generated from DAM/ts-TEMPLATE
fix: correct serve config assignment and clean up README
- serve.json: now uses ${TS_CERT_DOMAIN} with 443 (Tailscale default)
- serve.headscale.json: uses hardcoded example domain (Headscale)
- README: replace all {{service}} placeholders with vikunja
- Update logo to selfh.st icon
- Harden .gitignore
This commit is contained in:
11
.gitignore
vendored
11
.gitignore
vendored
@@ -1,14 +1,17 @@
|
|||||||
# Environment and secrets
|
# Real environment files (never commit)
|
||||||
.env
|
.env
|
||||||
.env.*
|
.env.local
|
||||||
|
.env.*.local
|
||||||
|
|
||||||
|
# Secrets and keys
|
||||||
*.key
|
*.key
|
||||||
tskey-*
|
tskey-*
|
||||||
authkey*
|
authkey*
|
||||||
|
|
||||||
# Tailscale state (never commit)
|
# Tailscale state
|
||||||
tailscale/tailscale-data/
|
tailscale/tailscale-data/
|
||||||
|
|
||||||
# OS / editor files
|
# OS / editor
|
||||||
.DS_Store
|
.DS_Store
|
||||||
*.swp
|
*.swp
|
||||||
*.swo
|
*.swo
|
||||||
|
|||||||
46
README.md
46
README.md
@@ -1,8 +1,8 @@
|
|||||||
# {{Service}} with Tailscale Integration
|
# Vikunja with Tailscale Integration
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
This project sets up a {{Service}} instance with Tailscale VPN integration using Docker Compose. It creates a secure, private network connection for your {{Service}} instance using Tailscale.
|
This project sets up a Vikunja instance with Tailscale VPN integration using Docker Compose. It creates a secure, private network connection for your Vikunja instance using Tailscale.
|
||||||
|
|
||||||
## Prerequisites
|
## Prerequisites
|
||||||
|
|
||||||
@@ -12,21 +12,21 @@ This project sets up a {{Service}} instance with Tailscale VPN integration using
|
|||||||
|
|
||||||
## Project Structure
|
## Project Structure
|
||||||
```
|
```
|
||||||
ts-{{service}}/
|
ts-vikunja/
|
||||||
├── docker-compose.yml
|
├── docker-compose.yml
|
||||||
├── tailscale/
|
├── tailscale/
|
||||||
│ ├── tailscale-data/ # Persistent Tailscale state
|
│ ├── tailscale-data/ # Persistent Tailscale state
|
||||||
│ └── config/ # Tailscale configuration files
|
│ └── config/ # Tailscale configuration files
|
||||||
└── {{service}}/
|
└── vikunja/
|
||||||
└── config/ # {{Service}} configuration files
|
└── config/ # Vikunja configuration files
|
||||||
```
|
```
|
||||||
|
|
||||||
## Setup Instructions
|
## Setup Instructions
|
||||||
|
|
||||||
1. **Clone the Repository**
|
1. **Clone the Repository**
|
||||||
```bash
|
```bash
|
||||||
git clone https://gitea.example.com/org/ts-{{service}}
|
git clone https://gitea.example.com/org/ts-vikunja
|
||||||
cd ts-{{service}}
|
cd ts-vikunja
|
||||||
```
|
```
|
||||||
2. Create Required Directories
|
2. Create Required Directories
|
||||||
```bash
|
```bash
|
||||||
@@ -37,7 +37,7 @@ ts-{{service}}/
|
|||||||
- Optionally, update the file in `tailscale/config/serve.json` if you need specific Tailscale serve configurations
|
- Optionally, update the file in `tailscale/config/serve.json` if you need specific Tailscale serve configurations
|
||||||
- CAUTION: Changing `"${TS_CERT_DOMAIN}:443": false` to `true` will expose the service to the internet
|
- CAUTION: Changing `"${TS_CERT_DOMAIN}:443": false` to `true` will expose the service to the internet
|
||||||
|
|
||||||
4. Configure {{Service}}
|
4. Configure Vikunja
|
||||||
- See the [documentation]({{service_docs}}) for configuration options
|
- See the [documentation]({{service_docs}}) for configuration options
|
||||||
|
|
||||||
5. Start the Services
|
5. Start the Services
|
||||||
@@ -48,30 +48,30 @@ ts-{{service}}/
|
|||||||
6. Wait for Certificate to propagate [~2m]
|
6. Wait for Certificate to propagate [~2m]
|
||||||
|
|
||||||
7. Login
|
7. Login
|
||||||
- After starting the services your service should be available via tailnet at https://{{service}}.{{YOUR_TAILNET_DOMAIN}}.ts.net ie https://{{service}}.tail12345.ts.net/
|
- After starting the services your service should be available via tailnet at https://vikunja.{{YOUR_TAILNET_DOMAIN}}.ts.net ie https://vikunja.tail12345.ts.net/
|
||||||
|
|
||||||
## Services
|
## Services
|
||||||
|
|
||||||
### {{service}}-ts (Tailscale)
|
### vikunja-ts (Tailscale)
|
||||||
|
|
||||||
- Runs Tailscale VPN client
|
- Runs Tailscale VPN client
|
||||||
- Image: tailscale/tailscale:latest
|
- Image: tailscale/tailscale:latest
