mirror of
https://github.com/juanfont/headscale.git
synced 2026-01-11 20:00:28 +01:00
No Branch/Tag Specified
main
update_flake_lock_action
gh-pages
kradalby/release-v0.27.2
dependabot/go_modules/golang.org/x/crypto-0.45.0
dependabot/go_modules/github.com/opencontainers/runc-1.3.3
copilot/investigate-headscale-issue-2788
copilot/investigate-visibility-issue-2788
copilot/investigate-issue-2833
copilot/debug-issue-2846
copilot/fix-issue-2847
dependabot/go_modules/github.com/go-viper/mapstructure/v2-2.4.0
dependabot/go_modules/github.com/docker/docker-28.3.3incompatible
kradalby/cli-experiement3
doc/0.26.1
doc/0.25.1
doc/0.25.0
doc/0.24.3
doc/0.24.2
doc/0.24.1
doc/0.24.0
kradalby/build-docker-on-pr
topic/docu-versioning
topic/docker-kos
juanfont/fix-crash-node-id
juanfont/better-disclaimer
update-contributors
topic/prettier
revert-1893-add-test-stage-to-docs
add-test-stage-to-docs
remove-node-check-interval
fix-empty-prefix
fix-ephemeral-reusable
bug_report-debuginfo
autogroups
logs-to-stderr
revert-1414-topic/fix_unix_socket
rename-machine-node
port-embedded-derp-tests-v2
port-derp-tests
duplicate-word-linter
update-tailscale-1.36
warn-against-apache
ko-fi-link
more-acl-tests
fix-typo-standalone
parallel-nolint
tparallel-fix
rerouting
ssh-changelog-docs
oidc-cleanup
web-auth-flow-tests
kradalby-gh-runner
fix-proto-lint
remove-funding-links
go-1.19
enable-1.30-in-tests
0.16.x
cosmetic-changes-integration
tmp-fix-integration-docker
fix-integration-docker
configurable-update-interval
show-nodes-online
hs2021
acl-syntax-fixes
ts2021-implementation
fix-spurious-updates
unstable-integration-tests
mandatory-stun
embedded-derp
prtemplate-fix
v0.28.0-beta.1
v0.27.2-rc.1
v0.27.1
v0.27.0
v0.27.0-beta.2
v0.27.0-beta.1
v0.26.1
v0.26.0
v0.26.0-beta.2
v0.26.0-beta.1
v0.25.1
v0.25.0
v0.25.0-beta.2
v0.24.3
v0.25.0-beta.1
v0.24.2
v0.24.1
v0.24.0
v0.24.0-beta.2
v0.24.0-beta.1
v0.23.0
v0.23.0-rc.1
v0.23.0-beta.5
v0.23.0-beta.4
v0.23.0-beta3
v0.23.0-beta2
v0.23.0-beta1
v0.23.0-alpha12
v0.23.0-alpha11
v0.23.0-alpha10
v0.23.0-alpha9
v0.23.0-alpha8
v0.23.0-alpha7
v0.23.0-alpha6
v0.23.0-alpha5
v0.23.0-alpha4
v0.23.0-alpha4-docker-ko-test9
v0.23.0-alpha4-docker-ko-test8
v0.23.0-alpha4-docker-ko-test7
v0.23.0-alpha4-docker-ko-test6
v0.23.0-alpha4-docker-ko-test5
v0.23.0-alpha-docker-release-test-debug2
v0.23.0-alpha-docker-release-test-debug
v0.23.0-alpha4-docker-ko-test4
v0.23.0-alpha4-docker-ko-test3
v0.23.0-alpha4-docker-ko-test2
v0.23.0-alpha4-docker-ko-test
v0.23.0-alpha3
v0.23.0-alpha2
v0.23.0-alpha1
v0.22.3
v0.22.2
v0.23.0-alpha-docker-release-test
v0.22.1
v0.22.0
v0.22.0-alpha3
v0.22.0-alpha2
v0.22.0-alpha1
v0.22.0-nfpmtest
v0.21.0
v0.20.0
v0.19.0
v0.19.0-beta2
v0.19.0-beta1
v0.18.0
v0.18.0-beta4
v0.18.0-beta3
v0.18.0-beta2
v0.18.0-beta1
v0.17.1
v0.17.0
v0.17.0-beta5
v0.17.0-beta4
v0.17.0-beta3
v0.17.0-beta2
v0.17.0-beta1
v0.17.0-alpha4
v0.17.0-alpha3
v0.17.0-alpha2
v0.17.0-alpha1
v0.16.4
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.16.0-beta7
v0.16.0-beta6
v0.16.0-beta5
v0.16.0-beta4
v0.16.0-beta3
v0.16.0-beta2
v0.16.0-beta1
v0.15.0
v0.15.0-beta6
v0.15.0-beta5
v0.15.0-beta4
v0.15.0-beta3
v0.15.0-beta2
v0.15.0-beta1
v0.14.0
v0.14.0-beta2
v0.14.0-beta1
v0.13.0
v0.13.0-beta3
v0.13.0-beta2
v0.13.0-beta1
upstream/v0.12.4
v0.12.4
v0.12.3
v0.12.2
v0.12.2-beta1
v0.12.1
v0.12.0-beta2
v0.12.0-beta1
v0.11.0
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.2
v0.5.1
v0.5.0
v0.4.0
v0.3.6
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.2
v0.2.1
v0.2.0
v0.1.1
v0.1.0
Labels
Clear labels
CLI
DERP
DNS
Nix
OIDC
SSH
bug
database
documentation
duplicate
enhancement
faq
good first issue
grants
help wanted
might-come
needs design doc
needs investigation
no-stale-bot
out of scope
performance
policy 📝
pull-request
question
regression
routes
stale
tags
tailscale-feature-gap
well described ❤️
wontfix
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/headscale#350
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @wsullv1234 on GitHub (Oct 14, 2022).
