Releases: tui-tools/tui-tailscale
Release list
v1.1.0
tui-tailscale v1.1.0
tui-tailscale 1.1.0
tui-tailscale 1.1.0 keeps a private tailnet's relays in-house and removes three frictions found setting up company control planes. S ends with a relay question and can enable headscale's embedded DERP relay as a minimal diff of config.yaml, with the STUN port read by readiness and opened through f. f now hands tui-firewall the ports readiness found closed, prefilled (tui-firewall --open 443/tcp,41641/udp --comment 'tailnet control plane and node'), one form and one confirm per port. A created pre-auth key is shown whole on a dialog of its own and never cut; on a terminal too narrow for it, no part of it is drawn, and w writes it once to a root-only file under /run. The header stays two rows at any width. Built on tui-kit v0.4.4: every child runs without a controlling terminal, and the headscale and tailscale installs use the kit's companion builders. Keys, flags and --check field names are unchanged; --check gains readiness.ports.stunPort and readiness.ports.stun when the embedded relay is on, and readiness.relays reports embedded or embedded+tailscale-public once it is.
Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, checksums.txt carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.
The commits in this release:
Changelog
v1.0.1
tui-tailscale v1.0.1
tui-tailscale 1.0.1
tui-tailscale 1.0.1 closes a policy bypass and four rough edges found setting up company control planes. On a control plane with OIDC, R no longer registers a node whose browser login the identity provider's allow lists refused, nor one whose login is still at the provider; any other registration there goes through a danger confirm that says it skips the provider's policy. r and the return from f look for binaries again, so tui-firewall installed in another terminal is picked up, and f offers to install tui-firewall when it is missing. The ports reader follows jumps and gotos into ufw's and firewalld's chains instead of reporting open ports as closed, and says "unknown" when a jump cannot be followed. The users panel and the readiness line say that relays go through Tailscale's public DERP servers unless headscale's embedded DERP is enabled, and the README's private tailnet walkthrough explains it. Every apt step runs with DEBIAN_FRONTEND=noninteractive NEEDRESTART_MODE=a (tui-kit v0.4.2), shown in the preview, so needrestart cannot hang i on Ubuntu. Keys, flags and --check field names are unchanged; --check gains readiness.refusedRegistrations, readiness.relays and readiness.relayHint.
Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, checksums.txt carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.
The commits in this release:
Changelog
v1.0.0
tui-tailscale v1.0.0
tui-tailscale 1.0.0: stable
tui-tailscale 1.0.0 is the first stable tool of the tui-tools family. Stable means a frozen contract under semver: the keys, the flags and the --check JSON only grow in minor releases, and anything removed or changed waits for a major release announced one minor ahead. It has run a real control plane and its nodes end to end, installs from apt, dnf, pacman and a static binary, and ships signed checksums, SBOMs and build provenance. This release also carries the fixes found on that real walkthrough: after a successful browser login the node screen waits while tailscaled comes up and then says who joined, instead of reporting an expired login, and a machine that is only a node shows the headscale tabs dimmed with where its control plane is; readiness no longer blocks on a spent single-use key once the first node has joined, and --check adds canJoinMore; a stopped or disabled tailscaled is started with u, and a headscale whose config.yaml was deleted is restored with i, both previewed, with tailscale.daemon, headscale.configPresent and headscale.stateDirPresent in --check. New demo cases: --demo=node-only and --demo=partial-reset.
Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, checksums.txt carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.
The commits in this release:
Changelog
v0.2.0
tui-tailscale v0.2.0
tui-tailscale 0.2.0: private tailnets, join profiles, DNS
Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, checksums.txt carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.
The commits in this release:
Changelog
v0.1.0
tui-tailscale v0.1.0
tui-tailscale 0.1.0: self-hosted Tailscale from the terminal, both ends. This node: join, accept and advertise routes, exit node, peers, install. The headscale control plane: transport (plain http, Let's Encrypt, own certificate, reverse proxy), OIDC with a Google preset, users, nodes, pre-auth keys, route approval, readiness. Validated end to end on a real Ubuntu 24.04 host with Google OIDC and a subnet router, and on the family lab (Ubuntu 24.04 and 26.04, Fedora 44, Omarchy Server 4.0.1).
Built by this repository's CI on the tag itself. Each archive ships a
CycloneDX SBOM, checksums.txt carries a keyless cosign signature, and
every file has SLSA build provenance — see the README's "Verify a
download" for the two commands that check them.
The commits in this release:
Changelog
- e2cd91f Bootstrap tui-tailscale 0.1.0: node and peers screens, join, prefs, install (#2)
- a8f7b52 Control plane: headscale users, nodes, keys, transport, OIDC presets, routes; re-probe after installs (#8)
- 5dd6eb2 Initial commit
- 59baa58 Prepare the 0.1.0 release: install channels on, first-tailnet walkthrough (#11)
- 038c820 Record the lab run on Ubuntu 26.04: tailscale 1.102.4 through the resolute plan (#7)
- e094062 compat: tailscale 1.102.4 tested on ubuntu-24.04, fedora-44 and omarchy-server-4.0.1 (#5)