2021-11-29 17:31:19 +00:00
# CHANGELOG
2024-09-21 10:05:36 +00:00
## Next
Redo OIDC configuration (#2020)
expand user, add claims to user
This commit expands the user table with additional fields that
can be retrieved from OIDC providers (and other places) and
uses this data in various tailscale response objects if it is
available.
This is the beginning of implementing
https://docs.google.com/document/d/1X85PMxIaVWDF6T_UPji3OeeUqVBcGj_uHRM5CI-AwlY/edit
trying to make OIDC more coherant and maintainable in addition
to giving the user a better experience and integration with a
provider.
remove usernames in magic dns, normalisation of emails
this commit removes the option to have usernames as part of MagicDNS
domains and headscale will now align with Tailscale, where there is a
root domain, and the machine name.
In addition, the various normalisation functions for dns names has been
made lighter not caring about username and special character that wont
occur.
Email are no longer normalised as part of the policy processing.
untagle oidc and regcache, use typed cache
This commits stops reusing the registration cache for oidc
purposes and switches the cache to be types and not use any
allowing the removal of a bunch of casting.
try to make reauth/register branches clearer in oidc
Currently there was a function that did a bunch of stuff,
finding the machine key, trying to find the node, reauthing
the node, returning some status, and it was called validate
which was very confusing.
This commit tries to split this into what to do if the node
exists, if it needs to register etc.
Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-10-02 12:50:17 +00:00
### BREAKING
- Remove `dns.use_username_in_magic_dns` configuration option [#2020 ](https://github.com/juanfont/headscale/pull/2020 )
- Having usernames in magic DNS is no longer possible.
- Redo OpenID Connect configuration [#2020 ](https://github.com/juanfont/headscale/pull/2020 )
- `strip_email_domain` has been removed, domain is _always_ part of the username for OIDC.
- Users are now identified by `sub` claim in the ID token instead of username, allowing the username, name and email to be updated.
- User has been extended to store username, display name, profile picture url and email.
- These fields are forwarded to the client, and shows up nicely in the user switcher.
- These fields can be made available via the API/CLI for non-OIDC users in the future.
2024-09-24 16:34:20 +00:00
- Remove versions older than 1.56 [#2149 ](https://github.com/juanfont/headscale/pull/2149 )
- Clean up old code required by old versions
Redo OIDC configuration (#2020)
expand user, add claims to user
This commit expands the user table with additional fields that
can be retrieved from OIDC providers (and other places) and
uses this data in various tailscale response objects if it is
available.
This is the beginning of implementing
https://docs.google.com/document/d/1X85PMxIaVWDF6T_UPji3OeeUqVBcGj_uHRM5CI-AwlY/edit
trying to make OIDC more coherant and maintainable in addition
to giving the user a better experience and integration with a
provider.
remove usernames in magic dns, normalisation of emails
this commit removes the option to have usernames as part of MagicDNS
domains and headscale will now align with Tailscale, where there is a
root domain, and the machine name.
In addition, the various normalisation functions for dns names has been
made lighter not caring about username and special character that wont
occur.
Email are no longer normalised as part of the policy processing.
untagle oidc and regcache, use typed cache
This commits stops reusing the registration cache for oidc
purposes and switches the cache to be types and not use any
allowing the removal of a bunch of casting.
try to make reauth/register branches clearer in oidc
Currently there was a function that did a bunch of stuff,
finding the machine key, trying to find the node, reauthing
the node, returning some status, and it was called validate
which was very confusing.
This commit tries to split this into what to do if the node
exists, if it needs to register etc.
Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-10-02 12:50:17 +00:00
### Changes
2024-09-21 10:05:36 +00:00
- Improved compatibilty of built-in DERP server with clients connecting over WebSocket.
2024-09-23 09:59:16 +00:00
- Allow nodes to use SSH agent forwarding [#2145 ](https://github.com/juanfont/headscale/pull/2145 )
2024-10-09 07:36:47 +00:00
- Fixed processing of fields in post request in MoveNode rpc [#2179 ](https://github.com/juanfont/headscale/pull/2179 )
2024-10-15 16:33:03 +00:00
- Added conversion of 'Hostname' to 'givenName' in a node with FQDN rules applied [#2198 ](https://github.com/juanfont/headscale/pull/2198 )
2024-10-17 15:45:33 +00:00
- Fixed updating of hostname and givenName when it is updated in HostInfo [#2199 ](https://github.com/juanfont/headscale/pull/2199 )
2024-11-11 06:06:44 +00:00
- Fixed missing `stable-debug` container tag [#2232 ](https://github.com/juanfont/headscale/pr/2232 )
2024-11-18 06:13:42 +00:00
- Added manual approval of nodes in the network [#2245 ](https://github.com/juanfont/headscale/pr/2245 )
Redo OIDC configuration (#2020)
expand user, add claims to user
This commit expands the user table with additional fields that
can be retrieved from OIDC providers (and other places) and
uses this data in various tailscale response objects if it is
available.
This is the beginning of implementing
https://docs.google.com/document/d/1X85PMxIaVWDF6T_UPji3OeeUqVBcGj_uHRM5CI-AwlY/edit
trying to make OIDC more coherant and maintainable in addition
to giving the user a better experience and integration with a
provider.
remove usernames in magic dns, normalisation of emails
this commit removes the option to have usernames as part of MagicDNS
domains and headscale will now align with Tailscale, where there is a
root domain, and the machine name.
In addition, the various normalisation functions for dns names has been
made lighter not caring about username and special character that wont
occur.
Email are no longer normalised as part of the policy processing.
untagle oidc and regcache, use typed cache
This commits stops reusing the registration cache for oidc
purposes and switches the cache to be types and not use any
allowing the removal of a bunch of casting.
try to make reauth/register branches clearer in oidc
Currently there was a function that did a bunch of stuff,
finding the machine key, trying to find the node, reauthing
the node, returning some status, and it was called validate
which was very confusing.
