summaryrefslogtreecommitdiff
path: root/roles/vpn/files
diff options
context:
space:
mode:
Diffstat (limited to 'roles/vpn/files')
-rw-r--r--roles/vpn/files/config/acl.json11
-rw-r--r--roles/vpn/files/docker-compose.yml4
2 files changed, 11 insertions, 4 deletions
diff --git a/roles/vpn/files/config/acl.json b/roles/vpn/files/config/acl.json
index 2dbb13a..7c28276 100644
--- a/roles/vpn/files/config/acl.json
+++ b/roles/vpn/files/config/acl.json
@@ -1,6 +1,7 @@
{
"groups": {
- "group:admin": ["elizabeth.hunt"]
+ "group:admin": ["elizabeth.hunt"],
+ "group:sys": ["sys"]
},
"tagOwners": {
"tag:prod": ["group:admin"],
@@ -14,8 +15,14 @@
"dst": [
"tag:dev:*",
"tag:private:*",
- "tag:prod:*"
+ "tag:prod:*",
+ "group:sys:*"
]
+ },
+ {
+ "action": "accept",
+ "src": ["group:sys"],
+ "dst": ["group:sys:*"]
}
]
}
diff --git a/roles/vpn/files/docker-compose.yml b/roles/vpn/files/docker-compose.yml
index dc5e961..38d58d3 100644
--- a/roles/vpn/files/docker-compose.yml
+++ b/roles/vpn/files/docker-compose.yml
@@ -7,7 +7,7 @@ services:
- ./config:/etc/headscale
- ./data:/var/lib/headscale
ports:
- - 27896:8080
+ - 127.0.0.1:27896:8080
command: headscale serve
restart: unless-stopped
headscale-ui:
@@ -15,4 +15,4 @@ services:
restart: unless-stopped
container_name: headscale-ui
ports:
- - 9443:443
+ - 127.0.0.1:9443:443