boot: 2026/05/30 07:06:28 Starting tailscaled
boot: 2026/05/30 07:06:28 Running healthcheck endpoint at 127.0.0.1:41234/healthz
boot: 2026/05/30 07:06:28 tailscaled in state "NoState", waiting
...
health(warnable=warming-up): ok
Switching ipn state Starting -> Running (WantRunning=true, nm=true)
[RATELIMIT] format("health(warnable=%s): ok")
[RATELIMIT] format("localapi: [%s] %s")
[RATELIMIT] format("control: [v\x00JSON]%d%s")
boot: 2026/05/30 07:06:34 Sending SIGTERM to tailscaled
boot: 2026/05/30 07:06:34 tailscaled got signal terminated; shutting down
boot: 2026/05/30 07:06:34 tailscaled exited
boot: 2026/05/30 07:06:34 Starting tailscaled
</details>
Tailscale sidecar comes healthy.
`
2026-05-30T07:06:28.299114000Z boot: 2026/05/30 07:06:28 Starting tailscaled
2026-05-30T07:06:28.299544000Z boot: 2026/05/30 07:06:28 Waiting for tailscaled socket at /tmp/tailscaled.sock
2026-05-30T07:06:28.305790000Z TPM: error opening: stat /dev/tpmrm0: no such file or directory
2026-05-30T07:06:28.306328000Z 2026/05/30 07:06:28 logtail started
2026-05-30T07:06:28.306409000Z 2026/05/30 07:06:28 Program starting: v1.98.4-t01c6b9661, Go 1.26.3: []string{"tailscaled", "--socket=/tmp/tailscaled.sock", "--statedir=/var/lib/tailscale"}
2026-05-30T07:06:28.306453000Z 2026/05/30 07:06:28 LogID: 8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b
2026-05-30T07:06:28.306558000Z 2026/05/30 07:06:28 logpolicy: using system state directory "/var/lib/tailscale"
2026-05-30T07:06:28.306610000Z 2026/05/30 07:06:28 dns: [rc=unknown ret=direct]
2026-05-30T07:06:28.306656000Z 2026/05/30 07:06:28 dns: using "direct" mode
2026-05-30T07:06:28.306690000Z 2026/05/30 07:06:28 dns: using *dns.directManager
2026-05-30T07:06:28.307032000Z 2026/05/30 07:06:28 dns: inotify: NewDirWatcher: context canceled
2026-05-30T07:06:28.330921000Z 2026/05/30 07:06:28 wgengine.NewUserspaceEngine(tun "tailscale0") ...
2026-05-30T07:06:28.333207000Z 2026/05/30 07:06:28 dns: [rc=unknown ret=direct]
2026-05-30T07:06:28.333391000Z 2026/05/30 07:06:28 dns: using "direct" mode
2026-05-30T07:06:28.335659000Z 2026/05/30 07:06:28 dns: using *dns.directManager
2026-05-30T07:06:28.336173000Z 2026/05/30 07:06:28 link state: interfaces.State{defaultRoute=eth0 ifs={eth0:[172.16.144.2/20]} v4=true v6=false}
2026-05-30T07:06:28.336235000Z 2026/05/30 07:06:28 router: portUpdate(port=37537, network=udp6)
2026-05-30T07:06:28.336286000Z 2026/05/30 07:06:28 router: using firewall mode pref
2026-05-30T07:06:28.336340000Z 2026/05/30 07:06:28 magicsock: disco key = d:6b77e4a16d5f08c7
2026-05-30T07:06:28.336433000Z 2026/05/30 07:06:28 Creating WireGuard device...
2026-05-30T07:06:28.336658000Z 2026/05/30 07:06:28 Bringing WireGuard device up...
2026-05-30T07:06:28.337671000Z 2026/05/30 07:06:28 external route: up
2026-05-30T07:06:28.337835000Z 2026/05/30 07:06:28 Bringing router up...
2026-05-30T07:06:28.339217000Z 2026/05/30 07:06:28 router: default choosing iptables
2026-05-30T07:06:28.342391000Z 2026/05/30 07:06:28 router: netfilter running in iptables mode v6 = true, v6filter = true, v6nat = true
2026-05-30T07:06:28.342589000Z 2026/05/30 07:06:28 router: portUpdate(port=54374, network=udp4)
2026-05-30T07:06:28.343087000Z 2026/05/30 07:06:28 Clearing router settings...
2026-05-30T07:06:28.343188000Z 2026/05/30 07:06:28 Starting network monitor...
2026-05-30T07:06:28.343250000Z 2026/05/30 07:06:28 Engine created.
2026-05-30T07:06:28.343824000Z 2026/05/30 07:06:28 pm: using backend prefs for "profile-1a37": Prefs{ra=false dns=true want=true routes=[] statefulFiltering=false nf=on update=check Persist{o=, n=[nnrpm] u="super-secure@gmail.com" ak=-}}
2026-05-30T07:06:28.344053000Z 2026/05/30 07:06:28 logpolicy: using system state directory "/var/lib/tailscale"
2026-05-30T07:06:28.344182000Z 2026/05/30 07:06:28 monitor: gateway and self IP changed: gw=172.16.144.1 self=172.16.144.2
2026-05-30T07:06:28.344918000Z 2026/05/30 07:06:28 linkChange: in state NoState; PAC or proxyConfig changed; updating routes
2026-05-30T07:06:28.346200000Z 2026/05/30 07:06:28 got LocalBackend in 14ms
2026-05-30T07:06:28.346340000Z 2026/05/30 07:06:28 Start
2026-05-30T07:06:28.346387000Z 2026/05/30 07:06:28 ipnext: "conn25": skipping extension
2026-05-30T07:06:28.346432000Z 2026/05/30 07:06:28 ipnext: active extensions: portlist, posture, clientupdate, relayserver, taildrop, conn25
2026-05-30T07:06:28.346469000Z 2026/05/30 07:06:28 load netmap from cache: netmap cache is not available
2026-05-30T07:06:28.346518000Z 2026/05/30 07:06:28 Backend: logs: be:8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b fe:
2026-05-30T07:06:28.346557000Z 2026/05/30 07:06:28 control: client.Login(0)
2026-05-30T07:06:28.346614000Z 2026/05/30 07:06:28 control: doLogin(regen=false, hasUrl=false)
2026-05-30T07:06:28.346819000Z 2026/05/30 07:06:28 health(warnable=warming-up): error: Tailscale is starting. Please wait.