This commit tries to split this into what to do if the node
exists, if it needs to register etc.
Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-10-02 12:50:17 +00:00
2024-09-21 10:05:36 +00:00
## 0.23.0 (2024-09-18)
2023-04-19 18:12:41 +00:00
2024-09-18 08:43:08 +00:00
This release was intended to be mainly a code reorganisation and refactoring, significantly improving the maintainability of the codebase. This should allow us to improve further and make it easier for the maintainers to keep on top of the project.
However, as you all have noticed, it turned out to become a much larger, much longer release cycle than anticipated. It has ended up to be a release with a lot of rewrites and changes to the code base and functionality of Headscale, cleaning up a lot of technical debt and introducing a lot of improvements. This does come with some breaking changes,
2023-09-24 21:18:19 +00:00
2023-09-25 21:27:03 +00:00
**Please remember to always back up your database between versions**
2023-09-24 21:18:19 +00:00
#### Here is a short summary of the broad topics of changes:
Code has been organised into modules, reducing use of global variables/objects, isolating concerns and “putting the right things in the logical place”.
The new [policy ](https://github.com/juanfont/headscale/tree/main/hscontrol/policy ) and [mapper ](https://github.com/juanfont/headscale/tree/main/hscontrol/mapper ) package, containing the ACL/Policy logic and the logic for creating the data served to clients (the network “map”) has been rewritten and improved. This change has allowed us to finish SSH support and add additional tests throughout the code to ensure correctness.
The [“poller”, or streaming logic ](https://github.com/juanfont/headscale/blob/main/hscontrol/poll.go ) has been rewritten and instead of keeping track of the latest updates, checking at a fixed interval, it now uses go channels, implemented in our new [notifier ](https://github.com/juanfont/headscale/tree/main/hscontrol/notifier ) package and it allows us to send updates to connected clients immediately. This should both improve performance and potential latency before a client picks up an update.
Headscale now supports sending “delta” updates, thanks to the new mapper and poller logic, allowing us to only inform nodes about new nodes, changed nodes and removed nodes. Previously we sent the entire state of the network every time an update was due.
2024-09-18 08:43:08 +00:00
While we have a pretty good [test harness ](https://github.com/search?q=repo%3Ajuanfont%2Fheadscale+path%3A_test.go&type=code ) for validating our changes, the changes came down to [284 changed files with 32,316 additions and 24,245 deletions ](https://github.com/juanfont/headscale/compare/b01f1f1867136d9b2d7b1392776eb363b482c525...ed78ecd ) and bugs are expected. We need help testing this release. In addition, while we think the performance should in general be better, there might be regressions in parts of the platform, particularly where we prioritised correctness over speed.
2023-09-24 21:18:19 +00:00
There are also several bugfixes that has been encountered and fixed as part of implementing these changes, particularly
after improving the test harness as part of adopting [#1460 ](https://github.com/juanfont/headscale/pull/1460 ).
2023-05-10 16:34:11 +00:00
### BREAKING
2023-11-23 07:31:33 +00:00
- Code reorganisation, a lot of code has moved, please review the following PRs accordingly [#1473 ](https://github.com/juanfont/headscale/pull/1473 )
2024-02-17 12:18:15 +00:00
- Change the structure of database configuration, see [config-example.yaml ](./config-example.yaml ) for the new structure. [#1700 ](https://github.com/juanfont/headscale/pull/1700 )
- Old structure has been remove and the configuration _must_ be converted.
2024-05-19 21:49:27 +00:00
- Adds additional configuration for PostgreSQL for setting max open, idle connection and idle connection lifetime.
2023-11-23 07:31:33 +00:00
- API: Machine is now Node [#1553 ](https://github.com/juanfont/headscale/pull/1553 )
- Remove support for older Tailscale clients [#1611 ](https://github.com/juanfont/headscale/pull/1611 )
2024-08-30 14:59:37 +00:00
- The oldest supported client is 1.42
2023-12-09 17:09:24 +00:00
- Headscale checks that _at least_ one DERP is defined at start [#1564 ](https://github.com/juanfont/headscale/pull/1564 )
- If no DERP is configured, the server will fail to start, this can be because it cannot load the DERPMap from file or url.
2023-12-10 14:23:23 +00:00
- Embedded DERP server requires a private key [#1611 ](https://github.com/juanfont/headscale/pull/1611 )
- Add a filepath entry to [`derp.server.private_key_path` ](https://github.com/juanfont/headscale/blob/b35993981297e18393706b2c963d6db882bba6aa/config-example.yaml#L95 )
2024-02-17 12:15:31 +00:00
- Docker images are now built with goreleaser (ko) [#1716 ](https://github.com/juanfont/headscale/pull/1716 ) [#1763 ](https://github.com/juanfont/headscale/pull/1763 )
- Entrypoint of container image has changed from shell to headscale, require change from `headscale serve` to `serve`
2024-02-17 12:36:19 +00:00
- `/var/lib/headscale` and `/var/run/headscale` is no longer created automatically, see [container docs ](./docs/running-headscale-container.md )
2024-02-18 18:31:29 +00:00
- Prefixes are now defined per v4 and v6 range. [#1756 ](https://github.com/juanfont/headscale/pull/1756 )
- `ip_prefixes` option is now `prefixes.v4` and `prefixes.v6`
2024-04-17 05:03:06 +00:00
- `prefixes.allocation` can be set to assign IPs at `sequential` or `random` . [#1869 ](https://github.com/juanfont/headscale/pull/1869 )
2024-06-26 11:44:40 +00:00
- MagicDNS domains no longer contain usernames []()
- This is in preperation to fix Headscales implementation of tags which currently does not correctly remove the link between a tagged device and a user. As tagged devices will not have a user, this will require a change to the DNS generation, removing the username, see [#1369 ](https://github.com/juanfont/headscale/issues/1369 ) for more information.
