Files
automations/deployments/headscale
57_Wolve 8fbeb8f6b0 feat: unified launcher, multi-OS hardening, login alerts & auto-updates
Restructure around a single entry point (automations.sh) with a Gum wizard and
a self-extracting bundle for repo-less installs. Add scripts/oslib.sh so the
provisioning scripts (setup-host, harden-ssh, harden-jumphost, sshuser) run on
Alpine/Debian/Alma; seed root keys from globals/.
- ntfy SSH-login alerts (user, source IP, key, region, jump target) via pam_exec
- daily auto-updates: AUTO_REBOOT=idle reboots only when no SSH active; opt-in
  Alpine stable-branch upgrades (ALLOW_RELEASE_UPGRADE)
- cloud-init: generic base/jumphost + per-deployment, which harden SSH by
  default on fresh VMs
- pocket-id: optional WebFinger block (BASE_DOMAIN), tag v2.8.0
- headscale: fix oidc.expiry schema for 0.28 so the container starts
- Gitea release workflow on tag (TOKEN_GITEA); repo URLs -> Gitea
- README/LICENSE/.gitignore/.gitattributes (force LF)
2026-06-12 15:24:30 -05:00
..

headscale

Headscale — a self-hosted Tailscale control server — behind Caddy, with OIDC login delegated to pocket-id.

Prerequisite

Register an OIDC client in pocket-id's admin UI with redirect URI:

https://${HEADSCALE_DOMAIN}/oidc/callback

Then paste its OIDC_CLIENT_ID / OIDC_CLIENT_SECRET below.

Required .env values

Variable Notes
HEADSCALE_DOMAIN Public hostname (e.g. hs.example.com). Clients connect here over HTTPS.
ACME_EMAIL Let's Encrypt registration email.
TAILNET_DOMAIN MagicDNS suffix (e.g. tail.example.com). Must differ from HEADSCALE_DOMAIN.
POCKETID_DOMAIN OIDC issuer hostname (your pocket-id).
OIDC_CLIENT_ID / OIDC_CLIENT_SECRET From the pocket-id client above.

The deploy substitutes these into config.yaml from the embedded template. See .env.example.

Deploy

./automations.sh        # Deploy on this host → deploy: headscale

Or build + run the self-contained artifact:

./build.sh
scp deploy.sh root@host:
ssh root@host 'bash deploy.sh'
# non-interactive: pass HEADSCALE_DOMAIN, ACME_EMAIL, TAILNET_DOMAIN,
#   POCKETID_DOMAIN, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, SKIP_PROMPTS=1

Unattended provisioning: cloud-init.yml.

DNS for HEADSCALE_DOMAIN must resolve to the host and 80/443 be reachable before deploy.