2026-05-30T07:06:28.399954000Z boot: 2026/05/30 07:06:28 Running healthcheck endpoint at 127.0.0.1:41234/healthz
2026-05-30T07:06:28.410706000Z boot: 2026/05/30 07:06:28 tailscaled in state "NoState", waiting
2026-05-30T07:06:28.440352000Z 2026/05/30 07:06:28 control: control server key from https://controlplane.tailscale.com: ts2021=[fSeS+], legacy=[nlFWp]
2026-05-30T07:06:28.440568000Z 2026/05/30 07:06:28 control: RegisterReq: onode= node=[nnrpm] fup=false nks=false
2026-05-30T07:06:28.516155000Z 2026/05/30 07:06:28 control: RegisterReq: got response; nodeKeyExpired=false, machineAuthorized=true; authURL=false
2026-05-30T07:06:28.584326000Z 2026/05/30 07:06:28 health(warnable=not-in-map-poll): ok
2026-05-30T07:06:28.584562000Z 2026/05/30 07:06:28 control: netmap: got new dial plan from control
2026-05-30T07:06:28.587493000Z 2026/05/30 07:06:28 active login: super-secure@gmail.com
2026-05-30T07:06:28.587638000Z 2026/05/30 07:06:28 serve: creating a new proxy handler for http://127.0.0.1:8090
2026-05-30T07:06:28.587724000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to true
2026-05-30T07:06:28.587767000Z 2026/05/30 07:06:28 netmap: suggested exit node: no preferred DERP, try again later
2026-05-30T07:06:28.587804000Z 2026/05/30 07:06:28 Switching ipn state NoState -> Starting (WantRunning=true, nm=true)
2026-05-30T07:06:28.587850000Z 2026/05/30 07:06:28 magicsock: SetPrivateKey called (init)
2026-05-30T07:06:28.587883000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
2026-05-30T07:06:28.587975000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring router
2026-05-30T07:06:28.620548000Z boot: 2026/05/30 07:06:28 tailscaled in state "Starting", waiting
2026-05-30T07:06:28.660243000Z 2026/05/30 07:06:28 router: enabling connmark-based rp_filter workaround
2026-05-30T07:06:28.667606000Z 2026/05/30 07:06:28 router: warning: failed to enable src_valid_mark: sysctl(net.ipv4.conf.all.src_valid_mark=1): open /proc/sys/net/ipv4/conf/all/src_valid_mark: read-only file system
2026-05-30T07:06:28.669955000Z 2026/05/30 07:06:28 wgengine: Reconfig: user dialer
2026-05-30T07:06:28.670118000Z 2026/05/30 07:06:28 tsdial: bart table size: 68
2026-05-30T07:06:28.670166000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring DNS
2026-05-30T07:06:28.670240000Z 2026/05/30 07:06:28 dns: Set: {DefaultResolvers:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] Routes:{super-secure.ts.net.:[] ts.net.:[199.247.155.53 2620:111:8007::53]}+65arpa SearchDomains:[super-secure.ts.net.] Hosts:66}
2026-05-30T07:06:28.670281000Z 2026/05/30 07:06:28 dns: Resolvercfg: {Routes:{.:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] ts.net.:[199.247.155.53 2620:111:8007::53]} Hosts:66 LocalDomains:[super-secure.ts.net.]+65arpa}
2026-05-30T07:06:28.670307000Z 2026/05/30 07:06:28 dns: OScfg: {Nameservers:[100.100.100.100 fd7a:115c:a1e0::53] SearchDomains:[super-secure.ts.net.] }
2026-05-30T07:06:28.670608000Z 2026/05/30 07:06:28 rename of "/etc/resolv.conf" to "/etc/resolv.pre-tailscale-backup.conf" failed (rename /etc/resolv.conf /etc/resolv.pre-tailscale-backup.conf: device or resource busy), falling back to copy+delete
2026-05-30T07:06:28.671576000Z 2026/05/30 07:06:28 peerapi: serving on http://100.101.121.100:46887
2026-05-30T07:06:28.671663000Z 2026/05/30 07:06:28 peerapi: serving on http://[fd7a:115c:a1e0::8539:7964]:57587
2026-05-30T07:06:28.690342000Z 2026/05/30 07:06:28 listening on [fd7a:115c:a1e0::8539:7964]:443
2026-05-30T07:06:28.748280000Z 2026/05/30 07:06:28 netmap: suggested exit node: no preferred DERP, try again later
2026-05-30T07:06:28.748362000Z 2026/05/30 07:06:28 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
2026-05-30T07:06:28.748421000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
2026-05-30T07:06:28.748917000Z 2026/05/30 07:06:28 listening on 100.101.121.100:443
2026-05-30T07:06:28.838445000Z 2026/05/30 07:06:28 magicsock: home DERP changing from derp-0 [0ms] to derp-26 [29ms] (forced=false)
2026-05-30T07:06:28.838603000Z 2026/05/30 07:06:28 magicsock: home is now derp-26 (nue)
2026-05-30T07:06:28.838657000Z 2026/05/30 07:06:28 magicsock: adding connection to derp-26 for home-keep-alive
2026-05-30T07:06:28.838701000Z 2026/05/30 07:06:28 magicsock: 1 active derp conns: derp-26=cr0s,wr0s
2026-05-30T07:06:28.838743000Z 2026/05/30 07:06:28 control: NetInfo: NetInfo{varies=false ipv6=false ipv6os=true udp=true icmpv4=false derp=#26 portmap= link="" firewallmode="ipt-default"}
2026-05-30T07:06:28.840458000Z 2026/05/30 07:06:28 writing netmap to disk cache
2026-05-30T07:06:28.840594000Z 2026/05/30 07:06:28 derphttp.Client.Connect: connecting to derp-26 (nue)
2026-05-30T07:06:28.840685000Z 2026/05/30 07:06:28 magicsock: endpoints changed: 77.20.152.2:54374 (stun), 172.16.144.2:54374 (local)
2026-05-30T07:06:28.848024000Z 2026/05/30 07:06:28 health(warnable=warming-up): ok
2026-05-30T07:06:28.848167000Z 2026/05/30 07:06:28 Switching ipn state Starting -> Running (WantRunning=true, nm=true)
2026-05-30T07:06:28.848231000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
2026-05-30T07:06:28.848276000Z boot: 2026/05/30 07:06:28 Running 'tailscale set'
2026-05-30T07:06:28.860328000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/check-prefs
2026-05-30T07:06:28.860922000Z 2026/05/30 07:06:28 localapi: [PATCH] /localapi/v0/prefs
2026-05-30T07:06:28.861719000Z boot: 2026/05/30 07:06:28 serve proxy: unsetting previous config
2026-05-30T07:06:28.862605000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/serve-config
2026-05-30T07:06:28.862713000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
2026-05-30T07:06:28.862951000Z 2026/05/30 07:06:28 serve: closing idle connections to http://127.0.0.1:8090
2026-05-30T07:06:28.863032000Z 2026/05/30 07:06:28 closing listener 100.101.121.100:443
2026-05-30T07:06:28.863084000Z 2026/05/30 07:06:28 closing listener [fd7a:115c:a1e0::8539:7964]:443
2026-05-30T07:06:28.863135000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to false
2026-05-30T07:06:28.895444000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
2026-05-30T07:06:28.895590000Z 2026/05/30 07:06:28 [RATELIMIT] format("health(warnable=%s): ok")
2026-05-30T07:06:28.919951000Z 2026/05/30 07:06:28 magicsock: derp-26 connected; connGen=1
2026-05-30T07:06:28.953883000Z 2026/05/30 07:06:28 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
2026-05-30T07:06:28.954040000Z 2026/05/30 07:06:28 tstun: peer config: peerConfigTable(nil)
2026-05-30T07:06:28.954253000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
2026-05-30T07:06:28.958844000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/debug
2026-05-30T07:06:28.965134000Z boot: 2026/05/30 07:06:28 Setting healthy true
2026-05-30T07:06:28.965464000Z boot: 2026/05/30 07:06:28 Startup complete, waiting for shutdown signal
2026-05-30T07:06:28.965634000Z boot: 2026/05/30 07:06:28 serve proxy: applying serve config
2026-05-30T07:06:28.965751000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/serve-config
2026-05-30T07:06:28.965815000Z 2026/05/30 07:06:28 [RATELIMIT] format("localapi: [%s] %s")
2026-05-30T07:06:28.966509000Z 2026/05/30 07:06:28 serve: creating a new proxy handler for http://127.0.0.1:8090
2026-05-30T07:06:28.966576000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to true
2026-05-30T07:06:28.966643000Z 2026/05/30 07:06:28 listening on 100.101.121.100:443
2026-05-30T07:06:28.966717000Z 2026/05/30 07:06:28 listening on [fd7a:115c:a1e0::8539:7964]:443
2026-05-30T07:06:29.018076000Z 2026/05/30 07:06:29 [RATELIMIT] format("control: [v\x00JSON]%d%s")
2026-05-30T07:06:29.019112000Z 2026/05/30 07:06:29 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
2026-05-30T07:06:29.019366000Z 2026/05/30 07:06:29 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
2026-05-30T07:06:29.019621000Z 2026/05/30 07:06:29 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
2026-05-30T07:06:34.092575000Z boot: 2026/05/30 07:06:34 Sending SIGTERM to tailscaled
2026-05-30T07:06:34.092934000Z 2026/05/30 07:06:34 tailscaled got signal terminated; shutting down
2026-05-30T07:06:34.093505000Z 2026/05/30 07:06:34 canceling captive portal context
2026-05-30T07:06:34.093981000Z 2026/05/30 07:06:34 control: client.Shutdown ...
2026-05-30T07:06:34.094031000Z 2026/05/30 07:06:34 control: authRoutine: exiting
2026-05-30T07:06:34.094099000Z 2026/05/30 07:06:34 control: updateRoutine: exiting
2026-05-30T07:06:34.094185000Z 2026/05/30 07:06:34 control: mapRoutine: exiting
2026-05-30T07:06:34.094222000Z 2026/05/30 07:06:34 control: Client.Shutdown done.
