mirror of
https://github.com/juanfont/headscale.git
synced 2026-01-11 20:00:28 +01:00
[Bug] 0.26.0 Custom DERPs not seeing some tailnet nodes after update #1042
Closed
opened 2025-12-29 02:27:53 +01:00 by adam
·
2 comments
No Branch/Tag Specified
main
update_flake_lock_action
gh-pages
kradalby/release-v0.27.2
dependabot/go_modules/golang.org/x/crypto-0.45.0
dependabot/go_modules/github.com/opencontainers/runc-1.3.3
copilot/investigate-headscale-issue-2788
copilot/investigate-visibility-issue-2788
copilot/investigate-issue-2833
copilot/debug-issue-2846
copilot/fix-issue-2847
dependabot/go_modules/github.com/go-viper/mapstructure/v2-2.4.0
dependabot/go_modules/github.com/docker/docker-28.3.3incompatible
kradalby/cli-experiement3
doc/0.26.1
doc/0.25.1
doc/0.25.0
doc/0.24.3
doc/0.24.2
doc/0.24.1
doc/0.24.0
kradalby/build-docker-on-pr
topic/docu-versioning
topic/docker-kos
juanfont/fix-crash-node-id
juanfont/better-disclaimer
update-contributors
topic/prettier
revert-1893-add-test-stage-to-docs
add-test-stage-to-docs
remove-node-check-interval
fix-empty-prefix
fix-ephemeral-reusable
bug_report-debuginfo
autogroups
logs-to-stderr
revert-1414-topic/fix_unix_socket
rename-machine-node
port-embedded-derp-tests-v2
port-derp-tests
duplicate-word-linter
update-tailscale-1.36
warn-against-apache
ko-fi-link
more-acl-tests
fix-typo-standalone
parallel-nolint
tparallel-fix
rerouting
ssh-changelog-docs
oidc-cleanup
web-auth-flow-tests
kradalby-gh-runner
fix-proto-lint
remove-funding-links
go-1.19
enable-1.30-in-tests
0.16.x
cosmetic-changes-integration
tmp-fix-integration-docker
fix-integration-docker
configurable-update-interval
show-nodes-online
hs2021
acl-syntax-fixes
ts2021-implementation
fix-spurious-updates
unstable-integration-tests
mandatory-stun
embedded-derp
prtemplate-fix
v0.28.0-beta.1
v0.27.2-rc.1
v0.27.1
v0.27.0
v0.27.0-beta.2
v0.27.0-beta.1
v0.26.1
v0.26.0
v0.26.0-beta.2
v0.26.0-beta.1
v0.25.1
v0.25.0
v0.25.0-beta.2
v0.24.3
v0.25.0-beta.1
v0.24.2
v0.24.1
v0.24.0
v0.24.0-beta.2
v0.24.0-beta.1
v0.23.0
v0.23.0-rc.1
v0.23.0-beta.5
v0.23.0-beta.4
v0.23.0-beta3
v0.23.0-beta2
v0.23.0-beta1
v0.23.0-alpha12
v0.23.0-alpha11
v0.23.0-alpha10
v0.23.0-alpha9
v0.23.0-alpha8
v0.23.0-alpha7
v0.23.0-alpha6
v0.23.0-alpha5
v0.23.0-alpha4
v0.23.0-alpha4-docker-ko-test9
v0.23.0-alpha4-docker-ko-test8
v0.23.0-alpha4-docker-ko-test7
v0.23.0-alpha4-docker-ko-test6
v0.23.0-alpha4-docker-ko-test5
v0.23.0-alpha-docker-release-test-debug2
v0.23.0-alpha-docker-release-test-debug
v0.23.0-alpha4-docker-ko-test4
v0.23.0-alpha4-docker-ko-test3
v0.23.0-alpha4-docker-ko-test2
v0.23.0-alpha4-docker-ko-test
v0.23.0-alpha3
v0.23.0-alpha2
v0.23.0-alpha1
v0.22.3
v0.22.2
v0.23.0-alpha-docker-release-test
v0.22.1
v0.22.0
v0.22.0-alpha3
v0.22.0-alpha2
v0.22.0-alpha1
v0.22.0-nfpmtest
v0.21.0
v0.20.0
v0.19.0
v0.19.0-beta2
v0.19.0-beta1
v0.18.0
v0.18.0-beta4
v0.18.0-beta3
v0.18.0-beta2
v0.18.0-beta1
v0.17.1
v0.17.0
v0.17.0-beta5
v0.17.0-beta4
v0.17.0-beta3
v0.17.0-beta2
v0.17.0-beta1
v0.17.0-alpha4
v0.17.0-alpha3
v0.17.0-alpha2
v0.17.0-alpha1
v0.16.4
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.16.0-beta7
v0.16.0-beta6
v0.16.0-beta5
v0.16.0-beta4
v0.16.0-beta3
v0.16.0-beta2
v0.16.0-beta1
v0.15.0
v0.15.0-beta6
v0.15.0-beta5
v0.15.0-beta4
v0.15.0-beta3
v0.15.0-beta2
v0.15.0-beta1
v0.14.0
v0.14.0-beta2
v0.14.0-beta1
v0.13.0
v0.13.0-beta3
v0.13.0-beta2
v0.13.0-beta1
upstream/v0.12.4
