Skip to content

Notes from the field

How it runs

The adapter starts Tailscale's own tailscaled program inside its container, in userspace networking mode. No special container privileges, no TUN device and no host networking are needed. Tailnet traffic on port 443 is passed through (TCP, not decrypted) to the Protequ front door, so the front door's own certificate is what the browser sees.

State volume

The container runs as an unprivileged user and the image has no shell, so a bind-mounted host folder (which Docker creates owned by root) would not be writable. The installer therefore mounts /var/lib/tailscale as a Docker volume without a name. Docker fills it from the image, so the unprivileged user owns it, and it survives restarts and in-place container re-creation. A volume without a name is not reattached after docker compose down, which the installer runs on every re-install or upgrade, so the node then registers again using the auth key, and the old machine entry should be deleted in the Tailscale console.

Gotchas

  • Parameters are read when the device starts. Edit, then restart the device.
  • A reusable key is required if the install may ever re-register (for example after the volume is removed).
  • The Tailscale name is not added to the sign-in allow-list automatically (see the connection guide).
  • The Tailscale program version is pinned in the image; upgrading it means a new adapter release.