mirror of
https://github.com/juanfont/headscale.git
synced 2026-01-11 20:00:28 +01:00
Some Permission denied by ACL when same tags on a couple of clients #673
Closed
opened 2025-12-29 02:21:53 +01:00 by adam
·
15 comments
No Branch/Tag Specified
main
update_flake_lock_action
gh-pages
kradalby/release-v0.27.2
dependabot/go_modules/golang.org/x/crypto-0.45.0
dependabot/go_modules/github.com/opencontainers/runc-1.3.3
copilot/investigate-headscale-issue-2788
copilot/investigate-visibility-issue-2788
copilot/investigate-issue-2833
copilot/debug-issue-2846
copilot/fix-issue-2847
dependabot/go_modules/github.com/go-viper/mapstructure/v2-2.4.0
dependabot/go_modules/github.com/docker/docker-28.3.3incompatible
kradalby/cli-experiement3
doc/0.26.1
doc/0.25.1
doc/0.25.0
doc/0.24.3
doc/0.24.2
doc/0.24.1
doc/0.24.0
kradalby/build-docker-on-pr
topic/docu-versioning
topic/docker-kos
juanfont/fix-crash-node-id
juanfont/better-disclaimer
update-contributors
topic/prettier
revert-1893-add-test-stage-to-docs
add-test-stage-to-docs
remove-node-check-interval
fix-empty-prefix
fix-ephemeral-reusable
bug_report-debuginfo
autogroups
logs-to-stderr
revert-1414-topic/fix_unix_socket
rename-machine-node
port-embedded-derp-tests-v2
port-derp-tests
duplicate-word-linter
update-tailscale-1.36
warn-against-apache
ko-fi-link
more-acl-tests
fix-typo-standalone
parallel-nolint
tparallel-fix
rerouting
ssh-changelog-docs
oidc-cleanup
web-auth-flow-tests
kradalby-gh-runner
fix-proto-lint
remove-funding-links
go-1.19
enable-1.30-in-tests
0.16.x
cosmetic-changes-integration
tmp-fix-integration-docker
fix-integration-docker
configurable-update-interval
show-nodes-online
hs2021
acl-syntax-fixes
ts2021-implementation
fix-spurious-updates
unstable-integration-tests
mandatory-stun
embedded-derp
prtemplate-fix
v0.28.0-beta.1
v0.27.2-rc.1
v0.27.1
v0.27.0
v0.27.0-beta.2
v0.27.0-beta.1
v0.26.1
v0.26.0
v0.26.0-beta.2
v0.26.0-beta.1
v0.25.1
v0.25.0
v0.25.0-beta.2
v0.24.3
v0.25.0-beta.1
v0.24.2
v0.24.1
v0.24.0
v0.24.0-beta.2
v0.24.0-beta.1
v0.23.0
v0.23.0-rc.1
v0.23.0-beta.5
v0.23.0-beta.4
v0.23.0-beta3
v0.23.0-beta2
v0.23.0-beta1
v0.23.0-alpha12
v0.23.0-alpha11
v0.23.0-alpha10
v0.23.0-alpha9
v0.23.0-alpha8
v0.23.0-alpha7
v0.23.0-alpha6
v0.23.0-alpha5
v0.23.0-alpha4
v0.23.0-alpha4-docker-ko-test9
v0.23.0-alpha4-docker-ko-test8
v0.23.0-alpha4-docker-ko-test7
v0.23.0-alpha4-docker-ko-test6
v0.23.0-alpha4-docker-ko-test5
v0.23.0-alpha-docker-release-test-debug2
v0.23.0-alpha-docker-release-test-debug
v0.23.0-alpha4-docker-ko-test4
v0.23.0-alpha4-docker-ko-test3
v0.23.0-alpha4-docker-ko-test2
v0.23.0-alpha4-docker-ko-test
v0.23.0-alpha3
v0.23.0-alpha2
v0.23.0-alpha1
v0.22.3
v0.22.2
v0.23.0-alpha-docker-release-test
v0.22.1
v0.22.0
v0.22.0-alpha3
v0.22.0-alpha2
v0.22.0-alpha1
v0.22.0-nfpmtest
v0.21.0
v0.20.0
v0.19.0
v0.19.0-beta2
v0.19.0-beta1
v0.18.0
v0.18.0-beta4
v0.18.0-beta3
v0.18.0-beta2
v0.18.0-beta1
v0.17.1
v0.17.0
v0.17.0-beta5
v0.17.0-beta4
v0.17.0-beta3
v0.17.0-beta2
v0.17.0-beta1
v0.17.0-alpha4
v0.17.0-alpha3
v0.17.0-alpha2
v0.17.0-alpha1
v0.16.4
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.16.0-beta7
v0.16.0-beta6
v0.16.0-beta5
v0.16.0-beta4
v0.16.0-beta3
v0.16.0-beta2
v0.16.0-beta1
v0.15.0
v0.15.0-beta6
v0.15.0-beta5
v0.15.0-beta4
v0.15.0-beta3
v0.15.0-beta2
v0.15.0-beta1
v0.14.0
v0.14.0-beta2
v0.14.0-beta1
v0.13.0
v0.13.0-beta3
v0.13.0-beta2
v0.13.0-beta1
upstream/v0.12.4
v0.12.4
v0.12.3
v0.12.2
v0.12.2-beta1
v0.12.1
v0.12.0-beta2
v0.12.0-beta1
v0.11.0
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.1
v0.6.0
v0.5.2
v0.5.1
v0.5.0
v0.4.0
v0.3.6
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.2
v0.2.1
v0.2.0
v0.1.1
v0.1.0
Labels
Clear labels
CLI
DERP
DNS
Nix
OIDC
SSH
bug
database
documentation
duplicate
enhancement
faq
good first issue
grants
help wanted
might-come
needs design doc
needs investigation
no-stale-bot
out of scope
performance
policy 📝
pull-request
question
regression
routes
stale
tags
tailscale-feature-gap
well described ❤️
wontfix
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/headscale#673
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @masterwishx on GitHub (Mar 19, 2024).
