An open source, self-hosted implementation of the Tailscale control server
Find a file
Kristoffer Dalby 770f3dcb93
Some checks failed
Build / build-nix (push) Has been cancelled
Build / build-cross (GOARCH=386 GOOS=linux) (push) Has been cancelled
Build / build-cross (GOARCH=amd64 GOOS=darwin) (push) Has been cancelled
Build / build-cross (GOARCH=amd64 GOOS=linux) (push) Has been cancelled
Build / build-cross (GOARCH=arm GOOS=linux GOARM=5) (push) Has been cancelled
Build / build-cross (GOARCH=arm GOOS=linux GOARM=6) (push) Has been cancelled
Build / build-cross (GOARCH=arm GOOS=linux GOARM=7) (push) Has been cancelled
Build / build-cross (GOARCH=arm64 GOOS=darwin) (push) Has been cancelled
Build / build-cross (GOARCH=arm64 GOOS=linux) (push) Has been cancelled
Tests / test (push) Has been cancelled
fix tags not resolving to username if email is present (#2309)
* ensure valid tags is populated on user gets too

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* ensure forced tags are added

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* remove unused envvar in test

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* debug log auth/unauth tags in policy man

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* defer shutdown in tags test

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add tag test with groups

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add email, display name, picture to create user

Updates #2166

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add ability to set display and email to cli

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* add email to test users in integration

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* fix issue where tags were only assigned to email, not username

Fixes #2300
Fixes #2307

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* expand principles to correct login name

and if fix an issue where nodeip principles might not expand to all
relevant IPs instead of taking the first in a prefix.

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* fix ssh unit test

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* update cli and oauth tests for users with email

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* index by test email

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

* fix last test

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>

---------

Signed-off-by: Kristoffer Dalby <kristoffer@tailscale.com>
2024-12-19 13:10:10 +01:00
.github Add worker reading extra_records_path from file (#2271) 2024-12-13 07:52:40 +00:00
cmd fix tags not resolving to username if email is present (#2309) 2024-12-19 13:10:10 +01:00
docs Set title for code listings 2024-12-17 14:08:34 +01:00
gen fix tags not resolving to username if email is present (#2309) 2024-12-19 13:10:10 +01:00
hscontrol fix tags not resolving to username if email is present (#2309) 2024-12-19 13:10:10 +01:00
integration fix tags not resolving to username if email is present (#2309) 2024-12-19 13:10:10 +01:00
proto fix tags not resolving to username if email is present (#2309) 2024-12-19 13:10:10 +01:00
.coderabbit.yaml add coderabbit config (#2060) 2024-08-19 10:06:55 +00:00
.dockerignore Added integration tests for the embedded DERP server 2022-03-05 19:34:06 +01:00
.envrc Add direnv flake support 2022-03-19 09:23:03 +00:00
.gitignore Only load needed part of configuration (#2109) 2024-09-07 09:23:58 +02:00
.golangci.yaml more linter fixups (#2212) 2024-11-22 15:54:58 +00:00
.goreleaser.yml fix: missing stable-debug tag (#2232) 2024-11-11 06:06:44 +00:00
.prettierignore Fix broken indent 2024-12-04 06:08:44 +01:00
buf.gen.yaml Create an initial gRPC service 2021-10-26 20:37:37 +00:00
CHANGELOG.md Changelog: support client verify for DERP 2024-12-17 14:08:34 +01:00
CODE_OF_CONDUCT.md Use discord server invite link (#2235) 2024-11-16 07:06:15 +01:00
config-example.yaml Update DNS documentation for dns.extra_records_path 2024-12-17 14:08:34 +01:00
CONTRIBUTING.md update godeps (#2098) 2024-09-04 07:55:16 +02:00
derp-example.yaml Fix key name about derp port 2022-04-10 09:53:27 +08:00
Dockerfile.derper feat: support client verify for derp (add integration tests) (#2046) 2024-11-22 13:23:05 +01:00
Dockerfile.integration Add worker reading extra_records_path from file (#2271) 2024-12-13 07:52:40 +00:00
Dockerfile.tailscale-HEAD Websocket derp test fixes (#2247) 2024-11-22 11:57:01 +01:00
flake.lock bump deps (#2308) 2024-12-17 15:35:42 +01:00
flake.nix bump deps (#2308) 2024-12-17 15:35:42 +01:00
go.mod bump deps (#2308) 2024-12-17 15:35:42 +01:00
go.sum bump deps (#2308) 2024-12-17 15:35:42 +01:00
LICENSE Initial commit 2020-06-21 11:21:07 +02:00
Makefile Add -race Flag to GitHub Action and Fix Data Race in CreateTailscaleNodesInUser (#2038) 2024-12-17 14:06:57 +01:00
mkdocs.yml Remove sealos documentation 2024-12-17 14:08:34 +01:00
README.md Fix README links to point to the stable version 2024-12-04 06:08:44 +01:00
swagger.go move swagger to root for now 2023-05-10 20:47:51 +02:00