- `use_username_in_magic_dns` can be used to turn this behaviour on again, but note that this option _will be removed_ when tags are fixed.
2024-08-19 09:41:05 +00:00
- dns.base_domain can no longer be the same as (or part of) server_url.
- This option brings Headscales behaviour in line with Tailscale.
2024-09-04 05:55:16 +00:00
- YAML files are no longer supported for headscale policy. [#1792 ](https://github.com/juanfont/headscale/pull/1792 )
2024-07-18 05:38:25 +00:00
- HuJSON is now the only supported format for policy.
2024-08-19 09:41:05 +00:00
- DNS configuration has been restructured [#2034 ](https://github.com/juanfont/headscale/pull/2034 )
- Please review the new [config-example.yaml ](./config-example.yaml ) for the new structure.
2023-05-10 16:34:11 +00:00
2023-04-19 18:12:41 +00:00
### Changes
2024-02-09 06:27:00 +00:00
- Use versioned migrations [#1644 ](https://github.com/juanfont/headscale/pull/1644 )
- Make the OIDC callback page better [#1484 ](https://github.com/juanfont/headscale/pull/1484 )
- SSH support [#1487 ](https://github.com/juanfont/headscale/pull/1487 )
- State management has been improved [#1492 ](https://github.com/juanfont/headscale/pull/1492 )
- Use error group handling to ensure tests actually pass [#1535 ](https://github.com/juanfont/headscale/pull/1535 ) based on [#1460 ](https://github.com/juanfont/headscale/pull/1460 )
- Fix hang on SIGTERM [#1492 ](https://github.com/juanfont/headscale/pull/1492 ) taken from [#1480 ](https://github.com/juanfont/headscale/pull/1480 )
- Send logs to stderr by default [#1524 ](https://github.com/juanfont/headscale/pull/1524 )
- Fix [TS-2023-006 ](https://tailscale.com/security-bulletins/#ts-2023-006 ) security UPnP issue [#1563 ](https://github.com/juanfont/headscale/pull/1563 )
- Turn off gRPC logging [#1640 ](https://github.com/juanfont/headscale/pull/1640 ) fixes [#1259 ](https://github.com/juanfont/headscale/issues/1259 )
- Added the possibility to manually create a DERP-map entry which can be customized, instead of automatically creating it. [#1565 ](https://github.com/juanfont/headscale/pull/1565 )
2024-02-12 10:31:21 +00:00
- Add support for deleting api keys [#1702 ](https://github.com/juanfont/headscale/pull/1702 )
2024-04-17 05:03:06 +00:00
- Add command to backfill IP addresses for nodes missing IPs from configured prefixes. [#1869 ](https://github.com/juanfont/headscale/pull/1869 )
2024-04-17 09:22:53 +00:00
- Log available update as warning [#1877 ](https://github.com/juanfont/headscale/pull/1877 )
2024-04-30 05:23:16 +00:00
- Add `autogroup:internet` to Policy [#1917 ](https://github.com/juanfont/headscale/pull/1917 )
2024-05-16 00:40:14 +00:00
- Restore foreign keys and add constraints [#1562 ](https://github.com/juanfont/headscale/pull/1562 )
2024-06-15 07:40:49 +00:00
- Make registration page easier to use on mobile devices
2024-06-23 20:06:59 +00:00
- Make write-ahead-log default on and configurable for SQLite [#1985 ](https://github.com/juanfont/headscale/pull/1985 )
2024-07-18 05:38:25 +00:00
- Add APIs for managing headscale policy. [#1792 ](https://github.com/juanfont/headscale/pull/1792 )
2024-09-03 07:22:17 +00:00
- Fix for registering nodes using preauthkeys when running on a postgres database in a non-UTC timezone. [#764 ](https://github.com/juanfont/headscale/issues/764 )
- Make sure integration tests cover postgres for all scenarios
2024-09-07 07:23:58 +00:00
- CLI commands (all except `serve` ) only requires minimal configuration, no more errors or warnings from unset settings [#2109 ](https://github.com/juanfont/headscale/pull/2109 )
- CLI results are now concistently sent to stdout and errors to stderr [#2109 ](https://github.com/juanfont/headscale/pull/2109 )
2024-09-09 12:10:22 +00:00
- Fix issue where shutting down headscale would hang [#2113 ](https://github.com/juanfont/headscale/pull/2113 )
2023-06-05 20:21:31 +00:00
2023-05-12 07:33:10 +00:00
## 0.22.3 (2023-05-12)
### Changes
- Added missing ca-certificates in Docker image [#1463 ](https://github.com/juanfont/headscale/pull/1463 )
2023-05-10 14:27:24 +00:00
## 0.22.2 (2023-05-10)
### Changes
2023-04-27 14:57:11 +00:00
- Add environment flags to enable pprof (profiling) [#1382 ](https://github.com/juanfont/headscale/pull/1382 )
2024-05-19 21:49:27 +00:00
- Profiles are continuously generated in our integration tests.
