https://{{service}}.{{YOUR_TAILNET_DOMAIN}}.ts.net ie https://{{service}}.tail12345.ts.net/ + - After starting the services your service should be available via tailnet at https://vikunja.{{YOUR_TAILNET_DOMAIN}}.ts.net ie https://vikunja.tail12345.ts.net/ ## Services -### {{service}}-ts (Tailscale) +### vikunja-ts (Tailscale) - Runs Tailscale VPN client - Image: tailscale/tailscale:latest -- Container name: {{service}}-ts -- Hostname: {{service}} +- Container name: vikunja-ts +- Hostname: vikunja - Requires NET_ADMIN and SYS_MODULE capabilities - Persists state in ./tailscale/tailscale-data - Uses configuration from ./tailscale/config -### {{service}} +### vikunja -- Depends on {{service}}-ts service +- Depends on vikunja-ts service ## Usage -- After starting the services your service should be available via tailnet at `https://{{service}}.{{YOUR_TAILNET_DOMAIN}}.ts.net` ie `https://{{service}}.tail12345.ts.net/` +- After starting the services your service should be available via tailnet at `https://vikunja.{{YOUR_TAILNET_DOMAIN}}.ts.net` ie `https://vikunja.tail12345.ts.net/` - To manually get the Tailscale IP/hostname of your container: ```bash - docker logs {{service}}-ts + docker logs vikunja-ts ``` Look for the Tailscale IP address in the logs. @@ -90,22 +90,22 @@ ts-{{service}}/ ## Troubleshooting - Check container logs: ```bash - docker logs {{service}}-ts - docker logs {{service}} + docker logs vikunja-ts + docker logs vikunja ``` - Ensure your Tailscale auth key is valid and not expired - Verify the configuration files have proper permissions - Make sure required directories exist before starting ## Notes -- The {{Service}} service uses the Tailscale service's network stack via `network_mode: service:{{service}}-ts` +- The Vikunja service uses the Tailscale service's network stack via `network_mode: service:vikunja-ts` - Direct port mapping is disabled by default as Tailscale handles the networking - Services restart automatically unless explicitly stopped - For more information: - Tailscale documentation: https://tailscale.com/kb/ - - {{Service}} [documentation]({{service_docs}}) - - {{Service}} [repository]({{service_repo}}) - - {{Service}} [linuxserve.io]({{service_lcsr}}) + - Vikunja [documentation]({{service_docs}}) + - Vikunja [repository]({{service_repo}}) + - Vikunja [linuxserve.io]({{service_lcsr}}) ## Tailscale Serve Configuration This repo includes two serve configuration files: diff --git a/tailscale/config/serve.headscale.json b/tailscale/config/serve.headscale.json index 27a1c25..4db16f8 100644 --- a/tailscale/config/serve.headscale.json +++ b/tailscale/config/serve.headscale.json @@ -5,7 +5,7 @@ } }, "Web": { - "${TS_CERT_DOMAIN}:80": { + "vikunja.example.com:80": { "Handlers": { "/": { "Proxy": "http://127.0.0.1:3456" diff --git a/tailscale/config/serve.json b/tailscale/config/serve.json index 4db16f8..2e3de3d 100644 --- a/tailscale/config/serve.json +++ b/tailscale/config/serve.json @@ -2,15 +2,28 @@ "TCP": { "80": { "HTTP": true + }, + "443": { + "HTTPS": true } }, "Web": { - "vikunja.example.com:80": { + "${TS_CERT_DOMAIN}:80": { + "Handlers": { + "/": { + "Proxy": "http://127.0.0.1:3456" + } + } + }, + "${TS_CERT_DOMAIN}:443": { "Handlers": { "/": { "Proxy": "http://127.0.0.1:3456" } } } + }, + "AllowFunnel": { + "${TS_CERT_DOMAIN}:443": false } }