The Tailscale Universal Docker Mod
tailscale.dev
tailscale.dev
I do that for my containers and it is incredibly useful for cross containers communication, especially for containers that are hosted in different dedicated servers.
https://mrpowergamerbr.com/us/blog/2023-03-20-untangling-you...
Asking because I've been happy with their containers so far
Ironically, the 1 container I really wanted to use this Tailscale mod for was not from linuxserver.
It's also too much magic for my liking. Some software distributed as a single executable binary gets packaged in some over complicated base image on top of another base image, when I can technically just copy the binary into a scratch and call it a day. I understand the benefits when they have to manage tons of images at scale, but my life has been much easier with images packaged by myself or the upstream projects.
To solve this problem I add another container which should never need to be restarted, and both the game and Tailscale use the networking of that container. This is also the exact use case of Kubernetes' pause containers, so I just use the EKS pause image from ECR public gallery.
Another tip I'd recommend is to run the Tailscale container with `TS_USERSPACE: 'false'` `TS_DEBUG_FIREWALL_MODE: nftables` (since autodetection fails on my machine) and give it `CAP_NET_ADMIN`. This allow Tailscale to use tun device instead of emulation, and it supposed to be more performant. But the clear benefit is that the game server will see everyone's Tailnet IP instead of 127.0.0.1.
In Thai: https://blog.whs.in.th/node/3676
If you were using userspace networking, you wouldn't be able to connect to other services in your tailnet without setting up a HTTP/SOCKS5 proxy https://tailscale.com/kb/1112/userspace-networking/
My users report better latency, but I doubt it.
keep it up guys!
I have over 25 containers running on my home server and not a single one of them is based on a LinuxServer.io image. This "universal" mod would work with 0 of them.
Managing all those household docs: https://docs.paperless-ngx.com
Backups of mail accounts: https://www.offlineimap.org
Cloud storage for phones: http://nextcloud.com
Mirroring podcasts locally: https://github.com/akhilrex/podgrab
Managing dynamic service dns via plugins: https://coredns.io
My own matrix instance: https://matrix-org.github.io/dendrite/
Backups: https://restic.net
Media Management: https://jellyfin.org
Relay only tor help: https://www.torproject.org
S3 compatible storage: https://github.com/seaweedfs/seaweedfs
Git + CI: https://about.gitlab.com
Managing SSL and container proxying: https://traefik.io
Mirror the docker registry locally: https://github.com/docker-library/docs/tree/master/registry
Samba support for the windows hosts: https://github.com/ServerContainers/samba
HTTP/S Proxy with support for modifying results: http://www.privoxy.org
Database: https://www.postgresql.org
Datastore: https://redis.io
and a bunch of support software. Paperless has Tika and Gotenberg as deps for example.
Thanks, that sums it up for me.
I used OC/NC for years but in the last three I mostly abandoned it because the desktop app (for Windows, at least) is atrocious and Android one... isn't good either.
But as on-demand document download with occasional upload it's fine.
I just read in the README that Tini is included by Docker since 1.13 if using --init flag.
Their official solution is to run a logout command before shutting down but that's not always possible.
The use-case where we find the renaming most frustrating is typically when we start a cloud instance with a Tailscale setup script in the cloud init (via Terraform). If we, say, change a parameter that requires Terraform to restart that instance, then the freshly-started instance will be given a `-1` name by Tailscale and the old instance will be offline.
I wish there would simply be a --force-hostname option or something of that nature that tells Tailscale "if a host is authenticating with this name, give it that name, any older machines using that name should be kicked off"
I wonder if the internals will be open sourced? I assume it’s a pretty “simple” go tcp proxy that listens on the tailnet instead of an open port. I had been thinking about writing one for our services at work, so maybe we can use this, but I’d prefer to build the binary directly into our containers.
All the code for LSIO images is available on their GitHub.
https://github.com/tailscale/tailscale/blob/main/ipn/serve.g...
And they also support direct embedding:
https://tailscale.dev/blog/embedded-funnel
I think this is built on the wireguard-go + gvisor mashup, that allows you to do this with just Wireguard:
https://github.com/WireGuard/wireguard-go/tree/master/tun/ne...
One of my favorite applications of this is this little tool that turns Wireguard VPNs into SOCKS5 proxies (which you can selectively enable in your browser)
Full disclosure, I am founder of Adaptive [1]. We use a similar technique to the one with VPN exposed as SOCK5 proxy but for accessing internal infrastructure resources.
If you're doing this with ephemeral containers then yes you'll need a way to roll auth keys. OAuth credentials don't expire and Tailscale has a command line single purpose tool to get an auth key given OAuth credentials, so that can be a viable alternative.
https://tailscale.com/kb/1215/oauth-clients/#get-authkey-uti...
Thanks!
So if the local tailscale address is 1.2.3.4, I do:
ports:
- 1.2.3.4:8080:8080
This doesn't actually add applications to the tailnet as in the OP, but it works.
It's actually even easier to use. Add `tailscale.com/expose: "true"` to a kubernetes service annotations and it will be added to the tailnet automatically