Post

Things Learnt Y2026 W40

Things Learnt Y2026 W40

How to run tailscale in containers

Tailscale, by default, wants access to /dev/tun in order to set up the VPN, so if you want to get a container (usually ephemeral) that doesn’t have access to /dev/tun onto your tailscale network, you’ll need to use tailscale in userspace networking mode.

1
2
3
sudo -n nohup tailscaled --tun=userspace-networking --socks5-server=localhost:1055 --outbound-http-proxy-listen=localhost:1055

sudo tailscale up --auth-key=tskey-auth-AAAAAAAA-BBBBBBBBBBBBBBBBBBBB

auth-key allows us to log into our tailnet without an interactive login. These can be configured to be ephemeral to remove that machine from the tailnet after the machine goes offline as well as configurable to be one-time use. Pretty cool!

After this, you will already be able to ssh to that container from your tailnet if “ordinary” prereqs are met (sshd running and your public key there). If you want to use tailscale ssh, you’ll need to explicitly allow that through tailscale.

Some ssh hacks

I like ssh a lot. The first time I ssh’d to a VPS running in the cloud somewhere, I felt like a complete wizard. Turns out I didn’t really know nuffink about remotely accessing machines…

Forward ports to your machine through an ssh tunnel

ssh -N -L [<local-bind-host>:]<localport>:<host-on-remote>:<remote-port>

So if running a dev server or equivalent on the remote host which is only bound to localhost there, you can forward this to your local machine and access it with something like:

ssh -N -L 9999:localhost:9999 gote1

Pretty nice when combined with python -m http.server 9999 to get a webserver quickly:

Example of webserver access using these commands

Jump through a “bastion” host to get somewhere else

Rather than ssh to the bastion, then ssh onward from that session, you can just “Proxy Jump” through.

ssh -J user@bastion.example.com user@internal-host

In my exact case most recently (ssh to a docker sbx running on a remote host directly from my machine), this didn’t work due to the remote host not running just ssh on the host to ssh onward, it was using a Proxy Command. In that case, you can also avoid this intermedate ssh session using a proxy command like so: ssh -t <bastion-host> ssh <on-ward-host>. An example config for accessing a docker sbx running on a remote machine is as follows:

1
2
3
4
5
6
7
# Docker sbxs running on gote
Host *.sbx
    User _default_user_
    ProxyCommand ssh gote /usr/bin/sbx ssh proxy %n
    IdentityFile /dev/null
    StrictHostKeyChecking no
    UserKnownHostsFile /dev/null

You can then access any *.sbx host running on that machine by simply running ssh <sbx-name>.sbx

  1. Yes, all my home network servers are named after go terms. ↩︎

This post is licensed under CC BY 4.0 by the author.