2026-05-30T07:06:34.094256000Z 2026/05/30 07:06:34 ipnext: work queue shutdown failed: execqueue shut down
2026-05-30T07:06:34.094294000Z 2026/05/30 07:06:34 magicsock: closing connection to derp-26 (conn-close), age 5s
2026-05-30T07:06:34.094764000Z 2026/05/30 07:06:34 magicsock: 0 active derp conns
2026-05-30T07:06:34.094856000Z 2026/05/30 07:06:34 dns: inotify: context canceled
2026-05-30T07:06:34.100381000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=fe80::/64, gw=, outif=3, table=254
2026-05-30T07:06:34.100569000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=fe80::3ddd:47f8:ce97:d69a/128, gw=, outif=3, table=255
2026-05-30T07:06:34.100609000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=ff00::/8, gw=, outif=3, table=255
2026-05-30T07:06:34.102630000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:254 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5210 Table:254 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026-05-30T07:06:34.102818000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:253 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5230 Table:253 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026-05-30T07:06:34.102868000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:0 Protocol:0 Scope:0 Type:7 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5250 Table:0 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026-05-30T07:06:34.102909000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:52 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5270 Table:52 Mark:0 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
2026-05-30T07:06:34.152884000Z 2026/05/30 07:06:34 flushing log.
2026-05-30T07:06:34.153028000Z 2026/05/30 07:06:34 logger closing down
2026-05-30T07:06:34.159966000Z boot: 2026/05/30 07:06:34 tailscaled exited
2026-05-30T07:06:34.435834000Z boot: 2026/05/30 07:06:34 Starting tailscaled
2026-05-30T07:06:34.436076000Z boot: 2026/05/30 07:06:34 Waiting for tailscaled socket at /tmp/tailscaled.sock
2026-05-30T07:06:34.441416000Z TPM: error opening: stat /dev/tpmrm0: no such file or directory
2026-05-30T07:06:34.442028000Z 2026/05/30 07:06:34 logtail started
2026-05-30T07:06:34.442116000Z 2026/05/30 07:06:34 Program starting: v1.98.4-t01c6b9661, Go 1.26.3: []string{"tailscaled", "--socket=/tmp/tailscaled.sock", "--statedir=/var/lib/tailscale"}
2026-05-30T07:06:34.442169000Z 2026/05/30 07:06:34 LogID: 8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b
2026-05-30T07:06:34.442793000Z 2026/05/30 07:06:34 logpolicy: using system state directory "/var/lib/tailscale"
2026-05-30T07:06:34.442868000Z 2026/05/30 07:06:34 dns: [rc=unknown ret=direct]
2026-05-30T07:06:34.442915000Z 2026/05/30 07:06:34 dns: using "direct" mode
2026-05-30T07:06:34.442958000Z 2026/05/30 07:06:34 dns: using *dns.directManager
2026-05-30T07:06:34.443279000Z 2026/05/30 07:06:34 dns: inotify: NewDirWatcher: context canceled
2026-05-30T07:06:34.471599000Z 2026/05/30 07:06:34 wgengine.NewUserspaceEngine(tun "tailscale0") ...
2026-05-30T07:06:34.473975000Z 2026/05/30 07:06:34 dns: [rc=unknown ret=direct]
2026-05-30T07:06:34.474139000Z 2026/05/30 07:06:34 dns: using "direct" mode
2026-05-30T07:06:34.475241000Z 2026/05/30 07:06:34 dns: using *dns.directManager
2026-05-30T07:06:34.475391000Z 2026/05/30 07:06:34 link state: interfaces.State{defaultRoute=eth0 ifs={eth0:[172.16.144.2/20]} v4=true v6=false}
2026-05-30T07:06:34.476113000Z 2026/05/30 07:06:34 router: portUpdate(port=43964, network=udp6)
2026-05-30T07:06:34.476203000Z 2026/05/30 07:06:34 router: using firewall mode pref
2026-05-30T07:06:34.476243000Z 2026/05/30 07:06:34 magicsock: disco key = d:aa46bcc5b2e47bcf
2026-05-30T07:06:34.476281000Z 2026/05/30 07:06:34 Creating WireGuard device...
2026-05-30T07:06:34.476383000Z 2026/05/30 07:06:34 Bringing WireGuard device up...
2026-05-30T07:06:34.476603000Z 2026/05/30 07:06:34 Bringing router up...
2026-05-30T07:06:34.476658000Z 2026/05/30 07:06:34 external route: up
2026-05-30T07:06:34.478601000Z 2026/05/30 07:06:34 router: default choosing iptables
2026-05-30T07:06:34.482743000Z 2026/05/30 07:06:34 router: netfilter running in iptables mode v6 = true, v6filter = true, v6nat = true
2026-05-30T07:06:34.482882000Z 2026/05/30 07:06:34 router: portUpdate(port=43161, network=udp4)
2026-05-30T07:06:34.483752000Z 2026/05/30 07:06:34 Clearing router settings...
2026-05-30T07:06:34.483875000Z 2026/05/30 07:06:34 Starting network monitor...
2026-05-30T07:06:34.483924000Z 2026/05/30 07:06:34 Engine created.
2026-05-30T07:06:34.484723000Z 2026/05/30 07:06:34 pm: using backend prefs for "profile-1a37": Prefs{ra=false dns=true want=true routes=[] statefulFiltering=false nf=on update=check Persist{o=, n=[nnrpm] u="super-secure@gmail.com" ak=-}}
2026-05-30T07:06:34.484865000Z 2026/05/30 07:06:34 monitor: gateway and self IP changed: gw=172.16.144.1 self=172.16.144.2
2026-05-30T07:06:34.485159000Z 2026/05/30 07:06:34 logpolicy: using system state directory "/var/lib/tailscale"
2026-05-30T07:06:34.485206000Z 2026/05/30 07:06:34 linkChange: in state NoState; PAC or proxyConfig changed; updating routes
2026-05-30T07:06:34.486348000Z 2026/05/30 07:06:34 got LocalBackend in 14ms
2026-05-30T07:06:34.486438000Z 2026/05/30 07:06:34 Start
2026-05-30T07:06:34.486528000Z 2026/05/30 07:06:34 ipnext: "conn25": skipping extension
2026-05-30T07:06:34.486575000Z 2026/05/30 07:06:34 ipnext: active extensions: relayserver, taildrop, conn25, portlist, posture, clientupdate
2026-05-30T07:06:34.486700000Z 2026/05/30 07:06:34 load netmap from cache: netmap cache is not available
2026-05-30T07:06:34.487264000Z 2026/05/30 07:06:34 Backend: logs: be:8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b fe:
2026-05-30T07:06:34.487316000Z 2026/05/30 07:06:34 control: client.Login(0)
2026-05-30T07:06:34.487345000Z 2026/05/30 07:06:34 control: doLogin(regen=false, hasUrl=false)
2026-05-30T07:06:34.487405000Z 2026/05/30 07:06:34 health(warnable=warming-up): error: Tailscale is starting. Please wait.
[tailscale-beszel] 2026-05-30T07:06:28.299114000Z boot: 2026/05/30 07:06:28 Starting tailscaled
[tailscale-beszel] 2026-05-30T07:06:28.299544000Z boot: 2026/05/30 07:06:28 Waiting for tailscaled socket at /tmp/tailscaled.sock
[tailscale-beszel] 2026-05-30T07:06:28.305790000Z TPM: error opening: stat /dev/tpmrm0: no such file or directory
[tailscale-beszel] 2026-05-30T07:06:28.306328000Z 2026/05/30 07:06:28 logtail started
[tailscale-beszel] 2026-05-30T07:06:28.306409000Z 2026/05/30 07:06:28 Program starting: v1.98.4-t01c6b9661, Go 1.26.3: []string{"tailscaled", "--socket=/tmp/tailscaled.sock", "--statedir=/var/lib/tailscale"}
[tailscale-beszel] 2026-05-30T07:06:28.306453000Z 2026/05/30 07:06:28 LogID: 8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b
[tailscale-beszel] 2026-05-30T07:06:28.306558000Z 2026/05/30 07:06:28 logpolicy: using system state directory "/var/lib/tailscale"
[tailscale-beszel] 2026-05-30T07:06:28.306610000Z 2026/05/30 07:06:28 dns: [rc=unknown ret=direct]
[tailscale-beszel] 2026-05-30T07:06:28.306656000Z 2026/05/30 07:06:28 dns: using "direct" mode
[tailscale-beszel] 2026-05-30T07:06:28.306690000Z 2026/05/30 07:06:28 dns: using *dns.directManager
[tailscale-beszel] 2026-05-30T07:06:28.307032000Z 2026/05/30 07:06:28 dns: inotify: NewDirWatcher: context canceled
[tailscale-beszel] 2026-05-30T07:06:28.330921000Z 2026/05/30 07:06:28 wgengine.NewUserspaceEngine(tun "tailscale0") ...