2023-04-30 14:48:50 +00:00
- Fix systemd service file location in `.deb` packages [#1391 ](https://github.com/juanfont/headscale/pull/1391 )
2023-05-02 06:15:33 +00:00
- Improvements on Noise implementation [#1379 ](https://github.com/juanfont/headscale/pull/1379 )
2023-04-28 14:11:02 +00:00
- Replace node filter logic, ensuring nodes with access can see eachother [#1381 ](https://github.com/juanfont/headscale/pull/1381 )
2023-05-10 13:04:18 +00:00
- Disable (or delete) both exit routes at the same time [#1428 ](https://github.com/juanfont/headscale/pull/1428 )
2023-05-10 14:27:24 +00:00
- Ditch distroless for Docker image, create default socket dir in `/var/run/headscale` [#1450 ](https://github.com/juanfont/headscale/pull/1450 )
2023-04-27 14:57:11 +00:00
2023-04-20 13:43:02 +00:00
## 0.22.1 (2023-04-20)
### Changes
2023-05-02 06:15:33 +00:00
- Fix issue where systemd could not bind to port 80 [#1365 ](https://github.com/juanfont/headscale/pull/1365 )
2023-04-20 13:43:02 +00:00
2023-04-19 19:50:33 +00:00
## 0.22.0 (2023-04-20)
2023-01-29 10:43:13 +00:00
2023-03-20 12:40:43 +00:00
### Changes
2023-04-19 15:13:33 +00:00
- Add `.deb` packages to release process [#1297 ](https://github.com/juanfont/headscale/pull/1297 )
- Update and simplify the documentation to use new `.deb` packages [#1349 ](https://github.com/juanfont/headscale/pull/1349 )
2023-03-28 16:43:33 +00:00
- Add 32-bit Arm platforms to release process [#1297 ](https://github.com/juanfont/headscale/pull/1297 )
2023-03-27 17:19:32 +00:00
- Fix longstanding bug that would prevent "\*" from working properly in ACLs (issue [#699 ](https://github.com/juanfont/headscale/issues/699 )) [#1279 ](https://github.com/juanfont/headscale/pull/1279 )
2023-04-19 15:16:24 +00:00
- Fix issue where IPv6 could not be used in, or while using ACLs (part of [#809 ](https://github.com/juanfont/headscale/issues/809 )) [#1339 ](https://github.com/juanfont/headscale/pull/1339 )
2023-04-07 10:35:19 +00:00
- Target Go 1.20 and Tailscale 1.38 for Headscale [#1323 ](https://github.com/juanfont/headscale/pull/1323 )
2023-03-27 17:19:32 +00:00
2023-03-20 12:40:43 +00:00
## 0.21.0 (2023-03-20)
### Changes
2023-03-03 12:42:45 +00:00
2023-03-15 11:31:38 +00:00
- Adding "configtest" CLI command. [#1230 ](https://github.com/juanfont/headscale/pull/1230 )
- Add documentation on connecting with iOS to `/apple` [#1261 ](https://github.com/juanfont/headscale/pull/1261 )
2023-03-17 14:56:15 +00:00
- Update iOS compatibility and added documentation for iOS [#1264 ](https://github.com/juanfont/headscale/pull/1264 )
2023-03-20 12:40:43 +00:00
- Allow to delete routes [#1244 ](https://github.com/juanfont/headscale/pull/1244 )
2023-03-03 13:55:29 +00:00
2023-03-03 12:42:45 +00:00
## 0.20.0 (2023-02-03)
2023-03-20 12:40:43 +00:00
### Changes
2023-01-29 10:43:13 +00:00
2023-01-29 11:55:29 +00:00
- Fix wrong behaviour in exit nodes [#1159 ](https://github.com/juanfont/headscale/pull/1159 )
2023-01-30 13:40:06 +00:00
- Align behaviour of `dns_config.restricted_nameservers` to tailscale [#1162 ](https://github.com/juanfont/headscale/pull/1162 )
2023-01-31 11:40:38 +00:00
- Make OpenID Connect authenticated client expiry time configurable [#1191 ](https://github.com/juanfont/headscale/pull/1191 )
- defaults to 180 days like Tailscale SaaS
- adds option to use the expiry time from the OpenID token for the node (see config-example.yaml)
2023-02-02 09:38:25 +00:00
- Set ControlTime in Map info sent to nodes [#1195 ](https://github.com/juanfont/headscale/pull/1195 )
- Populate Tags field on Node updates sent [#1195 ](https://github.com/juanfont/headscale/pull/1195 )
2023-01-29 10:43:13 +00:00
## 0.19.0 (2023-01-29)
2023-01-17 20:50:00 +00:00
### BREAKING
- Rename Namespace to User [#1144 ](https://github.com/juanfont/headscale/pull/1144 )
2023-01-19 10:59:12 +00:00
- **BACKUP your database before upgrading**
2023-01-26 07:41:21 +00:00
- Command line flags previously taking `--namespace` or `-n` will now require `--user` or `-u`
2023-01-17 20:50:00 +00:00
2023-01-29 10:43:13 +00:00
## 0.18.0 (2023-01-14)
2022-12-05 21:40:21 +00:00
2022-12-05 14:08:02 +00:00
### Changes
2022-12-07 08:37:45 +00:00
- Reworked routing and added support for subnet router failover [#1024 ](https://github.com/juanfont/headscale/pull/1024 )
- Added an OIDC AllowGroups Configuration options and authorization check [#1041 ](https://github.com/juanfont/headscale/pull/1041 )
- Set `db_ssl` to false by default [#1052 ](https://github.com/juanfont/headscale/pull/1052 )
2022-12-09 16:56:43 +00:00
- Fix duplicate nodes due to incorrect implementation of the protocol [#1058 ](https://github.com/juanfont/headscale/pull/1058 )
2022-12-13 22:32:48 +00:00
- Report if a machine is online in CLI more accurately [#1062 ](https://github.com/juanfont/headscale/pull/1062 )
2022-12-31 12:59:28 +00:00
- Added config option for custom DNS records [#1035 ](https://github.com/juanfont/headscale/pull/1035 )
2023-01-03 14:28:45 +00:00
- Expire nodes based on OIDC token expiry [#1067 ](https://github.com/juanfont/headscale/pull/1067 )
2023-01-03 12:35:24 +00:00
- Remove ephemeral nodes on logout [#1098 ](https://github.com/juanfont/headscale/pull/1098 )
2023-01-11 07:49:28 +00:00
- Performance improvements in ACLs [#1129 ](https://github.com/juanfont/headscale/pull/1129 )
2023-01-10 11:46:42 +00:00
- OIDC client secret can be passed via a file [#1127 ](https://github.com/juanfont/headscale/pull/1127 )
2022-12-07 08:37:45 +00:00
2022-12-05 14:08:02 +00:00
## 0.17.1 (2022-12-05)
2022-12-03 14:57:01 +00:00
### Changes
- Correct typo on macOS standalone profile link [#1028 ](https://github.com/juanfont/headscale/pull/1028 )
2022-12-05 14:07:07 +00:00
- Update platform docs with Fast User Switching [#1016 ](https://github.com/juanfont/headscale/pull/1016 )
2022-12-03 14:57:01 +00:00
2022-12-01 13:27:42 +00:00
## 0.17.0 (2022-11-26)
2022-08-14 21:22:41 +00:00
2022-09-11 19:37:38 +00:00
### BREAKING
2022-12-01 13:27:42 +00:00
- `noise.private_key_path` has been added and is required for the new noise protocol.
