You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/ipn
Andrew Lytvynov c9179bc261
various: disable stateful filtering by default (#12197)
After some analysis, stateful filtering is only necessary in tailnets
that use `autogroup:danger-all` in `src` in ACLs. And in those cases
users explicitly specify that hosts outside of the tailnet should be
able to reach their nodes. To fix local DNS breakage in containers, we
disable stateful filtering by default.

Updates #12108

Signed-off-by: Andrew Lytvynov <awly@tailscale.com>
4 months ago
..
conffile
ipnauth
ipnlocal various: disable stateful filtering by default (#12197) 4 months ago
ipnserver ipn/ipnserver: close a small race in ipnserver, ~simplify code 5 months ago
ipnstate cmd/tailscale,controlclient,ipnlocal: fix 'up', deflake tests more 5 months ago
localapi ipn/ipnlocal, all: plumb health trackers in tests 5 months ago
policy
store cmd/containerboot,kube,ipn/store/kubestore: allow interactive login on kube, check Secret create perms, allow empty state Secret (#11326) 5 months ago
backend.go ipn: remove unused Options.LegacyMigrationPrefs 5 months ago
conf.go cmd/k8s-operator,cmd/containerboot,ipn,k8s-operator: turn off stateful filter for egress proxies. (#12075) 5 months ago
doc.go
ipn_clone.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 4 months ago
ipn_test.go
ipn_view.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 4 months ago
prefs.go various: disable stateful filtering by default (#12197) 4 months ago
prefs_test.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 4 months ago
serve.go all: deprecate Node.Capabilities (more), remove PeerChange.Capabilities [capver 89] 6 months ago
serve_test.go
store.go ipn: add comment about thread-safety to StateStore 7 months ago
store_test.go