Skip to content
CAI
Software that uses CAICheck a score

tailscale/tailscale

52.7

Adequate · 6 August 2026

300.1k

lines of production code

Go

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Tailscale is a secure network connectivity platform that establishes encrypted, peer-to-peer connections between devices. It provides a comprehensive suite of tools for network management, including DNS routing, NAT traversal, and secure tunneling. The system supports diverse deployment environments, from Kubernetes clusters and Linux appliances to web browsers and cloud VMs, while offering modular features for file sharing, SSH access, and device posture checking.

How it got here

2020–2022 — infrastructure and platform expansion

91 changes.

This period focused on modernizing the codebase with modular architectures, introducing the DERP relay protocol, and adding support for WebAssembly, Kubernetes, and cloud storage backends. It also established new tooling for licensing, debugging, and testing, while refactoring core components like the control client and health reporting.

2023–2024 — Web client and Kubernetes operator expansion

68 changes.

This period focused on modernizing the web client with a React-based UI, introducing a comprehensive Kubernetes operator with extensive CRDs, and adding new tools for testing, release building, and system diagnostics.

2025–2026 — Modular feature system and Kubernetes operator enhancements

84 changes.

The codebase underwent a significant architectural shift to a modular feature system, enabling conditional compilation and runtime registration of optional capabilities to reduce binary size and attack surface. Concurrently, the Kubernetes operator was enhanced with multi-tenant support, automated service advertisement, and new reconcilers for peer relay and admission control.

Features

Add .deb package metadata extraction

A new \packages/deb\ package has been added to extract metadata from Debian (.deb) packages. This includes parsing the control file to retrieve the version, architecture, and control data, as well as computing MD5, SHA1, and SHA256 hashes of the package file. The implementation uses the \nfpm\ library to generate test fixtures and relies on standard library packages like \archive/tar\, \compress/gzip\, and \io\ for file reading and hashing.

packages/deb · high confidence

Add /healthz and /metrics HTTP endpoints for k8s-proxy and containerboot

The kube/health package now exposes a /healthz endpoint that returns 200 OK when the node has at least one tailnet IP address, and a /metrics endpoint that proxies requests to the tailscaled's /localapi/v0/usermetrics API. These new HTTP handlers allow external systems to monitor the health and metrics of the Kubernetes proxy and container boot processes.

kube/health · high confidence

Add AWS SSM-based state store with optional KMS encryption

Users can now store Tailscale state in AWS Systems Manager (SSM) Parameter Store. This new backend supports optional encryption using a specified AWS KMS key, allowing for secure, cloud-hosted state persistence. The implementation registers an 'arn:' scheme for automatic instantiation and includes a build tag to control binary size.

ipn/store/awsstore · high confidence

Add BIRD client with 10s timeout and multiline response handling

The chirp package now implements a client for the BIRD Internet Routing Daemon, introducing a 10-second timeout for all communication and supporting multiline responses from BIRD. This enables the system to automatically enable or disable the Tailscale protocol in BIRD when the node acts as a primary subnet router.

chirp · high confidence

Add Gokrazy-based Tailscale appliance and NATLab test appliance

New Gokrazy appliance definitions have been added for the Tailscale application (tsapp) and a NATLab test appliance (natlabapp). These directories contain the configuration (config.json), dependency manifests (gokrazydeps.go), and documentation (README.md) required to build Gokrazy Linux images that bundle the tailscale CLI, tailscaled, and related utilities. The tsapp configuration includes support for breakglass access and specific build tags, while the natlabapp is optimized for running in QEMU within NATLab environments.

gokrazy/tsapp · high confidence

Add Helm chart for the Kubernetes operator

The Helm chart for the Tailscale Kubernetes operator is now available, allowing users to install and manage the operator via Helm. The chart includes configurable values for the operator image, proxy image, OAuth credentials, ingress class, and various pod-level settings such as annotations, labels, tolerations, and extra environment variables. It also supports overriding resource names, configuring the login server, and setting up image pull secrets for private registries.

cmd/k8s-operator/deploy/chart · high confidence

Add JSON serialization for Tailnet Lock status and log data

The \tslockjsonv1\ package now provides stable v1 JSON converters for Tailnet Lock data. Specifically, \log.go\ adds a \LogResponse\ function that formats TKA (Trusted Key Authority) updates and AUMs into a structured JSON output, while \status.go\ adds a \StatusResponse\ function that serializes the current Tailnet Lock status, including trusted keys, visible peers, and node signatures. Helper functions in \tka.go\ handle the conversion of internal Tailscale structures (keys, signatures, peers) into the required JSON types.

feature/tailnetlock/tslockjsonv1 · high confidence

Add JSON struct tag analysis to the vet tool

The \cmd/vet/jsontags\ package has been introduced to the \vet\ tool, providing static analysis for Go struct tags related to JSON serialization. This new analyzer detects incompatible or deprecated usages of JSON struct tags, specifically flagging the use of \omitempty\ where \omitzero\ is preferred for Go 1.27's \encoding/json/v2\, identifying \string\ tags on non-numeric types, and warning about the unsupported \format\ tag option. It also includes an allowlist mechanism to suppress specific false positives.

cmd/vet/jsontags · high confidence

Add Kubernetes egress and ingress proxy support in containerboot

The containerboot binary now supports running as a network-layer proxy for Kubernetes cluster traffic. New files (egressservices.go, forwarding.go, ingressservices.go, kube.go) implement the logic to configure iptables/nftables rules to route traffic to tailnet targets (egress) and from cluster services (ingress). This includes managing state in Kubernetes Secrets, handling IP forwarding, and syncing configurations based on changes to mounted config files or Kubernetes resources. Tests are included to verify the rule generation and state management.

cmd/containerboot · high confidence

Add Kubernetes operator support for PeerRelay resources

The k8s-operator now includes a new reconciler for the PeerRelay custom resource, enabling the management of peer relay instances within a Kubernetes cluster. This change introduces the \peerrelay\ package, which handles the lifecycle of PeerRelay resources by creating and managing StatefulSets, LoadBalancer Services, and associated Secrets. The implementation includes logic for managing auth keys, including automatic reissuance when necessary, and ensures that each replica is properly configured with the correct Tailscale settings. Additionally, the ProxyClass reconciler was moved into its own package, and tests were added to verify the behavior of both the PeerRelay and ProxyClass reconcilers.

k8s-operator/reconciler/peerrelay · high confidence

Add Linux framebuffer status display for the Tailscale appliance

A new 'fbstatus' command has been added for Linux-based appliances, providing a visual status display on the Linux framebuffer. This tool renders the Tailscale logo, backend state, and device IP addresses, and displays a QR code for login enrollment. It is restricted to Linux systems, with a non-functional stub for other operating systems.

cmd/fbstatus · high confidence

Add Raspberry Pi arm64 Gokrazy appliance image

Users can now deploy Tailscale on Raspberry Pi devices using the new arm64 Gokrazy image. This adds a pre-configured, bootable image that includes Tailscale, DHCP, NTP, and serial console support, enabling headless appliance-style operation on 64-bit ARM hardware.

gokrazy/tsapp-pi.arm64 · high confidence

Add SSH no-authentication demo server

A new standalone SSH server demo has been added to help SSH client authors test their clients against a server that uses no client authentication. The demo allows any username except 'denyme' to connect, and includes multiple banner messages during the authentication phase to help identify client-side issues without needing a full Tailscale setup.

cmd/ssh-auth-none-demo · high confidence

Add TypeScript type definitions for the WebAssembly JS interface

New TypeScript declaration files (esbuild.d.ts, wasm\_js.d.ts) define the JavaScript API for the WebAssembly module, including the IPN interface with methods for login, logout, and SSH sessions, as well as callback types for state and network map notifications.

cmd/tsconnect/src/types · high confidence

Add Windows firewall implementation using the Windows Filtering Platform

The Windows-specific firewall implementation is now provided by the new \wf/firewall.go\ file, which uses the Windows Filtering Platform to manage firewall rules. This change introduces a concrete implementation for Windows, allowing the application to control network access via the OS firewall, including permitting Tailscale traffic, DNS, loopback, DHCP, and NDP, while blocking all other traffic.

wf · high confidence

Add Windows manifest generation and JSON output types for CLI commands

The \cmd/tailscale\ package now includes a \mkmanifest\ utility to generate Windows \.syso\ files from \windows-manifest.xml\, enabling proper Windows application metadata. Additionally, new packages \tsdnsjsonv0\ and \tsroutecheckjsonv0\ provide structured types for the JSON output of \tailscale dns\ and \tailscale routecheck\ commands, allowing users to parse command output programmatically. A dependency check test (\deps\_test.go\) and a \depaware.txt\ file are also added to enforce dependency constraints on the CLI.

cmd/tailscale · high confidence

Add XDP-based STUN server implementation

Introduce a new \derp/xdp\ package that implements a STUN server using an eBPF XDP program. The change adds the Go bindings (\bpf\_bpfeb.go\, \bpf\_bpfel.go\) generated from the C source (\xdp.c\) and includes the necessary libbpf headers (\headers/\) to compile the BPF program. The Go side provides an \STUNServer\ type that manages the lifecycle of the XDP program, including attaching it to a network interface and exposing metrics via Prometheus. A non-Linux stub is also provided for cross-platform compatibility.

derp/xdp · high confidence

Add XDP-based STUN server with configurable packet dropping

A new XDP-based STUN server implementation is introduced, allowing the server to operate in various XDP modes (xdp, xdpgeneric, xdpdrv, xdpoffload) and automatically detect the default network interface. The server now supports dynamically enabling or disabling STUN packet processing via HTTP endpoints, enabling users to drop STUN packets for debugging or testing purposes.

cmd/xdpderper · high confidence

Add arm64 NATLab appliance image support

A new arm64 appliance image for the NATLab Linux test environment has been added. This includes the configuration (config.json) and dependencies (gokrazydeps.go) required to run the image in QEMU, featuring Tailscale integration and a custom init process from the ts-gokrazy fork.

gokrazy/natlabapp.arm64 · high confidence

Add arm64 VM variant of the Gokrazy Tailscale Appliance

Users can now deploy the Tailscale Gokrazy appliance as an arm64 virtual machine image. This new variant includes a dedicated configuration (config.json) that sets the Go architecture to arm64, links the arm64 kernel and firmware packages, and configures the tailscaled service to read its configuration from the VM's user-data (e.g., EC2 user-data). The change also adds a README and Go dependency file to support this specific build target.

gokrazy/tsapp-vm.arm64 · medium confidence

Add auth key reissue and state management for Kubernetes clients

The kube/state package now includes new logic for handling auth key reissue requests between tailnet clients (containerboot, k8s-proxy) and the operator. The authkey package provides functions to set, clear, and wait for auth key reissue markers in the state Secret, while the state package manages device metadata (ID, FQDN, IPs) by watching the IPN bus for SelfChange notifications. Tests have been added for both packages.

kube/state · high confidence

Add automated generation of static Kubernetes manifests and Helm chart templates for all Tailscale CRDs

The K8s operator now includes a new \generate\ command that automatically creates static Kubernetes manifests and updates Helm chart templates for all Tailscale Custom Resource Definitions (Connector, ProxyClass, DNSConfig, Recorder, ProxyGroup, Tailnet, ProxyGroupPolicy, and PeerRelay). This tooling ensures that the static manifests and Helm chart templates are kept in sync with the source of truth, and the Helm chart now conditionally installs these CRDs based on the \installCRDs\ value.

cmd/k8s-operator/generate · high confidence

Add checkmetrics command to validate metric documentation

A new \checkmetrics\ CLI command has been added to the \cmd/checkmetrics\ package. This tool validates that all metrics registered by the Tailscale client are documented in a specified knowledge base, which can be provided either as a local file path or a remote URL. The command starts a temporary Tailscale server to collect all registered metrics and then checks each one against the provided knowledge base, failing if any metrics are found to be undocumented.

cmd/checkmetrics · high confidence

Add clipboard and utility helper functions to the web client

The web client now includes a new \clipboard.ts\ utility that provides a cross-browser compatible way to copy text to the system clipboard, supporting both immediate strings and asynchronous promises. Additionally, \util.ts\ introduces several helper functions including \pluralize\ for dynamic text formatting, \isTailscaleIPv6\ for validating Tailnet IPv6 addresses, and other utility functions like \isPromise\ and \isHTTPS\. These utilities are accompanied by corresponding unit tests in \util.test.ts\.

client/web/src/utils · high confidence

Add conditional expvar package for metrics omission

The feature/condlite/expvar package now supports conditional compilation via build tags. When the ts\_omit\_debug, ts\_omit\_clientmetrics, and ts\_omit\_usermetrics build tags are all set, the package provides a no-op Int type and Add method, allowing the application to be built without including expvar metrics. In all other cases, the package provides type aliases to the standard expvar types.

feature/condlite · high confidence

Add config loader for k8s-proxy

The k8s-proxy component now includes a new config package that watches for configuration changes from either a local file or a Kubernetes Secret. The implementation uses fsnotify for file-based configuration and the Kubernetes client to watch for Secret updates, ensuring the proxy can reload its configuration dynamically.

cmd/k8s-proxy/internal · high confidence

Add connector-gen tool for generating app connector configurations

A new command-line tool named 'connector-gen' has been added to the codebase. This utility generates Tailscale app connector configuration details from third-party data sources, specifically supporting AWS and GitHub. It fetches IP prefixes and domain information from these providers to pre-configure routes and auto-approvers, which accelerates the setup process for wide app connectors by avoiding frequent routing reconfiguration.

cmd/connector-gen · high confidence

Add debug portmap endpoint for diagnosing port mapping issues

A new debug endpoint has been added to the local API, allowing users to trigger and observe port mapping probes for PMP, PCP, and UPnP protocols. This tool streams detailed logs of the port mapping process, including gateway and self-IP resolution, probe results, and mapping status, which helps diagnose why port forwarding may not be working.

