[Feature] derper server supports namespace isolation #998

Closed
opened 2025-12-29 02:27:13 +01:00 by adam · 7 comments
Owner

Originally created by @happytrudy on GitHub (Apr 12, 2025).

Use case

Multiple namespaces can only share one derper server. If each namespace is configured separately

Description

Multiple namespaces can only share one derper server. If each namespace is configured separately

Contribution

  • I can write the design doc for this feature
  • I can contribute this feature

How can it be implemented?

No response

Originally created by @happytrudy on GitHub (Apr 12, 2025). ### Use case Multiple namespaces can only share one derper server. If each namespace is configured separately ### Description Multiple namespaces can only share one derper server. If each namespace is configured separately ### Contribution - [x] I can write the design doc for this feature - [x] I can contribute this feature ### How can it be implemented? _No response_
adam added the enhancement label 2025-12-29 02:27:13 +01:00
adam closed this issue 2025-12-29 02:27:13 +01:00
Author
Owner

@kradalby commented on GitHub (Apr 13, 2025):

What does this mean?

@kradalby commented on GitHub (Apr 13, 2025): What does this mean?
Author
Owner

@happytrudy commented on GitHub (Apr 13, 2025):

What does this mean?

Sorry, the current version has been changed to users. What I mean is that the local derper.yaml configured by the configuration file config.yaml is shared by all users. Can each user be configured to use their own configured derper server independently, that is, derper supports user isolation configuration

@happytrudy commented on GitHub (Apr 13, 2025): > What does this mean? Sorry, the current version has been changed to users. What I mean is that the local derper.yaml configured by the configuration file config.yaml is shared by all users. Can each user be configured to use their own configured derper server independently, that is, derper supports user isolation configuration
Author
Owner

@happytrudy commented on GitHub (Apr 13, 2025):

As far as I know, the official tailscale controller derper is configured in the acl rules. Each user can configure their own derper server after logging in.

@happytrudy commented on GitHub (Apr 13, 2025): As far as I know, the official tailscale controller derper is configured in the acl rules. Each user can configure their own derper server after logging in.
Author
Owner

@happytrudy commented on GitHub (Apr 14, 2025):

What does this mean?

do you have idea? is that supports?

@happytrudy commented on GitHub (Apr 14, 2025): > What does this mean? do you have idea? is that supports?
Author
Owner

@kradalby commented on GitHub (Apr 14, 2025):

No I don’t think so, and I do not think we will support that.

@kradalby commented on GitHub (Apr 14, 2025): No I don’t think so, and I do not think we will support that.
Author
Owner

@happytrudy commented on GitHub (Apr 14, 2025):

If the derper configuration is moved to the acl configuration, user isolation can be achieved. I still request to implement such a function, otherwise all derper users share

---Original---
From: "Kristoffer @.>
Date: Mon, Apr 14, 2025 20:27 PM
To: @.
>;
Cc: @.@.>;
Subject: Re: [juanfont/headscale] [Feature] derper server supports namespaceisolation (Issue #2524)

No I don’t think so, and I do not think we will support that.


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you authored the thread.Message ID: @.***>
kradalby left a comment (juanfont/headscale#2524)

No I don’t think so, and I do not think we will support that.


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you authored the thread.Message ID: @.***>

@happytrudy commented on GitHub (Apr 14, 2025): If the derper configuration is moved to the acl configuration, user isolation can be achieved. I still request to implement such a function, otherwise all derper users share ---Original--- From: "Kristoffer ***@***.***> Date: Mon, Apr 14, 2025 20:27 PM To: ***@***.***>; Cc: ***@***.******@***.***>; Subject: Re: [juanfont/headscale] [Feature] derper server supports namespaceisolation (Issue #2524) No I don’t think so, and I do not think we will support that. — Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you authored the thread.Message ID: ***@***.***> kradalby left a comment (juanfont/headscale#2524) No I don’t think so, and I do not think we will support that. — Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you authored the thread.Message ID: ***@***.***>
Author
Owner

@kradalby commented on GitHub (Apr 14, 2025):

Yes, since the derper is encrypted, we don’t consider that something to work on, so we won’t doing something like that.

We probably will not move the derp conf either.

@kradalby commented on GitHub (Apr 14, 2025): Yes, since the derper is encrypted, we don’t consider that something to work on, so we won’t doing something like that. We probably will not move the derp conf either.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/headscale#998