Skip to content

Add Tailscale device identity linking - #187

Merged
fifthsegment merged 2 commits into
masterfrom
feat/tailscale-device-linking
Sep 24, 2026
Merged

fifthsegment merged 2 commits into
masterfrom
feat/tailscale-device-linking

Conversation

@fifthsegment

Copy link
Copy Markdown
Owner

Summary

  • add a read-only, disabled-by-default Tailscale LocalAPI client and lifecycle manager using the local tailscaled Unix socket
  • let administrators explicitly link stable Tailscale nodes to existing canonical GateSentry devices so LAN and Tailscale traffic share one policy identity
  • add authenticated status, configuration, peer, link, and unlink APIs plus Settings and Devices UI
  • harden passive/mDNS discovery, canonical device persistence, migration, ambiguity handling, and GateSentry self-discovery suppression
  • document native and Docker socket access without exposing Tailscale credentials or treating WoL metadata as authoritative MAC identity

Safety and privacy

  • no Tailscale auth token or control-plane credentials are required
  • stable node IDs and peer inventories are excluded from diagnostics and decision logs
  • Tailscale hardware MAC addresses are not inferred; optional WoL MACs are informational only
  • collection remains disabled until explicitly enabled

Verification

  • cd application && go test ./dns/discovery ./dns/server ./policy ./tailscale ./webserver/endpoints ./backup
  • cd application && go test -race ./...
  • cd gatesentryproxy && go test -race ./...
  • cd ui && yarn vitest run && yarn check
  • ./scripts/frontend.sh validate
  • make verify
  • git diff --check
  • native LocalAPI socket detection and manager enable/disable smoke tests

Notes

  • The repository's existing root-wide race run still reports pre-existing startup/global-state and Bonjour-library races outside this feature's focused application and proxy race suites.
  • The untracked repository-local CLAUDE.md is intentionally excluded.

🤖 Generated with [CC]

fifthsegment and others added 2 commits September 24, 2026 10:20
Co-Authored-By: [CC] <noreply@anthropic.com>
Co-Authored-By: [CC] <noreply@anthropic.com>
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 71.90760% with 377 lines in your changes missing coverage. Please review.
✅ Project coverage is 50.45%. Comparing base (b9e3a50) to head (c76445d).

Files with missing lines Patch % Lines
application/dns/discovery/store.go 73.05% 99 Missing and 22 partials ⚠️
...plication/webserver/endpoints/handler_tailscale.go 69.95% 40 Missing and 21 partials ⚠️
application/dns/server/server.go 39.70% 39 Missing and 2 partials ⚠️
application/tailscale/manager.go 83.46% 26 Missing and 15 partials ⚠️
application/dns/discovery/persistence.go 75.80% 23 Missing and 7 partials ⚠️
application/dns/discovery/mdns.go 62.96% 18 Missing and 2 partials ⚠️
application/webserver/webserver.go 27.27% 11 Missing and 5 partials ⚠️
application/dns/discovery/types.go 0.00% 14 Missing and 1 partial ⚠️
application/policy/service.go 0.00% 12 Missing ⚠️
application/tailscale/client.go 89.32% 7 Missing and 4 partials ⚠️
... and 3 more
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.
Additional details and impacted files
@@            Coverage Diff             @@
##           master     #187      +/-   ##
==========================================
+ Coverage   48.50%   50.45%   +1.95%     
==========================================
  Files         125      128       +3     
  Lines       11138    12253    +1115     
==========================================
+ Hits         5402     6182     +780     
- Misses       5038     5309     +271     
- Partials      698      762      +64     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@fifthsegment
fifthsegment merged commit f271200 into master Sep 24, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants