Tailscale on CloudSonic

Access your server securely from any device without exposing SSH to the public internet

TL;DR Tailscale

Tailscale is installed on every CloudSonic server, providing a private encrypted network for secure access to Prometheus metrics, SSH, and internal services without open ports.

Tailscale is a zero-config VPN built on WireGuard that creates a secure private network between your devices and your CloudSonic server. It is installed on every CloudSonic server and used to restrict access to all monitoring infrastructure, with Prometheus exporters and Grafana accessible only via Tailscale so they are never reachable from the public internet. You can also use Tailscale to SSH into your server from any device on your tailnet without opening SSH to the world.

Prerequisites

Tailscale for Secure Server Access on CloudSonic

Tailscale on CloudSonic creates a private WireGuard network between your server and any device on your Tailscale account, used primarily to restrict access to monitoring infrastructure. All Prometheus exporters are bound to the Tailscale IP rather than the public interface, meaning Node Exporter, Nginx metrics, PHP-FPM metrics, Redis metrics, and database metrics are completely inaccessible from the public internet. Tailscale also enables secure SSH access to your server from any device on your tailnet without opening port 22 publicly, and can be used within GitHub Actions or GitLab CI pipelines to connect to your server over the private network during automated deployments.

Warning After running script 10, SSH is only accessible via Tailscale; ensure Tailscale is running on your local machine before closing your existing SSH session or you will be locked out.

Useful Commands

ssh -p 2222 cloudsonic@100.x.x.x