2022-09-11 19:37:38 +00:00
- Log level option `log_level` was moved to a distinct `log` config section and renamed to `level` [#768 ](https://github.com/juanfont/headscale/pull/768 )
2022-11-14 16:24:06 +00:00
- Removed Alpine Linux container image [#962 ](https://github.com/juanfont/headscale/pull/962 )
2022-09-11 19:44:28 +00:00
2022-11-26 10:57:51 +00:00
### Important Changes
2022-09-11 19:37:38 +00:00
2022-08-21 10:32:01 +00:00
- Added support for Tailscale TS2021 protocol [#738 ](https://github.com/juanfont/headscale/pull/738 )
2022-11-26 10:57:51 +00:00
- Add experimental support for [SSH ACL ](https://tailscale.com/kb/1018/acls/#tailscale-ssh ) (see docs for limitations) [#847 ](https://github.com/juanfont/headscale/pull/847 )
- Please note that this support should be considered _partially_ implemented
- SSH ACLs status:
- Support `accept` and `check` (SSH can be enabled and used for connecting and authentication)
- Rejecting connections **are not supported** , meaning that if you enable SSH, then assume that _all_ `ssh` connections **will be allowed** .
2024-05-19 21:49:27 +00:00
- If you decided to try this feature, please carefully managed permissions by blocking port `22` with regular ACLs or do _not_ set `--ssh` on your clients.
2022-11-26 10:57:51 +00:00
- We are currently improving our testing of the SSH ACLs, help us get an overview by testing and giving feedback.
- This feature should be considered dangerous and it is disabled by default. Enable by setting `HEADSCALE_EXPERIMENTAL_FEATURE_SSH=1` .
### Changes
2022-08-22 12:20:20 +00:00
- Add ability to specify config location via env var `HEADSCALE_CONFIG` [#674 ](https://github.com/juanfont/headscale/issues/674 )
2022-09-03 10:24:22 +00:00
- Target Go 1.19 for Headscale [#778 ](https://github.com/juanfont/headscale/pull/778 )
2022-09-03 21:19:07 +00:00
- Target Tailscale v1.30.0 to build Headscale [#780 ](https://github.com/juanfont/headscale/pull/780 )
2022-09-04 14:23:46 +00:00
- Give a warning when running Headscale with reverse proxy improperly configured for WebSockets [#788 ](https://github.com/juanfont/headscale/pull/788 )
2022-09-18 10:14:49 +00:00
- Fix subnet routers with Primary Routes [#811 ](https://github.com/juanfont/headscale/pull/811 )
2022-09-11 19:37:38 +00:00
- Added support for JSON logs [#653 ](https://github.com/juanfont/headscale/issues/653 )
2022-09-23 08:44:29 +00:00
- Sanitise the node key passed to registration url [#823 ](https://github.com/juanfont/headscale/pull/823 )
2022-09-23 08:13:48 +00:00
- Add support for generating pre-auth keys with tags [#767 ](https://github.com/juanfont/headscale/pull/767 )
2022-09-23 08:08:59 +00:00
- Add support for evaluating `autoApprovers` ACL entries when a machine is registered [#763 ](https://github.com/juanfont/headscale/pull/763 )
2022-09-26 08:01:01 +00:00
- Add config flag to allow Headscale to start if OIDC provider is down [#829 ](https://github.com/juanfont/headscale/pull/829 )
2022-11-01 11:00:40 +00:00
- Fix prefix length comparison bug in AutoApprovers route evaluation [#862 ](https://github.com/juanfont/headscale/pull/862 )
2022-08-31 11:41:01 +00:00
- Random node DNS suffix only applied if names collide in namespace. [#766 ](https://github.com/juanfont/headscale/issues/766 )
2022-10-30 21:31:18 +00:00
- Remove `ip_prefix` configuration option and warning [#899 ](https://github.com/juanfont/headscale/pull/899 )
2022-10-31 15:26:18 +00:00
- Add `dns_config.override_local_dns` option [#905 ](https://github.com/juanfont/headscale/pull/905 )
2022-10-31 14:59:50 +00:00
- Fix some DNS config issues [#660 ](https://github.com/juanfont/headscale/issues/660 )
2022-11-04 10:26:33 +00:00
- Make it possible to disable TS2019 with build flag [#928 ](https://github.com/juanfont/headscale/pull/928 )
2022-11-15 14:41:46 +00:00
- Fix OIDC registration issues [#960 ](https://github.com/juanfont/headscale/pull/960 ) and [#971 ](https://github.com/juanfont/headscale/pull/971 )
2022-11-07 20:10:06 +00:00
- Add support for specifying NextDNS DNS-over-HTTPS resolver [#940 ](https://github.com/juanfont/headscale/pull/940 )
2022-11-24 14:33:19 +00:00
- Make more sslmode available for postgresql connection [#927 ](https://github.com/juanfont/headscale/pull/927 )
2022-08-21 10:32:01 +00:00
2022-08-21 08:51:58 +00:00
## 0.16.4 (2022-08-21)
### Changes
2022-08-16 08:09:28 +00:00
- Add ability to connect to PostgreSQL over TLS/SSL [#745 ](https://github.com/juanfont/headscale/pull/745 )
2022-08-19 12:14:30 +00:00
- Fix CLI registration of expired machines [#754 ](https://github.com/juanfont/headscale/pull/754 )
2022-08-16 08:09:28 +00:00
2022-08-17 15:08:29 +00:00
## 0.16.3 (2022-08-17)
### Changes
- Fix issue with OIDC authentication [#747 ](https://github.com/juanfont/headscale/pull/747 )
2022-08-14 21:22:41 +00:00
## 0.16.2 (2022-08-14)
### Changes
- Fixed bugs in the client registration process after migration to NodeKey [#735 ](https://github.com/juanfont/headscale/pull/735 )
