Cloned VM with existing connection is not registered but has access/cannot deregister. #824

Closed
opened 2025-12-29 02:24:28 +01:00 by adam · 1 comment
Owner

Originally created by @plummo on GitHub (Oct 10, 2024).

Is this a support request?

  • This is not a support request

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Cloning a VM creates the same mkey and authuorises the device as if they are the same. Only one device appears as connected and removeing the primary device will still allow the other to be connected.

I have a VM running Almalinux which was connected to Headscale server. I cloned that VM and as soon as it started it connected as tailscale was running when I initiated clone. Both instances were provided the same IP by Headscale but only the primary device appears registered. I took down primary VM and it still showed online as the cloned VM was maintaining the same IP and registration details.

I changed the hostname of cloned VM and uninstalled tailscale. I reinstalled and ran a new connection to register. It worked but the above issue was repeated.

I disconnected both VM, uninstalled tailscale from both and removed the register from Headscale.

I reinstalled tailscale and ran a new registration on both and the same mkey was provide and repeated the issue. I assume the mkey is generated by certain machine information that has been cloned.

Expected Behavior

A cloned VM connects and requires a new registration and is provided a new identifier.

Both primary and cloned VM will have unique register.

Steps To Reproduce

  1. Clone a VM
  2. Register primary VM
  3. Register cloned VM
  4. Run headscale nodes list
  5. Observe primary VM and IP, do not observe cloned VM.
    6 Run ip -a on cloned vm showing tailscale0 with identical IP as primary.
    7 Tailscale down on primary VM
    8 Nodes list show primary VM still online and cloned VM can access network.

Environment

- OS: Alamlinux 9.4
- Headscale version: 0.23.0
- Tailscale version: 1.74.1

Runtime environment

  • Headscale is behind a (reverse) proxy
  • Headscale runs in a container

Anything else?

No response

Originally created by @plummo on GitHub (Oct 10, 2024). ### Is this a support request? - [X] This is not a support request ### Is there an existing issue for this? - [X] I have searched the existing issues ### Current Behavior Cloning a VM creates the same mkey and authuorises the device as if they are the same. Only one device appears as connected and removeing the primary device will still allow the other to be connected. I have a VM running Almalinux which was connected to Headscale server. I cloned that VM and as soon as it started it connected as tailscale was running when I initiated clone. Both instances were provided the same IP by Headscale but only the primary device appears registered. I took down primary VM and it still showed online as the cloned VM was maintaining the same IP and registration details. I changed the hostname of cloned VM and uninstalled tailscale. I reinstalled and ran a new connection to register. It worked but the above issue was repeated. I disconnected both VM, uninstalled tailscale from both and removed the register from Headscale. I reinstalled tailscale and ran a new registration on both and the same mkey was provide and repeated the issue. I assume the mkey is generated by certain machine information that has been cloned. ### Expected Behavior A cloned VM connects and requires a new registration and is provided a new identifier. Both primary and cloned VM will have unique register. ### Steps To Reproduce 1. Clone a VM 2. Register primary VM 3. Register cloned VM 4. Run headscale nodes list 5. Observe primary VM and IP, do not observe cloned VM. 6 Run ip -a on cloned vm showing tailscale0 with identical IP as primary. 7 Tailscale down on primary VM 8 Nodes list show primary VM still online and cloned VM can access network. ### Environment ```markdown - OS: Alamlinux 9.4 - Headscale version: 0.23.0 - Tailscale version: 1.74.1 ``` ### Runtime environment - [ ] Headscale is behind a (reverse) proxy - [X] Headscale runs in a container ### Anything else? _No response_
adam added the bug label 2025-12-29 02:24:28 +01:00
adam closed this issue 2025-12-29 02:24:28 +01:00
Author
Owner

@juanfont commented on GitHub (Oct 10, 2024):

This is completely expected. If you clone the VM it makes sense that it has the same contents as the source VM, including the file that has the machine key.

@juanfont commented on GitHub (Oct 10, 2024): This is completely expected. If you clone the VM it makes sense that it has the same contents as the source VM, including the file that has the machine key.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#824