|
||||||
- Container name: {{service}}-ts
|
- Container name: vikunja-ts
|
||||||
- Hostname: {{service}}
|
- Hostname: vikunja
|
||||||
- Requires NET_ADMIN and SYS_MODULE capabilities
|
- Requires NET_ADMIN and SYS_MODULE capabilities
|
||||||
- Persists state in ./tailscale/tailscale-data
|
- Persists state in ./tailscale/tailscale-data
|
||||||
- Uses configuration from ./tailscale/config
|
- Uses configuration from ./tailscale/config
|
||||||
|
|
||||||
### {{service}}
|
### vikunja
|
||||||
|
|
||||||
- Depends on {{service}}-ts service
|
- Depends on vikunja-ts service
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
- After starting the services your service should be available via tailnet at `https://{{service}}.{{YOUR_TAILNET_DOMAIN}}.ts.net` ie `https://{{service}}.tail12345.ts.net/`
|
- After starting the services your service should be available via tailnet at `https://vikunja.{{YOUR_TAILNET_DOMAIN}}.ts.net` ie `https://vikunja.tail12345.ts.net/`
|
||||||
- To manually get the Tailscale IP/hostname of your container:
|
- To manually get the Tailscale IP/hostname of your container:
|
||||||
```bash
|
```bash
|
||||||
docker logs {{service}}-ts
|
docker logs vikunja-ts
|
||||||
```
|
```
|
||||||
Look for the Tailscale IP address in the logs.
|
Look for the Tailscale IP address in the logs.
|
||||||
|
|
||||||
@@ -90,22 +90,22 @@ ts-{{service}}/
|
|||||||
## Troubleshooting
|
## Troubleshooting
|
||||||
- Check container logs:
|
- Check container logs:
|
||||||
```bash
|
```bash
|
||||||
docker logs {{service}}-ts
|
docker logs vikunja-ts
|
||||||
docker logs {{service}}
|
docker logs vikunja
|
||||||
```
|
```
|
||||||
- Ensure your Tailscale auth key is valid and not expired
|
- Ensure your Tailscale auth key is valid and not expired
|
||||||
- Verify the configuration files have proper permissions
|
- Verify the configuration files have proper permissions
|
||||||
- Make sure required directories exist before starting
|
- Make sure required directories exist before starting
|
||||||
|
|
||||||
## Notes
|
## Notes
|
||||||
- The {{Service}} service uses the Tailscale service's network stack via `network_mode: service:{{service}}-ts`
|
- The Vikunja service uses the Tailscale service's network stack via `network_mode: service:vikunja-ts`
|
||||||
- Direct port mapping is disabled by default as Tailscale handles the networking
|
- Direct port mapping is disabled by default as Tailscale handles the networking
|
||||||
- Services restart automatically unless explicitly stopped
|
- Services restart automatically unless explicitly stopped
|
||||||
- For more information:
|
- For more information:
|
||||||
- Tailscale documentation: https://tailscale.com/kb/
|
- Tailscale documentation: https://tailscale.com/kb/
|
||||||
- {{Service}} [documentation]({{service_docs}})
|
- Vikunja [documentation]({{service_docs}})
|
||||||
- {{Service}} [repository]({{service_repo}})
|
- Vikunja [repository]({{service_repo}})
|
||||||
- {{Service}} [linuxserve.io]({{service_lcsr}})
|
- Vikunja [linuxserve.io]({{service_lcsr}})
|
||||||
## Tailscale Serve Configuration
|
## Tailscale Serve Configuration
|
||||||
|
|
||||||
This repo includes two serve configuration files:
|
This repo includes two serve configuration files:
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"Web": {
|
"Web": {
|
||||||
"${TS_CERT_DOMAIN}:80": {
|
"vikunja.example.com:80": {
|
||||||
"Handlers": {
|
"Handlers": {
|
||||||
"/": {
|
"/": {
|
||||||
"Proxy": "http://127.0.0.1:3456"
|
"Proxy": "http://127.0.0.1:3456"
|
||||||
|
|||||||
@@ -2,15 +2,28 @@
|
|||||||
"TCP": {
|
"TCP": {
|
||||||
"80": {
|
"80": {
|
||||||
"HTTP": true
|
"HTTP": true
|
||||||
|
},
|
||||||
|
"443": {
|
||||||
|
"HTTPS": true
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"Web": {
|
"Web": {
|
||||||
"vikunja.example.com:80": {
|
"${TS_CERT_DOMAIN}:80": {
|
||||||
|
"Handlers": {
|
||||||
|
"/": {
|
||||||
|
"Proxy": "http://127.0.0.1:3456"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"${TS_CERT_DOMAIN}:443": {
|
||||||
"Handlers": {
|
"Handlers": {
|
||||||
"/": {
|
"/": {
|
||||||
"Proxy": "http://127.0.0.1:3456"
|
"Proxy": "http://127.0.0.1:3456"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"AllowFunnel": {
|
||||||
|
"${TS_CERT_DOMAIN}:443": false
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user