Expand description
Recipe helpers for stateful services bound exclusively to the Headscale mesh (R040-F16).
Inter-node TCP (Postgres primary↔replica, NATS clusters, etc.) lives on the
WireGuard mesh, not on Hetzner public IPs. Each node has a stable
100.64.x.x mesh IP that survives box replacement, so connection strings
and pg_hba.conf never need to churn when a CPX-22 is rebuilt.
§Standard pattern for a mesh-bound port
ServiceConfig {
name: "postgres",
bind_interface: Some("tailscale0"),
mesh_only: true,
...
}The compose renderer emits network_mode: "host" for such a service.
Pair it with the ufw rules from ufw_rules_for_mesh_port (applied by the
yubaba’s POST /compose via the firewall_cmds field) and the pg_hba
snippet from pg_hba_snippet (injected into the Postgres container via
a mounted config volume or env).
§First-boot POSTGRES_LISTEN_ADDRESSES
Postgres must bind to the node’s tailscale mesh IP, not 0.0.0.0. Since
the IP is only known at boot time, cloud-init or a systemd ExecStartPre
can resolve it:
# cloud-init write_files
- path: /etc/yah-cloud/mesh-ip.env
content: "" # overwritten by runcmd below
runcmd:
- sh -c 'echo "POSTGRES_LISTEN_ADDRESSES=$(tailscale ip --4)" > /etc/yah-cloud/mesh-ip.env'Then reference env_file: [/etc/yah-cloud/mesh-ip.env] in the compose
service block. The compose renderer sets this automatically when
bind_interface is set on a service that exposes port 5432.
Constants§
- MESH_
IP_ ENV_ FILE - The env file path written by cloud-init that holds the node’s mesh IP.
Referenced as
env_filein compose whenbind_interfaceis set. - MESH_
SUBNET - Tailscale/Headscale CGNAT subnet — all mesh peers have addresses in this range.
- TAILSCALE_
IFACE - The network interface name that carries Tailscale/Headscale mesh traffic.
Functions§
- mesh_
ip_ env_ runcmd - Build the cloud-init
runcmdlines that write the mesh IP env file at first boot. Append these to a machine’smirror.ymlruncmdblock to makePOSTGRES_LISTEN_ADDRESSESavailable to the compose stack viaenv_file: [{MESH_IP_ENV_FILE}]. - pg_
hba_ snippet - Generate a
pg_hba.confblock that allows connections from any mesh peer. - ufw_
rules_ for_ mesh_ port - Generate the ufw commands needed to make port
portreachable only on interfaceiface(typicallytailscale0), blocking all other ingress.