mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 11:52:00 -04:00
On Linux, serve's kernel listeners are now bound to the tunnel interface, which stops LAN-adjacent hosts completing a handshake with the listener (see #21420). That bind drops packets that arrive on another interface addressed to the node's Tailscale IP, which breaks the Kubernetes operator's `tailscale.com/experimental-forward-cluster-traffic-via-ingress` ingress feature. Add `TS_SERVE_ALLOW_ALL_INTERFACES`, which makes serve's listener skip the interface bind so those packets are answered again. It applies only to serve listeners, not the web client listener, which shares the same code but stays bound. It only affects serve; the peerapi listener stays bound too. This is a targeted opt-out for the operator to set on the affected proxies. Enabling it re-exposes the serve listener to the local network. Updates tailscale/corp#48248 Signed-off-by: chaosinthecrd <tom@tmlabs.co.uk>