[tailscale-beszel] 2026-05-30T07:06:28.333207000Z 2026/05/30 07:06:28 dns: [rc=unknown ret=direct]
[tailscale-beszel] 2026-05-30T07:06:28.333391000Z 2026/05/30 07:06:28 dns: using "direct" mode
[tailscale-beszel] 2026-05-30T07:06:28.335659000Z 2026/05/30 07:06:28 dns: using *dns.directManager
[tailscale-beszel] 2026-05-30T07:06:28.336173000Z 2026/05/30 07:06:28 link state: interfaces.State{defaultRoute=eth0 ifs={eth0:[172.16.144.2/20]} v4=true v6=false}
[tailscale-beszel] 2026-05-30T07:06:28.336235000Z 2026/05/30 07:06:28 router: portUpdate(port=37537, network=udp6)
[tailscale-beszel] 2026-05-30T07:06:28.336286000Z 2026/05/30 07:06:28 router: using firewall mode pref
[tailscale-beszel] 2026-05-30T07:06:28.336340000Z 2026/05/30 07:06:28 magicsock: disco key = d:6b77e4a16d5f08c7
[tailscale-beszel] 2026-05-30T07:06:28.336433000Z 2026/05/30 07:06:28 Creating WireGuard device...
[tailscale-beszel] 2026-05-30T07:06:28.336658000Z 2026/05/30 07:06:28 Bringing WireGuard device up...
[tailscale-beszel] 2026-05-30T07:06:28.337671000Z 2026/05/30 07:06:28 external route: up
[tailscale-beszel] 2026-05-30T07:06:28.337835000Z 2026/05/30 07:06:28 Bringing router up...
[tailscale-beszel] 2026-05-30T07:06:28.339217000Z 2026/05/30 07:06:28 router: default choosing iptables
[tailscale-beszel] 2026-05-30T07:06:28.342391000Z 2026/05/30 07:06:28 router: netfilter running in iptables mode v6 = true, v6filter = true, v6nat = true
[tailscale-beszel] 2026-05-30T07:06:28.342589000Z 2026/05/30 07:06:28 router: portUpdate(port=54374, network=udp4)
[tailscale-beszel] 2026-05-30T07:06:28.343087000Z 2026/05/30 07:06:28 Clearing router settings...
[tailscale-beszel] 2026-05-30T07:06:28.343188000Z 2026/05/30 07:06:28 Starting network monitor...
[tailscale-beszel] 2026-05-30T07:06:28.343250000Z 2026/05/30 07:06:28 Engine created.
[tailscale-beszel] 2026-05-30T07:06:28.343824000Z 2026/05/30 07:06:28 pm: using backend prefs for "profile-1a37": Prefs{ra=false dns=true want=true routes=[] statefulFiltering=false nf=on update=check Persist{o=, n=[nnrpm] u="super-secure@gmail.com" ak=-}}
[tailscale-beszel] 2026-05-30T07:06:28.344053000Z 2026/05/30 07:06:28 logpolicy: using system state directory "/var/lib/tailscale"
[tailscale-beszel] 2026-05-30T07:06:28.344182000Z 2026/05/30 07:06:28 monitor: gateway and self IP changed: gw=172.16.144.1 self=172.16.144.2
[tailscale-beszel] 2026-05-30T07:06:28.344918000Z 2026/05/30 07:06:28 linkChange: in state NoState; PAC or proxyConfig changed; updating routes
[tailscale-beszel] 2026-05-30T07:06:28.346200000Z 2026/05/30 07:06:28 got LocalBackend in 14ms
[tailscale-beszel] 2026-05-30T07:06:28.346340000Z 2026/05/30 07:06:28 Start
[tailscale-beszel] 2026-05-30T07:06:28.346387000Z 2026/05/30 07:06:28 ipnext: "conn25": skipping extension
[tailscale-beszel] 2026-05-30T07:06:28.346432000Z 2026/05/30 07:06:28 ipnext: active extensions: portlist, posture, clientupdate, relayserver, taildrop, conn25
[tailscale-beszel] 2026-05-30T07:06:28.346469000Z 2026/05/30 07:06:28 load netmap from cache: netmap cache is not available
[tailscale-beszel] 2026-05-30T07:06:28.346518000Z 2026/05/30 07:06:28 Backend: logs: be:8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b fe:
[tailscale-beszel] 2026-05-30T07:06:28.346557000Z 2026/05/30 07:06:28 control: client.Login(0)
[tailscale-beszel] 2026-05-30T07:06:28.346614000Z 2026/05/30 07:06:28 control: doLogin(regen=false, hasUrl=false)
[tailscale-beszel] 2026-05-30T07:06:28.346819000Z 2026/05/30 07:06:28 health(warnable=warming-up): error: Tailscale is starting. Please wait.
[tailscale-beszel] 2026-05-30T07:06:28.399954000Z boot: 2026/05/30 07:06:28 Running healthcheck endpoint at 127.0.0.1:41234/healthz
[tailscale-beszel] 2026-05-30T07:06:28.410706000Z boot: 2026/05/30 07:06:28 tailscaled in state "NoState", waiting
[tailscale-beszel] 2026-05-30T07:06:28.440352000Z 2026/05/30 07:06:28 control: control server key from https://controlplane.tailscale.com: ts2021=[fSeS+], legacy=[nlFWp]
[tailscale-beszel] 2026-05-30T07:06:28.440568000Z 2026/05/30 07:06:28 control: RegisterReq: onode= node=[nnrpm] fup=false nks=false
[tailscale-beszel] 2026-05-30T07:06:28.516155000Z 2026/05/30 07:06:28 control: RegisterReq: got response; nodeKeyExpired=false, machineAuthorized=true; authURL=false
[tailscale-beszel] 2026-05-30T07:06:28.584326000Z 2026/05/30 07:06:28 health(warnable=not-in-map-poll): ok
[tailscale-beszel] 2026-05-30T07:06:28.584562000Z 2026/05/30 07:06:28 control: netmap: got new dial plan from control
[tailscale-beszel] 2026-05-30T07:06:28.587493000Z 2026/05/30 07:06:28 active login: super-secure@gmail.com
[tailscale-beszel] 2026-05-30T07:06:28.587638000Z 2026/05/30 07:06:28 serve: creating a new proxy handler for http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:28.587724000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to true
[tailscale-beszel] 2026-05-30T07:06:28.587767000Z 2026/05/30 07:06:28 netmap: suggested exit node: no preferred DERP, try again later
[tailscale-beszel] 2026-05-30T07:06:28.587804000Z 2026/05/30 07:06:28 Switching ipn state NoState -> Starting (WantRunning=true, nm=true)
[tailscale-beszel] 2026-05-30T07:06:28.587850000Z 2026/05/30 07:06:28 magicsock: SetPrivateKey called (init)
[tailscale-beszel] 2026-05-30T07:06:28.587883000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
[tailscale-beszel] 2026-05-30T07:06:28.587975000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring router
[tailscale-beszel] 2026-05-30T07:06:28.620548000Z boot: 2026/05/30 07:06:28 tailscaled in state "Starting", waiting
[tailscale-beszel] 2026-05-30T07:06:28.660243000Z 2026/05/30 07:06:28 router: enabling connmark-based rp_filter workaround
[tailscale-beszel] 2026-05-30T07:06:28.667606000Z 2026/05/30 07:06:28 router: warning: failed to enable src_valid_mark: sysctl(net.ipv4.conf.all.src_valid_mark=1): open /proc/sys/net/ipv4/conf/all/src_valid_mark: read-only file system
[tailscale-beszel] 2026-05-30T07:06:28.669955000Z 2026/05/30 07:06:28 wgengine: Reconfig: user dialer
[tailscale-beszel] 2026-05-30T07:06:28.670118000Z 2026/05/30 07:06:28 tsdial: bart table size: 68
[tailscale-beszel] 2026-05-30T07:06:28.670166000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring DNS
[tailscale-beszel] 2026-05-30T07:06:28.670240000Z 2026/05/30 07:06:28 dns: Set: {DefaultResolvers:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] Routes:{super-secure.ts.net.:[] ts.net.:[199.247.155.53 2620:111:8007::53]}+65arpa SearchDomains:[super-secure.ts.net.] Hosts:66}
