Skip to content

Commit

Permalink
Add autogroup:shared
Browse files Browse the repository at this point in the history
Otherwise, users who has autogroup:shared access cannot access anywhere.
Also, set a URL alias for humans since the page has some level of access
traffic.
  • Loading branch information
nobuto-m committed Dec 26, 2024
1 parent f30a417 commit 174d7dc
Show file tree
Hide file tree
Showing 14 changed files with 332 additions and 312 deletions.
8 changes: 6 additions & 2 deletions content/ja/post/2023/1690694899/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,14 @@
# Documentation: https://wowchemy.com/docs/managing-content/

title: "TailscaleのACLを設定した"
slug: 1690694899
slug: configure-tailscale-acl
subtitle: ""
summary: ""
authors: []

aliases:
- 1690694899

tags: []
categories: []
keywords: []
Expand All @@ -17,7 +20,7 @@ share: false

year: 2023
date: 2023-07-30T14:28:19+09:00
lastmod: 2023-07-30T14:28:19+09:00
lastmod: 2024-12-26T15:54:55+09:00

featured: false
draft: false
Expand Down Expand Up @@ -77,6 +80,7 @@ ACLは初期ルールをコメントアウトするとデフォルトが全拒
//{"action": "accept", "src": ["*"], "dst": ["*:*"]},
{"action": "accept", "src": ["tag:client"], "dst": ["*:*"]},
{"action": "accept", "src": ["tag:scraper"], "dst": ["tag:server:9100"]},
{"action": "accept", "src": ["autogroup:shared"], "dst": ["tag:server:*"]},
],
}
```
Expand Down
2 changes: 1 addition & 1 deletion docs/ja/index.json

Large diffs are not rendered by default.

7 changes: 4 additions & 3 deletions docs/ja/index.xml
Original file line number Diff line number Diff line change
Expand Up @@ -1109,9 +1109,9 @@ necessary to do so.</p>

<item>
<title>TailscaleのACLを設定した</title>
<link>https://nobuto-m.github.io/ja/post/2023/1690694899/</link>
<link>https://nobuto-m.github.io/ja/post/2023/configure-tailscale-acl/</link>
<pubDate>Sun, 30 Jul 2023 14:28:19 +0900</pubDate>
<guid>https://nobuto-m.github.io/ja/post/2023/1690694899/</guid>
<guid>https://nobuto-m.github.io/ja/post/2023/configure-tailscale-acl/</guid>
<description>&lt;p&gt;&lt;a href=&#34;https://tailscale.com/kb/1018/acls/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;TailscaleのACL&lt;/a&gt;は簡単に設定できることは知ってたけど、自分のデバイス間は全許可というデフォルトのポリシーのまま使っていた。&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-json&#34; data-lang=&#34;json&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;acls&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;
Expand Down Expand Up @@ -1151,6 +1151,7 @@ necessary to do so.&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;//{&amp;#34;action&amp;#34;: &amp;#34;accept&amp;#34;, &amp;#34;src&amp;#34;: [&amp;#34;*&amp;#34;], &amp;#34;dst&amp;#34;: [&amp;#34;*:*&amp;#34;]},
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;&amp;#34;action&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;accept&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;src&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;tag:client&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;dst&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;*:*&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;&amp;#34;action&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;accept&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;src&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;tag:scraper&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;dst&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;tag:server:9100&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;&lt;span class=&#34;nt&#34;&gt;&amp;#34;action&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;accept&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;src&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;autogroup:shared&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt; &lt;span class=&#34;nt&#34;&gt;&amp;#34;dst&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;tag:server:*&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]},&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt; &lt;span class=&#34;p&#34;&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
Expand All @@ -1174,7 +1175,7 @@ necessary to do so.&lt;/p&gt;
&lt;figure id=&#34;figure-tagscraperのプレビュー&#34;&gt;
&lt;div class=&#34;d-flex justify-content-center&#34;&gt;
&lt;div class=&#34;w-100&#34; &gt;&lt;img alt=&#34;`tag:scraper`のプレビュー&#34;
src=&#34;https://nobuto-m.github.io/ja/post/2023/1690694899/featured.png&#34;
src=&#34;https://nobuto-m.github.io/ja/post/2023/configure-tailscale-acl/featured.png&#34;
loading=&#34;lazy&#34; data-zoomable /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;figcaption&gt;
&lt;code&gt;tag:scraper&lt;/code&gt;のプレビュー
Expand Down
Loading

0 comments on commit 174d7dc

Please sign in to comment.