mirror of
https://github.com/juanfont/headscale.git
synced 2026-01-11 20:00:28 +01:00
Interface-specific DNS not set if not overriding local nameserver #557
Closed
opened 2025-12-29 02:20:17 +01:00 by adam
·
11 comments
No Branch/Tag Specified
main
update_flake_lock_action
gh-pages
kradalby/release-v0.27.2
dependabot/go_modules/golang.org/x/crypto-0.45.0
dependabot/go_modules/github.com/opencontainers/runc-1.3.3
copilot/investigate-headscale-issue-2788
copilot/investigate-visibility-issue-2788
copilot/investigate-issue-2833
copilot/debug-issue-2846
copilot/fix-issue-2847
dependabot/go_modules/github.com/go-viper/mapstructure/v2-2.4.0
dependabot/go_modules/github.com/docker/docker-28.3.3incompatible
kradalby/cli-experiement3
doc/0.26.1
doc/0.25.1
doc/0.25.0
doc/0.24.3
doc/0.24.2
doc/0.24.1
doc/0.24.0
kradalby/build-docker-on-pr
topic/docu-versioning
topic/docker-kos
juanfont/fix-crash-node-id
juanfont/better-disclaimer
update-contributors
topic/prettier
revert-1893-add-test-stage-to-docs
add-test-stage-to-docs
remove-node-check-interval
fix-empty-prefix
fix-ephemeral-reusable
bug_report-debuginfo
autogroups
logs-to-stderr
revert-1414-topic/fix_unix_socket
rename-machine-node
port-embedded-derp-tests-v2
port-derp-tests
duplicate-word-linter
update-tailscale-1.36
warn-against-apache
ko-fi-link
more-acl-tests
fix-typo-standalone
parallel-nolint
tparallel-fix
rerouting
ssh-changelog-docs
oidc-cleanup
web-auth-flow-tests
kradalby-gh-runner
fix-proto-lint
remove-funding-links
go-1.19
enable-1.30-in-tests
0.16.x
cosmetic-changes-integration
tmp-fix-integration-docker
fix-integration-docker
configurable-update-interval
show-nodes-online
hs2021
acl-syntax-fixes
ts2021-implementation
fix-spurious-updates
unstable-integration-tests
mandatory-stun
embedded-derp
prtemplate-fix
v0.28.0-beta.1
v0.27.2-rc.1
v0.27.1
v0.27.0
v0.27.0-beta.2
v0.27.0-beta.1
v0.26.1
v0.26.0
v0.26.0-beta.2
v0.26.0-beta.1
v0.25.1
v0.25.0
v0.25.0-beta.2
v0.24.3
v0.25.0-beta.1
v0.24.2
v0.24.1
v0.24.0
v0.24.0-beta.2
v0.24.0-beta.1
v0.23.0
v0.23.0-rc.1
v0.23.0-beta.5
v0.23.0-beta.4
v0.23.0-beta3
v0.23.0-beta2
v0.23.0-beta1
v0.23.0-alpha12
v0.23.0-alpha11
v0.23.0-alpha10
v0.23.0-alpha9
v0.23.0-alpha8
v0.23.0-alpha7
v0.23.0-alpha6
v0.23.0-alpha5
v0.23.0-alpha4
v0.23.0-alpha4-docker-ko-test9
v0.23.0-alpha4-docker-ko-test8
v0.23.0-alpha4-docker-ko-test7
v0.23.0-alpha4-docker-ko-test6
v0.23.0-alpha4-docker-ko-test5
v0.23.0-alpha-docker-release-test-debug2
v0.23.0-alpha-docker-release-test-debug
v0.23.0-alpha4-docker-ko-test4
v0.23.0-alpha4-docker-ko-test3
v0.23.0-alpha4-docker-ko-test2
v0.23.0-alpha4-docker-ko-test
v0.23.0-alpha3
v0.23.0-alpha2
v0.23.0-alpha1
v0.22.3
v0.22.2
v0.23.0-alpha-docker-release-test
v0.22.1
v0.22.0
v0.22.0-alpha3
v0.22.0-alpha2
v0.22.0-alpha1
v0.22.0-nfpmtest
v0.21.0
v0.20.0
v0.19.0
v0.19.0-beta2
v0.19.0-beta1
v0.18.0
v0.18.0-beta4
v0.18.0-beta3
v0.18.0-beta2
v0.18.0-beta1
v0.17.1
v0.17.0
v0.17.0-beta5
v0.17.0-beta4
v0.17.0-beta3
v0.17.0-beta2
v0.17.0-beta1
v0.17.0-alpha4
v0.17.0-alpha3
v0.17.0-alpha2
v0.17.0-alpha1
v0.16.4
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.16.0-beta7
v0.16.0-beta6
v0.16.0-beta5
v0.16.0-beta4
v0.16.0-beta3
v0.16.0-beta2
v0.16.0-beta1
v0.15.0
v0.15.0-beta6
v0.15.0-beta5
v0.15.0-beta4
v0.15.0-beta3
v0.15.0-beta2
v0.15.0-beta1
v0.14.0
v0.14.0-beta2
v0.14.0-beta1
v0.13.0
v0.13.0-beta3
v0.13.0-beta2
v0.13.0-beta1
upstream/v0.12.4
v0.12.4
v0.12.3
v0.12.2
v0.12.2-beta1
v0.12.1
v0.12.0-beta2
v0.12.0-beta1
v0.11.0
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.2
v0.5.1
v0.5.0
v0.4.0
v0.3.6
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.2
v0.2.1
v0.2.0
v0.1.1
v0.1.0
Labels
Clear labels
CLI
DERP
DNS
Nix
OIDC
SSH
bug
database
documentation
duplicate
enhancement
faq
good first issue
grants
help wanted
might-come
needs design doc
needs investigation
no-stale-bot
out of scope
performance
policy 📝
pull-request
question
regression
routes
stale
tags
tailscale-feature-gap
well described ❤️
wontfix
Mirrored from GitHub Pull Request
No Label
bug
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/headscale#557
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @handsomexdd1024 on GitHub (Sep 18, 2023).
