Files
tailscale/cmd/k8s-operator/deploy
chaosinthecrd 7aa70218d2 cmd/k8s-operator: opt serve out of the tun bind for cluster-traffic ingress
An Ingress annotated with
`tailscale.com/experimental-forward-cluster-traffic-via-ingress` forwards
cluster traffic to the proxy's Pod IP, which is DNATed to the node's Tailscale IP
where serve answers it. On Linux the serve listener is bound to the tunnel
interface and drops that traffic, so set TS_SERVE_ALLOW_ALL_INTERFACES on the
proxy when this annotation is used, which makes serve answer it again.

Document on the annotation how the traffic reaches serve and that it bypasses
tailnet ACLs, and regenerate the CRD and operator manifests.

Updates tailscale/corp#48248

Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>
2026-09-25 16:35:59 +01:00
..

Tailscale Kubernetes operator deployment manifests

./cmd/k8s-operator/deploy contain various Tailscale Kubernetes operator deployment manifests.

Helm chart

./cmd/k8s-operator/deploy/chart contains Tailscale operator Helm chart templates. The chart templates are also used to generate the static manifest, so developers must ensure that any changes applied to the chart have been propagated to the static manifest by running go generate tailscale.com/cmd/k8s-operator

Static manifests

./cmd/k8s-operator/deploy/manifests/operator.yaml is a static manifest for the operator generated from the Helm chart templates for the operator.