in Docker by Nginx Proxy Manager on Oracle VPS in Ubuntu
using lasted version v0.23.0-alpha5
For webUI https://github.com/goodieshq/headscale-admin
When using same tag for couple of client ,then some clients not working as in ACLs . i tryed soem other tag but the same behavior :
tgas to client added from
i run tailscale ssh enabled on 3 vps , but vps 3 cant ssh to vps 2, but can to vps 1 other vps working fine .
also from unraid cant ssh to all vps ,only after changed tag on vm to
testso unraid have unique tag then its working ...Befor used other tags - like cloud,server ...
Tags added by headscale-admin
my ACL for now :
@masterwishx commented on GitHub (Mar 20, 2024):
from debug on client 3 : (no client 3 in list )
@github-actions[bot] commented on GitHub (Aug 7, 2024):
This issue is stale because it has been open for 90 days with no activity.
@almereyda commented on GitHub (Aug 7, 2024):
This was reproduced here.
@almereyda commented on GitHub (Sep 29, 2024):
Related to #1369
@kradalby commented on GitHub (May 5, 2025):
A beta with the new policy has been released, I think it should have improved the situation and would love to hear if this is still happening. https://github.com/juanfont/headscale/releases/tag/v0.26.0-beta.1
@masterwishx commented on GitHub (May 5, 2025):
I removed the old node as was unused, maybe I can reproduce it but not sure
@almereyda commented on GitHub (Sep 23, 2025):
This behaviour disappeared here after reloading the Headscale service.
Suggesting to close, if this can be confirmed by the OP.
@masterwishx Would you like to take a moment to check if restarting your Headscale service makes the observed behaviour disappear for you, too?
@masterwishx commented on GitHub (Sep 23, 2025):
I moved back from 0.26 to 0.25 after all issues, also I have only one cloud server now becose oracle problems.
Can't remember if it worked after updated from 0.23, I will try to check with virtual machines.
@almereyda commented on GitHub (Sep 23, 2025):
Glad to hear it might be possible to roll back one version without breaking the database. Let me eventually try with #2785 some time and report back.
@masterwishx commented on GitHub (Sep 23, 2025):
No, I have to use Backups to roll back
@kradalby commented on GitHub (Dec 12, 2025):
Changes to separate the tags from users has been merged into
mainin #2885 and #2931. I will encourage you to help testing this if you are able to buildmainand run it.I will close this to track progress, but there might still be bugs and the likes related to this change. As part of hardening this feature, we are tracking all related tags bugs over time in v0.28.0 milestone.
@masterwishx commented on GitHub (Dec 19, 2025):
Updated to 0.26.1,0.27.1 and 0.28beta1 : cant get to vps node anymore , from main pc , ssh also not working :( ,
all my old nodes are not shown in list (becouse old versions of tailscale as wrote in docs) ,
seems something broken for 3 nodes im really working for now :
@almereyda commented on GitHub (Dec 20, 2025):
Can you roll back to a snapshot or backup before the complete migration? Did the error appear already after one of the intermittent upgrades, or only at the end? Could you please open a separate issue with your questions and findings? Thanks.
@masterwishx commented on GitHub (Dec 20, 2025):
Thanks, sure I can.
For now I restored back to 0.25.1.
Will try again soon, maybe also related to headscale - admin 0.26 or/and headplane (that was need to be migrated to latest version).
Do you mean to check every update version if working fine?
@almereyda commented on GitHub (Dec 21, 2025):
Let's continue in a separate issue. Please link it here or feel free to ping me there.