Bug description
When connecting to headscale server, I configured

dns_config.override_local_dnsto false, and observed thatsystemd-resolved's interface-specific fortailscale0is not set to 100.100.100.100. In general, I tested several configurations, and the results are here:I expect that 100.100.100.100 be set as interface-specific nameserver even when override_local_dns is not enabled, otherwise FQDNs internal to my tailnet (hostname.username.base_domain) will not be resolved by 100.100.100.100, and thus is not giving back correct responses.
Everything else works as expected.
Environment
linux-6.1.0linux-6.5.3I'll post logs laterresolvectl status tailscale0outputs when connected to headscale:when connected to tailscale official server:
To Reproduce
override_local_dnsresolvectl status tailscale0on the client to check results@hrtkpf commented on GitHub (Sep 18, 2023):
I can confirm this issue.
Related: https://github.com/juanfont/headscale/issues/660#issuecomment-1712839303, #905
@purefns commented on GitHub (Oct 19, 2023):
I'm also experiencing the same issue on Linux Mint unfortunately. The system is using
systemd-resolvedin stub mode andtailscaledis setting the correct search domain, but not the control nameserver... It's too late for me to mess around with it right now but setting the DNS manually withresolvectl dns tailscale0 100.100.100.100works fine for now.My two other nodes - an Android, and a
tailscaleDocker container - are both working just fine. For reference, I have "Override Local DNS" off, and MagicDNS on. Setting override to on breaks DNS resolution for my LAN services so those settings work the best for me right now. Turning off MagicDNS changes nothing either.I'll update with logs from
journalctl -u tailscaledon the Mint host as soon as I can, and anything else I can think of.@9Ninety commented on GitHub (Dec 4, 2023):
Here is a temporary solution to make MagicDNS work without manually running the resolvectl command:
Create a service override configuration file:
Write the following content to the file:
Caution: Try the command
/bin/sh -c "sleep 15s && /usr/bin/resolvectl dns tailscale0 100.100.100.100and make sure it works on your machine before continuing.Reload the systemd configuration and restart the service:
@handsomexdd1024 commented on GitHub (Dec 4, 2023):
@9Ninety Brilliant solution! Thank you so much.
@github-actions[bot] commented on GitHub (Mar 4, 2024):
This issue is stale because it has been open for 90 days with no activity.
@hrtkpf commented on GitHub (Mar 4, 2024):
I think this is still relevant.
@almereyda commented on GitHub (Mar 4, 2024):
I'm not able to reproduce this on Ubuntu 23.10 (systemd 253) with latest Headscale 0.23.0-alpha5 and Tailscale 1.60.1 and
override_local_dns: falseand--accept-dnsenabled.`resolvectl status tailscale0`
Is this maybe an upstream condition, eventually related to distribution-specific packaging/configuration?
@mimnix commented on GitHub (Apr 20, 2024):
Same issue here with the following setup:
Headscale host: docker image
headscale/headscale:0.23.0-alpha8Tailscale client: v1.64.0 on Arch Linux Rolling with
linux-6.8.5@handsomexdd1024 commented on GitHub (Apr 29, 2024):
Recent tests showed that this bug has been fixed somehow, so I'm closing this issue.
@Matic-M commented on GitHub (Nov 16, 2025):
This issue has not been resolved
@mastier commented on GitHub (Nov 26, 2025):
Still failed on me on some older system like ubuntu jammy and tailscale 1.88.4 or debian
the problem dissaperared when I upgraded to the newest tailscale client 1.90.
https://pkgs.tailscale.com/stable/#ubuntu-jammy
For me the problem it was overriding the default resolved stub also
not it works correctly