summary refs log tree commit diff stats
diff options
context:
space:
mode:
authorAlan Pearce2024-12-03 14:50:54 +0100
committerAlan Pearce2024-12-03 14:50:54 +0100
commit8940ca006ef2ab98862060a9b0c71f8a0d6d4919 (patch)
tree97d9c2c6f4ca9f838717a1d9166fc54370d5bbfc
parent6bb58bbb6db5914b6177041714e625a0fe9ae5b1 (diff)
downloadnixfiles-8940ca006ef2ab98862060a9b0c71f8a0d6d4919.tar.lz
nixfiles-8940ca006ef2ab98862060a9b0c71f8a0d6d4919.tar.zst
nixfiles-8940ca006ef2ab98862060a9b0c71f8a0d6d4919.zip
linde: restrict access to paperless by tailnet
-rw-r--r--system/linde.nix1
1 files changed, 1 insertions, 0 deletions
diff --git a/system/linde.nix b/system/linde.nix
index bf89c30d..4e93ca33 100644
--- a/system/linde.nix
+++ b/system/linde.nix
@@ -880,6 +880,7 @@ in
                 }
                 forward_auth unix//run/tailscale-nginx-auth/tailscale-nginx-auth.sock {
                   uri /auth
+                  header_up Expected-Tailnet "${ts-domain}."
                   header_up Remote-Addr {remote_host}
                   header_up Remote-Port {remote_port}
                   header_up Original-URI {uri}