# share stack secrets — Tailscale `serve` nodes. # Read via env_file (no ${VAR} interpolation), so this git stack needs no # Portainer UI env vars. See memory portainer-env-interpolation. TZ=America/Chicago # ── Tailscale auth (shared by EVERY ts-* node in this stack) ────────────────── # ONE reusable, NON-ephemeral, TAGGED auth key from: # https://login.tailscale.com/admin/settings/keys ("Generate auth key") # - Reusable: ON - Ephemeral: OFF - Tags: tag:share # Prereq: add "tagOwners": { "tag:share": ["autogroup:admin"] } to your ACLs # first, or key generation rejects the tag. Tagged nodes never expire, so once # the nodes have joined this key is no longer needed (state lives in the volumes). TS_AUTHKEY=tskey-auth-kGQ7kgFizL11CNTRL-HWpbE5TudYTaV2ss4LDmYT7sZ8EddXVH