Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Replace interactive Tailscale browser auth with ephemeral auth keys

オープン
#58 コメント 1 件 リアクション 1 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
45/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
python
領域
cli, cloud, networking

調査の方向性

wait_for_tailscale_ip と setup_tailscale を含め、dropkit create、wake、enable-tailscale を通る既存の Tailscale の対話的なフローを追跡します。cloud-init と SSH が現在どのように認証データを受け取っているかを確認し、設定済みの認証キーをブラウザーのフォールバックとどのように共存させるべきかを判断します。対応しているフローで自動認証が機能し、フォールバックが引き続き利用可能で、wake 後に SSH 設定が更新されれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Problem

When creating a droplet with Tailscale enabled, dropkit requires the user to manually open a URL in their browser to authenticate the device. This is slow, breaks the flow of dropkit create, and doesn't work in headless/CI environments.

Proposed solution

Use Tailscale ephemeral pre-authorized auth keys to authenticate droplets automatically during cloud-init. No browser interaction needed. Ephemeral nodes auto-remove from the tailnet when they go offline (30-60 min), eliminating stale machine entries.

How it would work
  1. User configures a Tailscale auth key (or OAuth client credentials) in ~/.config/dropkit/config.yaml
  2. During dropkit create, dropkit injects the key into cloud-init
  3. Cloud-init runs tailscale up --authkey=<key> — device joins the tailnet unattended
  4. dropkit polls for the Tailscale IP (existing wait_for_tailscale_ip) and updates SSH config
  5. Same flow for wake and enable-tailscale (key passed via SSH instead of cloud-init)

When no auth key or OAuth credentials are configured, fall back to the current interactive browser flow.

Tailscale admin requirements

This is the main blocker. Generating auth keys or OAuth clients requires Owner, Admin, IT admin, or Network admin role in the Tailscale tailnet. Regular users cannot create them, even though they can already authenticate devices interactively via browser.

Options:

  • A Tailscale admin generates a shared reusable ephemeral auth key or OAuth client for the team (one-time setup) and shares it in 1password.

Ephemeral vs non-ephemeral nodes

Ephemeral nodes auto-remove from the tailnet 30-60 min after going offline. This means:

Scenario Ephemeral Non-ephemeral
Auto-cleanup on destroy Yes (30-60 min) No — relies on tailscale logout
Survives hibernate/wake No — must re-auth, gets new IP + hostname Yes — reconnects automatically
Survives reboot Only if back online within ~30-60 min Yes
Stale entries if destroy fails No Yes (manual cleanup needed)
Trade-off: IP and hostname change on wake

Ephemeral nodes get a new identity on each re-auth. The Tailscale IP and MagicDNS hostname will change after every hibernate/wake cycle.

What dropkit handles automatically:

  • SSH config is updated with the new Tailscale IP during setup_tailscale() on wake
  • dropkit uses dropkit.<name> for SSH hostnames, not Tailscale DNS names

What breaks:

  • Any direct references to the Tailscale IP or MagicDNS hostname outside of dropkit (scripts, bookmarks, other services pointing at the old IP) will break after wake

Any thoughts @ret2libc ?

主要言語
Python
スター
128
フォーク
14
平均マージ
10時間 13分
マージ済み PR(30日)
4

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

  • Dockerfile・Docker Compose ファイルなし
  • プルリクエストのテンプレートなし
  • コントリビューションガイドなし

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

trailofbits/dropkit のほかの issue

trailofbits/dropkit の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。