Files
tailscale/cmd
chaosinthecrd 7aa70218d2 cmd/k8s-operator: opt serve out of the tun bind for cluster-traffic ingress
An Ingress annotated with
`tailscale.com/experimental-forward-cluster-traffic-via-ingress` forwards
cluster traffic to the proxy's Pod IP, which is DNATed to the node's Tailscale IP
where serve answers it. On Linux the serve listener is bound to the tunnel
interface and drops that traffic, so set TS_SERVE_ALLOW_ALL_INTERFACES on the
proxy when this annotation is used, which makes serve answer it again.

Document on the annotation how the traffic reaches serve and that it bypasses
tailnet ACLs, and regenerate the CRD and operator manifests.

Updates tailscale/corp#48248

Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>
2026-09-25 16:35:59 +01:00
..
2026-07-10 14:26:11 -07:00
2026-07-10 14:26:11 -07:00
2026-07-10 14:26:11 -07:00