--- name: gateway-domain description: Give a tailnet box a real public HTTPS domain (.gtest.commoninternet.net) by mapping it on the shared testing gateway. Use when an agent needs a publicly reachable URL for a box with no public IP — an OAuth callback, a webhook receiver, a demo link, an ACME challenge. Covers the add/remove tool, where the admin password lives, and the traps (your box serves the TLS cert, not the gateway; hostname backends are unremovable). --- # Giving your box a public domain Your machine is on the tailnet with no public IP. You need a real HTTPS URL for it. The **testing gateway** already owns a wildcard DNS record, so every name under `*.gtest.commoninternet.net` resolves to it. Map your name to your tailnet IP and it forwards matching traffic to you. ```bash python3 engine/tools/gateway-domain.py add myapp # myapp.gtest.commoninternet.net -> 100.84.190.30 ``` That is the whole happy path. The backend defaults to **this box's own tailscale IP**, so run it on the machine that will serve the domain. ```bash python3 engine/tools/gateway-domain.py list python3 engine/tools/gateway-domain.py add myapp # this box, port 443 python3 engine/tools/gateway-domain.py add myapp 100.64.1.5 # another box python3 engine/tools/gateway-domain.py add myapp 100.64.1.5:8443 # backend not on 443 python3 engine/tools/gateway-domain.py remove myapp ``` A bare label is expanded to `