This is the output of the new misc/bumpdeps tool (#21325) run with --exclude-newer-than-days=7, which asks proxy.golang.org for the newest version of every direct dependency, ignoring releases younger than a week in favor of the newest older one, and runs a single go get. gvisor tracks its "go" branch, wireguard-go its "tailscale" branch, and golang-x-crypto its "main" branch (the proxy's @latest for it is a stray v0.91.0 tag from 2024 that predates our acme fork changes). Indirect deps only moved as far as MVS pulled them. The week-long cooldown held back gvisor, the gokrazy modules, chromedp/cdproto, and hashicorp/raft-boltdb/v2, whose only newer versions are days old; they'll come along next time. Several upstream changes needed small fixes: nfpm's PrepareForPackager takes a modification time now (a zero time keeps the old behavior of using the source file's mtime), esbuild's ServeOptions.Port became an int while ServeResult.Host became a Hosts slice, client-go's EventRecorder.Eventf is now recognized by vet as a printf wrapper (so the k8s-operator calls that passed a preformatted message switch to Event), google/nftables v0.3.0 reads back the kernel's NF_NAT_RANGE_PROTO_SPECIFIED flag into a new expr.NAT.Specified field (so the port map DNAT rule now sets it too or findRule never matches the rule it just added), and staticcheck v0.8.1 knows encoding/json/v2's embed tag option, so the two SA5008 suppressions for it are gone. Two tests assumed old library behavior. client-go's fake clientset now replays existing objects when a watch starts, as a real apiserver does, so the k8s-proxy config test must tolerate the loader ignoring that no-op event before the real reload arrives. fyne.io/systray moved its dbusmenu object path and answers the first GetLayout with depth 1, so the systray test now finds the menu via the item's Menu property and polls until the submenu entries appear. Then make tidy, make updatedeps, and make kube-generate-all (the controller-gen bump to v0.22.0 changes doc strings, stops listing top-level metadata as required, and crd-ref-docs now marks optional fields). Updates #8043 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I3f9a2c6e8b1d4705a9e2c7b8d1f4e6a0c2b5d8e3
tsnet
Package tsnet embeds a Tailscale node directly into a Go program, allowing it to join a tailnet and accept or dial connections without running a separate tailscaled daemon or requiring any system-level configuration.
Overview
Normally, Tailscale runs as a background system service (tailscaled) that manages a virtual network interface for the whole machine. tsnet takes a different approach: it runs a fully self-contained Tailscale node inside your process using a userspace TCP/IP stack (gVisor). This means:
- No root privileges required.
- No system daemons to install or manage.
- Multiple independent Tailscale nodes can run within a single binary.
- The node's Tailscale identity and state are stored in a directory you control.
The core type is Server, which represents one embedded Tailscale node. Calling Server.Listen or Server.Dial routes traffic exclusively over the tailnet. The standard library's net.Listener and net.Conn interfaces are returned, so any existing Go HTTP server, gRPC server, or other net-based code works without modification.
Usage
import "tailscale.com/tsnet"
s := &tsnet.Server{
Hostname: "my-service",
AuthKey: os.Getenv("TS_AUTHKEY"),
}
defer s.Close()
ln, err := s.Listen("tcp", ":80")
if err != nil {
log.Fatal(err)
}
log.Fatal(http.Serve(ln, myHandler))
On first run, if no Server.AuthKey is provided and the node is not already enrolled, the server logs an authentication URL. Open it in a browser to add the node to your tailnet.
Authentication
A Server authenticates using, in order of precedence:
-
The TS_AUTHKEY environment variable.
-
The TS_AUTH_KEY environment variable.
-
An OAuth client secret (Server.ClientSecret or TS_CLIENT_SECRET), used to mint an auth key.
-
Workload identity federation (Server.ClientID plus Server.IDToken or Server.Audience). Available only if the program imports the feature:
import _ "tailscale.com/feature/identityfederation"
The feature is not linked by default to keep the AWS SDK and other cloud-provider dependencies out of programs that don't use workload identity federation.
-
An interactive login URL printed to Server.UserLogf.
If the node is already enrolled (state found in Server.Store), the auth key is ignored unless TSNET_FORCE_LOGIN=1 is set.
Identifying callers
Use the WhoIs method on the client returned by Server.LocalClient to identify who is making a request:
lc, _ := srv.LocalClient()
http.Serve(ln, http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
who, err := lc.WhoIs(r.Context(), r.RemoteAddr)
if err != nil {
http.Error(w, err.Error(), 500)
return
}
fmt.Fprintf(w, "Hello, %s!", who.UserProfile.LoginName)
}))
Tailscale Funnel
Server.ListenFunnel exposes your service on the public internet. Tailscale Funnel currently supports TCP on ports 443, 8443, and 10000. HTTPS must be enabled in the Tailscale admin console.
ln, err := srv.ListenFunnel("tcp", ":443")
// ln is a TLS listener; connections can come from anywhere on the
// internet as well as from your tailnet.
// To restrict to public traffic only:
ln, err = srv.ListenFunnel("tcp", ":443", tsnet.FunnelOnly())
Tailscale Services
Server.ListenService advertises the node as a host for a named Tailscale Service. The node must use a tag-based identity. To advertise multiple ports, call ListenService once per port.
srv.AdvertiseTags = []string{"tag:myservice"}
ln, err := srv.ListenService("svc:my-service", tsnet.ServiceModeHTTP{
HTTPS: true,
Port: 443,
})
log.Printf("Listening on https://%s", ln.FQDN)
Using an exit node
A tsnet node can route its Server.Dial traffic to non-tailnet addresses through an exit node. Select the exit node by setting the ExitNodeID pref via Server.LocalClient:
lc, _ := srv.LocalClient()
_, err := lc.EditPrefs(ctx, &ipn.MaskedPrefs{
Prefs: ipn.Prefs{ExitNodeID: "nodeid"},
ExitNodeIDSet: true,
})
Dials of addresses outside the tailnet then go through the exit node. Dials within the tailnet are unaffected.
Running multiple nodes in one process
Each Server instance is an independent node. Give each a unique Server.Dir and Server.Hostname:
for _, name := range []string{"frontend", "backend"} {
srv := &tsnet.Server{
Hostname: name,
Dir: filepath.Join(baseDir, name),
AuthKey: os.Getenv("TS_AUTHKEY"),
Ephemeral: true,
}
srv.Start()
}