## 0.16.1 (2022-08-12)
### Changes
2022-07-25 08:35:21 +00:00
2022-08-10 09:04:42 +00:00
- Updated dependencies (including the library that lacked armhf support) [#722 ](https://github.com/juanfont/headscale/pull/722 )
2024-05-19 21:49:27 +00:00
- Fix missing group expansion in function `excludeCorrectlyTaggedNodes` [#563 ](https://github.com/juanfont/headscale/issues/563 )
2022-08-12 07:31:11 +00:00
- Improve registration protocol implementation and switch to NodeKey as main identifier [#725 ](https://github.com/juanfont/headscale/pull/725 )
2022-08-12 17:00:16 +00:00
- Add ability to connect to PostgreSQL via unix socket [#734 ](https://github.com/juanfont/headscale/pull/734 )
2022-08-04 08:51:06 +00:00
2022-07-25 08:35:21 +00:00
## 0.16.0 (2022-07-25)
**Note:** Take a backup of your database before upgrading.
2022-03-20 14:07:22 +00:00
2022-06-08 16:12:56 +00:00
### BREAKING
- Old ACL syntax is no longer supported ("users" & "ports" -> "src" & "dst"). Please check [the new syntax ](https://tailscale.com/kb/1018/acls/ ).
2022-03-21 08:49:14 +00:00
### Changes
2022-04-07 18:21:26 +00:00
2022-06-03 17:35:47 +00:00
- **Drop** armhf (32-bit ARM) support. [#609 ](https://github.com/juanfont/headscale/pull/609 )
2022-04-06 21:41:13 +00:00
- Headscale fails to serve if the ACL policy file cannot be parsed [#537 ](https://github.com/juanfont/headscale/pull/537 )
2022-03-21 08:49:14 +00:00
- Fix labels cardinality error when registering unknown pre-auth key [#519 ](https://github.com/juanfont/headscale/pull/519 )
2022-04-10 20:47:35 +00:00
- Fix send on closed channel crash in polling [#542 ](https://github.com/juanfont/headscale/pull/542 )
2022-04-30 14:50:55 +00:00
- Fixed spurious calls to setLastStateChangeToNow from ephemeral nodes [#566 ](https://github.com/juanfont/headscale/pull/566 )
2022-05-01 13:47:34 +00:00
- Add command for moving nodes between namespaces [#362 ](https://github.com/juanfont/headscale/issues/362 )
2024-05-19 21:49:27 +00:00
- Added more configuration parameters for OpenID Connect (scopes, free-form parameters, domain and user allowlist)
2022-05-13 09:51:31 +00:00
- Add command to set tags on a node [#525 ](https://github.com/juanfont/headscale/issues/525 )
- Add command to view tags of nodes [#356 ](https://github.com/juanfont/headscale/issues/356 )
2022-05-14 12:36:04 +00:00
- Add --all (-a) flag to enable routes command [#360 ](https://github.com/juanfont/headscale/issues/360 )
2022-05-30 11:27:57 +00:00
- Fix issue where nodes was not updated across namespaces [#560 ](https://github.com/juanfont/headscale/pull/560 )
- Add the ability to rename a nodes name [#560 ](https://github.com/juanfont/headscale/pull/560 )
- Node DNS names are now unique, a random suffix will be added when a node joins
- This change contains database changes, remember to **backup** your database before upgrading
2022-05-30 12:57:49 +00:00
- Add option to enable/disable logtail (Tailscale's logging infrastructure) [#596 ](https://github.com/juanfont/headscale/pull/596 )
- This change disables the logs by default
2022-05-31 07:42:50 +00:00
- Use [Prometheus]'s duration parser, supporting days (`d`), weeks (`w`) and years (`y`) [#598 ](https://github.com/juanfont/headscale/pull/598 )
2022-05-31 12:30:11 +00:00
- Add support for reloading ACLs with SIGHUP [#601 ](https://github.com/juanfont/headscale/pull/601 )
2022-06-08 16:12:56 +00:00
- Use new ACL syntax [#618 ](https://github.com/juanfont/headscale/pull/618 )
2022-06-05 15:15:21 +00:00
- Add -c option to specify config file from command line [#285 ](https://github.com/juanfont/headscale/issues/285 ) [#612 ](https://github.com/juanfont/headscale/pull/601 )
2022-06-11 12:49:17 +00:00
- Add configuration option to allow Tailscale clients to use a random WireGuard port. [kb/1181/firewalls ](https://tailscale.com/kb/1181/firewalls ) [#624 ](https://github.com/juanfont/headscale/pull/624 )
2022-06-12 13:18:49 +00:00
- Improve obtuse UX regarding missing configuration (`ephemeral_node_inactivity_timeout` not set) [#639 ](https://github.com/juanfont/headscale/pull/639 )
2022-06-26 07:30:16 +00:00
- Fix nodes being shown as 'offline' in `tailscale status` [#648 ](https://github.com/juanfont/headscale/pull/648 )
2022-06-26 07:29:33 +00:00
- Improve shutdown behaviour [#651 ](https://github.com/juanfont/headscale/pull/651 )
2022-07-19 12:45:23 +00:00
- Drop Gin as web framework in Headscale [648 ](https://github.com/juanfont/headscale/pull/648 ) [677 ](https://github.com/juanfont/headscale/pull/677 )
2022-07-12 10:52:03 +00:00
- Make tailnet node updates check interval configurable [#675 ](https://github.com/juanfont/headscale/pull/675 )
2022-07-21 21:59:44 +00:00
- Fix regression with HTTP API [#684 ](https://github.com/juanfont/headscale/pull/684 )
2022-07-22 20:47:37 +00:00
- nodes ls now print both Hostname and Name(Issue [#647 ](https://github.com/juanfont/headscale/issues/647 ) PR [#687 ](https://github.com/juanfont/headscale/pull/687 ))