Headscale version 16.4
Cannot decrypt response
I am getting an error on my ubuntu 20.04 server thats running headscale 16.4, everytime I try to run headscale it gives mew this error
2022-10-14T14:37:00Z ERR ../../../../../home/runner/work/headscale/headscale/api.go:114 > Cannot decode message error="cannot decrypt response"
I am not even sure on where to begin with troublshooting this issue
below is my config.yaml
The url clients will connect to.
Typically this will be a domain.
server_url: http://150.220.137.99:443
Address to listen to / bind to on the server
listen_addr: 0.0.0.0:443
Address to listen to /metrics, you may want
to keep this endpoint private to your internal
network
metrics_listen_addr: 0.0.0.0:9090
Address to listen for gRPC.
gRPC is used for controlling a headscale server
remotely with the CLI
Note: Remote access only works if you have
valid certificates.
grpc_listen_addr: 0.0.0.0:50443 ^_ Go To Line M-E Redo
Allow the gRPC admin interface to run in INSECURE
mode. This is not recommended as the traffic will
be unencrypted. Only enable if you know what you
are doing.
grpc_allow_insecure: true
Path to WireGuard private key file
private_key_path: /usr/local/opt/headscale/config/private.key
noise:
private_key_path: /usr/local/opt/headscale/config/noise_private.key
ip_prefixes: 100.64.0.0/10
DERP is a relay system that Tailscale uses when a direct
connection cannot be established.
https://tailscale.com/blog/how-tailscale-works/#encrypted-tcp-relays-derp
headscale needs a list of DERP servers that can be presented
to the clients.
derp:
server:
# If enabled, runs the embedded DERP server and
# merges it into the rest of the DERP config
# The Headscale server_url defined above MUST
# be using https, DERP requires TLS to be in place
enabled: false
List of externally available DERP maps encoded in JSON
urls: https://controlplane.tailscale.com/derpmap/default
Locally available DERP map files encoded in YAML
This option is mostly interesting for people hosting
their own DERP servers:
https://tailscale.com/kb/1118/custom-derp-servers/
paths:
- /etc/headscale/derp-example.yaml
paths: []
If enabled, a worker will be set up to periodically
refresh the given sources and update the derpmap
will be set up.
auto_update_enabled: true
How often should we check for updates?
update_frequency: 24h
Disables the automatic check for updates on startup
disable_check_updates: false
ephemeral_node_inactivity_timeout: 30m
SQLite config
db_type: sqlite3
db_path: /usr/local/opt/headscale/config/db.sqlite
# Postgres config
db_type: postgres
db_host: localhost
db_port: 5432
db_name: headscale
db_user: foo
db_pass: bar
#acme_url: https://acme-v02.api.letsencrypt.org/directory
#acme_email: ""
#tls_letsencrypt_hostname: ""
#tls_letsencrypt_listen: ":http"
#tls_letsencrypt_cache_dir: ".cache"
#tls_letsencrypt_challenge_type: HTTP-01
#tls_cert_path: ""
#tls_key_path: ""
Path to a file containg ACL policies.
#acl_policy_path: "/opt/headscale/config/acls.yaml"
#acl_policy_path: "/opt/headscale/config/acls.hjson"
#dns_config:
# Upstream DNS servers
nameservers:
- 100.64.0.1
- 107.152.39.57
domains: []
magic_dns: true
base_domain: domain.com
Unix socket used for the CLI to connect without authentication
Note: for local development, you probably want to change this to:
unix_socket: ./headscale.sock
unix_socket: /usr/local/opt/headscale/config/headscale.sock
unix_socket_permission: "0770"