[tailscale-beszel] 2026-05-30T07:06:28.670281000Z 2026/05/30 07:06:28 dns: Resolvercfg: {Routes:{.:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] ts.net.:[199.247.155.53 2620:111:8007::53]} Hosts:66 LocalDomains:[super-secure.ts.net.]+65arpa}
[tailscale-beszel] 2026-05-30T07:06:28.670307000Z 2026/05/30 07:06:28 dns: OScfg: {Nameservers:[100.100.100.100 fd7a:115c:a1e0::53] SearchDomains:[super-secure.ts.net.] }
[tailscale-beszel] 2026-05-30T07:06:28.670608000Z 2026/05/30 07:06:28 rename of "/etc/resolv.conf" to "/etc/resolv.pre-tailscale-backup.conf" failed (rename /etc/resolv.conf /etc/resolv.pre-tailscale-backup.conf: device or resource busy), falling back to copy+delete
[tailscale-beszel] 2026-05-30T07:06:28.671576000Z 2026/05/30 07:06:28 peerapi: serving on http://100.101.121.100:46887
[tailscale-beszel] 2026-05-30T07:06:28.671663000Z 2026/05/30 07:06:28 peerapi: serving on http://[fd7a:115c:a1e0::8539:7964]:57587
[tailscale-beszel] 2026-05-30T07:06:28.690342000Z 2026/05/30 07:06:28 listening on [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:28.748280000Z 2026/05/30 07:06:28 netmap: suggested exit node: no preferred DERP, try again later
[tailscale-beszel] 2026-05-30T07:06:28.748362000Z 2026/05/30 07:06:28 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
[tailscale-beszel] 2026-05-30T07:06:28.748421000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
[tailscale-beszel] 2026-05-30T07:06:28.748917000Z 2026/05/30 07:06:28 listening on 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:28.838445000Z 2026/05/30 07:06:28 magicsock: home DERP changing from derp-0 [0ms] to derp-26 [29ms] (forced=false)
[tailscale-beszel] 2026-05-30T07:06:28.838603000Z 2026/05/30 07:06:28 magicsock: home is now derp-26 (nue)
[tailscale-beszel] 2026-05-30T07:06:28.838657000Z 2026/05/30 07:06:28 magicsock: adding connection to derp-26 for home-keep-alive
[tailscale-beszel] 2026-05-30T07:06:28.838701000Z 2026/05/30 07:06:28 magicsock: 1 active derp conns: derp-26=cr0s,wr0s
[tailscale-beszel] 2026-05-30T07:06:28.838743000Z 2026/05/30 07:06:28 control: NetInfo: NetInfo{varies=false ipv6=false ipv6os=true udp=true icmpv4=false derp=#26 portmap= link="" firewallmode="ipt-default"}
[tailscale-beszel] 2026-05-30T07:06:28.840458000Z 2026/05/30 07:06:28 writing netmap to disk cache
[tailscale-beszel] 2026-05-30T07:06:28.840594000Z 2026/05/30 07:06:28 derphttp.Client.Connect: connecting to derp-26 (nue)
[tailscale-beszel] 2026-05-30T07:06:28.840685000Z 2026/05/30 07:06:28 magicsock: endpoints changed: 77.20.152.2:54374 (stun), 172.16.144.2:54374 (local)
[tailscale-beszel] 2026-05-30T07:06:28.848024000Z 2026/05/30 07:06:28 health(warnable=warming-up): ok
[tailscale-beszel] 2026-05-30T07:06:28.848167000Z 2026/05/30 07:06:28 Switching ipn state Starting -> Running (WantRunning=true, nm=true)
[tailscale-beszel] 2026-05-30T07:06:28.848231000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:28.848276000Z boot: 2026/05/30 07:06:28 Running 'tailscale set'
[tailscale-beszel] 2026-05-30T07:06:28.860328000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/check-prefs
[tailscale-beszel] 2026-05-30T07:06:28.860922000Z 2026/05/30 07:06:28 localapi: [PATCH] /localapi/v0/prefs
[tailscale-beszel] 2026-05-30T07:06:28.861719000Z boot: 2026/05/30 07:06:28 serve proxy: unsetting previous config
[tailscale-beszel] 2026-05-30T07:06:28.862605000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/serve-config
[tailscale-beszel] 2026-05-30T07:06:28.862713000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:28.862951000Z 2026/05/30 07:06:28 serve: closing idle connections to http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:28.863032000Z 2026/05/30 07:06:28 closing listener 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:28.863084000Z 2026/05/30 07:06:28 closing listener [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:28.863135000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to false
[tailscale-beszel] 2026-05-30T07:06:28.895444000Z 2026/05/30 07:06:28 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:28.895590000Z 2026/05/30 07:06:28 [RATELIMIT] format("health(warnable=%s): ok")
[tailscale-beszel] 2026-05-30T07:06:28.919951000Z 2026/05/30 07:06:28 magicsock: derp-26 connected; connGen=1
[tailscale-beszel] 2026-05-30T07:06:28.953883000Z 2026/05/30 07:06:28 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
[tailscale-beszel] 2026-05-30T07:06:28.954040000Z 2026/05/30 07:06:28 tstun: peer config: peerConfigTable(nil)
[tailscale-beszel] 2026-05-30T07:06:28.954253000Z 2026/05/30 07:06:28 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
[tailscale-beszel] 2026-05-30T07:06:28.958844000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/debug
[tailscale-beszel] 2026-05-30T07:06:28.965134000Z boot: 2026/05/30 07:06:28 Setting healthy true
[tailscale-beszel] 2026-05-30T07:06:28.965464000Z boot: 2026/05/30 07:06:28 Startup complete, waiting for shutdown signal
[tailscale-beszel] 2026-05-30T07:06:28.965634000Z boot: 2026/05/30 07:06:28 serve proxy: applying serve config
[tailscale-beszel] 2026-05-30T07:06:28.965751000Z 2026/05/30 07:06:28 localapi: [POST] /localapi/v0/serve-config
[tailscale-beszel] 2026-05-30T07:06:28.965815000Z 2026/05/30 07:06:28 [RATELIMIT] format("localapi: [%s] %s")
[tailscale-beszel] 2026-05-30T07:06:28.966509000Z 2026/05/30 07:06:28 serve: creating a new proxy handler for http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:28.966576000Z 2026/05/30 07:06:28 Hostinfo.WireIngress changed to true
[tailscale-beszel] 2026-05-30T07:06:28.966643000Z 2026/05/30 07:06:28 listening on 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:28.966717000Z 2026/05/30 07:06:28 listening on [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:29.018076000Z 2026/05/30 07:06:29 [RATELIMIT] format("control: [v\x00JSON]%d%s")
[tailscale-beszel] 2026-05-30T07:06:29.019112000Z 2026/05/30 07:06:29 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
[tailscale-beszel] 2026-05-30T07:06:29.019366000Z 2026/05/30 07:06:29 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
[tailscale-beszel] 2026-05-30T07:06:29.019621000Z 2026/05/30 07:06:29 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
[tailscale-beszel] 2026-05-30T07:06:34.092575000Z boot: 2026/05/30 07:06:34 Sending SIGTERM to tailscaled
[tailscale-beszel] 2026-05-30T07:06:34.092934000Z 2026/05/30 07:06:34 tailscaled got signal terminated; shutting down
[tailscale-beszel] 2026-05-30T07:06:34.093505000Z 2026/05/30 07:06:34 canceling captive portal context
[tailscale-beszel] 2026-05-30T07:06:34.093981000Z 2026/05/30 07:06:34 control: client.Shutdown ...
