4 ms·
That's already how it works at the data-plane layer. I'm talking about the control-plane layer where tailscale needs to maintain a server that gets its state fr
by waterTanuki 2mo ago
That's already how it works at the data-plane layer. I'm talking about the control-plane layer where tailscale needs to maintain a server that gets its state from somewhere (they need to know where to route your data, what your permissions ACLs are, device names, etc.). If everyone shared the same db cluster accessed over the network there is a real risk of an accident leaking the encryption keys (of the database itself, not your tailnet) to the db they would have to maintain, and leaking semi-sensitive info like these device names and IP addresses. Using sqlite means each tailnet's metadata is isolated to the container running it.
- inigyou 2mo agoIs it? They're backing them all up to S3 so what if the S3 keys leak?
- deleted 2mo ago[deleted]
- waterTanuki 2mo agoIt's harder to leak multiple S3 keys than a single postgres key.