Skip to content

ADR-0004: A dedicated LXC owns Headscale subnet routing

  • Status: Accepted
  • Date: 2026-07-01
  • Supersedes: Proxmox pve as the serving router

Context and decision

Subnet forwarding should not be coupled to the hypervisor's normal host role. Unprivileged CT 105 ts-router advertises approved LAN and DMZ routes with Tailscale SNAT enabled.

Alternatives

Keeping pve as router, installing clients on every service, or adding static return routes in OPNsense were considered.

Consequences

CT 105 becomes a remote-access dependency but can be restarted and recovered independently. pve retains approval as rollback evidence but does not serve.

Validation evidence

Headscale showed CT 105 serving 192.168.0.0/24 and 192.168.2.0/24 on 2026-07-17.