Notes from the field¶
How it runs¶
The adapter starts Tailscale's own tailscaled program inside its container, in userspace
networking mode. No special container privileges, no TUN device and no host networking are needed.
Tailnet traffic on port 443 is passed through (TCP, not decrypted) to the Protequ front door, so the
front door's own certificate is what the browser sees.
State volume¶
The container runs as an unprivileged user and the image has no shell, so a bind-mounted host folder
(which Docker creates owned by root) would not be writable. The installer therefore mounts
/var/lib/tailscale as a Docker volume without a name. Docker fills it from the image, so the
unprivileged user owns it, and it survives restarts and in-place container re-creation. A volume
without a name is not reattached after docker compose down, which the installer runs on every
re-install or upgrade, so the node then registers again using the auth key, and the
old machine entry should be deleted in the Tailscale console.
Gotchas¶
- Parameters are read when the device starts. Edit, then restart the device.
- A reusable key is required if the install may ever re-register (for example after the volume is removed).
- The Tailscale name is not added to the sign-in allow-list automatically (see the connection guide).
- The Tailscale program version is pinned in the image; upgrading it means a new adapter release.