<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>混合云 on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/%E6%B7%B7%E5%90%88%E4%BA%91/</link><description>Recent content in 混合云 on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Thu, 30 Apr 2026 15:00:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/%E6%B7%B7%E5%90%88%E4%BA%91/index.xml" rel="self" type="application/rss+xml"/><item><title>Playbook：自建 Headscale 零信任 Mesh，混合云内网访问的可执行落地方案</title><link>https://socake.github.io/playbook/zerotrust-mesh-headscale/</link><pubDate>Thu, 30 Apr 2026 15:00:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/playbook/zerotrust-mesh-headscale/</guid><description>数据库公网入口收紧后，开发调试需求仍然真实存在。SSM Port Forwarding 这类临时方案随着资源增加和团队扩大很快变得不可维护。Headscale + Tailscale 提供了一层统一的访问控制：单台 ECS 跑控制面，每个 K8s 集群部署 Subnet Router Pod，ACL 基于身份控制访问范围。本文给出从阿里云 ECS 创建命令、Caddyfile、完整 Headscale 配置、K8s 完整 manifest、运维脚本、客户端接入脚本到故障 runbook 的一整套可直接复制执行的工件，包含 5 个生产中真实踩到的坑。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/playbook/zerotrust-mesh-headscale/featured.jpg"/></item></channel></rss>