Skip to main content

Tailscale Infrastructure

Tailscale Infrastructure

Private mesh network for secure access to all BlueFly services.


Tailnet Information

  • Tailnet: tailcf98b3.ts.net
  • MagicDNS: Enabled
  • Zero Trust: WireGuard encryption
  • Account: flux423@mac.com

Active Devices

DeviceHostnameTailscale IPRoleStatus
Synology NASblueflynas.tailcf98b3.ts.net100.104.119.76Always-on storageActive
Vast.ai GPUvastai-gpu.tailcf98b3.ts.net100.76.214.65GPU computeOn-demand
Mac M4 Probluefly-m4.tailcf98b3.ts.net100.108.129.7Primary devWhen online
iPhoneiphone-t.tailcf98b3.ts.net100.67.125.25Mobile accessActive
GL-BE3600gl-be3600.tailcf98b3.ts.net100.116.110.123Subnet routerActive

Quick Access URLs

From Phone (via Tailscale app)

ServiceURL
NAS DSMhttps://blueflynas.tailcf98b3.ts.net:5001
MinIO S3http://blueflynas.tailcf98b3.ts.net:9000
MinIO Consolehttp://blueflynas.tailcf98b3.ts.net:9001
Ollama APIhttp://vastai-gpu.tailcf98b3.ts.net:11434
vLLM APIhttp://vastai-gpu.tailcf98b3.ts.net:8000

Network Principle

Tailscale = Private Access ONLY Cloudflare = Public Ingress ONLY

These planes must NEVER be mixed.

  • Use Tailscale for: Admin access, phone access, inter-service communication
  • Use Cloudflare for: GitLab webhooks, public APIs

Subnet Routing

RouterSubnetStatus
GL-BE3600192.168.8.0/24Approved
NAS (optional)192.168.68.0/24Can enable

Configuration Files

FilePurpose
ConfigurationTailscale setup
DevicesDevice inventory
RoutingSubnet routing
ACL PolicyAccess controls