feature/debugportmapper · high confidence

Add derpprobe binary for continuous DERP, STUN, TLS, and bandwidth probing

A new \cmd/derpprobe\ binary is introduced to perform continuous queuing delay, STUN, TLS, and bandwidth probes against DERP servers. The tool exposes an HTTP server with a /healthz endpoint, a status page, and handlers to trigger individual or all probes. It supports region filtering, mesh key configuration via environment variables, files, or a secrets manager, and exits with a non-zero status if any probe fails when run in one-shot mode.

cmd/derpprobe · high confidence

Add device serial number and hardware address collection for managed posture checks

The posture package now collects device identity information for managed posture checks. On macOS, Windows, Linux, and other supported platforms, the system serial number is retrieved via platform-specific mechanisms (IOKit, SMBIOS). On Android and iOS, the serial number is fetched from the MDM configuration. Additionally, the package now gathers non-loopback hardware (MAC) addresses across all platforms. This enables the system to report these identifiers during managed device checks.

posture · high confidence

Add distributed IP address pool with Raft consensus

The NATC component now supports a distributed IP pool backed by a Raft-based consensus mechanism, allowing IP address allocations to be shared and synchronized across a cluster of NATC instances. This new \ConsensusIPPool\ implementation ensures high availability and consistency for IPv4 address management, while the existing \SingleMachineIPPool\ remains available for single-instance deployments. The change includes serialization logic for state snapshots and restores, enabling the cluster to maintain a consistent view of IP allocations across nodes.

cmd/natc/ippool · high confidence

Add distsign CLI for verifying package signatures

A new command-line tool, distsign, has been added to verify and download packages from pkgs.tailscale.com. Users can now use the --pkg-name flag to specify a package for signature validation and download, with the tool handling the download to a temporary directory and confirming the package's integrity.

cmd/distsign · high confidence

Add doctor diagnostic checks for DNS resolvers

The doctor feature now includes checks for DNS resolvers, specifically detecting if any global DNS resolvers are Tailscale IPs, which can interfere with control plane connectivity. This adds a new diagnostic capability to identify potential configuration issues.

feature/doctor · high confidence

Add ethtool diagnostic check for Linux network interfaces

A new diagnostic check has been added for Linux systems that queries the 'ethtool' utility to report network interface features and statistics. On non-Linux platforms, the check gracefully reports that it is unsupported. This provides users with visibility into network interface capabilities and potential issues, such as AWS ENA driver statistics.

doctor/ethtool · high confidence

Add featureknob package to gate SSH and exit-node capabilities

A new featureknob package has been introduced to control whether Tailscale SSH and exit-node features can run based on environment variables or the current OS/distro. The CanRunTailscaleSSH function now returns an error for unsupported platforms (e.g., Synology, QNAP, or sandboxed macOS builds), and CanUseExitNode prevents exit-node usage on Synology and QNAP distros.

envknob/featureknob · high confidence

Add freedesktop helper for quoting desktop entry arguments

A new \Quote\ function has been added to the \client/freedesktop\ package to handle argument quoting according to the Desktop Entry Specification. This utility ensures that special characters (such as spaces, quotes, and shell metacharacters) are properly escaped, which is required for generating valid autostart files on Linux desktops.

client/freedesktop · high confidence

Add health-checking prober framework with support for multiple probe types

Introduces a new \prober\ package that provides a framework for building and managing health-checking probes. The framework supports various probe types including TLS, HTTP, TCP, DNS, and custom functions, each exposing Prometheus metrics. It includes a status page handler to monitor probe health and supports features like concurrent execution, custom timeouts, and region filtering.

prober · high confidence

Add identity federation support for automatic authkey generation

The new identityfederation package enables automatic authkey generation via OIDC identity federation. It registers hooks to resolve authkeys by exchanging an ID token for an access token and then creating a key with configurable ephemeral and pre-authorized settings. The implementation parses optional query parameters from the client ID to configure device behavior, and includes comprehensive unit tests for the resolution and attribute parsing logic.

feature/identityfederation · high confidence

Add in-memory state store implementation

The ipn/store/mem package now provides an in-memory implementation of the ipn.StateStore interface. This allows applications to use a temporary, non-persistent store for state management, which is useful for testing or scenarios where disk persistence is not required.

ipn/store/mem · high confidence

Add jsondb package for JSON-backed storage

A new jsondb package has been added, providing a generic Go type for saving and loading data structures to and from a JSON file on disk. The package includes an Open function to read or create a database and a Save method to persist changes, with corresponding tests verifying round-trip serialization.

jsondb · high confidence

Add k8s-nameserver for resolving MagicDNS names in Kubernetes

A new k8s-nameserver component has been added to resolve MagicDNS names for tailnet proxies within Kubernetes clusters. The nameserver listens on port 1053 and supports both IPv4 (A) and IPv6 (AAAA) record queries for the ts.net domain. It dynamically updates its in-memory DNS records by watching a mounted Kubernetes ConfigMap, allowing non-tailnet Kubernetes workloads to resolve MagicDNS names. The implementation includes comprehensive unit tests for A and AAAA record handling, including dual-stack scenarios and error cases.

cmd/k8s-nameserver · high confidence

Add kubectl exec/attach session recording via hijacker and tsrecorder

The k8s-operator now records kubectl exec and attach sessions by hijacking the HTTP connection and streaming terminal output to a tsrecorder instance in asciinema v2 format. This includes sending CastHeaders with terminal dimensions, resizing messages, and output data, with configurable fail-open/fail-closed behavior for recording failures. Test coverage is added via fakes and unit tests for the hijacker and tsrecorder components.

k8s-operator/sessionrecording · high confidence

Add license header insertion utility

A new 'addlicense' command has been introduced to automatically prepend a license header to generated code files. This tool is designed to be used with 'go generate' to ensure all generated files include the correct copyright and license information.

cmd/addlicense · high confidence

Add low-level Tailscale protocol client and tooling

The \control/tsp\ package introduces a new low-level client for communicating with the Tailscale coordination server over a Noise-encrypted channel. This includes a \Client\ for registration and map session management, supporting both streaming and non-streaming map responses with size limits to prevent memory exhaustion. The package also adds a \NodeFile\ struct and associated read/write functions to persist node credentials (node key, machine key, and server info) to and from a local JSON file. Tests verify the map session behavior and node file format.

control/tsp · high confidence

Add minimal Tailscale systray application for Linux

A new minimal systray application for Linux is introduced, providing quick access to common operations like profile switching and exit node selection. The application supports multiple color themes (dark, light) and connects to the tailscaled socket, with notifications currently supported on Linux as the primary target.

cmd/systray · high confidence

Add mkpkg tool for building deb/rpm packages

A new \cmd/mkpkg\ utility has been added to build Debian (.deb) and Red Hat (.rpm) packages using the nfpm library. This tool supports specifying package metadata (name, version, description), file contents, empty directories, and configuration files. It also allows defining package dependencies, recommendations, and replacement/conflict rules, as well as including post-install, pre-remove, and post-remove scripts for both package types.

cmd/mkpkg · high confidence

Add nardump tool to generate Nix NAR archives and hashes

A new Go-based utility, nardump, has been added to the repository to build Nix NAR (Nix Archive) files and compute their SHA256 hashes. This tool allows users to calculate Nix sha256 hashes without requiring Nix to be installed on the system, supporting both standard NAR output and Subresource Integrity (SRI) hash generation. The implementation includes support for symlinks and regular files, accompanied by a new test suite that validates the NAR generation against a known golden hash.

cmd/nardump · high confidence

Add new metrics types: LabelMap, MultiLabelMap, and Histogram

The metrics package now includes new types for structured monitoring: LabelMap for single-label metrics, MultiLabelMap for multi-label metrics with Prometheus formatting, and Histogram for value distributions. These types support expvar and Prometheus export, enabling more granular and structured metric reporting. Additionally, file descriptor counting is now optimized on Linux using a sync.Pool to avoid allocations.

metrics · high confidence

Add process permissions check to the doctor

The doctor now includes a new 'permissions' check that prints the running process's user and group IDs, as well as Linux capabilities. This provides users with visibility into the process's effective, real, and saved user/group IDs, and on Linux, the process capabilities.

doctor/permissions · high confidence

Add proxy-test-server for testing Tailscale proxy functionality

A new proxy-test-server command has been added to the codebase. This simple HTTP proxy server is designed for testing Tailscale's client proxy functionality. It supports restricting proxy requests to Tailscale targets, with the ability to additionally allow specific hosts. The server uses autocert for HTTPS, enabling HTTP/2 and ACME challenges.

cmd/proxy-test-server · high confidence

Add standalone STUN server binary

A new standalone STUN server binary (cmd/stund) is introduced, allowing users to run a separate STUN service on UDP port 3478 with an accompanying HTTP debug interface on port 3479. The implementation relies on the existing tailscale.com/net/stunserver package and includes a dependency manifest (depaware.txt) for the new command.

cmd/stund · high confidence

Add static code analysis tools to the build

The \cmd/vet\ package now includes a static analysis tool that enforces Go source code standards. Specifically, it adds a \jsontags\ checker that validates JSON struct tags against an allowlist, a \subtestnames\ analyzer, and a \lowerell\ checker that forbids variables named 'l' or 'I'. These tools are integrated into the build process to catch violations automatically.

cmd/vet · high confidence

Add stunc debug utility for STUN requests

A new command-line tool named stunc has been added to the codebase. This utility allows users to send STUN (Simple Traversal of UDP over NAT) requests to a specified host and port, with a configurable read timeout. It resolves the target address, sends a STUN request, and prints the response details, including the sent address, the server's response address, and the STUN-mapped address.

cmd/stunc · high confidence

Add subtestnames analyzer to the Go vet tool

The Go vet tool now includes a new 'subtestnames' analyzer that flags Go test subtest names containing characters that require quoting or escaping when re-running tests via 'go test -run'. This helps developers avoid common pitfalls with spaces, regex metacharacters, and leading/trailing dashes in subtest names.

cmd/vet/subtestnames · high confidence

Add support for reading system policy settings from environment variables and JSON files

The util/syspolicy/source package now includes new policy store implementations: EnvPolicyStore, which reads policy settings from environment variables (prefixed with TS\DEBUGSYSPOLICY\), and JSONPolicyStore, which reads settings from JSON files (with optional HuJSON support for comments and trailing commas). A central Reader component manages these sources, handling change notifications, locking, and caching of policy snapshots. This enables configuration of Tailscale policies via environment variables or local JSON configuration files, alongside the existing Windows registry-based policy store.

util/syspolicy · high confidence

Add systemd readiness and status notification support

On Linux systems running under systemd, the Tailscale daemon now signals its readiness and updates its status to systemd. This allows systemd to properly manage the service lifecycle and display status information via tools like systemctl. On non-Linux systems or when not running under systemd, this functionality becomes a no-op.

feature/sdnotify · high confidence

Add tsp command-line tool for low-level Tailscale protocol operations

A new 'tsp' CLI tool has been added to perform low-level Tailscale protocol tasks, including generating machine and node keys, creating node registration payloads, and discovering the coordination server's public key. This provides a composable set of building blocks for interacting with the Tailscale control plane directly.

cmd/tsp · high confidence

Add vnet binary with WebSocket proxy and virtual network simulation

The vnet tool now includes a new 'wsproxy' mode that runs a WebSocket server, enabling connection from clients like v86 to a virtual network simulation. The binary also supports flags for IPv4/IPv6, NAT configuration, port mapping, and PCAP logging, providing a userspace network stack for QEMU instances to connect to and simulate various network conditions.

cmd/vnet · high confidence

Add web UI for managing OIDC clients in the tsidp identity provider

The tsidp command now includes a built-in web interface for managing OpenID Connect (OIDC) clients. Administrators can use the UI to create, edit, and delete OIDC client registrations, as well as manage client secrets. The UI is served at the root path and is not available over Tailscale Funnel. The implementation includes HTML templates for the list, edit, and header views, along with CSS styling and Go handlers for the CRUD operations.

cmd/tsidp · high confidence

Add word lists for tails and scales

The words package now exposes two new accessor functions, Tails() and Scales(), which return lists of words loaded from the newly added tails.txt and scales.txt files. The implementation uses Go's embed directive to include the text files as resources, parsing them into string slices while filtering out empty lines and comments. A corresponding test suite validates that the lists are non-empty, contain no duplicates, and exclude previously rejected terms.

words · high confidence

Added Kubernetes client library for API interactions

The kube/kubeclient package now provides a dedicated client for interacting with the Kubernetes API, including methods for managing secrets and emitting events. This includes a new Client interface and implementation that handles authentication, URL configuration, and HTTP requests to the Kubernetes API server. A FakeClient is also provided for testing purposes.

kube/kubeclient · high confidence

Added Linux TAP support as a separate feature module

The codebase now includes a new \feature/tap\ package that registers and implements experimental Linux TAP (Layer 2) support. This change moves TAP-related logic out of the main \net/tstun\ package into a dedicated location, providing the underlying mechanism for handling TAP devices and associated network traffic on Linux.

feature/tap · high confidence

Added command-line speedtest utility

A new 'speedtest' command is now available, allowing users to run download or upload speed tests via the CLI. The tool supports both client and server modes, with configurable host, test duration, and reverse mode. It integrates with the existing net/speedtest package and uses the ffcli v3 framework for command-line argument parsing.

cmd/speedtest · medium confidence

Added identity federation support via conditional registration

The codebase now registers support for authkey resolution via identity federation, enabled by default unless the ts\_omit\_identityfederation build tag is set. This introduces a new package that conditionally imports the identity federation implementation, allowing the system to resolve authkeys through identity federation providers.

