네트워크와 접근 제어

public IP, wg-admin, Headscale tailnet, lab NAT 경계

네트워크와 접근 제어 public IP, wg-admin, Headscale tailnet, lab NAT 경계 공인 IP wg-admin 10.100.0.0/24 랩 내부 NAT 인터넷 · 80/443/10022/2323 · Architecture component 인터넷 80/443/10022/2323 관리자 · SSH · deploy · Architecture component 관리자 SSH · deploy VPN 사용자 · Tailscale client · Architecture component VPN 사용자 Tailscale client eta public · 141.164.53.203 · 공인 IP eta public 141.164.53.203 psi public · 117.16.251.37 · 공인 IP psi public 117.16.251.37 Headscale · hs.sjanglab.org · Architecture component Headscale hs.sjanglab.org eta wg · 10.100.0.1 · wg-admin 10.100.0.0/24 eta wg 10.100.0.1 psi wg · 10.100.0.2 · wg-admin 10.100.0.0/24 psi wg 10.100.0.2 rho wg · 10.100.0.3 · wg-admin 10.100.0.0/24 › 랩 내부 NAT rho wg 10.100.0.3 tau wg · 10.100.0.4 · wg-admin 10.100.0.0/24 › 랩 내부 NAT tau wg 10.100.0.4 Tailnet · 100.64.0.0/10 · Architecture component Tailnet 100.64.0.0/10 psi services · tag:ai · Architecture component psi services tag:ai rho services · tag:monitoring · 랩 내부 NAT rho services tag:monitoring tau services · tag:apps · 랩 내부 NAT tau services tag:apps 공개 포트 공인 IP host SSH WireGuard WireGuard WireGuard OIDC login Magic DNS tag:ai tag:monitoring tag:apps Legend External Security Backend Message bus

방화벽 원칙

  • • wg-admin 인터페이스는 신뢰 관리망
  • • rho/tau는 NAT 뒤에서 WireGuard로 연결
  • • 사용자 서비스는 Headscale ACL tag로 제한