Skip to content

Optional TLS for the control-plane transport (fixes #16) - #25

Open
dexif wants to merge 4 commits into
CamM2325:mainfrom
espkvm:feat/tls-control-plane
Open

Optional TLS for the control-plane transport (fixes #16)#25
dexif wants to merge 4 commits into
CamM2325:mainfrom
espkvm:feat/tls-control-plane

Conversation

@dexif

@dexif dexif commented Aug 3, 2026

Copy link
Copy Markdown

Fixes #16. The coordination transport was plaintext TCP + HTTP/1.1 Upgrade on :80, so it couldn't reach a Headscale behind an HTTPS reverse proxy — or the hosted Tailscale service, which is HTTPS-only. This adds a ctrl_tls flag that wraps the coord socket in TLS (reusing the DERP client's mbedTLS-over-lwIP setup; VERIFY_NONE, since the ts2021 Noise handshake authenticates the control plane), defaulting to port 443.
Also included: a build fix for WiFi-less SoCs (ESP32-P4), an Ethernet fix for the DISCO local endpoint, and a minimal Ethernet example.

Verified on ESP32-P4 over Ethernet against the official Tailscale service (controlplane.tailscale.com): the node registers, receives MapResponse, connects to DERP, and shows up in the tailnet.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support TLS-capable transport or configurable control-plane transport for reverse-proxy (HTTPS) environments

1 participant