feature/condregister/identityfederation · high confidence

Added package signing and verification library

Added a new \clientupdate/distsign\ library that implements signature and validation of distributable files using Ed25519 keys. The library provides functions to generate, parse, and use root and signing keys, and includes a \Client\ for downloading and verifying signed packages from a distribution server. This enables clients to verify the integrity and authenticity of downloaded updates.

clientupdate/distsign · high confidence

Added shell tab-completion for the Tailscale CLI

Users can now use tab-completion in bash, zsh, fish, and PowerShell shells. The \tailscale completion\ subcommand generates the necessary shell scripts, and the \\_\_complete\ internal command provides live suggestions for subcommands, flags, and arguments. This feature is controlled by the \ts\_omit\_completion\ build tag to allow builds without shell completion if desired.

cmd/tailscale/cli/ffcomplete · high confidence

Added static analyzer to enforce consistent JSON import usage

The \cmd/jsonimports\ tool now includes a static analyzer that automatically rewrites Go source files to use explicit package aliases for JSON imports. Specifically, \encoding/json\ and \github.com/go-json-experiment/json/v1\ are imported as \jsonv1\ (or \jsonv1std\ if conflicting), while \github.com/go-json-experiment/json\ is imported as \jsonv2\. This change ensures that code continues to build correctly and clarifies whether \Marshal\ or \Unmarshal\ calls refer to v1 or v2 of the JSON library, addressing potential confusion with Go 1.25's \goexperiment.jsonv2\ support.

cmd/jsonimports · high confidence

Added support for using system proxies

The application now supports using system proxies. This is achieved by registering hooks in the 'feature/useproxy' package that connect the 'net/tshttpproxy' implementation to the core feature system, allowing the application to respect environment-based proxy settings.

feature/condregister/useproxy, feature/useproxy · high confidence

Automated TLS certificate management for Kubernetes services

The system now automatically discovers TLS domains from TCP TerminateTLS handlers and HTTP endpoints, then manages their certificates via a background loop. This includes a retry schedule following Let's Encrypt's recommendations, honoring Retry-After headers, and skipping escalation on transient errors to ensure reliable certificate issuance and renewal for HA Ingress and kube-apiserver proxy groups.

kube/certs · high confidence

Automatic workload identity token generation for AWS, GCP, and GitHub

The new wif package enables automatic generation of identity tokens for Workload Identity Federation across multiple cloud providers. Users can now obtain ID tokens for AWS (via IMDSv2 and ECS), GCP (via metadata headers), and GitHub Actions environments without manual configuration. The system detects the current environment and acquires the appropriate token, supporting audiences for each provider.

wif · high confidence

Centralize and standardize default file and directory paths

The codebase now uses a dedicated \paths\ package to manage default paths for configuration, state, and sockets across all platforms. This introduces a unified migration mechanism (\TryConfigFileMigration\) that safely moves legacy config files to their new locations, ensuring existing users' settings are preserved. Platform-specific logic is now encapsulated: Windows applies restrictive ACLs to state directories, Unix systems use \/var/lib\ or \/var/db\ for state files, and fallbacks like \XDG\_DATA\_HOME\ are implemented for non-root users. This change simplifies path management and improves security by ensuring state directories have correct permissions on all supported operating systems.

paths · high confidence

Centralized and automated license reporting for all platforms

The project has introduced a new \licenses\ directory that centralizes and automates the generation of open-source license reports for each platform. A new \licenses.go\ file provides a \LicensesURL()\ function that directs users to the correct license page for their operating system (Android, Apple, Windows, or the CLI/daemon). Corresponding Markdown files (\android.md\, \apple.md\, \windows.md\, \tailscale.md\) now list the specific dependencies and their licenses for each platform, with the \README.md\ explaining that these are generated using the \go-licenses\ tool. This replaces the previous scattered or manual license management with a structured, automated approach that ensures all clients (including macOS, iOS, tvOS, and Android) have up-to-date and accurate license information.

licenses · high confidence

Centralized runtime control knobs for client features

The client's configurable features are now managed through a centralized \controlknobs.Knobs\ struct, which replaces scattered global variables and simplifies the API. This change introduces a unified mechanism for the control plane to toggle features at runtime, including disabling UPnP, randomizing client ports, forcing background STUN, disabling delta updates, enabling peer MTU discovery, suppressing disco heartbeats, forcing specific Linux netfiltering backends, probing UDP lifetime, storing app connector routes, using user-dial for DNS, disabling split DNS on iOS, disabling local DNS override on Windows, disabling captive portal detection, skipping status queue updates, disabling hosts file updates, forcing IPv4-only MagicDNS registration, emitting runtime metrics, disabling UDP/TUN GRO/GSO, and caching network maps.

control/controlknobs · high confidence

Cloner tool now supports deep cloning for complex nested types

The cloner tool now generates deep-copy methods for structs containing arbitrarily nested maps, maps with pointer or interface values, maps of slices, and named map/slice types. This allows the tool to correctly handle complex data structures like \map\[string\]map\[string\]map\[string\]int\ and \map\[string\]\[\]\*SliceContainer\ without aliasing memory, ensuring that cloned objects are fully independent of the original.

cmd/cloner/clonerex · high confidence

DERP clients can now connect over WebSockets

The DERP HTTP client now supports establishing connections via WebSockets, allowing the client to look like a standard WebSocket connection to intercepting proxies or firewalls. This capability is enabled by default on JavaScript (Go WASM) builds and on Linux/Darwin when the ts\_debug\_websockets build tag is used; on other platforms, the WebSocket path remains disabled.

derp/derphttp · high confidence

DERP protocol and client implementation

The DERP (Designated Encrypted Relay for Packets) package has been introduced to handle packet relaying between Tailscale nodes. This includes the core protocol definitions, client implementation with support for rate limiting and ping/pong keep-alives, and a server-side component. The system relays encrypted WireGuard packets and discovery messages, allowing nodes to maintain connectivity when direct paths are unavailable. The implementation includes a new \derp\ package with client and server logic, along with a \derpconst\ package for shared constants.

derp · high confidence

DERP server gains bootstrap DNS, ACE proxy, and self-signed certificate support

The \cmd/derper\ binary now supports bootstrap DNS resolution, allowing the server to provide DNS records to clients via a new \/bootstrap-dns\ endpoint. It also adds support for the ACE (Application Control Engine) HTTP CONNECT proxy, enabling the server to forward specific requests to Tailscale control planes. Additionally, the server can now generate and serve self-signed certificates for IP addresses in manual certificate mode, and supports GCP Certificate Manager for ACME-based certificate management. These changes enhance the flexibility and security of self-hosted DERP servers.

cmd/derper · high confidence

Debug endpoint for Tailnet Lock log

A new debug endpoint at /debug/tka/log has been added to retrieve the Tailnet Lock log in JSON format. This allows users to inspect the log of Tailnet Lock events, with a default limit of 50 entries and a maximum of 1000. The endpoint returns a JSON response containing the schema version and an array of log messages.

feature/tailnetlock · high confidence

Exposes IPN client and SSH session runner in the NPM package

The 'tsconnect' NPM package now exposes the 'createIPN' function, allowing developers to initialize the Tailscale IPN client with a configuration object that includes an auth key, optional WASM URL, and a panic handler. Additionally, the 'runSSHSession' function is exported from the package, enabling direct invocation of SSH sessions within the browser environment.

cmd/tsconnect/src/pkg · high confidence

Exposes SSH session management and state storage in the Tailscale Connect npm package

The Tailscale Connect npm package now exposes the \runSSHSession\ function, allowing developers to programmatically initiate and manage SSH terminal sessions within a browser. This change introduces a new \js-state-store.ts\ module for persisting IPN state in the browser's session storage, and updates the SSH session logic to handle window unloads via the \unload\ event on the parent window. Users can now pass custom terminal options, receive connection progress and error callbacks, and have web links in the terminal open in new tabs.

cmd/tsconnect/src/lib · high confidence

Extract LocalAPI test client and server into ipn/lapitest

The LocalAPI test client and server have been extracted from ipn/ipnserver and ipn/ipntest into the new ipn/lapitest package. This provides a reusable in-process LocalAPI server and client for black-box testing, allowing tests to interact with the backend via a simulated HTTP/Unix socket interface. The new package includes helpers to create a test server, generate test clients with unique user identities, and configure backend options such as logging, context, and control client mocking.

ipn/lapitest · high confidence

Extract client update logic into a modular clientupdate package

The client update logic has been extracted into a new \clientupdate\ Go package, consolidating update handling for Windows, Linux, and Gokrazy into a single, modular component. This refactoring introduces a unified \Updater\ struct and \Arguments\ struct that manage update parameters such as version, release track (stable, unstable, or release-candidate), and platform-specific installation steps. The package includes platform-specific implementations for downloading and installing updates, with build tags ensuring the correct code is compiled for each target. This change also adds support for updating Gokrazy appliances via GAF (Gokrazy Archive Format) and improves the handling of Windows updates by ensuring the \tailscale.exe\ binary is correctly located and executed for updates. The refactoring also includes test cases for updating Debian and YUM repository configurations to switch between release tracks.

clientupdate · high confidence

Initial release of the Tailscale Kubernetes Operator Helm chart

The Helm chart templates for the Tailscale Kubernetes Operator are now available, providing a complete set of Kubernetes manifests for deploying the operator. This includes the operator Deployment, RBAC roles and bindings for the operator and its proxies, an IngressClass resource, OAuth secret management, and helper templates for naming. The chart also includes a NOTES.txt file with post-installation guidance and a .gitignore to exclude generated CRD files from version control.

cmd/k8s-operator/deploy/chart/templates · high confidence

Internal client adds support for VIP Services and identity federation

The internal client now includes new files to support VIP Services and identity federation. New files \vip\_service.go\ adds methods to create, list, get, and delete VIP Services, enabling users to manage VIP services via the internal API. Additionally, \identityfederation.go\ and \oauthkeys.go\ introduce hooks for resolving auth keys via Web Identity Federation (WIF) and OAuth, allowing the client to handle federated identity tokens and OAuth secrets. The \tailscale.go\ file wraps the external client and defines type aliases, while \awsparamstore.go\ adds support for resolving values from AWS Parameter Store.

internal/client · medium confidence

Introduce AppConnector subsystem with DNS-based route advertisement

The appc package now implements the AppConnector, a subsystem that monitors DNS responses to dynamically advertise routes for configured domains. The AppConnector maintains a map of domains to resolved IP addresses and advertises routes when new addresses are observed. It supports wildcard domains, CNAME chain resolution, and persists route information to a StateStore. The conn25 feature adds custom DNS address schemes for split DNS entries and allows selecting connector peers based on tags and capabilities. Tests cover domain updates, route advertisement, and DNS route generation.

appc · high confidence

Introduce C2N API types and structured port range parsing

The tailcfg package introduces a new set of types for the control-to-node (C2N) API, including request and response structures for SSH username suggestions, update status, posture identity, TLS certificate status, VIP services, and debug netmaps. Additionally, a new ProtoPortRange type is added to handle protocol and port range specifications, with corresponding tests for parsing and serialization.

tailcfg · high confidence

Introduce Gokrazy-based Tailscale appliance image for VMs and Raspberry Pi

Users can now build and run a minimal Tailscale appliance image using Gokrazy, supporting both x86\_64 and arm64 architectures for VMs and Raspberry Pi. The new build tooling allows creating a \~70MB image that includes the Linux kernel and Tailscale, with configuration options for cloud-init/user-data on AWS or serial console setup. The change adds a Makefile with targets for building images, running QEMU, and generating QCOW2 formats for testing, along with a build.go script that exposes AMI pipeline steps and supports JSON output for automation.

gokrazy · high confidence

Introduce ProxyGroupPolicy reconciler for Kubernetes admission control

Added a new reconciler for the ProxyGroupPolicy custom resource, which automatically generates and manages Kubernetes ValidatingAdmissionPolicy and ValidatingAdmissionPolicyBinding resources. This allows administrators to restrict which proxy groups can be used in Service and Ingress resources via the 'tailscale.com/proxy-group' annotation, with the operator merging multiple policies into a single set of admission rules per namespace.

k8s-operator/reconciler/proxygrouppolicy · high confidence

Introduce SNI proxy and port forwarding capabilities to the sniproxy component

The sniproxy component now supports transparent TCP port forwarding and SNI-based proxying. Users can configure the proxy to forward specific TCP ports to designated destinations, and the server can route traffic based on the Server Name Indication (SNI) header, allowing for host-based routing. The implementation includes new handler types for round-robin and SNI-based proxying, along with corresponding metrics for monitoring TCP and SNI connections.

cmd/sniproxy · high confidence

Introduce TPM-based state encryption and hardware attestation

On Linux and Windows, the client now supports encrypting the local state store using the system's Trusted Platform Module (TPM). This adds a new \ipn.StateStore\ implementation that seals state data to the TPM, ensuring that the state file cannot be read or modified without the hardware. Additionally, the client can now report TPM availability and generate hardware-backed attestation keys for device identity. These features are only available on Linux and Windows.

feature/tpm · high confidence

Introduce Tailnet Key Authority (TKA) with support for key management, state synchronization, and device signing

The Tailnet Key Authority (TKA) subsystem is introduced, providing the core logic for managing the tailnet's key authority. This includes the AUM (Authority Update Message) structure and serialization, an UpdateBuilder for creating and signing key changes (add, remove, update keys, votes, and metadata), and state synchronization mechanics. The change also adds support for credential and rotation signatures, device signing via secure deep links, and in-memory storage for the authority state. This enables administrators to manage the trust roots of the tailnet and verify device signing requests.