[tailscale-beszel] 2026-05-30T07:06:34.094031000Z 2026/05/30 07:06:34 control: authRoutine: exiting
[tailscale-beszel] 2026-05-30T07:06:34.094099000Z 2026/05/30 07:06:34 control: updateRoutine: exiting
[tailscale-beszel] 2026-05-30T07:06:34.094185000Z 2026/05/30 07:06:34 control: mapRoutine: exiting
[tailscale-beszel] 2026-05-30T07:06:34.094222000Z 2026/05/30 07:06:34 control: Client.Shutdown done.
[tailscale-beszel] 2026-05-30T07:06:34.094256000Z 2026/05/30 07:06:34 ipnext: work queue shutdown failed: execqueue shut down
[tailscale-beszel] 2026-05-30T07:06:34.094294000Z 2026/05/30 07:06:34 magicsock: closing connection to derp-26 (conn-close), age 5s
[tailscale-beszel] 2026-05-30T07:06:34.094764000Z 2026/05/30 07:06:34 magicsock: 0 active derp conns
[tailscale-beszel] 2026-05-30T07:06:34.094856000Z 2026/05/30 07:06:34 dns: inotify: context canceled
[tailscale-beszel] 2026-05-30T07:06:34.100381000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=fe80::/64, gw=, outif=3, table=254
[tailscale-beszel] 2026-05-30T07:06:34.100569000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=fe80::3ddd:47f8:ce97:d69a/128, gw=, outif=3, table=255
[tailscale-beszel] 2026-05-30T07:06:34.100609000Z 2026/05/30 07:06:34 monitor: RTM_DELROUTE: src=, dst=ff00::/8, gw=, outif=3, table=255
[tailscale-beszel] 2026-05-30T07:06:34.102630000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:254 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5210 Table:254 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
[tailscale-beszel] 2026-05-30T07:06:34.102818000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:253 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5230 Table:253 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
[tailscale-beszel] 2026-05-30T07:06:34.102868000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:0 Protocol:0 Scope:0 Type:7 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5250 Table:0 Mark:16711680 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
[tailscale-beszel] 2026-05-30T07:06:34.102909000Z 2026/05/30 07:06:34 monitor: ip rule deleted: {Family:2 DstLength:0 SrcLength:0 Tos:0 Table:52 Protocol:0 Scope:0 Type:1 Flags:0 Attributes:{Dst:<nil> Src:<nil> Gateway:<nil> OutIface:0 Priority:5270 Table:52 Mark:0 Pref:<nil> Expires:<nil> Metrics:<nil> Multipath:[]}}
[tailscale-beszel] 2026-05-30T07:06:34.152884000Z 2026/05/30 07:06:34 flushing log.
[tailscale-beszel] 2026-05-30T07:06:34.153028000Z 2026/05/30 07:06:34 logger closing down
[tailscale-beszel] 2026-05-30T07:06:34.159966000Z boot: 2026/05/30 07:06:34 tailscaled exited
[tailscale-beszel] 2026-05-30T07:06:34.435834000Z boot: 2026/05/30 07:06:34 Starting tailscaled
[tailscale-beszel] 2026-05-30T07:06:34.436076000Z boot: 2026/05/30 07:06:34 Waiting for tailscaled socket at /tmp/tailscaled.sock
[tailscale-beszel] 2026-05-30T07:06:34.441416000Z TPM: error opening: stat /dev/tpmrm0: no such file or directory
[tailscale-beszel] 2026-05-30T07:06:34.442028000Z 2026/05/30 07:06:34 logtail started
[tailscale-beszel] 2026-05-30T07:06:34.442116000Z 2026/05/30 07:06:34 Program starting: v1.98.4-t01c6b9661, Go 1.26.3: []string{"tailscaled", "--socket=/tmp/tailscaled.sock", "--statedir=/var/lib/tailscale"}
[tailscale-beszel] 2026-05-30T07:06:34.442169000Z 2026/05/30 07:06:34 LogID: 8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b
[tailscale-beszel] 2026-05-30T07:06:34.442793000Z 2026/05/30 07:06:34 logpolicy: using system state directory "/var/lib/tailscale"
[tailscale-beszel] 2026-05-30T07:06:34.442868000Z 2026/05/30 07:06:34 dns: [rc=unknown ret=direct]
[tailscale-beszel] 2026-05-30T07:06:34.442915000Z 2026/05/30 07:06:34 dns: using "direct" mode
[tailscale-beszel] 2026-05-30T07:06:34.442958000Z 2026/05/30 07:06:34 dns: using *dns.directManager
[tailscale-beszel] 2026-05-30T07:06:34.443279000Z 2026/05/30 07:06:34 dns: inotify: NewDirWatcher: context canceled
[tailscale-beszel] 2026-05-30T07:06:34.471599000Z 2026/05/30 07:06:34 wgengine.NewUserspaceEngine(tun "tailscale0") ...
[tailscale-beszel] 2026-05-30T07:06:34.473975000Z 2026/05/30 07:06:34 dns: [rc=unknown ret=direct]
[tailscale-beszel] 2026-05-30T07:06:34.474139000Z 2026/05/30 07:06:34 dns: using "direct" mode
[tailscale-beszel] 2026-05-30T07:06:34.475241000Z 2026/05/30 07:06:34 dns: using *dns.directManager
[tailscale-beszel] 2026-05-30T07:06:34.475391000Z 2026/05/30 07:06:34 link state: interfaces.State{defaultRoute=eth0 ifs={eth0:[172.16.144.2/20]} v4=true v6=false}
[tailscale-beszel] 2026-05-30T07:06:34.476113000Z 2026/05/30 07:06:34 router: portUpdate(port=43964, network=udp6)
[tailscale-beszel] 2026-05-30T07:06:34.476203000Z 2026/05/30 07:06:34 router: using firewall mode pref
[tailscale-beszel] 2026-05-30T07:06:34.476243000Z 2026/05/30 07:06:34 magicsock: disco key = d:aa46bcc5b2e47bcf
[tailscale-beszel] 2026-05-30T07:06:34.476281000Z 2026/05/30 07:06:34 Creating WireGuard device...
[tailscale-beszel] 2026-05-30T07:06:34.476383000Z 2026/05/30 07:06:34 Bringing WireGuard device up...
[tailscale-beszel] 2026-05-30T07:06:34.476603000Z 2026/05/30 07:06:34 Bringing router up...
[tailscale-beszel] 2026-05-30T07:06:34.476658000Z 2026/05/30 07:06:34 external route: up
[tailscale-beszel] 2026-05-30T07:06:34.478601000Z 2026/05/30 07:06:34 router: default choosing iptables
[tailscale-beszel] 2026-05-30T07:06:34.482743000Z 2026/05/30 07:06:34 router: netfilter running in iptables mode v6 = true, v6filter = true, v6nat = true
[tailscale-beszel] 2026-05-30T07:06:34.482882000Z 2026/05/30 07:06:34 router: portUpdate(port=43161, network=udp4)
[tailscale-beszel] 2026-05-30T07:06:34.483752000Z 2026/05/30 07:06:34 Clearing router settings...
[tailscale-beszel] 2026-05-30T07:06:34.483875000Z 2026/05/30 07:06:34 Starting network monitor...
[tailscale-beszel] 2026-05-30T07:06:34.483924000Z 2026/05/30 07:06:34 Engine created.
