# Tailscale
Secure mesh VPN connecting all Kaburu infrastructure nodes using WireGuard. No port forwarding required anywhere — all nodes reach each other directly over the Tailscale subnet.
Account: `[email protected]`
## Nodes
| Hostname | Tailscale IP | Role |
| ———- | ————- | —— |
| kaburuaibox | 100.120.18.44 | AI nerve centre — Z840 |
| kaburusvr.uk | 100.112.54.2 | Hetzner VPS — hosting |
| kabururd | 100.122.46.3 | Hetzner CX23 — RustDesk relay (moved 2026-08-05) |
| ubuntu-svr | 100.101.7.86 | Minisforum — Frigate/Omada |
| firewall | 100.127.64.74 | OPNsense router |
| truenas-scale | 100.74.178.14 | NAS storage |
## Access restrictions
- SSH to Hetzner (kaburusvr.uk) is only accessible via Tailscale — outbound SSH from LAN is blocked by OPNsense policy - Open WebUI: `http://100.120.18.44:3000` — Tailscale only - Hermes dashboard: `http://100.120.18.44:8765` — Tailscale only - Hermes agent uses Tailscale to SSH to Hetzner for monitoring
## Adding a new device
1. Install Tailscale on the device 2. Authenticate with `[email protected]` (Google or Microsoft login) 3. Device joins the tailnet automatically — no configuration needed
## Notes
- Tailscale IPs are stable and do not change - The Hermes SSH key (`/opt/hermes/config/hetzner_id_ed25519`) authenticates to Hetzner via Tailscale IP 100.112.54.2