v0.12.4
v0.12.3
v0.12.2
v0.12.2-beta1
v0.12.1
v0.12.0-beta2
v0.12.0-beta1
v0.11.0
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.2
v0.5.1
v0.5.0
v0.4.0
v0.3.6
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.2
v0.2.1
v0.2.0
v0.1.1
v0.1.0
Labels
Clear labels
CLI
DERP
DNS
Nix
OIDC
SSH
bug
database
documentation
duplicate
enhancement
faq
good first issue
grants
help wanted
might-come
needs design doc
needs investigation
no-stale-bot
out of scope
performance
policy 📝
pull-request
question
regression
routes
stale
tags
tailscale-feature-gap
well described ❤️
wontfix
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/headscale#1042
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @alfredomagallon on GitHub (May 31, 2025).
Is this a support request?
Is there an existing issue for this?
Current Behavior
After updating to 0.26.0, I noticed a decrease in performance.
Investigating custom DERPs, I noticed that they are not seeing much of the tailnet nodes anymore.
The policy has been migrated to include @ after user names, and seems everything else except the DERPs is working fine.
We were using:
https://github.com/tailscale/tailscale/issues/13097#issuecomment-2354349031
Maybe it's not valid anymore?
Expected Behavior
DERPs should have continued seeing all nodes in the tailnet
Steps To Reproduce
Headscale 0.25.1 tailnet with custom DERP servers
Update to headscale 0.26.0 and see if all nodes stay in the tailnet
Environment
Runtime environment
Debug information
DERPER LOGS:
journalctl -f -u derper
(Full of)
May 30 23:48:37 derp-europe-west10-a bash[3464]: 2025/05/30 23:48:37 derp: 63.32.235.50:2850: client nodekey:cf5ade5e18760133924736fc641acfc9824400c5938ae0248a2b91acccd9625a rejected: peer nodekey:cf5ade5e18760133924736fc641acfc9824400c5938ae0248a2b91acccd9625a not authorized (not found in local tailscaled)
May 30 23:48:38 derp-europe-west10-a bash[3464]: 2025/05/30 23:48:38 derp: 34.93.48.85:1072: client nodekey:b2fc8042ec07674e4f0ef815bff65091221de793ad0aec27bfb05ab62c1bd368 rejected: peer nodekey:b2fc8042ec07674e4f0ef815bff65091221de793ad0aec27bfb05ab62c1bd368 not authorized (not found in local tailscaled)
May 30 23:48:40 derp-europe-west10-a bash[3464]: 2025/05/30 23:48:40 derp: 20.244.76.6:5122: client nodekey:4f4baa9c6a1064ad4ba9823aceb98d86685218cafb232e0e1521a22575263a70 rejected: peer nodekey:4f4baa9c6a1064ad4ba9823aceb98d86685218cafb232e0e1521a22575263a70 not authorized (not found in local tailscaled)
May 30 23:48:41 derp-europe-west10-a bash[3464]: 2025/05/30 23:48:41 derp: 172.189.93.123:3141: client nodekey:f8628d29b23d92c70d4e19e3f5b1f93fc046435cb49239e8e1d4a04c1e91c95a rejected: peer nodekey:f8628d29b23d92c70d4e19e3f5b1f93fc046435cb49239e8e1d4a04c1e91c95a not authorized (not found in local tailscaled)
@alfredomagallon commented on GitHub (May 31, 2025):
Note, just in case is related:
All the nodes that don't appear in the DERP's
tailscale statusare the ones which users appear without a "@" suffix in my local machinetailscale status(including my other custom DERP)I appended a @ to all usernames in the policy, following the docs. Not sure why in my
tailscale statussome of them appear with the "@", some others not.@alfredomagallon commented on GitHub (May 31, 2025):
I continued investigating and seems not an issue with headscale update but with tailscale latest version 1.84:
https://github.com/tailscale/tailscale/issues/16099