|
|
||
|---|---|---|
| .. | ||
| Caddyfile.example | ||
| README.md | ||
| bootstrap-to-sms.sh | ||
| http-edge.compose.yml | ||
| ssh-relay.compose.yml | ||
README.md
Taylor sms.taylor-co.com (split DNS) layout
If HTTP DNS for a hostname points at the SMS public IP (e.g. 134.209.x.x) but the
better-argo-tunnels tunnel-server and Traefik live on ingress.nixc.us, you get
HTTP 404 on the public URL while the tunnel and routes are actually healthy on ingress.
Install onto sms (one shot)
From this repo, with SSH to ingress and sms:
cd deploy/sms
export SMS_SSH=root@sms.taylor-co.com
export INGRESS_SSH=root@ingress.nixc.us
./bootstrap-to-sms.sh
This will:
scpthe tunnelauthorized_keysfromingress(/home/tunnel/.ssh/authorized_keysby default).scpthe compose files andCaddyfile.exampleto/opt/taylor-sms-edge/.- Append (deduped) those public keys to
/root/.ssh/authorized_keyson SMS, with a timestamped backup of the previous file if one existed. Override withSMS_KEYS_USER=….
To use a local file instead of pulling from ingress: export AUTHORIZED_KEYS_LOCAL=/path/to/keys.
To keep the same Raspberry Pi tunnel clients and keys and still use SMS in front:
1. SSH relay (optional)
Run ssh-relay.compose.yml on the SMS host so Pis can set:
TUNNEL_SERVER=sms.taylor-co.com:2222
Traffic is forwarded to the real tunnel-server (default ingress.nixc.us:2222).
- Authorize the same client public key on ingress (
authorized_keysfor the tunnel user) — the relay is TCP-only, not another SSH key step.
2. HTTPS edge (this fixes 404 for names that resolve to SMS)
Run http-edge.compose.yml with a Caddyfile (see Caddyfile.example):
- Set
INGRESSto the IP or stable hostname of the Traefik host (ingresspublic IP/hostname). - Add one Caddy
serverblock per Taylor hostname (e.g.king73.taylor-co.com).
Caddy gets Let’s Encrypt certs for those names on the SMS machine and reverse-proxies to
https://$INGRESS, preserving Host:, so Traefik on ingress still matches Host(\...`)` rules.
Security note: the proxy uses tls_insecure_skip_verify to the origin because the
connection is often IP-based. Restrict network path (same DC/VPC) or pin to a private IP if
you can.
3. Simpler alternative
Point the Taylor hostnames’ A/AAAA at ingress.nixc.us and skip the SMS HTTP edge.
Files
| File | Role |
|---|---|
bootstrap-to-sms.sh |
scp keys from ingress + these files to /opt/taylor-sms-edge, merge keys on SMS |
ssh-relay.compose.yml |
TCP :2222 → upstream tunnel-server |
http-edge.compose.yml |
Caddy on :80 / :443 → Traefik (HTTPS upstream) |
Caddyfile.example |
Template for one hostname; duplicate blocks as needed |