Files
tailscale/tsnet
Brad Fitzpatrick daafc49acd tsnet: deflake TestUserMetricsByteCounters
TestUserMetricsByteCounters is currently our top flake at http://flakes/

The test waited for a direct path between its two localhost nodes by
polling s1's status until CurAddr was set, then asserted that the
transferred bytes appeared in the path="direct_ipv4" counters. Both
steps were flaky:

- CurAddr is only reported while magicsock has a confirmed, currently
  trusted UDP address for the peer, which depends on a heartbeat ping
  and CallMeMaybe cycle that can lag arbitrarily under CI load. In the
  CI failure logs the transfer itself went direct and the byte counter
  assertions passed; the only failure was the polling helper's
  t.Error.

- On a machine where localhost has both IPv4 and IPv6, magicsock can
  pick ::1 (it prefers IPv6 on latency ties), so the transfer lands in
  the direct_ipv6 counters instead.

- If no direct path is established yet, the transfer goes over DERP, whose
  wire-byte total (relay framing, plus TCP retransmissions inside the
  tunnel under load) can exceed any fixed tolerance; one flakestress
  run counted 33% more than the payload sent.

Drop the direct-path wait and the hardcoded path label, and assert the
one invariant the test actually cares about: at least the number of
bytes sent must be counted across all path counters combined. There is
deliberately no upper bound, since the counters legitimately include
overhead, retransmissions, and the duplicate copies magicsock sends on
several paths while a direct path is being confirmed.

Verified with flakestress: the old test failed within 7 runs, while the
fixed test passed 33,521 runs with no failures.

See
http://flakes/analyze-test?name=tailscale.com%2ftsnet.TestUserMetricsByteCounters

Updates #deflake

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I4d8a9bfb9549ea9d8d33d3a3b55b4d03f9b9be78
2026-09-14 08:56:14 -07:00
..
2026-07-10 17:39:16 -07:00

tsnet

Go Reference

Package tsnet embeds a Tailscale node directly into a Go program, allowing it to join a tailnet and accept or dial connections without running a separate tailscaled daemon or requiring any system-level configuration.

Overview

Normally, Tailscale runs as a background system service (tailscaled) that manages a virtual network interface for the whole machine. tsnet takes a different approach: it runs a fully self-contained Tailscale node inside your process using a userspace TCP/IP stack (gVisor). This means:

  • No root privileges required.
  • No system daemons to install or manage.
  • Multiple independent Tailscale nodes can run within a single binary.
  • The node's Tailscale identity and state are stored in a directory you control.

The core type is Server, which represents one embedded Tailscale node. Calling Server.Listen or Server.Dial routes traffic exclusively over the tailnet. The standard library's net.Listener and net.Conn interfaces are returned, so any existing Go HTTP server, gRPC server, or other net-based code works without modification.

Usage

import "tailscale.com/tsnet"

s := &tsnet.Server{
	Hostname: "my-service",
	AuthKey:  os.Getenv("TS_AUTHKEY"),
}
defer s.Close()

ln, err := s.Listen("tcp", ":80")
if err != nil {
	log.Fatal(err)
}
log.Fatal(http.Serve(ln, myHandler))

On first run, if no Server.AuthKey is provided and the node is not already enrolled, the server logs an authentication URL. Open it in a browser to add the node to your tailnet.

Authentication

A Server authenticates using, in order of precedence:

  1. Server.AuthKey.

  2. The TS_AUTHKEY environment variable.

  3. The TS_AUTH_KEY environment variable.

  4. An OAuth client secret (Server.ClientSecret or TS_CLIENT_SECRET), used to mint an auth key.

  5. Workload identity federation (Server.ClientID plus Server.IDToken or Server.Audience). Available only if the program imports the feature:

    import _ "tailscale.com/feature/identityfederation"

    The feature is not linked by default to keep the AWS SDK and other cloud-provider dependencies out of programs that don't use workload identity federation.

  6. An interactive login URL printed to Server.UserLogf.

If the node is already enrolled (state found in Server.Store), the auth key is ignored unless TSNET_FORCE_LOGIN=1 is set.

Identifying callers

Use the WhoIs method on the client returned by Server.LocalClient to identify who is making a request:

lc, _ := srv.LocalClient()
http.Serve(ln, http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
	who, err := lc.WhoIs(r.Context(), r.RemoteAddr)
	if err != nil {
		http.Error(w, err.Error(), 500)
		return
	}
	fmt.Fprintf(w, "Hello, %s!", who.UserProfile.LoginName)
}))

Tailscale Funnel

Server.ListenFunnel exposes your service on the public internet. Tailscale Funnel currently supports TCP on ports 443, 8443, and 10000. HTTPS must be enabled in the Tailscale admin console.

ln, err := srv.ListenFunnel("tcp", ":443")
// ln is a TLS listener; connections can come from anywhere on the
// internet as well as from your tailnet.

// To restrict to public traffic only:
ln, err = srv.ListenFunnel("tcp", ":443", tsnet.FunnelOnly())

Tailscale Services

Server.ListenService advertises the node as a host for a named Tailscale Service. The node must use a tag-based identity. To advertise multiple ports, call ListenService once per port.

srv.AdvertiseTags = []string{"tag:myservice"}

ln, err := srv.ListenService("svc:my-service", tsnet.ServiceModeHTTP{
	HTTPS: true,
	Port:  443,
})
log.Printf("Listening on https://%s", ln.FQDN)

Using an exit node

A tsnet node can route its Server.Dial traffic to non-tailnet addresses through an exit node. Select the exit node by setting the ExitNodeID pref via Server.LocalClient:

lc, _ := srv.LocalClient()
_, err := lc.EditPrefs(ctx, &ipn.MaskedPrefs{
	Prefs:         ipn.Prefs{ExitNodeID: "nodeid"},
	ExitNodeIDSet: true,
})

Dials of addresses outside the tailnet then go through the exit node. Dials within the tailnet are unaffected.

Running multiple nodes in one process

Each Server instance is an independent node. Give each a unique Server.Dir and Server.Hostname:

for _, name := range []string{"frontend", "backend"} {
	srv := &tsnet.Server{
		Hostname:  name,
		Dir:       filepath.Join(baseDir, name),
		AuthKey:   os.Getenv("TS_AUTHKEY"),
		Ephemeral: true,
	}
	srv.Start()
}