TL;DR Tailscale
Tailscale is installed on every CloudSonic server, providing a private encrypted network for secure access to Prometheus metrics, SSH, and internal services without open ports.
Tailscale is a zero-config VPN built on WireGuard that creates a secure private network between your devices and your CloudSonic server. It is installed on every CloudSonic server and used to restrict access to all monitoring infrastructure, with Prometheus exporters and Grafana accessible only via Tailscale so they are never reachable from the public internet. You can also use Tailscale to SSH into your server from any device on your tailnet without opening SSH to the world.
- Tailscale account
- Tailscale client on local machine
Tailscale for Secure Server Access on CloudSonic
Tailscale on CloudSonic creates a private WireGuard network between your server and any device on your Tailscale account, used primarily to restrict access to monitoring infrastructure. All Prometheus exporters are bound to the Tailscale IP rather than the public interface, meaning Node Exporter, Nginx metrics, PHP-FPM metrics, Redis metrics, and database metrics are completely inaccessible from the public internet. Tailscale also enables secure SSH access to your server from any device on your tailnet without opening port 22 publicly, and can be used within GitHub Actions or GitLab CI pipelines to connect to your server over the private network during automated deployments.
Useful Commands
ssh -p 2222 [email protected]