█████╗ ██████╗ ██████╗███████╗███████╗███████╗
██╔══██╗██╔════╝██╔════╝██╔════╝██╔════╝██╔════╝
███████║██║ ██║ █████╗ ███████╗███████╗
██╔══██║██║ ██║ ██╔══╝ ╚════██║╚════██║
██║ ██║╚██████╗╚██████╗███████╗███████║███████║
╚═╝ ╚═╝ ╚═════╝ ╚═════╝╚══════╝╚══════╝╚══════╝
tailnet-only access to the datrics agent workspace
▚ PART 1 · CONNECT THE VPN (datrics.ai tailnet)
vpn:~$ install tailscale
# macOS / Windows / iOS / Android →
tailscale.com/download
# Linux →
curl -fsSL https://tailscale.com/install.sh | sh && sudo tailscale up
vpn:~$ sign in
open Tailscale →
"Sign in with Google" → your
you@datrics.ai (work, not personal)
device goes to
pending → an admin approves it
(usually within hours)
vpn:~$ # Linux only, once: sudo tailscale set --accept-routes
vpn:~$ tailscale status # should show you connected
what the VPN unlocks:
· Azure staging & databases — subnets 10.0.0.0/16, 10.20.0.0/16 (+ split-DNS for *.postgres.database.azure.com)
· need a whitelisted egress IP? turn on Exit Node → vpn-us-1; your public IP becomes 157.55.176.25 (verify at ip.me). turn it off when done.
· need an EU (Netherlands) IP instead? Exit Node → vpn-nl-1 → 20.61.188.149. client whitelists = vpn-us-1 only
▚ PART 2 · LOG IN TO THE MACHINE (agents-work)
agents-work:~$ # [0] be onboarded by an admin, once:
admin runs add-employee <user> <email> · your <user> = the part of your email before @
agents-work:~$ # [1] connect (Tailscale SSH — no password, no key):
ssh <user>@agents-work.ts.datrics.ai
· authenticated by your tailnet identity · you can log in ONLY as your own account
· first time: accept the host key (yes)
agents-work:~$ # [2] first run — your own Anthropic key:
echo 'export ANTHROPIC_API_KEY=sk-ant-...' >> ~/.bashrc && source ~/.bashrc
claude
isolation & limits:
· your home / ~/.claude / processes are yours only (0750) — teammates can't see them
· per-user caps: ~8 GiB soft / 14 GiB hard RAM, up to 6 CPU cores — nobody can starve the box
· Docker available (you're in the docker group) · long jobs survive logout — use tmux
· system packages: sudo apt install <pkg> (scoped sudo — apt/apt-get only, no password)
▚ PART 3 · PUBLISH TO THE WEB
Every user has a personal subdomain namespace over valid HTTPS (tailnet-only):
https://<name>.<user>.agents-work.ts.datrics.ai # run `my-subdomain` for your exact URLs
agents-work:~$ # static — a page, a report, or a built site:
mkdir -p ~/sites/report && cp analysis.html ~/sites/report/index.html
→ https://report.<user>.agents-work.ts.datrics.ai # clean root — SPA/framework routing works as-is
agents-work:~$ # dynamic — a running app / dev server on a local port:
expose <name> <port> # e.g. expose app 3000 · websockets ok
unexpose <name> # revert that subdomain back to static
how it works:
· a shared nginx maps <name>.<user>… → your ~/sites/<name>/, read via an ACL — the rest of your home stays private (0750)
· expose writes a reverse-proxy vhost pinned to YOUR name and 127.0.0.1:<port> only (you can't touch another user's namespace)
· HTTPS is a real Let's Encrypt *.<user>.agents-work.ts.datrics.ai cert (DNS-01 via Azure DNS, auto-renews); browsers force https here via HSTS — expected & fine
· links resolve on the tailnet only · new subdomains work instantly, no setup · your Claude Code has a publish-web skill that knows all this
▚ STUCK?
· tailscale status — is it up, and are you signed in as @datrics.ai?
· new device may be waiting for admin approval
· check your <user> and that an admin onboarded you
· VPN/DB flaky? toggle Tailscale off/on
contact admin: kk@datrics.ai