Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> ... updates ...

Do you think it is sufficient to rely on update channels via distributions? Wouldn't a bug in your code potentially expose an internal node to the internet?

> Each node has its own view of the world

I haven't read the docs enough, but can a node belong to many domains at once? If so, does it need one port per domain that it is shared on?



> Do you think it is sufficient to rely on update channels via distributions?

Tailscale employee here. Most officially supported distributions use our own package repo server (https://pkgs.tailscale.com), which would pull Tailscale updates in your normal system updates. The other distributions that aren't in the package repo server (Alpine, Arch, Gentoo, NixOS, Void Linux, etc.) use packages made by the distribution themselves. We do our best to make sure they get updated (contacting the maintainers can be a slog at times), but we do not completely control the update process for them.

> I haven't read the docs enough, but can a node belong to many domains at once? If so, does it need one port per domain that it is shared on?

Not currently, follow this bug (https://github.com/tailscale/tailscale/issues/713) to be updated on the details for this. You can sorta hack around it with node sharing (https://tailscale.com/kb/1084/sharing/), but that's unidirectional instead of bidirectional.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: