tailnet-only access to the datrics agent workspace

▚ PART 1 · CONNECT THE VPN (datrics.ai tailnet)

vpn:~$ install tailscale # macOS / Windows / iOS / Android → tailscale.com/download # Linux → curl -fsSL https://tailscale.com/install.sh | sh && sudo tailscale up vpn:~$ sign in open Tailscale → "Sign in with Google" → your you@datrics.ai (work, not personal) device goes to pending → an admin approves it (usually within hours) vpn:~$ # Linux only, once: sudo tailscale set --accept-routes vpn:~$ tailscale status # should show you connected
what the VPN unlocks: · Azure staging & databases — subnets 10.0.0.0/16, 10.20.0.0/16 (+ split-DNS for *.postgres.database.azure.com) · need a whitelisted egress IP? turn on Exit Node → vpn-us-1; your public IP becomes 157.55.176.25 (verify at ip.me). turn it off when done. · need an EU (Netherlands) IP instead? Exit Node → vpn-nl-1 → 20.61.188.149. client whitelists = vpn-us-1 only

▚ PART 2 · LOG IN TO THE MACHINE (agents-work)

agents-work:~$ # [0] be onboarded by an admin, once: admin runs add-employee <user> <email> · your <user> = the part of your email before @ agents-work:~$ # [1] connect (Tailscale SSH — no password, no key): ssh <user>@agents-work.ts.datrics.ai · authenticated by your tailnet identity · you can log in ONLY as your own account · first time: accept the host key (yes) agents-work:~$ # [2] first run — your own Anthropic key: echo 'export ANTHROPIC_API_KEY=sk-ant-...' >> ~/.bashrc && source ~/.bashrc claude
isolation & limits: · your home / ~/.claude / processes are yours only (0750) — teammates can't see them · per-user caps: ~8 GiB soft / 14 GiB hard RAM, up to 6 CPU cores — nobody can starve the box · Docker available (you're in the docker group) · long jobs survive logout — use tmux · system packages: sudo apt install <pkg> (scoped sudo — apt/apt-get only, no password)

▚ PART 3 · PUBLISH TO THE WEB

Every user has a personal subdomain namespace over valid HTTPS (tailnet-only): https://<name>.<user>.agents-work.ts.datrics.ai # run `my-subdomain` for your exact URLs agents-work:~$ # static — a page, a report, or a built site: mkdir -p ~/sites/report && cp analysis.html ~/sites/report/index.html → https://report.<user>.agents-work.ts.datrics.ai # clean root — SPA/framework routing works as-is agents-work:~$ # dynamic — a running app / dev server on a local port: expose <name> <port> # e.g. expose app 3000 · websockets ok unexpose <name> # revert that subdomain back to static
how it works: · a shared nginx maps <name>.<user>… → your ~/sites/<name>/, read via an ACL — the rest of your home stays private (0750) · expose writes a reverse-proxy vhost pinned to YOUR name and 127.0.0.1:<port> only (you can't touch another user's namespace) · HTTPS is a real Let's Encrypt *.<user>.agents-work.ts.datrics.ai cert (DNS-01 via Azure DNS, auto-renews); browsers force https here via HSTS — expected & fine · links resolve on the tailnet only · new subdomains work instantly, no setup · your Claude Code has a publish-web skill that knows all this

▚ STUCK?

· tailscale status — is it up, and are you signed in as @datrics.ai? · new device may be waiting for admin approval · check your <user> and that an admin onboarded you · VPN/DB flaky? toggle Tailscale off/on contact admin: kk@datrics.ai

‹ back to home