fix: enable netbird agent network on existing proxy

Agent Network needs NB_PROXY_PRIVATE=true on the single existing
reverse-proxy, not a separate container. The previous standalone
an-proxy had no TLS cert (removed certs volume + ACME) and crashed
with 'open certs/tls.crt: no such file', so its overlay peer IP
(100.91.226.149) never came up and drop.p.az-gruppe.com timed out.

The auto-generated endpoint under the existing *.p.az-gruppe.com
wildcard (drop.p.az-gruppe.com -> overlay peer IP via MagicDNS) is
the correct URL; the invented a.az-gruppe.com had no DNS.

- set NB_PROXY_PRIVATE=true on netbird-proxy (keeps ACME + certs)
- remove standalone netbird-an-proxy container, anProxyIp, anProxyDomain
- drop netbird-an-proxy-env secret (nix refs + age file)
This commit is contained in:
2026-08-04 12:47:23 +02:00
parent bdfeb1f36c
commit 165ac75ba9
4 changed files with 8 additions and 40 deletions
-1
View File
@@ -40,7 +40,6 @@ in {
"secrets/netbird-dashboard-env.age".publicKeys = systems ++ users;
"secrets/netbird-server-env.age".publicKeys = systems ++ users;
"secrets/netbird-proxy-env.age".publicKeys = systems ++ users;
"secrets/netbird-an-proxy-env.age".publicKeys = systems ++ users;
"secrets/outline-env.age".publicKeys = systems ++ users;
"secrets/snipe-it-app-key.age".publicKeys = systems ++ users;
"secrets/snipe-it-db-password.age".publicKeys = systems ++ users;