2022-03-21 08:49:14 +00:00
2022-03-20 12:36:25 +00:00
## 0.15.0 (2022-03-20)
2021-12-24 15:46:04 +00:00
2022-02-28 22:50:35 +00:00
**Note:** Take a backup of your database before upgrading.
### BREAKING
2022-02-25 09:30:58 +00:00
- Boundaries between Namespaces has been removed and all nodes can communicate by default [#357 ](https://github.com/juanfont/headscale/pull/357 )
- To limit access between nodes, use [ACLs ](./docs/acls.md ).
2022-03-02 12:22:29 +00:00
- `/metrics` is now a configurable host:port endpoint: [#344 ](https://github.com/juanfont/headscale/pull/344 ). You must update your `config.yaml` file to include:
```yaml
metrics_listen_addr: 127.0.0.1:9090
```
2022-02-25 09:30:58 +00:00
2022-03-01 14:18:24 +00:00
### Features
2022-02-27 08:08:29 +00:00
- Add support for writing ACL files with YAML [#359 ](https://github.com/juanfont/headscale/pull/359 )
2022-03-01 20:16:33 +00:00
- Users can now use emails in ACL's groups [#372 ](https://github.com/juanfont/headscale/issues/372 )
2022-03-02 09:53:07 +00:00
- Add shorthand aliases for commands and subcommands [#376 ](https://github.com/juanfont/headscale/pull/376 )
2022-03-04 09:52:42 +00:00
- Add `/windows` endpoint for Windows configuration instructions + registry file download [#392 ](https://github.com/juanfont/headscale/pull/392 )
2022-03-20 11:36:30 +00:00
- Added embedded DERP (and STUN) server into Headscale [#388 ](https://github.com/juanfont/headscale/pull/388 )
2022-02-27 08:08:29 +00:00
2022-02-28 22:50:35 +00:00
### Changes
2022-02-25 08:44:16 +00:00
- Fix a bug were the same IP could be assigned to multiple hosts if joined in quick succession [#346 ](https://github.com/juanfont/headscale/pull/346 )
2022-02-28 22:11:31 +00:00
- Simplify the code behind registration of machines [#366 ](https://github.com/juanfont/headscale/pull/366 )
2024-05-19 21:49:27 +00:00
- Nodes are now only written to database if they are registered successfully
2022-03-01 21:50:22 +00:00
- Fix a limitation in the ACLs that prevented users to write rules with `*` as source [#374 ](https://github.com/juanfont/headscale/issues/374 )
2022-03-02 08:15:21 +00:00
- Reduce the overhead of marshal/unmarshal for Hostinfo, routes and endpoints by using specific types in Machine [#371 ](https://github.com/juanfont/headscale/pull/371 )
2024-05-19 21:49:27 +00:00
- Apply normalization function to FQDN on hostnames when hosts registers and retrieve information [#363 ](https://github.com/juanfont/headscale/issues/363 )
2022-03-18 08:34:18 +00:00
- Fix a bug that prevented the use of `tailscale logout` with OIDC [#508 ](https://github.com/juanfont/headscale/issues/508 )
2022-03-20 11:36:30 +00:00
- Added Tailscale repo HEAD and unstable releases channel to the integration tests targets [#513 ](https://github.com/juanfont/headscale/pull/513 )
2022-02-25 08:44:16 +00:00
2022-02-28 22:50:35 +00:00
## 0.14.0 (2022-02-24)
2022-02-20 19:47:12 +00:00
2022-02-28 22:50:35 +00:00
**UPCOMING ### BREAKING
From the **next\*\* version (`0.15.0`), all machines will be able to communicate regardless of
2022-02-21 15:06:20 +00:00
if they are in the same namespace. This means that the behaviour currently limited to ACLs
will become default. From version `0.15.0` , all limitation of communications must be done
2022-02-20 19:47:12 +00:00
with ACLs.
This is a part of aligning `headscale` 's behaviour with Tailscale's upstream behaviour.
2022-02-28 22:50:35 +00:00
### BREAKING
2022-02-14 13:02:18 +00:00
2022-02-20 19:47:12 +00:00
- ACLs have been rewritten to align with the bevaviour Tailscale Control Panel provides. **NOTE:** This is only active if you use ACLs
- Namespaces are now treated as Users
- All machines can communicate with all machines by default
2022-02-21 15:06:20 +00:00
- Tags should now work correctly and adding a host to Headscale should now reload the rules.