[tailscale-beszel] 2026-05-30T07:06:34.484723000Z 2026/05/30 07:06:34 pm: using backend prefs for "profile-1a37": Prefs{ra=false dns=true want=true routes=[] statefulFiltering=false nf=on update=check Persist{o=, n=[nnrpm] u="super-secure@gmail.com" ak=-}}
[tailscale-beszel] 2026-05-30T07:06:34.484865000Z 2026/05/30 07:06:34 monitor: gateway and self IP changed: gw=172.16.144.1 self=172.16.144.2
[tailscale-beszel] 2026-05-30T07:06:34.485159000Z 2026/05/30 07:06:34 logpolicy: using system state directory "/var/lib/tailscale"
[tailscale-beszel] 2026-05-30T07:06:34.485206000Z 2026/05/30 07:06:34 linkChange: in state NoState; PAC or proxyConfig changed; updating routes
[tailscale-beszel] 2026-05-30T07:06:34.486348000Z 2026/05/30 07:06:34 got LocalBackend in 14ms
[tailscale-beszel] 2026-05-30T07:06:34.486438000Z 2026/05/30 07:06:34 Start
[tailscale-beszel] 2026-05-30T07:06:34.486528000Z 2026/05/30 07:06:34 ipnext: "conn25": skipping extension
[tailscale-beszel] 2026-05-30T07:06:34.486575000Z 2026/05/30 07:06:34 ipnext: active extensions: relayserver, taildrop, conn25, portlist, posture, clientupdate
[tailscale-beszel] 2026-05-30T07:06:34.486700000Z 2026/05/30 07:06:34 load netmap from cache: netmap cache is not available
[tailscale-beszel] 2026-05-30T07:06:34.487264000Z 2026/05/30 07:06:34 Backend: logs: be:8770e618164e2c9946923cf4ef0dee91bc30350898354a63d8c3eed5ac3f1a5b fe:
[tailscale-beszel] 2026-05-30T07:06:34.487316000Z 2026/05/30 07:06:34 control: client.Login(0)
[tailscale-beszel] 2026-05-30T07:06:34.487345000Z 2026/05/30 07:06:34 control: doLogin(regen=false, hasUrl=false)
[tailscale-beszel] 2026-05-30T07:06:34.487405000Z 2026/05/30 07:06:34 health(warnable=warming-up): error: Tailscale is starting. Please wait.
[tailscale-beszel] 2026-05-30T07:06:34.536429000Z boot: 2026/05/30 07:06:34 Running healthcheck endpoint at 127.0.0.1:41234/healthz
[tailscale-beszel] 2026-05-30T07:06:34.546857000Z boot: 2026/05/30 07:06:34 [warning] failed to symlink socket: file exists
[tailscale-beszel] 2026-05-30T07:06:34.547007000Z To interact with the Tailscale CLI please use `tailscale --socket="/tmp/tailscaled.sock"`
[tailscale-beszel] 2026-05-30T07:06:34.548285000Z boot: 2026/05/30 07:06:34 tailscaled in state "NoState", waiting
[tailscale-beszel] 2026-05-30T07:06:34.848094000Z 2026/05/30 07:06:34 control: control server key from https://controlplane.tailscale.com: ts2021=[fSeS+], legacy=[nlFWp]
[tailscale-beszel] 2026-05-30T07:06:34.848266000Z 2026/05/30 07:06:34 control: RegisterReq: onode= node=[nnrpm] fup=false nks=false
[tailscale-beszel] 2026-05-30T07:06:34.912367000Z 2026/05/30 07:06:34 control: RegisterReq: got response; nodeKeyExpired=false, machineAuthorized=true; authURL=false
[tailscale-beszel] 2026-05-30T07:06:34.977808000Z 2026/05/30 07:06:34 health(warnable=not-in-map-poll): ok
[tailscale-beszel] 2026-05-30T07:06:34.977849000Z 2026/05/30 07:06:34 control: netmap: got new dial plan from control
[tailscale-beszel] 2026-05-30T07:06:34.977889000Z 2026/05/30 07:06:34 active login: super-secure@gmail.com
[tailscale-beszel] 2026-05-30T07:06:34.977925000Z 2026/05/30 07:06:34 serve: creating a new proxy handler for http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:34.977981000Z 2026/05/30 07:06:34 Hostinfo.WireIngress changed to true
[tailscale-beszel] 2026-05-30T07:06:34.978149000Z 2026/05/30 07:06:34 netmap: suggested exit node: no preferred DERP, try again later
[tailscale-beszel] 2026-05-30T07:06:34.978186000Z 2026/05/30 07:06:34 Switching ipn state NoState -> Starting (WantRunning=true, nm=true)
[tailscale-beszel] 2026-05-30T07:06:34.978460000Z 2026/05/30 07:06:34 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
[tailscale-beszel] 2026-05-30T07:06:34.978519000Z 2026/05/30 07:06:34 magicsock: SetPrivateKey called (init)
[tailscale-beszel] 2026-05-30T07:06:34.978561000Z 2026/05/30 07:06:34 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
[tailscale-beszel] 2026-05-30T07:06:34.978594000Z 2026/05/30 07:06:34 wgengine: Reconfig: configuring router
[tailscale-beszel] 2026-05-30T07:06:35.007855000Z boot: 2026/05/30 07:06:35 tailscaled in state "Starting", waiting
[tailscale-beszel] 2026-05-30T07:06:35.057125000Z 2026/05/30 07:06:35 router: enabling connmark-based rp_filter workaround
[tailscale-beszel] 2026-05-30T07:06:35.064418000Z 2026/05/30 07:06:35 router: warning: failed to enable src_valid_mark: sysctl(net.ipv4.conf.all.src_valid_mark=1): open /proc/sys/net/ipv4/conf/all/src_valid_mark: read-only file system
[tailscale-beszel] 2026-05-30T07:06:35.066490000Z 2026/05/30 07:06:35 wgengine: Reconfig: user dialer
[tailscale-beszel] 2026-05-30T07:06:35.066617000Z 2026/05/30 07:06:35 tsdial: bart table size: 68
[tailscale-beszel] 2026-05-30T07:06:35.066666000Z 2026/05/30 07:06:35 wgengine: Reconfig: configuring DNS
[tailscale-beszel] 2026-05-30T07:06:35.066900000Z 2026/05/30 07:06:35 dns: Set: {DefaultResolvers:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] Routes:{super-secure.ts.net.:[] ts.net.:[199.247.155.53 2620:111:8007::53]}+65arpa SearchDomains:[super-secure.ts.net.] Hosts:66}
[tailscale-beszel] 2026-05-30T07:06:35.066973000Z 2026/05/30 07:06:35 dns: Resolvercfg: {Routes:{.:[100.104.100.29 1.1.1.1 1.0.0.1 2606:4700:4700::1111 2606:4700:4700::1001] ts.net.:[199.247.155.53 2620:111:8007::53]} Hosts:66 LocalDomains:[super-secure.ts.net.]+65arpa}
[tailscale-beszel] 2026-05-30T07:06:35.067024000Z 2026/05/30 07:06:35 dns: OScfg: {Nameservers:[100.100.100.100 fd7a:115c:a1e0::53] SearchDomains:[super-secure.ts.net.] }
[tailscale-beszel] 2026-05-30T07:06:35.067056000Z 2026/05/30 07:06:35 rename of "/etc/resolv.conf" to "/etc/resolv.pre-tailscale-backup.conf" failed (rename /etc/resolv.conf /etc/resolv.pre-tailscale-backup.conf: device or resource busy), falling back to copy+delete
[tailscale-beszel] 2026-05-30T07:06:35.067536000Z 2026/05/30 07:06:35 peerapi: serving on http://100.101.121.100:46887
[tailscale-beszel] 2026-05-30T07:06:35.067607000Z 2026/05/30 07:06:35 peerapi: serving on http://[fd7a:115c:a1e0::8539:7964]:57587
[tailscale-beszel] 2026-05-30T07:06:35.069554000Z 2026/05/30 07:06:35 netmap: suggested exit node: no preferred DERP, try again later
[tailscale-beszel] 2026-05-30T07:06:35.069823000Z 2026/05/30 07:06:35 tstun: peer config: peerConfigTable(nil)
[tailscale-beszel] 2026-05-30T07:06:35.070041000Z 2026/05/30 07:06:35 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
[tailscale-beszel] 2026-05-30T07:06:35.139198000Z 2026/05/30 07:06:35 listening on [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:35.143809000Z 2026/05/30 07:06:35 netmap: suggested exit node: no preferred DERP, try again later
[tailscale-beszel] 2026-05-30T07:06:35.144542000Z 2026/05/30 07:06:35 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
[tailscale-beszel] 2026-05-30T07:06:35.144589000Z 2026/05/30 07:06:35 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
[tailscale-beszel] 2026-05-30T07:06:35.157284000Z 2026/05/30 07:06:35 listening on 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:35.213197000Z 2026/05/30 07:06:35 magicsock: home DERP changing from derp-0 [0ms] to derp-4 [34ms] (forced=false)
[tailscale-beszel] 2026-05-30T07:06:35.213332000Z 2026/05/30 07:06:35 magicsock: home is now derp-4 (fra)
[tailscale-beszel] 2026-05-30T07:06:35.213379000Z 2026/05/30 07:06:35 magicsock: adding connection to derp-4 for home-keep-alive
[tailscale-beszel] 2026-05-30T07:06:35.213421000Z 2026/05/30 07:06:35 writing netmap to disk cache
[tailscale-beszel] 2026-05-30T07:06:35.213467000Z 2026/05/30 07:06:35 magicsock: 1 active derp conns: derp-4=cr0s,wr0s
[tailscale-beszel] 2026-05-30T07:06:35.213544000Z 2026/05/30 07:06:35 derphttp.Client.Connect: connecting to derp-4 (fra)
[tailscale-beszel] 2026-05-30T07:06:35.213613000Z 2026/05/30 07:06:35 magicsock: endpoints changed: 77.20.152.2:43161 (stun), 172.16.144.2:43161 (local)
[tailscale-beszel] 2026-05-30T07:06:35.223236000Z 2026/05/30 07:06:35 control: NetInfo: NetInfo{varies=false ipv6=false ipv6os=true udp=true icmpv4=false derp=#4 portmap= link="" firewallmode="ipt-default"}
[tailscale-beszel] 2026-05-30T07:06:35.223363000Z 2026/05/30 07:06:35 Switching ipn state Starting -> Running (WantRunning=true, nm=true)
[tailscale-beszel] 2026-05-30T07:06:35.223404000Z 2026/05/30 07:06:35 health(warnable=warming-up): ok
[tailscale-beszel] 2026-05-30T07:06:35.223448000Z 2026/05/30 07:06:35 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:35.223516000Z boot: 2026/05/30 07:06:35 Running 'tailscale set'
[tailscale-beszel] 2026-05-30T07:06:35.235932000Z 2026/05/30 07:06:35 localapi: [POST] /localapi/v0/check-prefs
[tailscale-beszel] 2026-05-30T07:06:35.236095000Z 2026/05/30 07:06:35 localapi: [PATCH] /localapi/v0/prefs
[tailscale-beszel] 2026-05-30T07:06:35.236960000Z boot: 2026/05/30 07:06:35 serve proxy: unsetting previous config
[tailscale-beszel] 2026-05-30T07:06:35.237404000Z 2026/05/30 07:06:35 localapi: [POST] /localapi/v0/serve-config
[tailscale-beszel] 2026-05-30T07:06:35.238175000Z 2026/05/30 07:06:35 serve: closing idle connections to http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:35.238268000Z 2026/05/30 07:06:35 closing listener 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:35.238315000Z 2026/05/30 07:06:35 closing listener [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:35.238361000Z 2026/05/30 07:06:35 Hostinfo.WireIngress changed to false
[tailscale-beszel] 2026-05-30T07:06:35.250963000Z 2026/05/30 07:06:35 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:35.261322000Z 2026/05/30 07:06:35 health(warnable=no-derp-connection): ok
[tailscale-beszel] 2026-05-30T07:06:35.261438000Z 2026/05/30 07:06:35 [RATELIMIT] format("health(warnable=%s): ok")
[tailscale-beszel] 2026-05-30T07:06:35.281129000Z 2026/05/30 07:06:35 magicsock: derp-4 connected; connGen=1
[tailscale-beszel] 2026-05-30T07:06:35.303630000Z 2026/05/30 07:06:35 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
[tailscale-beszel] 2026-05-30T07:06:35.303881000Z 2026/05/30 07:06:35 tstun: peer config: peerConfigTable(nil)
[tailscale-beszel] 2026-05-30T07:06:35.304114000Z 2026/05/30 07:06:35 wgengine: Reconfig: configuring userspace WireGuard config (with 65 peers)
[tailscale-beszel] 2026-05-30T07:06:35.308153000Z 2026/05/30 07:06:35 localapi: [POST] /localapi/v0/debug
[tailscale-beszel] 2026-05-30T07:06:35.312657000Z boot: 2026/05/30 07:06:35 Setting healthy true
[tailscale-beszel] 2026-05-30T07:06:35.313209000Z boot: 2026/05/30 07:06:35 Startup complete, waiting for shutdown signal
[tailscale-beszel] 2026-05-30T07:06:35.313299000Z boot: 2026/05/30 07:06:35 serve proxy: applying serve config
[tailscale-beszel] 2026-05-30T07:06:35.313351000Z 2026/05/30 07:06:35 localapi: [POST] /localapi/v0/serve-config
[tailscale-beszel] 2026-05-30T07:06:35.313391000Z 2026/05/30 07:06:35 [RATELIMIT] format("localapi: [%s] %s")
[tailscale-beszel] 2026-05-30T07:06:35.314297000Z 2026/05/30 07:06:35 serve: creating a new proxy handler for http://127.0.0.1:8090
[tailscale-beszel] 2026-05-30T07:06:35.314468000Z 2026/05/30 07:06:35 Hostinfo.WireIngress changed to true
[tailscale-beszel] 2026-05-30T07:06:35.314608000Z 2026/05/30 07:06:35 listening on [fd7a:115c:a1e0::8539:7964]:443
[tailscale-beszel] 2026-05-30T07:06:35.314652000Z 2026/05/30 07:06:35 listening on 100.101.121.100:443
[tailscale-beszel] 2026-05-30T07:06:35.344328000Z 2026/05/30 07:06:35 [RATELIMIT] format("control: [v\x00JSON]%d%s")
[tailscale-beszel] 2026-05-30T07:06:35.345493000Z 2026/05/30 07:06:35 netmap: suggested exit node: airvpn-frankfurt (nVKwErXaZJ11CNTRL)
[tailscale-beszel] 2026-05-30T07:06:35.345785000Z 2026/05/30 07:06:35 tstun: peer config: peerConfigTable{nativeAddr4: 100.101.121.100, nativeAddr6: fd7a:115c:a1e0::8539:7964, }
[tailscale-beszel] 2026-05-30T07:06:35.345861000Z 2026/05/30 07:06:35 [RATELIMIT] format("tstun: peer config: %v")
[tailscale-beszel] 2026-05-30T07:06:35.345990000Z 2026/05/30 07:06:35 wgengine: Reconfig: configuring userspace WireGuard config (with 88 peers)
[tailscale-beszel] 2026-05-30T07:06:35.346081000Z 2026/05/30 07:06:35 [RATELIMIT] format("wgengine: Reconfig: configuring userspace WireGuard config (with %d peers)")
`
Bug Description
Hello, I've done a manual analysis on this problem and have used AI to summarize and clean up my notes. I've double checked the below text and it represents the actual problem ;-)
Since approximately this week (observed on tailscale/tailscale:latest, version v1.98.4), Tailscale sidecar containers in Docker Compose stacks produce [RATELIMIT] log messages during startup. More critically, the sidecar container repeatedly fails its Docker healthcheck, causing dependent application containers (configured with depends_on: condition: service_healthy) to never start automatically. The stack only comes up correctly after manually starting the application service.
To Reproduce
Expected behavior
The Tailscale sidecar should pass its healthcheck after successfully reaching the Running state, and dependent services should start automatically without manual intervention.
Observed behavior
The sidecar logs show [RATELIMIT] messages appearing immediately after the daemon reaches the Running state, specifically:
Environment
Logs
Tailscale sidecar container logs (startup + restart cycle)
Additional context
Expected Behavior
Tailscale sidecar comes healthy.
Actual Behavior
Tailscale sidecar goes into a restart loop
Screenshots
No response
Operating System
Linux
Tailscale Version
v1.98.4-t01c6b9661
Docker Version
29.5.2, build 79eb04c
Relevant Logs or Error Messages
Docker Compose Configuration
Environment Configuration (.env file)
Additional Context
No response