Passing correct IP from Tailscale plugin to SWAG container?

Hi everyone, I'm trying to set up some subdomains on my server so that they're only accessible via machines connected with Tailscale. I got the configuration working on SWAG's side with the following lines added to the respective server blocks I want to limit access to:



# Allow only Tailscale IP blocks
deny all;


Unfortunately, when I check the logs, all connection attempts from Tailscale are logged as, or the internal Docker network gateway. Therefore, the rule ends up blocking connections.


I'm guessing this is because the connection goes something like my computer -> Tailscale servers -> Tailscale plugin -> Docker network -> SWAG container. Is there a way to properly pass the Tailscale internal address to the SWAG container?

