Tailscale v1.66.3
This release fixes login URL display in the console and improves Android VPN service connection logic including persistent status notifications. The Kubernetes operator gains cloud service exposure capabilities, ProxyClass CRD support for environment variables and metrics, and better error handling for container deployments.
Note: Tailscale v1.66.2 was an internal-only release.
All platforms- Fixed: Login URLs did not always appear in the console when running
tailscale up.
- Changed: Reintroduced the Quick Settings title that v1.66.0 temporarily removed.
- Changed: Improved the VPN service connection logic, especially when rebooting the device with Always-On VPN enabled.
- Changed: The persistent VPN status notification now informs the user with a muted icon when the VPN is disconnected. VPN status notifications can be disabled in the system notification settings.
- Fixed: The "Enable" button in the exit node selector banner now renders with the correct background color.
- Breaking change: Starting with v1.66, the Kubernetes operator must always run the same or later version as the proxies it manages.
- New: Expose cloud services on cluster network to the tailnet, using Kubernetes
ExternalNameServices. This allows exposing cloud services, such as RDS instances, to tailnet by their DNS names. - New: Expose tailnet services that use Tailscale HTTPS to cluster workloads. Refer to #11019.
- New: Cluster workloads can now refer to Tailscale Ingress resources by their MagicDNS names. Refer to #11019.
- New: Configure environment variables for Tailscale Kubernetes operator proxies using
ProxyClassCRD. Refer toProxyClassAPI. - New: Expose
tailscaledmetrics endpoint for Tailscale Kubernetes operator proxies throughProxyClassCRD. Note that thetailscaledmetrics are unstable and will likely change in the future. Refer toProxyClassAPI. - New: Configure labels for the Kubernetes operator Pods with Helm chart values. Refer to Helm chart values.
- New: Configure affinity rules for Kubernetes operator proxy Pods with
ProxyClass. Refer toProxyClassAPI. - Fixed: Kubernetes operator proxy
initcontainer no longer attempts to enable IPv6 forwarding on systems that don't have IPv6 module loaded. Refer to #11867.
- Fixed: Tailscale containers running on Kubernetes no longer error if an empty Kubernetes
Secretis pre-created for thetailscaledstate. Refer to #11326. - Fixed: Improved the ambiguous error messages when Tailscale running on Kubernetes does not have the right permissions to perform actions against the
tailscaledstateSecret. Refer to #11326.
Source: original entry ↗
More from Tailscale
Follow Tailscale to get its new changes in your feed and email digest.
Tailscale v1.104.1 — Performance and Features Release
Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.
Declarative node sharing
Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.
Linux client reconnection stability fix
Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.