Kristoffer Dalby
21f6e46fb8
state: refresh policy nodes inside the peer map build
...
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
311d9323e0
policy/v2: count node-driven recompiles
...
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
05fc17bc85
state: decide whole-peer updates at each caller, not in persist
...
persistNodeAndRefreshPolicy no longer fabricates NodeAdded; RenameNode
and SetNodeTags add it since both are peer visible.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
86b4f7c430
state,policy: add peer map and NodeStore write benchmarks
...
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
d813144f3b
state: fail when a Node field is not classified for peer map reuse
...
Every exported types.Node field is pinned to relation/election/payload
in nodeFieldImpact; a new field fails until classified, and each
relation/election field gets a mutation check against updateChanges.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
1613023be9
state: check NodeStore adjacency against a full peer map build
...
Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9ce160ed5b
policy/v2: keep the live policy when SetPolicy fails to compile
...
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
3417e4cb77
policy/v2: add via exit node captures with unrelated rules
...
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
adbf4ba0f0
servertest: compare via capture filters as rule sets
...
Headscale merges rules sharing sources; SaaS does not. Compare
(src, dst, ports) triples, keyed by every captured node's addresses.
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7f5fdbe5d2
policy/v2: send exit nodes every user's autogroup:self rules
...
Same as other rules: exit routes contain every self destination.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
61d1599393
policyutil: send approved exit nodes every rule
...
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7efd22d0bb
policy/v2: let autogroup:internet rules lift via exit steering
...
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
c700b32eec
policy/v2: stop narrow rules from undoing via exit steering
...
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.
Fixes #3493
2026-09-30 17:20:46 +02:00
yuwk
3486ab2fc2
docs: fix "is may be" grammar in policy reference
...
Signed-off-by: yuwk <1729065730@qq.com >
2026-09-29 18:30:38 +02:00
yuwk
32939914d3
docs: fix "specfic" typo in policy reference
...
Signed-off-by: yuwk <1729065730@qq.com >
2026-09-29 18:30:38 +02:00
github-actions[bot]
6d2fa015c4
Update VOUCHED list
...
https://github.com/juanfont/headscale/issues/3510#issuecomment-5890061652
2026-09-29 18:25:29 +02:00
Kristoffer Dalby
00663fbbfe
nix: run the headscale VM test on the test kit
...
Drops nginx, the cert and dead ip_prefixes. Proves DERP relay and TLS noise
after a restart, and puts nix/module.nix under CI.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
200c2c01e8
nix: add a NixOS test kit for Tailscale clients
...
nixosModules.testkit makes a node a control server every client joins without
trust setup; testkit-peer joins it with hs-join.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
35a90e0018
derp: serve a self-signed TLS listener for tests
...
HEADSCALE_DEBUG_INSECURE_TLS_LISTEN_ADDR serves the router over throwaway TLS
and marks the embedded region InsecureForTests: TLS DERP for CA-less clients
(tailscale-rs, Android), plus the :443 noise fallback Go redials use.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
740f930523
nix: list flake systems explicitly
...
eachDefaultSystem includes x86_64-darwin, which nixpkgs dropped; nix flake
show failed evaluating it.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
d48883ca9b
nix: write split DNS where headscale reads it
...
module.nix emitted dns.split; headscale reads dns.nameservers.split, so the
typed option was silently ignored. Old path now asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
f0ff407c05
nix: stop module.nix writing the deprecated ephemeral key
...
Its default made headscale warn on every start. The camelCase rename now
targets node.ephemeral.inactivity_timeout, and the old path asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
62f89ca25d
cli: accept a user name in preauthkeys create --user
...
Resolved through lookupUser like the users commands, so scripts skip the
users list round trip. Digit-only values stay IDs.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
715c5a4a1c
cli: split the user lookup out of resolveSingleUser
...
Lets commands with their own flags resolve a user the same way.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
fbb04c5611
testcapture: read captures through util.ReadFileByExt
...
Drops its private HuJSON decoder.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
906016beb4
dns: pick the extra_records_path format by file extension
...
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
dd8ce695cf
derp: pick the derp.paths format by file extension
...
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
d20a412079
util: decode files by their extension
...
UnmarshalByExt picks JSON, HuJSON or YAML from the file name; content can't
tell them apart, since YAML parses JSON syntax.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
90732bdaaf
derp: drop regions set to null in derp.paths
...
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
99cbba7aff
.github: run the version bump daily
...