2022-02-20 19:47:12 +00:00
- The documentation have a [fictional example ](docs/acls.md ) that should cover some use cases of the ACLs features
2022-02-28 22:50:35 +00:00
### Features
2022-02-21 21:44:49 +00:00
2022-02-24 11:09:05 +00:00
- Add support for configurable mTLS [docs ](docs/tls.md#configuring-mutual-tls-authentication-mtls ) [#297 ](https://github.com/juanfont/headscale/pull/297 )
2022-02-28 22:50:35 +00:00
### Changes
2022-02-22 16:18:25 +00:00
- Remove dependency on CGO (switch from CGO SQLite to pure Go) [#346 ](https://github.com/juanfont/headscale/pull/346 )
2022-02-18 18:54:27 +00:00
**0.13.0 (2022-02-18):**
2022-01-30 08:21:11 +00:00
2022-02-28 22:50:35 +00:00
### Features
2022-01-30 08:25:49 +00:00
2022-01-30 08:21:11 +00:00
- Add IPv6 support to the prefix assigned to namespaces
2022-01-25 22:11:15 +00:00
- Add API Key support
- Enable remote control of `headscale` via CLI [docs ](docs/remote-cli.md )
- Enable HTTP API (beta, subject to change)
2022-02-24 12:34:36 +00:00
- OpenID Connect users will be mapped per namespaces
- Each user will get its own namespace, created if it does not exist
- `oidc.domain_map` option has been removed
2022-08-16 08:09:28 +00:00
- `strip_email_domain` option has been added (see [config-example.yaml ](./config-example.yaml ))
2022-01-30 08:21:11 +00:00
2022-02-28 22:50:35 +00:00
### Changes
2022-01-29 14:33:54 +00:00
2022-01-30 08:25:49 +00:00
- `ip_prefix` is now superseded by `ip_prefixes` in the configuration [#208 ](https://github.com/juanfont/headscale/pull/208 )
2022-02-11 08:45:02 +00:00
- Upgrade `tailscale` (1.20.4) and other dependencies to latest [#314 ](https://github.com/juanfont/headscale/pull/314 )
2022-02-11 10:56:46 +00:00
- fix swapped machine< - > namespace labels in `/metrics` [#312 ](https://github.com/juanfont/headscale/pull/312 )
2022-02-12 20:50:17 +00:00
- remove key-value based update mechanism for namespace changes [#316 ](https://github.com/juanfont/headscale/pull/316 )
2022-01-29 14:31:42 +00:00
2022-01-29 20:04:56 +00:00
**0.12.4 (2022-01-29):**
2022-02-28 22:50:35 +00:00
### Changes
2022-01-29 20:04:56 +00:00
2022-01-29 14:31:42 +00:00
- Make gRPC Unix Socket permissions configurable [#292 ](https://github.com/juanfont/headscale/pull/292 )
- Trim whitespace before reading Private Key from file [#289 ](https://github.com/juanfont/headscale/pull/289 )
2022-01-29 14:33:12 +00:00
- Add new command to generate a private key for `headscale` [#290 ](https://github.com/juanfont/headscale/pull/290 )
2022-01-28 21:00:13 +00:00
- Fixed issue where hosts deleted from control server may be written back to the database, as long as they are connected to the control server [#278 ](https://github.com/juanfont/headscale/pull/278 )
2022-01-29 14:31:42 +00:00
2022-02-28 22:50:35 +00:00
## 0.12.3 (2022-01-13)
2022-01-13 11:42:56 +00:00
2022-02-28 22:50:35 +00:00
### Changes
2022-01-13 11:42:56 +00:00
- Added Alpine container [#270 ](https://github.com/juanfont/headscale/pull/270 )
- Minor updates in dependencies [#271 ](https://github.com/juanfont/headscale/pull/271 )
2022-02-28 22:50:35 +00:00
## 0.12.2 (2022-01-11)
2022-01-11 14:45:13 +00:00
Happy New Year!
2022-02-28 22:50:35 +00:00
### Changes
2022-01-11 14:45:13 +00:00
- Fix Docker release [#258 ](https://github.com/juanfont/headscale/pull/258 )
- Rewrite main docs [#262 ](https://github.com/juanfont/headscale/pull/262 )
- Improve Docker docs [#263 ](https://github.com/juanfont/headscale/pull/263 )
2022-02-28 22:50:35 +00:00
## 0.12.1 (2021-12-24)
2021-12-24 15:39:22 +00:00
(We are skipping 0.12.0 to correct a mishap done weeks ago with the version tagging)
2021-11-29 17:31:19 +00:00
2022-02-28 22:50:35 +00:00
### BREAKING
2021-11-29 17:31:19 +00:00
2021-11-29 17:34:41 +00:00
- Upgrade to Tailscale 1.18 [#229 ](https://github.com/juanfont/headscale/pull/229 )
- This change requires a new format for private key, private keys are now generated automatically:
1. Delete your current key
2. Restart `headscale` , a new key will be generated.
3. Restart all Tailscale clients to fetch the new key
2021-11-29 17:31:19 +00:00
2022-02-28 22:50:35 +00:00
### Changes
2021-11-29 17:34:41 +00:00
2021-11-30 09:17:21 +00:00
- Unify configuration example [#197 ](https://github.com/juanfont/headscale/pull/197 )
2021-11-29 17:31:19 +00:00
- Add stricter linting and formatting [#223 ](https://github.com/juanfont/headscale/pull/223 )
2021-11-29 19:45:31 +00:00
2022-02-28 22:50:35 +00:00
### Features
2021-11-30 09:16:09 +00:00
2021-11-30 09:17:21 +00:00
- Add gRPC and HTTP API (HTTP API is currently disabled) [#204 ](https://github.com/juanfont/headscale/pull/204 )
- Use gRPC between the CLI and the server [#206 ](https://github.com/juanfont/headscale/pull/206 ), [#212 ](https://github.com/juanfont/headscale/pull/212 )
- Beta OpenID Connect support [#126 ](https://github.com/juanfont/headscale/pull/126 ), [#227 ](https://github.com/juanfont/headscale/pull/227 )
2021-11-30 09:16:09 +00:00
2022-02-28 22:50:35 +00:00
## 0.11.0 (2021-10-25)
2021-11-29 19:45:31 +00:00
2022-02-28 22:50:35 +00:00
### BREAKING
2021-11-29 19:45:31 +00:00
- Make headscale fetch DERP map from URL and file [#196 ](https://github.com/juanfont/headscale/pull/196 )