Skip to content

SYS-685 disable gateway access logs, fix headscale for gateway - #317

Merged
instantlinux merged 2 commits into
mainfrom
SYS-685_tailscale_envoy
Sep 27, 2026
Merged

instantlinux merged 2 commits into
mainfrom
SYS-685_tailscale_envoy

Conversation

@instantlinux

@instantlinux instantlinux commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary of Changes

The tailscale VPN client would not connect following migration from ingress-nginx to gateway API.

  • Add infra helm chart parameter to turn off (hugely noisy) gateway access logs
  • Add envoy backend traffic policy to headscale for custom websocket upgrade tailscale-control-protocol
  • Bump restic version number
  • Increase default memory limit of apache chart

Why is this change being made?

There are hundreds of misleading online suggestions for how to get headscale to work again after migration from ingress-nginx to envoy API gateway. (The tailscale up command hangs for 60 seconds, then outputs EOF.) NONE OF THEM WORK. The rabbit holes I ran into mostly involved fruitless efforts to define an EnvoyPatchPolicy that can edit settings on the envoy pods within namespace envoy-gateway-system. There are suggestions involving an upgrade_configs parameter using JSONPatch. Some suggest that you need to define a two-entry list for upgrade_type, specifying websocket and tailscale-control-protocol. There's even some that suggest setting a ClientTrafficPolicy to specify parameters like streamIdleTimeout or connectionBufferLimitBytes. Flying blind, you're told to install egctl (which relies on socat) and type commands like egctl x status httproute --all-namespaces. NONE OF THOSE ARE TRUE. And Gemini's AI is trained on all these outdated suggestions, which may or may not have worked with versions of Envoy Gateway before 1.9.1. If you landed here after an exasperating search: see the 11-line yaml file gateway-backend.yaml attached to this PR: all you need is to define the httpUpgrade parameter in a BackendTrafficPolicy for the /ts2021 (or top-level "/") HTTPRoute of your headscale installation (edit: see also #318 which adjusts how this parameter is applied).

How was this tested? How can the reviewer verify your testing?

Manual testing.

Completion checklist

  • The pull request is linked to all related issues
  • This change has unit test coverage
  • Documentation has been updated
  • Dependencies have been updated and verified

@instantlinux
instantlinux merged commit 3b16f7c into main Sep 27, 2026
1 check passed
@instantlinux
instantlinux deleted the SYS-685_tailscale_envoy branch September 27, 2026 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant