megachangelog
Feature1.78.1

Tailscale Kubernetes operator v1.78.1

This release introduces multiple new features for the Tailscale Kubernetes operator including client metrics support, topology spread constraints, Connector CRD configuration, and improved Kubernetes integration with event logging and CSI driver support. Several improvements enhance reliability by reducing API server timeouts and state management operations.

A new release of the Tailscale Kubernetes operator is available. For guidance on installing and updating, see installation instructions.

  • New: Tailscale client metrics can be enabled using a ProxyClass with the .spec.metrics.enable field set.

  • New: All Tailscale container images are annotated with Open Container Initiative (OCI) annotations.

  • New: ProxyClass supports configuring topology spread constraints for the Proxy Pods.

  • New: Connector Custom Resource Definition (CRD) can be used to configure the Kubernetes Operator to deploy a Tailscale app connector on Kubernetes.

  • New: Tailscale running on Kubernetes and using a Kubernetes Secret as a state store writes Kubernetes Events to its Pod when changes occur to the state stored in the Kubernetes Secret. The same is true when there are errors related to reading or writing the state. This should help debugging issues related to transient errors when talking to the Kubernetes API server to retrieve or update the state Secret.

  • New: Kubernetes Operator can optionally create a Prometheus ServiceMonitor for proxy resources that have Tailscale client metrics enabled.

  • New: Container Storage Interface (CSI) driver volume for the operator's OAuth client credentials can be configured by using Helm values.

  • New: Kubernetes Ingress has clearer warnings if it has been deployed to a tailnet that has no HTTPS enabled. Specifically, a new warning in proxy logs and empty hostname on the Ingress status.

  • Changed: tailscale.com/tailnet-ip annotation is validated that it holds a valid IP address.

  • Changed: Timeout for Kubernetes API server calls for reading/updating tailscaled state stored in a Kubernetes Secret has been changed from 5 seconds to the total of 30 seconds for the read/update operation and an operation to emit an Event about the state update. This should reduce errors related to slow API server connections.

  • Changed: The ProxyClass field .spec.metrics.enable enables metrics at both /metrics and /debug/metrics, but /debug/metrics is deprecated. Users relying on /debug/metrics need to set .spec.statefulSet.pod.tailscaleContainer.debug.enable (which is a new field in Tailscale 1.78.1) until Tailscale 1.82.0 releases. When 1.82.0 releases, /metrics and /debug/metrics will both independently default to false.

  • Changed: Kubernetes operator proxy containers created for ingress and egress Service resources, Connectors and ProxyGroups are privileged. This is needed because of recent changes in containerd. For more context, see tailscale/tailscale/pull/14262.

  • Fixed: Tailscale running on Kubernetes reads its state from a Secret only once, and that is upon initial start. This should reduce bugs caused by transient issues when connecting to the Kubernetes API server as well as reduce the load on the API server and improve latency for state operations.

  • Fixed: Kubernetes Egress Service ports for ProxyGroup can be changed from a single unnamed port to one or more named ports.

  • Fixed: Clients should more accurately detect whether they are in a container when checking for updates.

kubernetesoperatormetricsreliabilityconfiguration

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →