---
name: oracle-tailscale
description: Use when exposing an Oracle desk across the user's own Tailscale tailnet.
---

> Oracle native tools: `oracle_cli`, `vault_status`, `signer_status`, `signer_execute`. Use YOUR tailnet only.

# Tailscale (your tailnet)

Use Tailscale so **your** machines reach **your** Oracle desk. Do not publish the desk to the public internet. Do not bind exec/signer to `0.0.0.0`.

## Rules

1. Use a MagicDNS name or the 100.x address of **this install's** node. Never paste a third-party 100.x.
2. Data/public plane may listen on the tailnet IP if you want remote `oracle` reads.
3. Local signer stays `127.0.0.1`. Vault keys do not ride the tailnet.
4. Confirm `tailscale status` shows only nodes you own before opening ports.

## Client env (placeholders)

```bash
# ~/.config/oracle/env  (0600)
ORACLE_DESK_URL=http://YOUR_NODE:8799
ORACLE_DATA_URL=http://YOUR_NODE:8799
ORACLE_PUBLIC_URL=http://YOUR_NODE:8799
```

Replace `YOUR_NODE` with your MagicDNS hostname. Verify with `oracle doctor` / `oracle scan chains`.

## Not this skill

Fleet boxes, someone else's Arch, shared operator wallets, GitHub admin packs.
