Repository navigation
Pi-hole, Copyparty, Node-RED: fix web interface access through Tailscale Serve - #362
Merged
Merged
Conversation
…ale Serve - Pi-hole: forward Serve to port 80 instead of /admin. The /admin target made every redirect of Pi-hole loop, so the web interface never loaded. - Copyparty: serve /w, the path where the stack mounts the shared folder. The config pointed at /data, which does not exist in the container. - Node-RED: forward Serve to port 1880, the port Node-RED listens on, and set SERVICEPORT to the same value.
4 tasks done
crypt0rr
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Three stacks could not serve their web interface through Tailscale Serve. Each fix is one value.
compose.yaml): Serve forwarded/tohttp://127.0.0.1:80/admin. Pi-hole redirects to/admin/login, which Serve then forwarded to/admin/admin/login, so the browser looped until it gave up. Serve now forwards tohttp://127.0.0.1:80, and the web interface is athttps://pihole.<tailnet>.ts.net/admin. The root path/answers403, which is Pi-hole's own behaviour.compose.yaml): the built-in config served/data, but the stack mounts the shared folder at/w. Copyparty loggedfilesystem-path did not exist: '/data'and showed nothing. The config now serves/w.compose.yaml,.env): Serve forwarded to port1080, but Node-RED listens on1880, so the Tailnet address answered502. Serve now forwards to1880, andSERVICEPORThas the same value, so the optionalportsblock maps the right port as well.Related Issues
Verification
Each stack ran from a scratch copy, joined to the Tailnet, first with the files from
mainand then with this branch. The requests went tohttps://<name>.<tailnet>.ts.netthrough Tailscale Serve. They were sent from inside the network of the stack, because the Tailnet policy of the test nodes blocks the Docker host.Pi-hole (
pihole/pihole, Pi-hole 6)main/302to/admin/login, then a redirect loop (curl: maximum of 50 redirects)403/admin308to/admin/,302to/admin/login,200(login page)404200Copyparty (
copyparty/ac, Copyparty 1.20.25), with a test folder that holdsprobe.txtmainfilesystem-path did not exist: '/data'/asadmin404200, showsprobe.txt, permissionsread,write,getadmin403201, file is in the host folder/without loginNode-RED (
nodered/node-red, Node-RED 5.0.7)main18801880127.0.0.1:1080127.0.0.1:1880https://<name>.<tailnet>.ts.net/502200docker compose config --quietinservices/pihole,services/copyparty, andservices/nodered: passed.git diff --check: passed.Checklist
Additional Context
/cfg, because the stack shares the root-owned./configfolder with Tailscale. It then disables sessions. This pull request does not change that.