Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bradfitz
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
181.
▲
by
bradfitz
4y ago
Thanks for the feedback. I've filed https://github.com/tailscale/tailscale/issues/4911 to fix that.
182.
▲
by
bradfitz
4y ago
It only messes with /etc/resolv.conf if you did `--accept-dns` and don't have systemd-resolved, which nowadays is much more common. Linux DNS is a clusterfun: https://tailscale.com/blog/sisyphean-dns-clie
183.
▲
by
bradfitz
4y ago
> Tailscale SSH should do the same. It does. You can "turn the fucker off" (as you say) at the OS level and Tailscale SSH will still work. We don't send the Tailscale SSH packets through the OS for it to block them. Well,
184.
▲
by
bradfitz
4y ago
I agree that'd be fun. We have something similar in the works for other protocols, but maybe SSH isn't a huge stretch to extend it to!
185.
▲
by
bradfitz
4y ago
> I know it says it's linux-only right now, but is that client side or server only? Can my Windows users TailSSH into linux boxes? Linux-only on the server right. macOS support is kinda there (in git) but not entirely done and not i
186.
▲
by
bradfitz
4y ago
There are two things have have to be enabled to turn it on: (1) a target server needs to run "tailscale up --ssh" to enable the SSH server (2) your Tailscale ACLs have to permit it. Our default, if you've never set your ACLs
187.
▲
by
bradfitz
4y ago
Actually pretty soon, probably. It's working. It needs some UI love first and some docs so people know how it works and don't immediately freak out. :)
188.
▲
by
bradfitz
4y ago
Security groups where? On the Tailscale ACL side, you need to allow tcp/22 in. On your host where you're running Tailscale, usually nothing. You can keep everything locked down for ingress. Outbound UDP only, but usually cloud VMs
189.
▲
by
bradfitz
4y ago
Yes: https://github.com/tailscale/tailscale/blob/v1.26.1/ssh/tail...
190.
▲
by
bradfitz
4y ago
FWIW, Tailscale SSH can also record sessions in asciinema cast format: https://github.com/tailscale/tailscale/blob/v1.26.1/ssh/tail... We haven't yet fully "productized" it yet becaus
191.
▲
by
bradfitz
4y ago
Tailscale SSH doesn't mess with your port 22 packets if it's off so almost certainly unrelated. Have you reached out to support or filed a bug?
192.
▲
by
bradfitz
4y ago
If you're already running recent-ish Tailscale on them, they're already running an SSH server that's just disabled. Run "tailscale up --ssh" to turn it on. The code's at https://github.com/tails
193.
▲
by
bradfitz
4y ago
You could do a Tailscale SSH bastion thing, yeah. But before you build a funky setup to avoid pricing concerns, at least reach out to the sales folk to see what it is. We're usually pretty flexible on exact quotas and realize that diff
194.
▲
by
bradfitz
4y ago
We don't modify or require changes to your SSH client. You can use any SSH client you want.
195.
▲
by
bradfitz
4y ago
I'm one of the authors of this. Happy to answer any questions. One of the fun technical details is that, when enabled on a machine (tailscale up --ssh), the userspace tailscaled process takes over all TCP port 22 packets after the Wire
196.
▲
by
bradfitz
4y ago
Yup! In fact, that was the very first sentence of the original GitHub bug about TLS certs: https://github.com/tailscale/tailscale/issues/1235 ... "Many new web APIs (eg: geolocation, sensors, http/2
197.
▲
by
bradfitz
4y ago
Yeah, but e.g. no rsh (or telnet!) on macOS. It's likewise a bit silly that we had to add TLS support to Tailscale: https://tailscale.com/blog/tls-certs/ But we want to interoperate well with the clients peop
198.
▲
by
bradfitz
4y ago
They weren't reserved words. The lexer just discarded those tokens entirely.
199.
▲
by
bradfitz
4y ago
A lot of it was because we were using the cell radio when wifi was available. Have you tried 1.24.2 that's just as of yesterday on the App Store? It fixes one of the worst of the offenders (but not all yet). In any case, we understand
200.
▲
by
bradfitz
4y ago
(Tailscale engineer here) That's https://github.com/tailscale/tailscale/issues/1572 which we haven't given up on. It's just not done. We did it for macOS and we thought the same thing would
201.
▲
by
bradfitz
4y ago
Tailscale engineer here. I confirm. Only cryptographically valid packets are accepted, and then we only return peer identity information for flows from said authenticated & authorized packets.
202.
▲
by
bradfitz
5y ago
Tailscale engineer here. Unrelated. We just haven't worked on it much. A bunch of other stuff has been a higher priority. But better ACL management will happen.
203.
▲
by
bradfitz
5y ago
I suggested that footnote text just for these comments. :)
204.
▲
by
bradfitz
5y ago
Tailscale engineer here. > Using a text file and ... > It seems like something you'd do as a proof of concept I mean, using a text file for the proof of concept is exactly what happened. And then it grew too quickly and had to ge
205.
▲
by
bradfitz
5y ago
Tailscale employee here. Our database needs are tiny, as explained in the earlier post. So we optimize for things like: "can we run all our tests quickly and easily in many environments without containers and VMs?" All three of ou
206.
▲
by
bradfitz
5y ago
Good thing C doesn't run the world!
207.
▲
by
bradfitz
5y ago
FWIW, we do sell an on-prem version to certain customers. It's not widely available anybody yet, but it exists. (I work at Tailscale)
208.
▲
by
bradfitz
5y ago
We use it on all platforms _except_ iOS, for binary size/memory reasons. (iOS 15 bumped the Network Extension memory limit to 50 MB, but we still need to be super trim for iOS 14's 15 MB limit)
209.
▲
by
bradfitz
5y ago
> Last I heard[0] they were experimenting but hadn't shipped it. AFAIK their client still requires root, no? Tailscale's gvisor/netstack-based userspace networking mode has been supported and in wide use for quite some tim
210.
▲
by
bradfitz
5y ago
"If you have a procedure with ten parameters, you probably missed some." -- Alan Perlis
More ›