This is the output of the new misc/bumpdeps tool (#21325) run with --exclude-newer-than-days=7, which asks proxy.golang.org for the newest version of every direct dependency, ignoring releases younger than a week in favor of the newest older one, and runs a single go get. gvisor tracks its "go" branch, wireguard-go its "tailscale" branch, and golang-x-crypto its "main" branch (the proxy's @latest for it is a stray v0.91.0 tag from 2024 that predates our acme fork changes). Indirect deps only moved as far as MVS pulled them. The week-long cooldown held back gvisor, the gokrazy modules, chromedp/cdproto, and hashicorp/raft-boltdb/v2, whose only newer versions are days old; they'll come along next time. Several upstream changes needed small fixes: nfpm's PrepareForPackager takes a modification time now (a zero time keeps the old behavior of using the source file's mtime), esbuild's ServeOptions.Port became an int while ServeResult.Host became a Hosts slice, client-go's EventRecorder.Eventf is now recognized by vet as a printf wrapper (so the k8s-operator calls that passed a preformatted message switch to Event), google/nftables v0.3.0 reads back the kernel's NF_NAT_RANGE_PROTO_SPECIFIED flag into a new expr.NAT.Specified field (so the port map DNAT rule now sets it too or findRule never matches the rule it just added), and staticcheck v0.8.1 knows encoding/json/v2's embed tag option, so the two SA5008 suppressions for it are gone. Two tests assumed old library behavior. client-go's fake clientset now replays existing objects when a watch starts, as a real apiserver does, so the k8s-proxy config test must tolerate the loader ignoring that no-op event before the real reload arrives. fyne.io/systray moved its dbusmenu object path and answers the first GetLayout with depth 1, so the systray test now finds the menu via the item's Menu property and polls until the submenu entries appear. Then make tidy, make updatedeps, and make kube-generate-all (the controller-gen bump to v0.22.0 changes doc strings, stops listing top-level metadata as required, and crd-ref-docs now marks optional fields). Updates #8043 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I3f9a2c6e8b1d4705a9e2c7b8d1f4e6a0c2b5d8e3
Caution
Development of tsidp has been moved to https://github.com/tailscale/tsidp and it is no longer maintained here. Please visit the new repository to see the latest updates, file an issue, or contribute.
tsidp - Tailscale OpenID Connect (OIDC) Identity Provider
tsidp is an OIDC Identity Provider (IdP) server that integrates with your Tailscale network. It allows you to use Tailscale identities for authentication in applications that support OpenID Connect, enabling single sign-on (SSO) capabilities within your tailnet.
Prerequisites
- A Tailscale network (tailnet) with magicDNS and HTTPS enabled
- A Tailscale authentication key from your tailnet
- Docker installed on your system
Installation using Docker
Pre-built image
A pre-built tsidp image exists at tailscale/tsidp:unstable.
Building from Source
# Clone the Tailscale repository
git clone https://github.com/tailscale/tailscale.git
cd tailscale
# Build and publish to your own registry
make publishdevtsidp REPO=ghcr.io/yourusername/tsidp TAGS=v0.0.1 PUSH=true
Running the Container
Replace YOUR_TAILSCALE_AUTHKEY with your Tailscale authentication key:
docker run -d \
--name tsidp \
-p 443:443 \
-e TS_AUTHKEY=YOUR_TAILSCALE_AUTHKEY \
-e TAILSCALE_USE_WIP_CODE=1 \
-v tsidp-data:/var/lib/tsidp \
ghcr.io/yourusername/tsidp:v0.0.1 \
tsidp --hostname=idp --dir=/var/lib/tsidp
Verify Installation
docker logs tsidp
Visit https://idp.tailnet.ts.net to confirm the service is running.
Usage Example: Proxmox Integration
Here's how to configure Proxmox to use tsidp for authentication:
-
In Proxmox, navigate to Datacenter > Realms > Add OpenID Connect Server
-
Configure the following settings:
- Issuer URL:
https://idp.velociraptor.ts.net - Realm:
tailscale(or your preferred name) - Client ID:
unused - Client Key:
unused - Default:
true - Autocreate users:
true - Username claim:
email
- Issuer URL:
-
Set up user permissions:
- Go to Datacenter > Permissions > Groups
- Create a new group (e.g., "tsadmins")
- Click Permissions in the sidebar
- Add Group Permission
- Set Path to
/for full admin access or scope as needed - Set the group and role
- Add Tailscale-authenticated users to the group
Configuration Options
The tsidp server supports several command-line flags:
--verbose: Enable verbose logging--port: Port to listen on (default: 443)--local-port: Allow requests from localhost--use-local-tailscaled: Use local tailscaled instead of tsnet--hostname: tsnet hostname--dir: tsnet state directory
Environment Variables
TS_AUTHKEY: Your Tailscale authentication key (required)TS_HOSTNAME: Hostname for thetsidpserver (default: "idp", Docker only)TS_STATE_DIR: State directory (default: "/var/lib/tsidp", Docker only)TAILSCALE_USE_WIP_CODE: Enable work-in-progress code (default: "1")
Support
This is an experimental, work in progress, community project. For issues or questions, file issues on the GitHub repository.
License
BSD-3-Clause License. See LICENSE for details.