Replace interactive Tailscale browser auth with ephemeral auth keys
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- python
- 領域
- cli, cloud, networking
調査の方向性
wait_for_tailscale_ip と setup_tailscale を含め、dropkit create、wake、enable-tailscale を通る既存の Tailscale の対話的なフローを追跡します。cloud-init と SSH が現在どのように認証データを受け取っているかを確認し、設定済みの認証キーをブラウザーのフォールバックとどのように共存させるべきかを判断します。対応しているフローで自動認証が機能し、フォールバックが引き続き利用可能で、wake 後に SSH 設定が更新されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Problem
When creating a droplet with Tailscale enabled, dropkit requires the user to manually open a URL in their browser to authenticate the device. This is slow, breaks the flow of dropkit create, and doesn't work in headless/CI environments.
Proposed solution
Use Tailscale ephemeral pre-authorized auth keys to authenticate droplets automatically during cloud-init. No browser interaction needed. Ephemeral nodes auto-remove from the tailnet when they go offline (30-60 min), eliminating stale machine entries.
How it would work
- User configures a Tailscale auth key (or OAuth client credentials) in
~/.config/dropkit/config.yaml - During
dropkit create, dropkit injects the key into cloud-init - Cloud-init runs
tailscale up --authkey=<key>— device joins the tailnet unattended - dropkit polls for the Tailscale IP (existing
wait_for_tailscale_ip) and updates SSH config - Same flow for
wakeandenable-tailscale(key passed via SSH instead of cloud-init)
When no auth key or OAuth credentials are configured, fall back to the current interactive browser flow.
Tailscale admin requirements
This is the main blocker. Generating auth keys or OAuth clients requires Owner, Admin, IT admin, or Network admin role in the Tailscale tailnet. Regular users cannot create them, even though they can already authenticate devices interactively via browser.
Options:
- A Tailscale admin generates a shared reusable ephemeral auth key or OAuth client for the team (one-time setup) and shares it in 1password.
Ephemeral vs non-ephemeral nodes
Ephemeral nodes auto-remove from the tailnet 30-60 min after going offline. This means:
| Scenario | Ephemeral | Non-ephemeral |
|---|---|---|
| Auto-cleanup on destroy | Yes (30-60 min) | No — relies on tailscale logout |
| Survives hibernate/wake | No — must re-auth, gets new IP + hostname | Yes — reconnects automatically |
| Survives reboot | Only if back online within ~30-60 min | Yes |
| Stale entries if destroy fails | No | Yes (manual cleanup needed) |
Trade-off: IP and hostname change on wake
Ephemeral nodes get a new identity on each re-auth. The Tailscale IP and MagicDNS hostname will change after every hibernate/wake cycle.
What dropkit handles automatically:
- SSH config is updated with the new Tailscale IP during
setup_tailscale()on wake - dropkit uses
dropkit.<name>for SSH hostnames, not Tailscale DNS names
What breaks:
- Any direct references to the Tailscale IP or MagicDNS hostname outside of dropkit (scripts, bookmarks, other services pointing at the old IP) will break after wake
Any thoughts @ret2libc ?
- 主要言語
- Python
- スター
- 128
- フォーク
- 14
- 平均マージ
- 10時間 13分
- マージ済み PR(30日)
- 4
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
trailofbits/dropkit のほかの issue
-
Publish on PyPI?オープン
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
trailofbits/dropkit#73 · リアクション 1 件 ·
-
Support creating droplets from snapshots (clone workflow)対応中かも @gwpl が 201 日前に担当しました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
trailofbits/dropkit#52 ·
trailofbits/dropkit の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 60/100
521xueweihan/HelloGitHub#3924 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 67/100
wilbowes/EchoMuse#869 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
-
namespace operations
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
EclipseFdn/open-vsx.org#14043 ·
メンテナーはふだん 1 日以内に返信
-
test: TestServeUntilStale races the server's close against the client's sendall (BrokenPipeError under load)対応中かも @evoludigit が今日担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 89/100
メンテナーはふだん 1 日以内に返信