fix: disable Grafana enforce_domain to allow LAN proxy access #6

Merged
greg merged 1 commits from klaatu/nixos:fix/grafana-enforce-domain into main 2026-03-25 22:42:17 +00:00
1 Commits
Author SHA1 Message Date
root 053e383046 fix: disable Grafana enforce_domain to allow LAN proxy access
buildbot/nix-build Build done.
buildbot/nix-eval Build done. (1 warning)
With enforce_domain = true, Grafana redirects any request not matching
the configured domain (hosea.shire-zebra.ts.net) back to that hostname.
Since the nginx proxy serves Grafana at grafana.thehellings.lan, every
proxied request gets redirected to the Tailscale address, making the
proxy useless for non-Tailscale clients.

The domain setting is still correct for cookie scoping; enforce_domain
is only needed if direct port access is a concern, which is mitigated
by the firewall (port 3001 is not open on the LAN).
2026-03-25 17:40:38 -05:00