Files
esh-pfi-infrastructure/persistent-memory.d/2026-09-06-headscale-mesh-phase1.md
T

1.1 KiB

2026-09-06 — Headscale overlay mesh: control plane + 3 subnet routers live, not cut over

Operator-directed (Headscale over NetBird; NH3 for the control plane, never the colo; 443 direct; names nh3-headscale / nh3-scale / esh-scale / ana-scale). Full state, lessons and next steps in docs/pfi/headscale-mesh-plan.md § Status. Headline facts:

  • https://headscale.phasefinal.com = CT 106 on nh3-pve (10.100.50.45), headscale v0.29.3, LE cert via TLS-ALPN-01, UDM forward tcp/443, DDNS timer on nh3-dev (user systemd).
  • Routers CT 107 nh3-scale / CT 108 esh-scale / CT 114 ana-scale advertise their /16s, approved, SNAT off, accept-routes OFF. nh3-dev enrolled as first client (100.64.0.4).
  • ⚠ Old tunnels (Site Magic, IPsec) are STILL the site-to-site path. The mesh currently rides inside them. Nothing has been disabled.
  • ⚠ Lesson: --accept-routes on a client before a return path for 100.64.0.0/10 exists black-holes that client's LAN (own-site /16 included). Return path first.
  • Pre-auth keys in the vault (headscale/preauth-*-48h-20260906, expire 09-08).
  • infra-ops user now exists on all four PVE hosts (needed apt install sudo first).