tka · high confidence

Introduce Tailscale Connect browser client build and distribution tooling

The \cmd/tsconnect\ directory now contains the complete build, serve, and NPM package generation tooling for the Tailscale Connect browser client. Users can run \tsconnect dev\ for a live-updating development server, \tsconnect build\ to generate static assets, and \tsconnect serve\ to serve them. The tooling also supports \tsconnect build-pkg\ to generate an NPM package (\@tailscale/connect\) with pre-compressed WebAssembly, and \tsconnect dev-pkg\ for two-sided development. This includes configuration for TypeScript, Tailwind CSS, and esbuild, along with a new \wasmbuild\ package to manage Go build tags and feature flags for the WebAssembly client.

cmd/tsconnect · high confidence

Introduce Tailscale Connect web UI for SSH and device management

The Tailscale Connect web application now features a new React-based UI for managing SSH sessions and device status. Users can initiate SSH connections to online peers, view connection progress, and handle errors via a dedicated terminal interface. The app also displays QR codes for authentication URLs, shows device approval and tailnet lock status, and provides a logout mechanism. This change adds the core frontend components (app, header, SSH form/session, URL display, and panic/error handling) to the cmd/tsconnect/src/app directory.

cmd/tsconnect/src/app · high confidence

Introduce WebAssembly-based Tailscale Connect browser client

Adds a new Go package at cmd/tsconnect/wasm that compiles a WebAssembly module to expose Tailscale APIs to JavaScript in the browser. The module registers a global newIPN function that initializes the local backend, netstack, and server, and exposes methods for running the client, logging in, logging out, and establishing SSH connections. This enables the Tailscale Connect browser client to function as a full-featured Tailscale node within the browser environment.

cmd/tsconnect/wasm · high confidence

Introduce atomicfile package for safe, atomic file writes

A new \atomicfile\ package has been added to provide a safe, atomic file-writing utility. On Windows, it uses \ReplaceFile\ to preserve file attributes and ACLs during the rename, while on other platforms it uses standard rename operations. The implementation also rejects overwriting irregular files (like sockets or device nodes) and avoids calling \Chmod\ on Windows.

atomicfile · high confidence

Introduce automated git hooks for commit messages, pre-commit checks, and push validation

Developers can now run \./tool/go run ./misc/add-git-hooks.go\ to install a suite of git hooks that enforce project standards: the commit-msg hook automatically appends a Change-Id trailer; the pre-commit hook blocks commits containing forbidden markers like 'DO NOT SUBMIT'; and the pre-push hook rejects pushes containing large files or disallowed go.mod replace directives. The hooks are managed via a shared \githook\ package that supports automatic rebuilding when the \HOOK\_VERSION\ is bumped, and users can chain custom logic by adding \.local\ scripts.

misc · high confidence

Introduce cigocacher command for remote build caching

A new \cigocacher\ command is added to act as a client for the internal gocached service, enabling remote build caching. The tool supports authentication via GitHub OIDC tokens, allows fetching cache statistics, and implements asynchronous PUT operations with configurable timeouts to ensure that build failures do not occur if the cache is unavailable. A test is also added to verify the logic for calculating async PUT timeouts based on payload size.

cmd/cigocacher · high confidence

Introduce client-side audit logging

Added a new audit logging system that captures and queues client-side events for transmission to the control plane. The implementation includes a persistent, queue-based logger that retries failed sends and stores logs to disk, with platform-specific default storage paths for Windows and in-memory fallbacks for other platforms. The change also adds a test suite for the audit log functionality.

ipn/auditlog · high confidence

Introduce composite WebDAV handler with metadata caching

Added a new \compositedav\ package that composes multiple WebDAV services into a single service, presenting each as a subfolder. This includes a \StatCache\ that caches PROPFIND results to reduce round-trips to backend servers, with support for Unicode normalization and path-based invalidation. The handler also rewrites headers and paths to correctly proxy requests to child services.

drive/driveimpl/compositedav · high confidence

Introduce config file support for tailscaled

The ipn package now supports loading configuration from a file, allowing users to set options like exit nodes, advertised routes, and relay server endpoints via a JSON config file. This includes the ConfigVAlpha struct and ToPrefs conversion logic, which maps file-based settings to internal Prefs. Tests confirm that routes are validated and that the config file acts as the source of truth for advertised services and relay server configuration.

ipn · high confidence

Introduce controlbase package for secure control protocol transport

The control/controlbase package has been introduced to implement the base transport for the Tailscale control protocol, utilizing Noise IK with Curve25519, ChaCha20-Poly1305, and BLAKE2s. This new component provides a secure, encrypted connection (Conn) that supports protocol versioning, allowing clients and servers to negotiate and verify the protocol version used during the handshake. The implementation includes optimized memory usage by removing unnecessary buffers when idle and ensuring that the protocol version is selectable and verifiable, enhancing the security and flexibility of the control plane communication.

control/controlbase · high confidence

Introduce dist command for building release packages

The \cmd/dist\ tool is now responsible for building Tailscale release packages, including support for QNAP and Synology targets. The command accepts flags for GCP credentials and QNAP signing certificates, enabling the generation of signed packages for these platforms.

cmd/dist · high confidence

Introduce drive package for Taildrive file sharing

The drive package is introduced to provide a filesystem interface for sharing folders between Tailscale nodes using WebDAV. This includes defining the Share struct and associated view/clone methods, implementing permission handling for read-only and read-write access, and normalizing share names. The package exposes interfaces for local and remote file system interactions, supporting both UNIX and non-UNIX platforms with platform-specific behaviors for user impersonation.

drive · high confidence

Introduce egressservices package for shared egress configuration types

A new \kube/egressservices\ package has been added, defining shared Go types for egress service configuration and status, including \Config\, \TailnetTarget\, \PortMap\, and \ServiceStatus\. This refactors the egress service logic into a separate package to be consumed by non-Kubernetes components like the K8s operator and containerboot, while also adding corresponding tests for JSON marshalling and unmarshalling of these types.

kube/egressservices · high confidence

Introduce envknob package for environment-variable debug settings

A new envknob package has been added to provide a centralized, thread-safe way to read and track environment-variable-based debug settings. It supports registering string, boolean, optional boolean, duration, and integer environment variables, allowing them to be changed at runtime via Setenv. The package also includes a GOOS function that can be overridden for testing purposes.

envknob · high confidence

Introduce experimental NGINX authentication service

Adds a new \nginx-auth\ tool that enables Tailscale Whois authentication for NGINX reverse proxies. The service listens on a UNIX socket (or via systemd socket activation) and validates users by calling the Tailscale API. It returns HTTP headers containing user details (login, name, tailnet) and supports an \Expected-Tailnet\ header to restrict access to a specific tailnet. The package includes Debian and RPM build scripts, systemd unit files, and maintainer scripts for installation and removal.

cmd/nginx-auth · high confidence

Introduce featuretags command for managing Go build tags

A new 'featuretags' command-line tool has been added to help build tools select Tailscale's Go build tags. It supports listing all known features, adding or removing specific features via flags (--add, --remove, --min), and automatically resolves feature dependencies to ensure that dependent features are not inadvertently removed. This tool is intended for use in build scripts to dynamically generate the correct set of Go build tags.

cmd/featuretags · high confidence

Introduce flakytest helper package for marking and retrying flaky tests

A new \flakytest\ package has been added to provide a \Mark\ function that allows tests to be annotated as flaky. This enables the test wrapper to automatically retry failed tests and report them as flaky if they eventually pass. The package also supports skipping flaky tests via the \TS\_SKIP\_FLAKY\_TESTS\ environment variable and includes a \Marked\ helper to check if a test or its parents are marked as flaky.

cmd/testwrapper/flakytest · high confidence

Introduce gitops-pusher CLI tool for GitOps-based ACL management

The new gitops-pusher command-line tool enables a GitOps workflow for managing Tailscale ACLs. It supports applying policy changes to the control plane and running ACL tests in CI pipelines. The tool introduces a cache file (version-cache.json) to track previous ETags, allowing detection of external modifications to ACLs. It also adds a --fail-on-manual-edits flag to enforce strict CI failure on manual console edits, and supports GitHub Actions error syntax for better CI integration.

cmd/gitops-pusher · high confidence

Introduce ipnauth package for LocalAPI access control

The ipn/ipnauth package has been introduced to centralize and manage access control for the LocalAPI. This includes a new Actor interface that represents the security context of the caller (such as a specific Windows user or the tailscaled process itself), along with implementations like WindowsActor and Self. The package also defines ProfileAccess for per-profile permissions and integrates with syspolicy to enforce rules like Always-On mode, ensuring that operations are performed in the correct user's security context and subject to policy checks.

ipn/ipnauth · high confidence

Introduce k8s-proxy binary with auth key renewal and state management

The k8s-proxy component is introduced as a standalone binary that proxies traffic between the tailnet and the Kubernetes API server. It now manages its own state via Kubernetes Secrets, including resetting state on pod recreation and clearing stale reissue markers. Additionally, it monitors the IPN bus for authentication failures and automatically triggers an auth key reissue flow by disconnecting from control and waiting for the operator to provide a new key.

cmd/k8s-proxy · high confidence

Introduce linter to ban confusing variable names

A new static analysis check, 'lowerell', has been added to the Go vet tooling. It flags variables named 'l' (lowercase ell) or 'I' (uppercase i), as these characters are easily confused with the digit '1' or each other in many fonts. The analyzer covers function parameters, return values, struct fields, and other common declaration sites, providing specific error messages that link to a GitHub issue for context.

cmd/vet/lowerell, cmd/vet/lowerell/testdata · high confidence

Introduce new React-based web client UI components

Added a suite of new React components for the web client, including an exit node selector, device details view, SSH view, and update notification card. The app now uses a router-based structure with separate views for home, device details, subnets, SSH, and updates, along with supporting components like ACL tags, address copy cards, and login toggles.

client/web/src/components · high confidence

Introduce new React-based web client with SWR data fetching and Tailwind styling

The web client has been rebuilt using React, featuring a new API layer that leverages SWR for data fetching and state management. This update introduces a modernized UI with Tailwind CSS styling and the Inter font, while establishing the foundational types and hooks (such as \useAPI\) that power the new interface.

client/web/src · high confidence

Introduce new ts2021 client implementation

The ts2021 package now provides a new client implementation for the Tailscale 2021 control protocol, handling the Noise layer and subsequent HTTP/2 connection. The Client struct manages HTTP/2 connections to the coordination server, supporting early payload headers and connection pooling. The Conn wrapper handles the early noise payload and provides a way to return connections to a pool when closed. This new implementation replaces the previous internal/noiseconn package, offering a cleaner separation for the controlclient split.

control/ts2021 · high confidence

Introduce new utility packages for backoff, metrics, and cloud detection

Added several new packages in the util directory: backoff for exponential backoff timers, clientmetric for client-side metrics, cloudenv for detecting cloud environments, cloudinfo for querying cloud metadata, and cmpver for version comparison. These additions expand the available utility functions for common tasks like handling retries, tracking metrics, and identifying the cloud provider.

util · high confidence

Introduce peer relay server feature

The peer relay server feature is now available, allowing nodes to act as relays for other peers. This includes a new HTTP debug endpoint at /debug-peer-relay-sessions to view session status, and the server lifecycle is now managed via the ipnext.Extension interface, responding to profile state changes and node attributes to enable or disable the relay server dynamically.

feature/relayserver · high confidence

Introduce pgproxy as a TLS-enforcing Postgres proxy

A new 'pgproxy' tool is added to the codebase, providing a proxy for the Postgres wire protocol that enforces strict TLS verification for upstream database connections. The proxy runs an in-process Tailscale instance to secure client connections and verifies the upstream server's TLS certificate against a provided CA file, addressing security risks where Postgres clients might not properly validate server certificates. The implementation includes a main entry point, a proxy struct handling connection forwarding, and metrics exposure via expvar.

cmd/pgproxy · high confidence

Introduce proxy-to-grafana utility for Tailscale-Grafana integration

A new cmd/proxy-to-grafana tool is added, providing a reverse proxy that identifies users via their Tailscale identity and maps them to Grafana users. The tool supports setting Grafana roles (Viewer, Editor, Admin) through Tailscale ACL grants, automatically creates Grafana users if they do not exist, and uses the local client to fetch certificates and status. Tests verify that user headers are correctly set and that malicious or pre-existing X-Webauth headers are stripped or overwritten.

cmd/proxy-to-grafana · high confidence

Introduce proxymap package for localhost port-to-IP mapping

A new \proxymap\ package has been added to manage temporary mappings between localhost IP:ports and remote Tailscale IPs. This component allows local applications to query which Tailscale identity corresponds to a specific localhost port, supporting both TCP and UDP protocols. The implementation includes methods to register and unregister these temporary mappings and provides a lookup mechanism with a brief retry loop to handle potential race conditions during registration.

proxymap · high confidence

Introduce routecheck feature to verify peer reachability

Added a new routecheck feature that checks the reachability of overlapping routers to help the client choose between multiple network paths. This includes a new ipn extension that tracks router nodes via the IPN bus, a localapi endpoint to retrieve reachability reports, and a test suite for the router tracker.

feature/routecheck · high confidence

Introduce safeweb package for secure HTTP server defaults

The safeweb package provides a wrapper around http.Server that applies default security headers (CSP, X-Content-Type-Options, Referer-Policy, Strict-Transport-Security) and enforces CSRF protection on browser routes. It distinguishes between browser and API routes, blocking form-encoded content types for API endpoints and supporting custom CSP and CORS configurations.

safeweb · high confidence

Introduce shared path and file utility types for the drive implementation

Added new shared utilities in the drive package to standardize path handling and file metadata representation. This includes pathutil.go for URL path manipulation (CleanAndSplit, Normalize, Join, etc.), readonlydir.go for a virtual directory implementation that lazily loads children, stat.go for static file info structures, and xml.go for XML escaping. These changes support the broader drive refactoring by providing consistent, reusable components for path and file operations.

