3 ms·
Probably because Tailscale needs to manipulate networking hence needs root, so user units won't work easily.
by zaarn 4y ago
Probably because Tailscale needs to manipulate networking hence needs root, so user units won't work easily.
- anaisbetts 4y agosystemd user-scoped services are great for other software though, especially running syncthing to sync game saves between the Steam Deck and a PC
- zaarn 4y agoAlso great for running an SSH Agent, since they aren't coupled to some magic invocation in some bashrc but will always be started when the user session starts and cleanly terminated when you log out (or linger if you set that up)
- anaisbetts 4y agoHoly shit, that is an incredible idea!
- WhyNotHugo 4y agoHere's a sample: https://git.sr.ht/~whynothugo/dotfiles/tree/c0bf9296c6ca8661f1eb9ee79e33606e6e88cc7c/item/home/.config/systemd/user/ssh-agent.service https://git.sr.ht/~whynothugo/dotfiles/tree/c0bf9296c6ca8661... Note that the ordering is important so that `SSH_AUTH_SOCK` is passed down to other services.
- zaarn 4y agoYou can order them using user targets. Ie, create a ssh-agent.target and have the default target depend on it. Now your ssh-agent is guaranteed to be online when the default target comes up.
- georgyo 4y agoHis method already does that. Creating a target for a single service is very much overkill. Though creating a target like setup or pre-default and putting in there might be a fine idea if you have other services you want to run that way. But, since the unit is already setting a fixed path for the agent, I would just put that path in my .profile and call it a day. Having systems do environment variable injection seems too fragile to me, especially for static variables.
- WhyNotHugo 4y agoI mostly do the injection to keep EVERYTHING related to the agent in a single file. But yeah, `environment.d` or `.profile` would be simpler. I mostly opted to keep everything in one place.
- ctippett 4y agoThis isn’t entirely accurate, Tailscale works just fine in userspace networking mode[0]. It’s a bit of a faff to setup, but it works. [0] https://tailscale.com/kb/1112/userspace-networking/ https://tailscale.com/kb/1112/userspace-networking/
- xena 4y agoThe main disadvantage about userspace networking in this case in particular is that SMB mounting in the kernel can't use it.