Tailscale
Reach Nifty over HTTPS from your own devices only, with no ports opened.
With Tailscale, Nifty is at https://<machine>.<tailnet>.ts.net, reachable from devices on your tailnet and nothing
else. Tailscale provides the certificate.
Before you start
- Tailscale is installed and up on the server (
sudo tailscale up). - MagicDNS and HTTPS Certificates are on, in Tailscale's admin console under DNS.
Set it up
The easiest way is install.sh: choose Over Tailscale, or pass --tailscale (Install on Linux).
To switch an existing server:
Let the
niftyuser managetailscale serve:sudo tailscale set --operator=niftyIn
/etc/nifty.env, set:NIFTY_TAILSCALE_SERVE=onNifty must listen on loopback, as it does by default (
127.0.0.1:4000). It works out its address; if you setNIFTY_ORIGIN, it must match.Restart:
sudo systemctl restart nifty.
Each time it starts, Nifty runs tailscale serve to pass https://<machine>.<tailnet>.ts.net to itself. To use
another port, set NIFTY_TAILSCALE_PORT=8443; Nifty won't take a port that serves something else.
The operator setting
Tailscale's operator can change any Tailscale setting on the machine: log it out, change exit nodes, other serves.
Making nifty the operator means a compromised Nifty could too. There's one operator, so this replaces any other.
If you'd rather not, run tailscale serve yourself, once, as root (install.sh --tailscale --no-tailscale-operator
does this):
sudo tailscale serve --bg --https=443 http://127.0.0.1:4000
Then, in /etc/nifty.env, leave NIFTY_TAILSCALE_SERVE off and set:
NIFTY_ORIGIN=https://<machine>.<tailnet>.ts.net
NIFTY_TRUSTED_PROXIES=127.0.0.1
Tailscale keeps the serve across restarts, but if it's ever removed, run the command again.
Check it
tailscale serve status
Serves stay after Nifty stops. To remove Nifty's: sudo tailscale serve --https=443 off.