drive/driveimpl/shared · high confidence

Introduce shared types for exposing Kubernetes Services to tailnet

A new 'ingressservices' package is added to define shared types for exposing Kubernetes Services to the tailnet. This includes structures for ingress configuration (mapping Tailscale Service IPs to Cluster IPs) and status tracking per ingress proxy Pod, enabling non-Kubernetes shared libraries to consume these types without pulling in Kubernetes-specific dependencies.

kube/ingressservices · high confidence

Introduce the Conn25 app connector feature

The new Conn25 feature adds support for an app connector that routes traffic for configured domains via connector devices, avoiding the 'too many routes' limitation of the previous app connector. This change introduces the core implementation, including address assignment management, a flow table for NAT operations, and API endpoints to query active state.

feature/conn25 · high confidence

Introduce the \`cloner\` code generation tool for deep-cloning structs

A new \cmd/cloner\ tool has been added to automatically generate \Clone\ methods for Go structs. The tool analyzes struct fields and generates deep-copy logic that ensures no memory is aliased between the original and the clone. It supports complex nested types including slices of pointers, maps with pointer or slice values, and interface types. The generated code handles nil checks and deep copies of all contained pointer and map structures to prevent shared state. A corresponding test suite verifies the correctness of the generated clone methods against various edge cases like nil values and empty collections.

cmd/cloner · high confidence

Introduce the \`cmd/viewer\` codegen tool for generating read-only view wrappers

A new \cmd/viewer\ tool has been added to automatically generate 'view' wrapper types that provide read-only accessor methods for underlying struct fields. The generated code includes methods for JSON serialization (supporting both \json/v1\ and \json/v2\), deep cloning, and field access. The tool handles various field types including slices, maps, and pointers, and respects user-defined \View()\ methods on named types. A corresponding test suite (\viewer\_test.go\) validates the generation logic and import tracking.

cmd/viewer · high confidence

Introduce the gocross build wrapper and a Windows Go executable wrapper

Adds a new \gocross\ tool that acts as a \go\ wrapper, automatically injecting build flags and environment variables based on the target OS and architecture. The \gocross-wrapper.sh\ and \gocross-wrapper.ps1\ scripts manage downloading and caching the correct Go toolchain, while \tool/go\ and \tool/goexe\ provide a seamless \go\ command experience on Unix and Windows respectively. This change enables consistent, hermetic builds across different platforms and architectures.

tool · high confidence

Introduce the natc NAT-based connector

A new 'natc' command is added to provide a NAT-based connector for Tailscale, allowing traffic to be routed to a specific domain through a specific node. The implementation includes command-line flags for configuration (such as hostname, site ID, and DNS servers), integration with the local Tailscale client, and support for an optional consensus-based IP pool for high-availability clusters. A corresponding test file is also added to verify core logic like ULA generation and DNS response handling.

cmd/natc · high confidence

Introduce the safesocket package for cross-platform local socket communication

The safesocket package is introduced to standardize how the Tailscale client connects to the local tailscaled daemon. It provides a unified API (Connect, ConnectContext, Listen) that automatically selects the appropriate transport for each platform: Unix sockets on Linux, macOS, and FreeBSD; named pipes on Windows; and a memory-connection fallback for WebAssembly. The implementation includes platform-specific logic to handle authentication tokens and port discovery, such as reading the 'sameuserproof' file on macOS or using Windows access tokens for authentication. This change replaces the previous ad-hoc connection logic with a consistent, cross-platform socket abstraction.

safesocket · high confidence

Introduce tsconsensus package for Raft-based cluster consensus

The new tsconsensus package provides a Raft-based consensus mechanism for groups of tsnet.Servers. It enables cluster peer discovery based on Tailscale tags, allows executing commands on the cluster leader, and manages inter-node communication over Tailscale using the hashicorp/raft library. The package includes HTTP handlers for joining the cluster and executing commands, an authorization layer that validates peer access, and a monitoring endpoint to inspect cluster status.

tsconsensus · high confidence

Introduce tsd.System to unify subsystem initialization

The new tsd package provides a System struct that aggregates all subsystems (such as the event bus, dialer, DNS manager, engine, and health tracker) into a single, unified container. This change replaces scattered global state and ad-hoc initialization patterns with a structured approach, making it easier to wire up and manage dependencies across different parts of the Tailscale daemon.

tsd · high confidence

Introduce versioned JSON output support in the Tailscale CLI

The \cmd/tailscale/jsonoutput\ package now provides a stable, versioned JSON serialization format for CLI output. Users can specify the output format using the \-format\ flag (accepting \json\ or \json-line\) or the \-json\ flag (supporting both boolean and versioned values like \-json=2\). This change allows scripts and clients to parse consistent JSON responses, with the \ResponseEnvelope\ struct ensuring every JSON response includes a \SchemaVersion\ field. The \Format\ type implements the \flag.Value\ interface to coordinate between \-format\ and \-json\ flags, ensuring that setting \-json\ implies a JSON output format and defaults to schema version 1 for backward compatibility.

cmd/tailscale/jsonoutput · high confidence

Introduces a modular feature registry for build-time feature toggles

The feature/featuretags package now provides a central registry of all ts\_omit-able build tags, allowing individual features to be selectively included or excluded from the binary at build time. This includes a FeatureTag type with methods to check if a feature is omittable, retrieve its corresponding build tag, and resolve feature dependencies (both direct and transitive). The implementation adds a comprehensive list of features such as ACE, ACME, AppConnectors, AWS, and others, each with a description and optional dependencies. A corresponding test suite verifies that all declared features have valid dependencies, that the dependency resolution works correctly, and that all ts\omit\ build tags in the codebase are properly declared in the registry.

feature/featuretags · high confidence

Introduces an extension framework for LocalBackend

The ipn/ipnext package now provides an extension system that allows additional features and services to be registered and initialized alongside the core LocalBackend. This new architecture enables modular functionality to interact with the backend in a controlled, thread-safe manner through a defined Host interface, supporting lifecycle management via Init and Shutdown callbacks.

ipn/ipnext · high confidence

Introduces internal Kubernetes API type definitions

The kube/kubeapi package now defines internal Go structs for Kubernetes API types (TypeMeta, ObjectMeta, Secret, Event, etc.) copied from the official k8s.io/api packages. This allows internal components to interact with Kubernetes resources without pulling in the full Kubernetes client library dependencies, keeping the dependency footprint smaller for consumers of these types.

kube/kubeapi · high confidence

Kubernetes operator adds status conditions and utility helpers for managing resource states

The k8s-operator now includes a new conditions.go file that standardizes how status conditions are set and removed for Kubernetes resources like Connector, ProxyClass, DNSConfig, Service, Recorder, ProxyGroup, Tailnet, and PeerRelay. This change ensures consistent status reporting and state tracking across the operator's managed resources. Additionally, a new utils.go file provides helper functions for label value truncation and config file naming, while api-docs-config.yaml and api.md define the API documentation structure for the operator's custom resources.

k8s-operator · high confidence

Kubernetes operator adds support for KubeAPIServer ProxyGroup type and Connector resources

The Kubernetes operator now supports configuring proxies via the new ProxyGroup custom resource, including a dedicated KubeAPIServer ProxyGroup type for high-availability API server proxying, and a Connector resource for subnet routers, exit nodes, and app connectors. The operator creates and manages the necessary Tailscale Services, StatefulSets, and status conditions for these resources, while also handling cleanup and validation of these new resource types.

cmd/k8s-operator · high confidence

Kubernetes store implementation for Tailscale state persistence

The kubestore package now provides a complete implementation of the ipn.StateStore interface backed by Kubernetes Secrets. This enables Tailscale to persist node state, TLS certificates, and ACME account keys within a Kubernetes cluster, with support for read/write and read-only cert-sharing modes, in-memory caching, and key sanitization.

ipn/store/kubestore · high confidence

Linux systray applet gains startup integration and improved status indicators

The Linux system tray applet now supports automatic startup via systemd user services and freedesktop autostart files, allowing the systray to launch automatically on login. The applet also introduces animated loading icons and distinct visual states for the tray icon: a disconnected state (all gray dots), a connected state (white dots), and a loading animation. Additionally, the applet now displays a warning when launched with sudo or doas, and handles the case where a suggested exit node has no location data, preventing a potential crash.

client/systray · high confidence

Modular build features enable optional compilation of components

The build system now supports compiling the Tailscale binary with many features disabled to reduce size and attack surface. A new \buildfeatures\ package generates boolean constants (e.g., \HasDNS\, \HasIPTables\) that allow the codebase to conditionally include or exclude functionality like DNS, iptables, and client updates via build tags. This enables the creation of minimal or specialized builds that omit specific capabilities.

feature/buildfeatures · high confidence

Modular feature system enables conditional compilation and runtime registration of optional capabilities

The codebase introduces a modular feature architecture where optional capabilities (such as BIRD integration, captive portal detection, and remote config) are registered conditionally via build tags (e.g., ts\_omit\_bird, ts\_omit\_c2n). The \feature/condregister\ package acts as a central registry, importing specific feature packages only when their respective build tags are active. This allows users to exclude unused features from their builds or disable them at runtime, reducing binary size and attack surface while maintaining a consistent extension point for new capabilities.

feature/condregister · high confidence

Modular feature system for conditional linking

The codebase introduces a modular feature system that allows individual capabilities (such as SSH, syslog, Wake-on-LAN, and remote config) to be conditionally linked into the binary. This enables resource-constrained builds to omit unused features, reducing binary size and memory footprint. The system uses build tags (e.g., \ts\omit\\<name\>\) and runtime registration to manage feature availability, with hooks allowing features to register themselves and expose functionality to the rest of the application without tight coupling.

feature · high confidence

Modularize debug and child-process hooks in tailscaled

The tailscaled binary now supports modular debug tools and child-process hooks. A new \childproc\ package allows other packages to register code to run as a child process, avoiding duplicated build tags. Additionally, a \debug\ subcommand has been added to \tailscaled\, providing network interface state printing, link change monitoring, portmap debugging, URL fetching, and Prometheus metrics exposure via \/debug/metrics\ and \/debug/pprof\ endpoints. These changes enable more flexible debugging and testing capabilities within the daemon.

cmd/tailscaled · high confidence

Modularized device posture checking into a standalone feature

The device posture checking functionality has been extracted from the main application into a modular, pluggable extension. This change registers the posture module to handle C2N (Control-to-Node) identity requests, allowing the system to collect and report machine-specific information like serial numbers and hardware addresses to the control plane. The implementation now supports policy-based enabling of posture checking and includes health tracking for serial number collection failures.

feature/posture · medium confidence

New 'gafpush' tool for OTA updates to Tailscale appliances

A new 'gafpush' utility has been added to the gokrazy/gafpush package. It enables over-the-air (OTA) updates to running Tailscale appliances by securely copying a Gokrazy Archive Format (GAF) file to the device via SCP, triggering the 'tailscale update' command via SSH, and then cleaning up the temporary file. This allows developers to push updates to appliances from behind NAT or firewalls without needing direct SSH access to the device's root filesystem.

gokrazy/gafpush · high confidence

New /debug/ debug page and request ID tracking

The /debug/ endpoint now uses a new DebugHandler that renders a structured debug homepage with key/value pairs, links, and custom sections. It registers sub-endpoints like /debug/pprof/ and /debug/gc, and supports optional Prometheus metrics via the promvarz package. Additionally, every HTTP request now carries a unique RequestID (header X-Tailscale-Request-Id) that is logged in AccessLogRecord and displayed in error messages to help correlate client errors with server logs.

tsweb · high confidence

New CLI commands for app connector routes and bug reports

The Tailscale CLI now includes a new 'appc-routes' subcommand to display App Connector route status and a 'bugreport' subcommand to generate shareable diagnostic identifiers. These additions expand the CLI's capabilities for managing and troubleshooting network configurations and support cases.

cmd/tailscale/cli · high confidence

New Custom Resources for Kubernetes Operator: Connector, ProxyClass, ProxyGroup, and more

The Kubernetes operator now supports a comprehensive set of new Custom Resource Definitions (CRDs) to manage Tailscale components within a cluster. Users can now deploy and configure Connectors (for subnet routing, exit nodes, and app connectors), ProxyGroups (for egress, ingress, and kube-apiserver proxying), and PeerRelays (with AWS Elastic IP support). Additionally, the operator introduces ProxyClass for centralized proxy configuration, Tailnet for multi-tenant authentication, DNSConfig for internal DNS resolution, Recorder for SSH session recording, and ProxyGroupPolicy for namespace-level access control. These resources allow users to define high-availability, multi-replica, and highly customizable Tailscale nodes directly via Kubernetes manifests.

k8s-operator/apis/v1alpha1 · high confidence

New Go client library for the Tailscale Control Plane API

A new Go client library for the Tailscale Control Plane API has been added to the \client/tailscale\ package. This library provides a structured way to interact with the Tailscale API, including methods for managing devices, keys, DNS settings, and ACLs. The package includes types for device details, key capabilities, and DNS configurations, along with helper functions for building URLs and handling HTTP requests. Additionally, deprecated aliases for the local client have been added to maintain backward compatibility.

client/tailscale · high confidence

New React hooks for authentication, exit nodes, self-updates, and connectivity

Added new React hooks to the web client: \useAuth\ manages the authentication flow and session creation, \useExitNodes\ handles filtering and grouping of exit nodes (including Mullvad locations), \useInstallUpdate\ tracks self-update progress, \useToaster\ provides toast notifications, and \useTSWebConnected\ checks connectivity to the local Tailscale web interface.

client/web/src/hooks · high confidence

New Tailnet reconciler for multi-tenant Kubernetes operator

The k8s-operator now supports managing multiple Tailnets, each with its own set of credentials and configuration. A new reconciler watches for Tailnet custom resources, validates the referenced secrets (containing OAuth client IDs/secrets or audience fields for workload identity), and maintains a registry of initialized Tailscale clients. This enables the operator to authenticate to and manage devices, keys, and VIP services for each distinct Tailnet configured in the cluster.

