feat(docker): Tailscale integration support via host socket mount

Add the Tailscale CLI to the production image and document how to
  enable Let's Encrypt cert provisioning for virtual printers from a
  Docker-deployed Bambuddy.

  - Dockerfile installs `tailscale` from the official Debian repo. Only
    the CLI is used at runtime; tailscaled itself stays on the host.
    The binary is harmless if the socket isn't mounted — the code logs
    an actionable hint and falls back to self-signed certs.
  - docker-compose.yml adds a commented-out volume mount for
    /var/run/tailscale/tailscaled.sock with inline setup instructions.
  - tailscale.py's docker-socket hint now also fires when the binary is
    present but the daemon socket is unreachable (i.e. the new Docker
    pattern), not just when the binary is missing, so users get the
    actionable "mount the socket" message instead of opaque CLI stderr.

  Enabling the integration on a Docker host:
    1. `curl -fsSL https://tailscale.com/install.sh | sh` on host
    2. `sudo tailscale up`
    3. `sudo tailscale set --operator=<user>` for the container PUID
    4. Uncomment the tailscaled.sock mount in docker-compose.yml
    5. `docker compose up -d --force-recreate`
    6. Flip the Tailscale toggle on the VP card
This commit is contained in:
maziggy
2026-04-24 12:01:22 +02:00
parent a00ce61064
commit e927ccefb1
3 changed files with 38 additions and 3 deletions
+10
View File
@@ -43,6 +43,16 @@ services:
# Backups default to DATA_DIR/backups/ inside the data volume.
# Uncomment to store them externally (e.g. on a NAS share).
#- /path/to/nas/bambuddy-backups:/app/data/backups
#
# Tailscale integration (optional): mount the host's tailscaled socket
# so Bambuddy can request Let's Encrypt certs for virtual printers via
# your tailnet's MagicDNS name. Requires:
# 1. Tailscale installed + `tailscale up` completed on the host
# 2. `sudo tailscale set --operator=<container-user>` on the host so
# the user running the container can call `tailscale cert`
# Without this mount, the Tailscale toggle in the UI is harmless —
# Bambuddy falls back to self-signed certs.
#- /var/run/tailscale/tailscaled.sock:/var/run/tailscale/tailscaled.sock
environment:
- TZ=${TZ:-Europe/Berlin}
# Port BamBuddy runs on (default: 8000)