Homelab
Tailscale Router Under Enforcement
The Post-DNAT NetworkPolicy Trap, Third Face: Letting the Tailscale Subnet Router Reach MetalLB Services Under kube-router
Overview
Testing the finished Gateway migration from off the LAN through Tailscale, FileBrowser and the Longhorn UI refused to connect while the node VIP kept working. The cause is the trap the enforcement article teaches with the frpc lanes and the public-tier appendix meets again with the proxy's container port: egress is evaluated after kube-proxy rewrites a Service address to its backend pod. The subnet router's egress allowed the LAN network and nothing else on the way to a Service, so every MetalLB Service had been unreachable through it from the moment enforcement went live. One rule fixes it, and this appendix records the third face of the trap so it can be recognized the next time.
Having trouble? See v2.12.1 for reference.
This article isn't ready yet
Check back soon for the full article.