k8s-operator/reconciler/tailnet · high confidence

New UI component library for the web client

The web client's user interface has been refactored by splitting out a shared set of UI components, including Badge, Button, Card, Collapsible, Dialog, EmptyState, Input, LoadingDots, Popover, ProfilePic, QuickCopy, SearchInput, Spinner, Toaster, and Toggle. These components provide a consistent visual language and functionality across the web UI, supporting features like confirmation dialogs, copyable text, and status badges.

client/web/src/ui · high confidence

New client/local package exposes LocalAPI client methods for certificates, routing, and Tailnet Lock

The client/local package now provides a comprehensive Go client for the Tailscale LocalAPI. This includes methods to fetch and manage TLS certificates (CertPair, GetCertificate, SetDNS), check and probe network routes (RouteCheck, RouteCheckProbe), and manage Tailnet Lock (formerly Network Lock) state and keys (TailnetLockStatus, TailnetLockInit, TailnetLockModify, etc.). It also exposes system policy retrieval (GetEffectivePolicy), service client preferences, and debug portmap utilities. The package includes a test suite verifying core client behaviors.

client/local · high confidence

New concurrency primitives in the syncs package

The syncs package now provides a suite of new synchronization primitives for high-performance concurrent programming. This includes sharded data structures (ShardedInt, ShardedMap) that reduce lock contention by partitioning data across multiple internal locks, a generic AtomicValue for lock-free atomic storage, a MutexValue for mutex-protected generic values, a WaitGroupChan for signaling completion via channels, and a Semaphore for managing resource limits. Additionally, debug-mode assertions (AssertLocked, AssertWLocked, AssertRLocked) are added to validate mutex usage during development.

syncs · high confidence

New disco package for parsing and marshaling discovery messages

The \disco\ package has been introduced to handle the parsing and marshaling of discovery messages, including types such as Ping, Pong, CallMeMaybe, and various UDP relay endpoint messages. This change consolidates the logic for handling these specific message formats, providing a dedicated interface for serializing and deserializing them. The package includes a fuzzer and comprehensive tests to ensure correct round-trip behavior for all supported message types.

disco · high confidence

New example for running an HTTPS server with Tailscale TLS

Added a new demo program, servetls, which demonstrates how to run an HTTPS server using a Tailscale certificate via LetsEncrypt. The example utilizes the local.Client to manage TLS certificates, providing a concrete reference for integrating Tailscale's TLS capabilities into Go applications.

client/tailscale/example · high confidence

New get-authkey CLI tool for OAuth-based auth key generation

A new standalone CLI tool, cmd/get-authkey, has been added to generate authentication keys using OAuth2 client credentials. The tool requires TS\_API\_CLIENT\_ID and TS\_API\_CLIENT\_SECRET environment variables and mandates the specification of at least one tag. It supports options for reusable, ephemeral, and pre-authorized keys, and allows configuration of the Tailscale API base URL.

cmd/get-authkey · high confidence

New health warning messages for node status and configuration

The health package now includes specific warning messages for users regarding node connectivity and security states. This includes alerts for when peers advertise routes but --accept-routes is disabled, when a node is locked out of the tailnet, and when Tailnet Lock state is stored only in memory rather than on disk. These messages provide users with actionable information about their node's operational status.

health/healthmsg · high confidence

New hostinfo package for host environment detection

The hostinfo package has been introduced to centralize and improve the detection of the host environment, including OS version, package type, and container status. This change refactors host information gathering from the controlclient package, adding support for more specific environment types (such as Kubernetes, Docker Desktop, and various Linux distros) and improving accuracy in desktop and container detection.

hostinfo · high confidence

New in-depth healthcheck framework in the doctor package

A new 'doctor' package has been added to support running in-depth healthchecks for diagnosing issues. This includes a core framework (doctor.go) that runs checks in parallel and a specific routetable check (doctor/routetable/routetable.go) that dumps the system's route table to the log. The addition is accompanied by corresponding tests (doctor/doctor\_test.go) to verify the check execution logic.

doctor, doctor/routetable · high confidence

New installer script and kube-deepcopy helper

The repository now includes a new scripts/installer.sh script that detects the current operating system and installs Tailscale according to that OS's conventions, supporting a wide range of Linux distributions (including Ubuntu, Debian, RHEL, Alpine, FreeBSD, and many derivatives) with support for stable and unstable tracks. Additionally, a scripts/kube-deepcopy.sh helper was added to generate Kubernetes deepcopy functions, with specific handling to exclude plan9 builds.

scripts · high confidence

New ipnstate package for network status reporting

The ipnstate package has been introduced to encapsulate the entire state of the Tailscale network. This includes the main Status struct containing node and peer information, as well as specific structures for Tailnet Lock (TKA) status, exit node status, and peer details. The package also provides helper methods, such as IsRouter, to determine if a peer is acting as a router or exit node based on their allowed IP ranges.

ipn/ipnstate · high confidence

New logtail package with in-memory and file-based buffering for log uploads

The logtail package now includes a new Buffer interface and implementations: a memory-based buffer (memBuffer) and a file-based buffer (filch) that captures stderr. The Logger struct has been updated to support configurable flush delays, compression, and metrics tracking. The filch package provides a ring-buffer for log files with configurable size limits (default 50MB per file). Example tools (logadopt, logreprocess, logtail) demonstrate how to use the new API for log adoption and reprocessing.

logtail · high confidence

New netlogfmt tool for human-readable network traffic logs

A new command-line tool, cmd/netlogfmt, has been added to parse and pretty-print network traffic logs from stdin. It converts JSON-formatted network log messages into a structured, human-readable format that displays virtual and physical traffic statistics, including packet and byte rates for TCP connections. The tool supports resolving IP addresses to synonymous labels (node IDs, hostnames, or users) via the --resolve-addrs flag, which queries the Tailscale API to enrich log data with node metadata.

cmd/netlogfmt · high confidence

New network map cache for offline resilience

A new persistent cache for network map data has been added to the local client, allowing the application to start up using stale but previously-valid state even if a connection to the control plane is not immediately available. The cache stores key components of the network map, including packet filters, DNS configuration, SSH policies, and peer information, ensuring that critical network state is preserved locally.

ipn/ipnlocal/netmapcache · high confidence

New omitsize tool to analyze binary size impact of features

A new 'omitsize' command-line tool has been added to help developers understand how much each build tag (feature) contributes to the final binary size. The tool can either start with a minimal binary and show the size increase when adding individual features, or start with a full binary and show the size reduction when removing them. It supports combining features with '+' (AND) and respects feature dependencies, allowing users to see the impact of feature combinations. The tool also supports caching results for faster subsequent runs.

cmd/omitsize · high confidence

New printdep command for build system information

A new 'printdep' command has been added to the build system, allowing users to retrieve key build metadata directly from the CLI. It supports the --go flag to print the current Go toolchain git hash, the --go-url flag to print the corresponding tarball download URL (for Linux and Darwin), and the --alpine flag to print the active Alpine Docker image tag. Additionally, the --next flag can be combined with --go or --go-url to retrieve the upcoming release candidate hash and URL instead of the current stable versions.

cmd/printdep · high confidence

New shared reconciler utilities for Kubernetes controllers

The k8s-operator/reconciler package now provides shared utilities for Kubernetes controller reconciliation loops, including functions to manage finalizers (SetFinalizer, RemoveFinalizer, EnsureFinalizer, ClearFinalizer), generate standard ownership labels (Labels), and enqueue parent resources when child resources change (EnqueueForChild). It also includes a thread-safe ResourceTracker to monitor the count of managed resources via a metric gauge. These changes refactor and centralize common reconciliation logic previously scattered across the codebase.

k8s-operator/reconciler · high confidence

New sync-containers tool to sync container image tags between registries

Added a new command-line tool, sync-containers, which synchronizes container image tags from a source registry (e.g., Docker Hub) to a destination registry (e.g., GitHub Container Registry). The tool supports a dry-run mode, limits the number of tags to sync, and uses GitHub's OIDC-based authentication (github.Keychain) to avoid storing long-lived personal access tokens. It copies both single-architecture images and multi-architecture image indexes, updating 'latest' and 'stable' tags as needed.

cmd/sync-containers · high confidence

New test control server for integration testing

A new command-line tool, cmd/testcontrol, has been added to run a simple test control server for integration tests. The server initializes a test environment with optional fake nodes and exposes an HTTP interface at 127.0.0.1:9911, allowing test suites to interact with a controlled network state during integration testing.

cmd/testcontrol · high confidence

New time utility packages: mono, rate, and format helpers

The codebase now includes a new \tstime\ package providing time utilities. This includes a \mono\ sub-package for fast, monotonic time tracking with JSON serialization support, a \rate\ sub-package implementing a token-bucket rate limiter and an exponentially weighted moving average (EWMA) for measuring event rates, and top-level helpers for parsing durations (including 'd' and 'w' suffixes), formatting time strings, and sleeping with context cancellation. Tests are included for all new functionality.

tstime · high confidence

New tl-longchain tool to re-sign nodes with long rotation signatures

A new command-line tool, tl-longchain, has been added to help tailnet administrators identify nodes with excessively long signature chains and print commands to re-sign those node keys with a fresh direct signature. The tool queries the Tailnet Lock status and, for any node where the rotation signature chain exceeds a configurable limit (default 10, max 16), outputs a 'tailscale lock sign' command. This addresses the implicit limit on the number of rotation signatures that can be chained before the signature becomes too long.

cmd/tl-longchain · high confidence

New tsnet-proxy command for exposing local services on the tailnet

A new \tsnet-proxy\ command-line tool has been added to the \cmd/tsnet-proxy\ directory. It allows users to expose a local TCP port on the tailnet, with optional HTTP/HTTPS reverse proxying that automatically injects Tailscale user identity headers (Tailscale-User-\*) based on the connecting client's WhoIs information. The tool supports raw TCP, HTTP, and HTTPS modes, with automatic certificate issuance for HTTPS.

cmd/tsnet-proxy · high confidence

New types and constants for Kubernetes operator configuration

The kube/kubetypes package now includes new Go types and constants that define the configuration schema for the Kubernetes operator. This includes the KubernetesCapRule struct, which introduces support for recording kubectl exec sessions via Recorders and EnforceRecorder fields, as well as the ability to enable kubectl API request events. Additionally, the APIServerProxyMode type and its associated constants (auth, noauth) are introduced to specify whether the API server proxy adds impersonation headers based on the caller's Tailscale identity.

kube/kubetypes · high confidence

New types for app connectors, DNS resolvers, and geographic locations

Added new types and packages to support app connectors, DNS resolver configuration, and geographic location handling. The \types/appctype\ package introduces configuration structures for application connectors, including DNAT and SNI proxy settings, route updates, and connection state tracking for the Conn25 feature. The \types/dnstype\ package defines a \Resolver\ type for DNS configurations, including support for DNS over HTTPS (DoH) and exit node usage. The \types/geo\ package provides types and functions for representing and processing geographical locations on a spherical Earth, including latitude/longitude handling, distance calculations, and location quantization for privacy. Additionally, the \types/bools\ package offers utility functions for boolean operations, and \types/empty\ provides an empty struct type for optional fields.

types · high confidence

New web UI views for device management and self-updates

The web client now includes dedicated views for device details, SSH server configuration, subnet routing, and self-updates. Users can view detailed device information, manage subnet routes, toggle the SSH server, and initiate self-updates directly from the web UI. The home view provides a central hub for device status and settings, while the disconnected view handles logout states. These components form the core of the new web UI frontend for self-updates and device management.

client/web/src/components/views · high confidence

New web client with browser session authentication and platform-specific login flows

The web client now uses browser sessions to authenticate users, requiring them to verify their identity via the control server before accessing the full management interface. This change introduces a new authentication flow where users must log in to the web client, with specific handling for Synology and QNAP NAS platforms. The web client now supports three modes: login, read-only, and manage. The login mode allows users to log into a tailnet, while the manage mode requires authentication via browser sessions. The read-only mode is designed for platforms where the device is configured by other means. The web client also includes a new Vite-based development server for local development, and the assets are now served from a prebuilt directory or a Vite dev server in development mode.

client/web · high confidence

Open-sourced release build logic for Unix packages

The release build logic for Unix packages (Debian, RPM, and tarballs) has been moved from the private corp repository to the public Tailscale repository. This change exposes the internal \release/dist\ package, including the \dist.Build\ context, CLI commands for key generation and verification, and target definitions for QNAP and Synology NAS devices, making the entire release pipeline available for public inspection and contribution.

release · high confidence

Portlist feature implemented as a backend extension

The portlist functionality is now implemented as a backend extension (feature/portlist) that registers itself via ipnext. The extension hooks into profile state changes and self-node updates to determine when to poll for open ports. It uses an eventbus publisher to report discovered services to the control plane, addressing a previous issue where the poller might miss updates to the CollectServices setting.

feature/portlist · high confidence

Portmapper feature module initialization

The portmapper functionality is now initialized via a dedicated feature module. This registers the 'portmapper' feature and sets up the factory function that creates port mapping clients for NAT-PMP, PCP, and UPnP protocols, allowing the system to establish direct connections through NATs.

feature/portmapper · high confidence

Refactor and expand the DNS resolution subsystem

The DNS resolution logic has been significantly refactored to improve reliability and support for modern DNS features. The codebase now supports DNS-over-HTTPS (DoH) for forwarding queries, which provides encrypted DNS traffic and improved security. Additionally, the system now supports MagicDNS on IPv6-only nodes, allowing for consistent name resolution across different network configurations. The DNS manager has been updated to handle split DNS configurations more robustly on Windows, ensuring that local DNS settings are not overwritten by other applications. These changes collectively enhance the reliability and security of DNS resolution across all supported platforms.

