You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/ipn
Andrew Lytvynov c9179bc261
various: disable stateful filtering by default (#12197)
After some analysis, stateful filtering is only necessary in tailnets
that use `autogroup:danger-all` in `src` in ACLs. And in those cases
users explicitly specify that hosts outside of the tailnet should be
able to reach their nodes. To fix local DNS breakage in containers, we
disable stateful filtering by default.

Updates #12108

Signed-off-by: Andrew Lytvynov <awly@tailscale.com>
2 years ago
..
conffile ipn/{conffile,ipnlocal}: start booting tailscaled from a config file w/ auth key 2 years ago
ipnauth go.mod, all: move away from inet.af domain seized by Taliban 2 years ago
ipnlocal various: disable stateful filtering by default (#12197) 2 years ago
ipnserver ipn/ipnserver: close a small race in ipnserver, ~simplify code 2 years ago
ipnstate cmd/tailscale,controlclient,ipnlocal: fix 'up', deflake tests more 2 years ago
localapi ipn/ipnlocal, all: plumb health trackers in tests 2 years ago
policy ipn,tailconfig: clean up unreleased and removed app connector service 2 years ago
store cmd/containerboot,kube,ipn/store/kubestore: allow interactive login on kube, check Secret create perms, allow empty state Secret (#11326) 2 years ago
backend.go ipn: remove unused Options.LegacyMigrationPrefs 2 years ago
conf.go cmd/k8s-operator,cmd/containerboot,ipn,k8s-operator: turn off stateful filter for egress proxies. (#12075) 2 years ago
doc.go all: update copyright and license headers 3 years ago
ipn_clone.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 2 years ago
ipn_test.go net/packet: split off checksum munging into different pkg 2 years ago
ipn_view.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 2 years ago
prefs.go various: disable stateful filtering by default (#12197) 2 years ago
prefs_test.go ipn,wgengine: remove vestigial Prefs.AllowSingleHosts 2 years ago
serve.go all: deprecate Node.Capabilities (more), remove PeerChange.Capabilities [capver 89] 2 years ago
serve_test.go {ipn/serve,cmd/tailscale/cli}: move some shared funcs to ipn 2 years ago
store.go ipn: add comment about thread-safety to StateStore 2 years ago
store_test.go ipn: avoid useless no-op WriteState calls 2 years ago