1. The hook: the self-hosting dilemma
Frame the exact tension this setup resolves.
- Running your own agents and data means the services live on home/lab machines behind a residential NAT.
- The naive fixes are bad: port-forwarding exposes your network; a VPS-everything approach defeats the point and the economics.
- Thesis: split the problem — private by default, public by exception — and use the right tool for each half.
2. The mental model: two planes of traffic
Give the one diagram-in-words the whole piece hangs on.
- Internal plane (you ↔ your machines, machine ↔ machine): Tailscale.
- Public plane (the world ↔ a chosen few services): Cloudflare Tunnel.
- The rule of thumb: if a human other than you should never see it, it never leaves the Tailscale plane.
3. Tailscale: the private mesh
Explain what it is and why it's the backbone, without a vendor-pitch tone.
- WireGuard under the hood, but with the key-exchange and NAT-traversal pain removed — nodes just find each other.
- MagicDNS: stable names for machines instead of chasing IPs; what this does for agent-to-agent and agent-to-DB calls.
- ACLs as code: expressing "the agent node may reach the database node on this port, and nothing else."
- Tailscale SSH for admin access without managing keys or opening port 22 to anyone.
4. Cloudflare Tunnel: the public doorway
The complementary half — exposing specific services safely.
cloudflaredmakes an outbound connection to Cloudflare — no inbound ports, no origin IP leaked.- Mapping a hostname to a local service; how a static site or a dashboard on a home machine becomes a real URL.
- Why this is strictly better than port-forwarding: the origin is never directly addressable from the internet.
5. Gating the public surfaces
The security posture — concrete and demonstrable.
- Public-but-private: using Cloudflare Access / auth to put specific paths (a dashboard, an admin view) behind a login while the marketing pages stay open.
- Edge hardening that comes along for free: HSTS, blocking paths that should never be served (e.g.
/.git/), and redirect rules for gated areas. - A worked example: a mostly-public portfolio site where a few routes return a redirect-to-auth instead of content.
6. Where the AI agents fit
Connect the infrastructure back to the actual workload.
- Agents and their state living on internal nodes, talking to each other over the mesh with human-in-the-loop approval gates.
- Why you want this isolation for anything that can take consequential action — the network boundary is part of the safety model.
- Reaching the agents from your phone via Tailscale without ever exposing them publicly.
7. Failure modes and operational notes
Earn credibility by naming what's annoying.
- Key/cert and token management: where the secrets live and how to escrow them off-machine.
- What breaks when a node is offline, and how MagicDNS/ACLs behave under partial outages.
- Debugging "it works on the mesh but not publicly" — the usual suspects in a tunnel config.
8. When not to do this
Judgment section — the honest counterweight.
- Where managed hosting is simply the right call, and where self-hosting's control and cost actually pay off.
- The real maintenance tax, stated plainly.
Takeaway to land: "private by default, public by exception" lets one person run real infrastructure with an attack surface they can actually reason about.