net · high confidence

Session recording now supports the v2 API endpoint

The session recording module has been refactored to support the v2 recording endpoint, allowing the client to probe for and connect to newer recorder instances that support the /v2/record and /v2/event endpoints. The \ConnectToRecorder\ function now automatically detects recorder capabilities and routes traffic accordingly, ensuring compatibility with both legacy (v1) and modern (v2) recording backends. Additionally, the \Event\ struct now includes \Destination\ fields to capture node information for Kubernetes API requests.

sessionrecording · high confidence

Structured JSON output for \`tailscale lock\` commands

The \tailscale lock\ commands (\log\ and \status\) now support a \--json\ flag that outputs structured JSON. This change introduces the \tslockjsonv1\ package, which defines Go structs for unmarshaling the JSON output, including \LogResponse\ for the log command and \StatusResponse\ for the status command. These structs expose Tailnet Lock details such as AUM hashes, key signatures, and peer states, enabling external tools to programmatically parse lock state and history.

cmd/tailscale/tslockjsonv1 · high confidence

Support fetching secrets from AWS Parameter Store

The client can now resolve secret values stored in AWS Systems Manager (SSM) Parameter Store. When a secret is specified as an SSM ARN, the system automatically fetches and decrypts the value from AWS, allowing users to reference secrets stored in AWS Parameter Store directly in their configurations.

feature/awsparamstore, feature/condregister/awsparamstore · high confidence

Support for automatic authkey generation via OAuth client secrets

The new oauthkey feature allows users to use an OAuth client secret (prefixed with tskey-client-) to automatically request and receive an authkey for logging in. The secret can include query parameters to configure the generated key: ephemeral (default true), preauthorized (default false), and baseURL (default https://api.tailscale.com). This enables seamless node registration via federated identity without manual key management.

feature/oauthkey · high confidence

Vendored Tailscale's fork of golang.org/x/crypto/acme

Added a vendored copy of the \acme\ package from \github.com/tailscale/golang-x-crypto/acme\ into \tempfork/acme\. This fork of \golang.org/x/crypto/acme\ is maintained to allow rebasing from upstream Go and to support Tailscale-specific features like profiles. The package includes the full implementation and associated tests, along with a test (\TestSyncedToUpstream\) that ensures the vendored files remain in sync with the upstream fork.

tempfork · high confidence

Windows desktop session management for multi-user and Always-On mode

A new 'desktop' package has been added to manage Windows desktop sessions, enabling Tailscale to maintain a connection when 'Always On' mode is enabled and automatically switch to the appropriate user profile when users sign in, lock their screens, or disconnect remote sessions.

ipn/desktop · high confidence

k8s-proxy config file format and parsing

The k8s-proxy now uses a structured, versioned configuration file (v1alpha1) to manage settings such as the auth key, local address and port for health checks and metrics, and API server proxy options. The new config loader supports both root-level and versioned sub-object formats, with backward compatibility for existing configurations. This change introduces a more robust and extensible way to configure the k8s-proxy, including support for static endpoints and service advertisement.

kube/k8s-proxy · high confidence

stunstamp: multi-protocol latency measurement and Linux kernel timestamping

The stunstamp tool now supports measuring round-trip latency for multiple protocols, including ICMP (v4/v6), HTTPS, and TCP, in addition to the existing STUN measurements. On Linux, the tool uses kernel-level timestamps for more accurate latency readings, while non-Linux platforms fall back to userspace or return unsupported errors. The tool also supports probing multiple destination ports and includes a local ephemeral port pool for TCP connections.

cmd/stunstamp · high confidence

tsnet: add SSH, Funnel, Services, and example programs

The tsnet package now supports listening for SSH connections via the new ListenSSH method, enabling custom SSH applications to run over the tailnet. It also introduces ListenFunnel for exposing services to the public internet, and ListenService for advertising Tailscale Services. Additionally, the package now includes several example programs (tshello, ssh-game, tsnet-funnel, tsnet-http-client, tsnet-services, and web-client) that demonstrate these new capabilities.

tsnet · high confidence

Removals

Removal of the standalone tsshd SSH server

The standalone tsshd binary, which previously functioned as an experimental SSH server for Tailscale networks, has been removed. Its functionality has been integrated into the main tailscaled daemon, meaning users no longer need to run a separate process for SSH access over Tailscale.

cmd/tsshd · high confidence

Security

Enhanced security and auditability for Tailscale SSH sessions

Tailscale SSH now enforces a strict whitelist of forwarded environment variables, actively blocking dangerous dynamic linker variables (LD\\, DYLD\\) and other sensitive keys to prevent privilege escalation and secret leaks. On Linux, SSH login events are now reported to the system audit daemon (auditd) via D-Bus, providing deeper visibility into remote access. Additionally, the SSH server now generates and manages its own host keys (RSA, ECDSA, Ed25519) when running as root, ensuring consistent identity across restarts.

ssh · high confidence

Architecture

Centralized constants into the tsconst package

The tsconst package has been created to serve as a single source of truth for various constants used across the codebase. This includes health warning codes, Linux firewall packet mark constants, ping timeout and interval defaults, Windows Wintun interface descriptions, the web client listen port, and the pinned Wintun DLL version and checksum. Users benefit from a more organized codebase where these shared values are consolidated, reducing duplication and making future updates to these specific values easier to manage.

tsconst · high confidence

Extracted Kubernetes API proxy logic into a shared library

The Kubernetes API proxy implementation has been moved from the k8s-operator and k8s-proxy commands into a new shared library at k8s-operator/api-proxy. This refactoring consolidates the proxy logic, making it reusable by both the operator and the standalone proxy binary. The new package includes the core proxying, impersonation header handling, and session recording event generation, along with comprehensive unit tests for impersonation headers and recorder configuration.

k8s-operator/api-proxy · high confidence

LocalAPI handlers are reorganized into modular, build-tag-gated files

The localapi package is refactored to improve build-time modularity and code organization. Handlers are now split into separate files gated by build tags (e.g., \ts\_omit\_debug\, \ts\_omit\_drive\, \ts\_omit\_tailnetlock\), allowing unused features to be omitted from builds. The main \localapi.go\ now registers handlers conditionally based on feature flags, and stub implementations are provided for platforms where certain features are disabled. This change does not alter the external API but improves internal structure and reduces binary size for builds that disable specific capabilities.

ipn/localapi · high confidence

Refactored Taildrop into a modular feature package

The Taildrop file-sharing functionality has been moved out of the monolithic LocalBackend and restructured into a dedicated \feature/taildrop\ package. This change introduces a modular architecture where the Taildrop logic is implemented as a pluggable extension (registering with \ipnext\ and \localapi\), separating concerns such as file operations, peer API handling, and state management. The refactoring includes a new \FileOps\ interface to abstract filesystem interactions (supporting both standard paths and Android's Storage Access Framework) and a dedicated \fileDeleter\ for managing the asynchronous cleanup of received files. This structural shift improves code maintainability and allows the Taildrop feature to be initialized and managed independently within the application lifecycle.

feature/taildrop · high confidence

Refactored control HTTP client and server into a dedicated package

The control HTTP client and server logic has been extracted into the new \control/controlhttp\ package. This change introduces a \Dialer\ struct for configuring and establishing control connections over HTTP/HTTPS, supporting both standard HTTP upgrades and WebSocket-based communication for environments like JavaScript. The server-side handler has been separated into \controlhttpserver\ to manage protocol switching and WebSocket acceptance. Additionally, the \Dialer\ now supports a \DialPlan\ for multi-candidate connection strategies and uses a configurable \netx.DialFunc\ for network dialing.

control/controlhttp · high confidence

Refactored control client into modular components

The control client implementation has been split into separate files (auto.go, client.go, direct.go, map.go, errors.go) to improve code organization and maintainability. The Auto client now uses a cleaner separation between the high-level Auto client and the lower-level Direct client, with dedicated files for map session handling and error types. This refactoring also includes adding tests for the new structure.

control/controlclient · high confidence

Behavioural changes

Add build-time configuration to omit AWS support

The codebase now includes files (aws\_def.go, aws\_omit.go, omit.go) that allow AWS support to be omitted from the binary build via the ts\_omit\_aws build tag. This enables users to produce smaller binaries by excluding AWS-related code paths at compile time.

omit · high confidence

Add new root signing keys for client update distribution

New public root keys are added to the trusted roots for verifying client update signatures. This includes the 'crawshaw-root' and 'distsign-prod-root-1-pub' keys, enabling the client to validate updates signed with these specific production signing keys.

clientupdate/distsign/roots · high confidence

Add support for loading Tailscale configuration from a file or cloud metadata

The ipn/conffile package introduces a new mechanism for booting tailscaled from a configuration file, supporting both local file paths and cloud provider metadata (specifically AWS EC2 user-data). The system distinguishes between an absent configuration source (returning ErrNoConfig) and an invalid one, allowing optional configuration modes. It also supports a legacy serve config format alongside a new declarative services configuration format, with optional HuJSON parsing for non-mobile platforms.

ipn/conffile · high confidence

Added local disk logging for Windows clients and socket statistics

Windows clients now write local disk logs to the %ProgramData% directory, with file rotation and size limits (100 MB per file, 50 files). A new \filelogger\ package handles this on Windows, while a \sockstatlog\ package captures network socket statistics, logging them to disk every 10 seconds and limiting log files to 5 MB. Tests were added for the date prefix removal and resource cleanup.

log · high confidence

Added packet capture and Wireshark dissector for debugging

The packet capture functionality has been moved into the feature/capture directory, providing a debug endpoint that streams packet data in pcap format. Additionally, a new Lua-based Wireshark dissector has been added to decode Tailscale-specific headers, including improved decoding for disco frame types and NAT metadata.

feature/capture · medium confidence

Automated service advertisement and unadvertisement in Kubernetes environments

The Kubernetes client now automatically advertises Tailscale services on startup and cleans them up on shutdown. A new \localclient\ package provides a mockable interface for local client operations, while the \services\ package implements logic to ensure services are advertised via \EditPrefs\ on container boot and unadvertised on termination, including a 20-second wait period to allow for failover.

kube/localclient · medium confidence

Centralized API type definitions for Local and control plane

The apitype package in client/tailscale/apitype now contains the shared type definitions for the LocalAPI and control plane APIs. This includes the new LocalAPIHost constant, the RequestReasonHeader and RequestReasonKey for passing justification headers, and response types such as WhoIsResponse, FileTarget, ReloadConfigResponse, ExitNodeSuggestionResponse, and DNSOSConfig. Additionally, the control plane DNS configuration types (DNSConfig, DNSResolver) are now defined here, providing a single source of truth for these API contracts.

client/tailscale/apitype · high confidence

Centralized store factory with automatic migration and TPM sealing support

The ipn/store package now provides a unified factory (New) that dispatches to specific store implementations (file, memory, AWS, Kubernetes, or TPM-sealed) based on a registered prefix in the path. This change introduces automatic migration from plaintext state files to encrypted TPM-sealed storage, ensuring that existing state data is preserved and secured without manual intervention. Additionally, the system now supports optional state enumeration via StateStore.All, and handles Windows state file migration from legacy AppData locations.

ipn/store · high confidence

Client update logic is now a modular feature

The client update functionality has been restructured into a modular feature, allowing it to be enabled or disabled independently. This change introduces a new extension that registers C2N and LocalAPI endpoints for update management and tracks update progress. As a result, the system now explicitly checks for the 'clientupdate' feature being linked before sending the 'AllowsUpdate' flag, meaning the update capability is now gated by this feature flag rather than being always available.

feature/clientupdate · high confidence

DERP server refactored into a separate package with platform-specific RTT stats and WebSocket support

The DERP server implementation has been split out of the main derp package into a new derp/derpserver package, separating the server logic from the protocol definitions. On Linux, the server now collects TCP RTT metrics via a background stats loop, while on other platforms this feature is disabled. Additionally, the server now supports WebSocket-based connections for browser clients, allowing the Tailscale web client to connect to DERP servers. The refactoring also includes test-only methods for client info hooks and updates to the HTTP handler to support both standard TCP and WebSocket upgrades.

derp/derpserver · medium confidence

Enforce Go toolchain version matching at runtime

The Tailscale binary now panics at startup if it was built with the \tailscale\_go\ build tag but the Go toolchain used to build it does not match the expected version recorded in \go.toolchain.rev\. This ensures that the binary is running with the correct Go toolchain, preventing potential issues from version mismatches. A new \TS\_PERMIT\_TOOLCHAIN\_MISMATCH=1\ environment variable can be used to bypass this check if needed.

