Tailscale Kubernetes operator v1.78.1
This release introduces multiple new features for the Tailscale Kubernetes operator including client metrics support, topology spread constraints, Connector CRD configuration, and improved Kubernetes integration with event logging and CSI driver support. Several improvements enhance reliability by reducing API server timeouts and state management operations.
A new release of the Tailscale Kubernetes operator is available. For guidance on installing and updating, see installation instructions.
-
New: Tailscale client metrics can be enabled using a
ProxyClasswith the.spec.metrics.enablefield set. -
New: All Tailscale container images are annotated with Open Container Initiative (OCI) annotations.
-
New:
ProxyClasssupports configuring topology spread constraints for the Proxy Pods. -
New: Connector Custom Resource Definition (CRD) can be used to configure the Kubernetes Operator to deploy a Tailscale app connector on Kubernetes.
-
New: Tailscale running on Kubernetes and using a Kubernetes Secret as a state store writes Kubernetes Events to its Pod when changes occur to the state stored in the Kubernetes Secret. The same is true when there are errors related to reading or writing the state. This should help debugging issues related to transient errors when talking to the Kubernetes API server to retrieve or update the state Secret.
-
New: Kubernetes Operator can optionally create a Prometheus ServiceMonitor for proxy resources that have Tailscale client metrics enabled.
-
New: Container Storage Interface (CSI) driver volume for the operator's OAuth client credentials can be configured by using Helm values.
-
New: Kubernetes Ingress has clearer warnings if it has been deployed to a tailnet that has no HTTPS enabled. Specifically, a new warning in proxy logs and empty hostname on the Ingress status.
-
Changed:
tailscale.com/tailnet-ipannotation is validated that it holds a valid IP address. -
Changed: Timeout for Kubernetes API server calls for reading/updating
tailscaledstate stored in a Kubernetes Secret has been changed from 5 seconds to the total of 30 seconds for the read/update operation and an operation to emit an Event about the state update. This should reduce errors related to slow API server connections. -
Changed: The
ProxyClassfield.spec.metrics.enableenables metrics at both/metricsand/debug/metrics, but/debug/metricsis deprecated. Users relying on/debug/metricsneed to set.spec.statefulSet.pod.tailscaleContainer.debug.enable(which is a new field in Tailscale 1.78.1) until Tailscale 1.82.0 releases. When 1.82.0 releases,/metricsand/debug/metricswill both independently default to false. -
Changed: Kubernetes operator proxy containers created for ingress and egress Service resources, Connectors and ProxyGroups are privileged. This is needed because of recent changes in
containerd. For more context, see tailscale/tailscale/pull/14262. -
Fixed: Tailscale running on Kubernetes reads its state from a Secret only once, and that is upon initial start. This should reduce bugs caused by transient issues when connecting to the Kubernetes API server as well as reduce the load on the API server and improve latency for state operations.
-
Fixed: Kubernetes Egress Service ports for
ProxyGroupcan be changed from a single unnamed port to one or more named ports. -
Fixed: Clients should more accurately detect whether they are in a container when checking for updates.
Source: original entry ↗
More from Tailscale
Follow Tailscale to get its new changes in your feed and email digest.
Tailscale v1.104.1 — Performance and Features Release
Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.
Declarative node sharing
Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.
Linux client reconnection stability fix
Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.