With enforce_domain = true, Grafana redirects any request not matching the configured domain (hosea.shire-zebra.ts.net) back to that hostname. Since the nginx proxy serves Grafana at grafana.thehellings.lan, every proxied request gets redirected to the Tailscale address, making the proxy useless for non-Tailscale clients. The domain setting is still correct for cookie scoping; enforce_domain is only needed if direct port access is a concern, which is mitigated by the firewall (port 3001 is not open on the LAN).