(repo-wide) · high confidence

Extract Linux DNS file-watching logic into a dedicated feature

The inotify-based file watching for /etc/resolv.conf has been moved from the existing linuxdnsfight package into a new, dedicated feature module. This change isolates the Linux-specific DNS detection logic, making the codebase more modular and allowing the DNS package to register a hook for watching file changes without tightly coupling the implementation details.

feature/linuxdnsfight · high confidence

Extract OAuth key resolution into a separate package

The OAuth key resolution logic has been moved into a new, separate package (feature/condregister/oauthkey) to prevent the OAuth packages from being linked into the tailscaled binary, as only the CLI and tsnet require this functionality.

feature/condregister/oauthkey · medium confidence

Hello server binary refactored into a separate package

The main function in cmd/hello/hello.go has been simplified to instantiate and run the server from the new helloserver package, indicating a structural refactoring that separates the server logic from the entry point.

cmd/hello · high confidence

Hello service UI and server logic moved to dedicated package

The Hello service's HTTP server implementation and its associated static assets (HTML template, CSS, and JavaScript) have been moved into a new \helloserver\ package. This change encapsulates the server logic, template rendering, and static file serving within a single, cohesive unit, improving code organization for the Hello service.

cmd/hello/helloserver · high confidence

Improved exit node selection and management

The client now selects an exit node automatically based on traffic steering scores and online status, and remembers the last suggested exit node. The 'tailscale status' command now displays the currently active exit node, and the CLI offers a new 'exit-node' subcommand to list and filter exit nodes. Additionally, the system policy now supports configuring the 'RunExitNode' preference, and the client will respect the 'ExitNode.AllowOverride' policy setting.

ipn/ipnlocal · high confidence

Improved file access reliability with authentication and Unicode support

The local file server now requires a secret token for all access, preventing potential security issues. Additionally, the drive implementation now handles Unicode normalization mismatches in filenames, ensuring that files can be accessed correctly regardless of the Unicode normalization form (NFC or NFD) used by different clients. A new \connListener\ component was added to manage connections, and tests were added to verify the new functionality.

drive/driveimpl · high confidence

Improved network connectivity and stability for mobile and complex network conditions

The network engine now handles mobile connectivity changes more gracefully by reducing unnecessary STUN/STUN-like probes when idle, which helps preserve battery life and reduce latency spikes on mobile devices. Additionally, the system now more reliably detects and recovers from network state changes, including fixing data races and deadlocks that previously caused crashes or connection drops. The update also improves the reliability of the peer discovery and relay selection logic, ensuring that connections are established more quickly and robustly, particularly in environments with unstable or frequently changing network conditions.

wgengine · medium confidence

Improved reliability of kubectl session recording over WebSockets

The k8s-operator's WebSocket handler for recording kubectl exec/attach sessions was refactored to robustly handle multiple WebSocket frames per read and frame headers split across network reads. This ensures that terminal resize messages (carrying terminal width and height) are correctly parsed and recorded, even when data arrives in fragmented or interleaved chunks. The change adds comprehensive tests for frame parsing and splitting to prevent future regressions in session recording.

k8s-operator/sessionrecording/ws · high confidence

Improved terminal session recording with terminal size headers

The k8s-operator's session recording for 'kubectl exec/attach' sessions has been refactored to ensure that terminal sessions include the terminal size (width and height) in the recording header. This change, implemented in the new \k8s-operator/sessionrecording/spdy\ package, parses SPDY frames to extract resize messages and update the CastHeader before recording begins, ensuring the tsrecorder can properly play back terminal sessions. The implementation includes a new \conn.go\ file for handling SPDY connections, \frame.go\ for parsing SPDY frames, and \zlib-reader.go\ for handling compressed data, all accompanied by comprehensive unit tests.

k8s-operator/sessionrecording/spdy · medium confidence

Introduce in-memory filesystem builder for /perm partition

Added a new 'mkfs' package that creates the writable /perm ext4 filesystem inside a gokrazy disk image or block device. The implementation uses an in-memory sparse buffer to build the filesystem, which avoids writing hundreds of megabytes of zero-initialized metadata to slow storage. This change improves the performance and memory efficiency of the 'tailscale configure flash-appliance' command by reducing the amount of data written to the SD card during the flash process.

gokrazy/mkfs · high confidence

Kubernetes operator now supports multi-tenant client management via a new Provider abstraction

The k8s-operator/tsclient package introduces a Provider type that manages multiple Tailscale client instances for different tailnets, replacing the previous single-client approach. This allows the operator to maintain separate API clients for each tailnet, with readiness checks and error handling for missing or unready clients. The Client interface and its resource interfaces (DeviceResource, KeyResource, VIPServiceResource) are now wrapped to support this multi-tenant architecture.

k8s-operator/tsclient · high confidence

Log target configuration via environment variable and custom HTTP client

The logpolicy package now supports overriding the log target via the TS\_LOG\_TARGET environment variable, allowing users to direct logs to a custom server. The Options struct accepts a custom http.Client, enabling advanced configuration of the HTTP transport used for log uploads. Tests verify that invalid log targets are handled gracefully without panicking.

logpolicy · high confidence

Move ACME certificate management into a dedicated feature extension

The ACME/TLS certificate acquisition, renewal, and caching logic has been moved from the ipn/ipnlocal package into a new feature/acme package, which registers as an ipnext.Extension. This refactors how the LocalBackend manages per-domain ACME state, including domain-specific locking, account key storage, and background refresh loops, while preserving the same user-facing behavior for obtaining and renewing TLS certificates.

feature/acme · high confidence

Network flow logging is now a conditional feature

Network flow logging is now a conditional feature that can be omitted at build time. The logging logic has been moved into a separate package (feature/netlog) that registers itself with the WireGuard engine only when the ts\_omit\_netlog and ts\_omit\_logtail build tags are not set. This allows builds that disable these tags to exclude the network flow logging code entirely, reducing binary size and attack surface for environments where network flow logs are not needed.

feature/condregister/netlog, feature/netlog · high confidence

Open-sourced the version generation utility

The build system now uses a new Go-based utility at cmd/mkversion to generate version information and shell variables for embedding into binaries. This change makes the version generation logic open-source, allowing contributors to see and modify how version metadata and copyright information are constructed during the build process.

cmd/mkversion · high confidence

Pin tool dependencies to prevent removal by go mod tidy

A new internal package \internal/tooldeps\ has been introduced to explicitly import tool dependencies such as \golangci-lint\, \depaware\, \policybottest\, and \goimports\. This ensures these tools remain in the \go.mod\ file and are not accidentally removed by \go mod tidy\.

internal/tooldeps · high confidence

Refactored gokrazy build tooling into a reusable Go package

The Gokrazy build logic has been extracted from a single monolithic file into a structured, reusable Go package (gokrazy/build). This change replaces the previous shell-based AWS CLI interactions with the official AWS SDK for Go v2, providing more robust and idiomatic cloud integration. The new Builder API exposes composable steps for building images, uploading to S3, and registering AMIs, while also improving user feedback by showing import-snapshot progress during interactive runs and suppressing it in CI environments.

gokrazy/build · medium confidence

Refactored health reporting to use a structured Warnable system with eventbus integration

The health package has been refactored to replace the previous global state and direct callback mechanisms with a new \Tracker\ type that utilizes an \eventbus\ for state change notifications. This change introduces a structured \Warnable\ system, where health issues are represented by specific \Warnable\ definitions (such as \updateAvailableWarnable\, \NetworkStatusWarnable\, and \noDERPConnectionWarnable\) that include titles, severity levels, and dynamic text generation. The \Tracker\ now manages the state of these warnables, handling visibility delays, dependency chains (e.g., suppressing child warnings if a parent is unhealthy), and control-plane message integration. This allows for more granular and consistent health reporting to the user via \tailscale status\ and the local API.

health · high confidence

Refactored ipnserver into a modular package with improved access control and testing

The ipnserver package has been restructured to improve modularity and testability. The codebase now includes a new ipnauth package that encapsulates actor identity and access control logic, separating it from the server implementation. The server now supports concurrent connections from different users, with explicit handling of the 'in-use' state to prevent conflicts. Additionally, the server exposes a testable interface via new helper functions, and includes a proxy CONNECT handler for Windows GUI logging. These changes enhance the robustness of the local API server and provide better isolation of authentication and authorization logic.

ipn/ipnserver · high confidence

Refactored portlist package with OS-specific implementations

The portlist package has been refactored to use an OS-specific implementation pattern, introducing a new \Poller\ type that delegates to platform-specific \osImpl\ interfaces. Linux now reads directly from \/proc/net/tcp\ and \/proc/net/udp\ files, while macOS uses \netstat\ and \lsof\ commands. Windows utilizes the \netstat\ package for process disambiguation. A new \argvSubject\ helper normalizes process names, and the \Poller\ exposes a synchronous \Poll\ method for retrieving listening ports, with support for filtering localhost bindings and disabling collection via the \TS\_DEBUG\_DISABLE\_PORTLIST\ environment variable.

portlist · high confidence

Refine service discovery filtering for Windows

The service discovery logic now explicitly filters ports on Windows to reduce noise, while treating PeerAPI4, PeerAPI6, and DNS services as interesting. For other operating systems, all TCP listeners are considered interesting.

ipn/policy · high confidence

TTA test agent adds Linux-specific networking and firewall controls

The TTA test agent now includes platform-specific files to manage the test environment on Linux and macOS. On Linux, it configures a userspace WireGuard interface and applies nftables firewall rules to control traffic flow. On macOS, it implements a vsock-based IP assignment mechanism to bypass slow DHCP, while non-Linux/Non-macOS platforms receive no-op stubs for these features.

cmd/tta · high confidence

Test wrapper now surfaces race reports and skips retries on detection

The test wrapper in \cmd/testwrapper\ has been updated to detect and surface Go race conditions in test output. New test data files (A through F) cover various race scenarios, including races during test bodies, races in spawned goroutines, delayed races, races in TestMain, and parallel test races. The wrapper now processes these race reports, ensuring that race conditions are properly attributed to the affected tests and that the system can handle different race detection outcomes.

cmd/testwrapper/testdata · medium confidence

Versioning system refactored with new comparison and detection logic

The version package has been refactored to improve how Tailscale identifies the running binary and compares version numbers. On non-Windows systems, the \CmdName\ function now uses \debug.ReadBuildInfo\ to identify the binary, avoiding slower disk reads. A new \AtLeast\ function allows for robust version comparison, supporting both standard semantic versions (e.g., 1.2.3) and OSS datestamps. Additionally, the \distro\ package has been reorganized to provide a more structured way to identify the operating system or device, with explicit support for platforms like JetKVM, Unraid, and Western Digital MyCloud.

version · high confidence

Web client build tool now pre-compresses static assets

The build-webclient tool has been updated to automatically pre-compress the generated static assets (such as JavaScript and CSS files) into gzip and brotli formats during the build process. This change improves load times for the web client by serving pre-compressed files directly, reducing the need for the server to compress them on each request. The tool also cleans up intermediate compressed files after processing.

cmd/build-webclient · high confidence

testwrapper refactored to use a new argument-parsing and retry engine

The testwrapper tool was rewritten to use a new argument-parsing system that cleanly separates pre-test flags, package patterns, and post-test flags, and implements a configurable retry engine that automatically retries flaky tests up to 10 times within a 10-minute budget, emitting structured JSON output for both flaky and permanent failures. The new implementation also supports the -cachelink flag, handles timeouts as test failures, surfaces race detector reports, and allows environment variables (TS\_TESTWRAPPER\_BUDGET, TS\_TESTWRAPPER\_MIN\_RETRIES, TS\_TESTWRAPPER\_MAX\_RETRY\_TIME) to tune retry behavior.

cmd/testwrapper · high confidence

Test coverage

Added end-to-end tests for the Kubernetes operator; Added test data for certificate files; Added test data for the subtestnames analyzer; Added tests for the viewer code generator; New test helper for validating route advertisement behavior; New test utilities and integration test infrastructure.

Dependencies

Add web client and tsconnect frontend dependency manifests

Introduced new package.json and yarn.lock files for the web client (client/web) and the Tailscale Connect browser client (cmd/tsconnect). These files define the JavaScript/TypeScript dependencies for the respective frontends, including React, Vite, Tailwind CSS, and xterm.js, establishing the build and runtime environment for these web-based interfaces.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 53.

Lenses

  • Code Health 84
  • Architecture 100
  • Maturity 70
  • Readiness 64
  • Security 57
  • Domain Modelling 100
  • Event-Driven 100
  • Accessibility 37

Changes since last survey

  • 300 commits — 276 feature/other, 24 fixes

By area

  • ipn/ipnlocal — 40 commits
  • (root) — 35 commits
  • cmd/tailscale — 23 commits
  • cmd/k8s-operator — 21 commits
  • feature/conn25 — 16 commits
  • tstest/natlab — 11 commits
  • cmd/tailscaled — 9 commits
  • wgengine/magicsock — 7 commits
  • ssh/tailssh — 6 commits
  • .github/workflows — 5 commits
  • net/dns — 5 commits
  • control/controlclient — 4 commits
  • feature/acme — 4 commits
  • net/packet — 4 commits
  • cmd/containerboot — 3 commits
  • cmd/derper — 3 commits
  • gokrazy/build — 3 commits
  • k8s-operator/reconciler — 3 commits
  • kube/certs — 3 commits
  • net/tstun — 3 commits

Notable commits

  • fix: .github/workflows: fix natlab test discovery with fully-excluded files
  • fix: Revert "control/controlclient: continue map poll during key expiry to receive extensions" (#20257)
  • fix: Revert "go.mod: Update vulnerable dependencies (#20388)" (#20420)
  • fix: all: fix JSON serialization under Go 1.27's finalized encoding/json/v2
  • fix: client/systray: fix crash when suggested exit node has no location
  • fix: cmd/tailscale/cli: fix capitalisation of flags
  • fix: cmd/tailscale/cli: fix nil dereference in configure kubeconfig (#20324)
  • fix: cmd/tailscale/cli: fix plain TCP serve status
  • fix: control/controlclient,net/tstun,wgengine/magicsock: fix handling of zero keys in TSMP (#20508)
  • fix: disco: fix UDPRelayEndpoint.AddrPorts slice cap math
  • fix: go.mod: revert tailscale/breakglass fork require
  • fix: go.mod: revert update vulnerable dependencies (#20435) (#20456)
  • fix: gokrazy/tsapp: revert breakglass access lockdown
  • fix: ipn/ipnlocal: fix reporting of active ipnext extensions
  • fix: k8s-operator/dnsrecords: fix dnsRR dropping reconcile events on lock err (#19968)
  • fix: net/packet: fix TSMPType docs
  • fix: ssh/tailssh: fix exit-status frame ordering
  • fix: tka/sync: add regression test for compacted nodes on forked chains
  • fix: tool/gocross: fix gocross-wrapper.ps1 toolchain staleness check for rc versions
  • fix: tsnet: fix data race in chanTUN test device
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tailscale/tailscale was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit deded79f0e6c5d97ac7efd2b10291f58c800caf6 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.