headscale logo

ci

An open source, self-hosted implementation of the Tailscale control server.

Join our Discord server for a chat.

Note: Always select the same GitHub tag as the released version you use to ensure you have the correct example configuration and documentation. The main branch might contain unreleased changes.

What is Tailscale

Tailscale is a modern VPN built on top of Wireguard. It works like an overlay network between the computers of your networks - using NAT traversal.

Everything in Tailscale is Open Source, except the GUI clients for proprietary OS (Windows and macOS/iOS), and the control server.

The control server works as an exchange point of Wireguard public keys for the nodes in the Tailscale network. It assigns the IP addresses of the clients, creates the boundaries between each user, enables sharing machines between users, and exposes the advertised routes of your nodes.

A Tailscale network (tailnet) is private network which Tailscale assigns to a user in terms of private users or an organisation.

Design goal

Headscale aims to implement a self-hosted, open source alternative to the Tailscale control server. Headscale's goal is to provide self-hosters and hobbyists with an open-source server they can use for their projects and labs. It implements a narrow scope, a single Tailnet, suitable for a personal use, or a small open-source organisation.

Supporting Headscale

If you like headscale and find it useful, there is a sponsorship and donation buttons available in the repo.

Features

Please see "Features" in the documentation.

Client OS support

Please see "Client and operating system support" in the documentation.

Running headscale

Please note that we do not support nor encourage the use of reverse proxies and container to run Headscale.

Please have a look at the documentation.

Talks

Disclaimer

This project is not associated with Tailscale Inc.

However, one of the active maintainers for Headscale is employed by Tailscale and he is allowed to spend work hours contributing to the project. Contributions from this maintainer are reviewed by other maintainers.

The maintainers work together on setting the direction for the project. The underlying principle is to serve the community of self-hosters, enthusiasts and hobbyists - while having a sustainable project.

Contributing

Please read the CONTRIBUTING.md file.

Requirements

To contribute to headscale you would need the latest version of Go and Buf (Protobuf generator).

We recommend using Nix to setup a development environment. This can be done with nix develop, which will install the tools and give you a shell. This guarantees that you will have the same dev env as headscale maintainers.

Code style

To ensure we have some consistency with a growing number of contributions, this project has adopted linting and style/formatting rules:

The Go code is linted with golangci-lint and formatted with golines (width 88) and gofumpt. Please configure your editor to run the tools while developing and make sure to run make lint and make fmt before committing any code.

The Proto code is linted with buf and formatted with clang-format.

The rest (Markdown, YAML, etc) is formatted with prettier.

Check out the .golangci.yaml and Makefile to see the specific configuration.

Install development tools

  • Go
  • Buf
  • Protobuf tools

Install and activate:

nix develop

Testing and building

Some parts of the project require the generation of Go code from Protobuf (if changes are made in proto/) and it must be (re-)generated with:

make generate

Note: Please check in changes from gen/ in a separate commit to make it easier to review.

To run the tests:

make test

To build the program:

nix build

or

make build

Contributors

Made with contrib.rocks.