Implement Tailscale VPN #57

Open
opened 2022-12-18 18:57:52 -08:00 by kzrl · 3 comments
kzrl commented 2022-12-18 18:57:52 -08:00 (Migrated from gitlab.com)

User auth via Tailscale

User auth via Tailscale
kzrl commented 2022-12-19 00:38:25 -08:00 (Migrated from gitlab.com)

Replace HTTP Basic auth with Tailscale

Replace HTTP Basic auth with Tailscale
kzrl commented 2022-12-22 16:35:07 -08:00 (Migrated from gitlab.com)

Also replace nginx with Caddy+DNS challenges for HTTPS certs.

Should also move DNS from Google Cloud DNS to Cloudflare.

Also replace nginx with Caddy+DNS challenges for HTTPS certs. Should also move DNS from Google Cloud DNS to Cloudflare.
kzrl commented 2022-12-22 17:00:05 -08:00 (Migrated from gitlab.com)

Should also enforce 2FA on GSuite accounts.
Can add tailscale ACL to only allow from CMC office IP address (if it's static)

Should also enforce 2FA on GSuite accounts. Can add tailscale ACL to only allow from CMC office IP address (if it's static)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: springup/cmc-sales#57
No description provided.