mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 20:01:54 -04:00
ipn/ipnlocal: add TS_SERVE_ALLOW_ALL_INTERFACES to opt serve out of the tun bind
On Linux, serve's kernel listeners are now bound to the tunnel interface, which stops LAN-adjacent hosts completing a handshake with the listener (see #21420). That bind drops packets that arrive on another interface addressed to the node's Tailscale IP, which breaks the Kubernetes operator's `tailscale.com/experimental-forward-cluster-traffic-via-ingress` ingress feature. Add `TS_SERVE_ALLOW_ALL_INTERFACES`, which makes serve's listener skip the interface bind so those packets are answered again. It applies only to serve listeners, not the web client listener, which shares the same code but stays bound. It only affects serve; the peerapi listener stays bound too. This is a targeted opt-out for the operator to set on the affected proxies. Enabling it re-exposes the serve listener to the local network. Updates tailscale/corp#48248 Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>
This commit is contained in:
500 Internal Server Error
Gitea Version: 1.28.0+dev-477-g8b6ad49a5f