diff --git a/docs/pfi/headscale-mesh-plan.md b/docs/pfi/headscale-mesh-plan.md index c815e30..0160af7 100644 --- a/docs/pfi/headscale-mesh-plan.md +++ b/docs/pfi/headscale-mesh-plan.md @@ -162,3 +162,31 @@ empty policy) until told otherwise. 443); (d) disable ONE old tunnel and re-test router paths; (e) cut over: static routes for the other two /16s on each gateway, disable Site Magic + IPsec; (f) v6 AAAA once NH3 LAN v6 is on; (g) self-hosted DERP at ESH; (h) PVE upgrades on pfi-pve/nh3-pve. + +### 06:05Z — return path built and verified (operator approved 05:50Z) + +Static route `100.64.0.0/10` → local router on all three gateways: NH3 UDM +(`mesh-100.64-via-nh3-scale` → 10.100.50.46, classic REST), ESH UDM +(`mesh-100.64-via-esh-scale` → 10.0.50.65; ⚠ that vault item is a 19-line note — extract with +`secret get unifi/esh-udmpm-api-key | grep '^key:' | awk '{print $2}'`, a raw pipe gives nginx +400 and the NH3 key gives 401), FortiGate (`config router static`, dst 100.64.0.0/255.192.0.0, +gw 10.250.50.45, device `servers`; config backed up to flash as `pre-mesh-route-20260906` +first). Routers re-set to `--accept-routes=true` — a router MUST accept the other sites' routes +or its replies to remote-LAN sources leave via its default gateway with a 100.64 source and die; +a node never accepts its own advertised route, so the nh3-dev failure mode does not apply to +routers. + +Verified (LAN host → gateway → local router → mesh → far router, and back): nh3-docker→ana-scale +9 ms, esh-docker-vm→ana-scale and →nh3-scale 0% loss, ana-docker→nh3-scale and →esh-scale 0% +loss. All three sites can reach mesh addresses from plain LAN hosts with no client installed. + +**LAN-resident clients (nh3-dev) keep `--accept-routes=false`:** they reach other sites via +their gateway like any LAN host. `--accept-routes` is for roaming devices (laptop/iPad off-site) +only. Consequence: a LAN-resident client is reachable by its mesh IP only from the mesh, not +from other sites' LANs (ana-docker→100.64.0.4 fails by design; →100.64.0.1 works). + +**Enrolling GUI devices (Mac/iPad) without OIDC:** the apps do not take a pre-auth key. Point +the app at `https://headscale.phasefinal.com`, it opens a registration page showing a +`headscale nodes register --user pfi --key mkey:…` command; run that on nh3-headscale +(`pct exec 106 -- headscale nodes register --user 1 --key `). CLI Linux/macOS builds can +use the vaulted client key instead.