2.1 KiB
2.1 KiB
Tailscale Subnet Router LXC Deployment — CHECKPOINT
Status: 2026-06-11 22:20 UTC
Progress
- ✅ 3030 (MK33): Online, advertising
192.168.0.0/18, route approved - ✅ 3031 (MK33): FIXED — tailscaled running, route approved by Bobby in console
- ✅ Skill created:
tailscale-lxc-subnet-router— documents 3031 fix + critical route hijacking pitfall - ✅ Artemis LAN partition FIXED:
tailscale set --accept-routes=falserestored direct L2 routing - ✅ Bobby can now SSH directly to Artemis (was blocked by Tailscale routing table hijacking)
- ⏳ 3032/3033 (MK50): Terraform ready — awaiting deploy signal
Critical Discovery — Tailscale Route Hijacking
Root cause of Artemis "network partition": tailscale set --accept-routes=true installed kernel routing rules (table 52) that redirected ALL 192.168.0.0/18 traffic through tailscale0 instead of direct eno1.
| Before Fix | After Fix |
|---|---|
ip route get 192.168.50.41 → dev tailscale0 |
ip route get 192.168.50.41 → dev eno1 ✅ |
| Bobby could NOT SSH to Artemis via LAN | Bobby CAN SSH to Artemis via LAN ✅ |
| Artemis could NOT reach fleet nodes via LAN | Artemis routing table correct (pings still fail for some nodes — separate issues) |
Standing rule: Artemis must NOT accept-routes while advertising 192.168.0.0/18. Subnet routers (3030/3031) handle tailnet→LAN; Artemis stays direct L2 for LAN peers.
3031 Fix Summary
Root cause: /etc/default/tailscaled missing PORT variable → systemd unit --port=${PORT} expanded to --port= → INVALIDARGUMENT
Solution: pct exec from MK33 host, wrote PORT=41641 + FLAGS=, daemon-reload, restart, re-auth with route-capable key
Credentials
- Latest LXC auth key stored in
fleet.envasTAILSCALE_AUTH_KEY_LXC - MK50 PVE API token exists in
fleet.env
Next Actions
- Deploy 3032/3033 on MK50 via Terraform when Bobby signals
- Verify all 4 LXCs advertise
192.168.0.0/18and routes approved - Investigate remaining LAN unreachability for MK50/MK33/Shield (may be their own accept-routes conflicts)