AGENTS.md says the tool "opens one pull request a day", but the workflow
only had workflow_dispatch, so since it merged it has run zero times.
2026-09-28 11:56:25 +02:00
github-actions[bot]
8af711b50e
all: regenerate generated files
2026-09-28 07:28:19 +02:00
github-actions[bot]
3603418d70
.github: bump 13 action pins
2026-09-28 07:28:19 +02:00
github-actions[bot]
f0591d9047
Dockerfile: bump rust 1.95-trixie to 1.98-trixie
2026-09-28 07:28:19 +02:00
github-actions[bot]
adde0b6a4c
Dockerfile: bump node 24-alpine to 26-alpine
2026-09-28 07:28:19 +02:00
github-actions[bot]
41dc3ae539
Dockerfile: bump alpine 3.23 to 3.24
2026-09-28 07:28:19 +02:00
github-actions[bot]
3512566963
Dockerfile: bump golang builders to 1.27.1 / 1.27.1
2026-09-28 07:28:19 +02:00
github-actions[bot]
30bc139820
go.mod: update dependencies
2026-09-28 07:28:19 +02:00
github-actions[bot]
8548583f0e
docs: raise 3 docs requirement floors
2026-09-28 07:28:19 +02:00
github-actions[bot]
d82f90aa87
Makefile: bump oapi-codegen v2.7.1 to v2.8.0
2026-09-28 07:28:19 +02:00
github-actions[bot]
14daea7622
flake.lock: update flake-checks, nixpkgs, treefmt-nix
2026-09-28 07:28:19 +02:00
Florian Preinstorfer
53113e2a67
Reformat pr-unvouched-message
2026-09-26 08:48:10 +02:00
Kristoffer Dalby
393dd3e2d9
db: store all credentials in one SHA-256-hashed table
...
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00
Kristoffer Dalby
e90500e3a9
db: drop migrations predating 0.29
...
Only 0.29.x -> 0.30 upgrades are supported; checkMinimumMigration refuses
older databases instead of silently skipping the removed steps.
2026-09-26 00:33:12 +02:00
Michael Lopez
04d1e3c83f
db: name the nodes that block a user deletion
...
The error only said the user still has nodes, which the CLI prompt did
not mention at all. Wrap ErrUserStillHasNodes with the ID and hostname
of every blocking node so the operator knows what to remove. Run the
DestroyUser test table on Postgres as well as SQLite, since the two
schemas define different foreign-key actions; the Postgres variant
skips without a local server.
2026-09-25 23:56:02 +02:00
MsfPablo
d60bac5c79
db: reject unknown OAuth client scopes at creation ( #3424 )
...
Unknown scopes grant nothing, so clients were silently under-privileged.
Report every invalid scope at once.
Fixes #3406
2026-09-25 21:24:37 +02:00
Michael Lopez
3746ad20db
cli: distinguish no match from ambiguous match when resolving users
...
resolveSingleUser reported every non-single result as "multiple users
match query", including zero matches. An explicit --identifier 0 was
sent to the API, which treats id=0 as no filter, so it listed every
user and failed as ambiguous. Return a not-found error for zero matches,
list the matching users when several match, and reject a non-positive
identifier before calling the API.
2026-09-25 20:00:15 +02:00
Kristoffer Dalby
e4b4b89448
.github: vouch recent contributors
...
Merged or approved PRs since the list was seeded, plus MichaelGooden.
Updates #3388
2026-09-25 17:31:17 +02:00
Kristoffer Dalby
eebeab3c1e
docs: document joining nodes with an OAuth client
...
Prefix swap, baseURL, every attribute; examples for tailscale up,
container, tsnet, GitHub Action.
2026-09-25 17:09:19 +02:00
Kristoffer Dalby
c3e48f039c
ci: integration-test the tailscale GitHub action against headscale
...
Stand up a nix-built headscale over self-signed TLS with embedded DERP and a
regular node joined via pre-auth, then drive the official tailscale/github-action
against it: connect over OAuth (tskey-client-) and an auth key with ping as the
success gate, and exercise its hostname, version, tailscaled-args, statedir and
args inputs.
2026-09-25 17:09:19 +02:00
Kristoffer Dalby
bb3c0b4cd6
servertest: drive tailscale client oauthkey flow against v2 API
...
Real feature/oauthkey resolver via tsnet: tskey-client- secret,
?baseURL attributes, CreateKey, register re-advertising key tags.
2026-09-25 17:09:19 +02:00