github-actions[bot]
38d25418a0
flake.lock: Update
...
Flake lock file updates:
• Updated input 'nixpkgs':
'github:nixos/nixpkgs/8be7bd0' (2026-08-14)
→ 'github:nixos/nixpkgs/a831408' (2026-08-22)
2026-08-23 08:30:30 +00:00
github-actions[bot]
9375e18b55
chore: update flake.lock ( #563 )
2026-08-18 21:45:18 -04:00
Julian Lehrhuber
cd59c310f6
Add key expiry disable/enable toggle ( #554 )
2026-08-18 21:41:30 -04:00
Jade
0feab692bd
fix(ui): submit raw number input value for auth key expiry ( #609 )
...
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-18 21:40:53 -04:00
Sandro
e1f9db4c4e
Fix restty links across docs pages ( #595 )
2026-08-18 21:39:38 -04:00
Aarnav Tale
b3c0c1c691
fix(agent): always spawn agent with pre-auth key and auto-approve
...
- Generate a fresh pre-auth key for every agent startup
- Preserve existing tailscale state to avoid creating a new host
- Auto-approve pending auth requests via /api/v1/auth/approve
- Show approval link in settings UI as fallback
Closes HP-558
2026-07-13 11:00:43 -04:00
Sandro
3d9b9b0f7e
Fix typo url in code to docs ( #586 )
2026-07-12 18:20:07 -04:00
Sandro
f52c4161cc
Fix wasm ssh in nix build ( #588 )
2026-07-12 18:18:48 -04:00
Tommy Nevtelen
fb73181cba
fix: treat Go pseudo-versions as unknown server versions ( #590 )
...
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-07-12 18:18:21 -04:00
Aarnav Tale
17e7b35478
chore: v0.7.0
v0.7.0
2026-07-04 11:10:57 -04:00
Aarnav Tale
51a4613295
chore: fix unit tests
2026-07-04 00:55:42 -04:00
Aarnav Tale
1345b7ca13
fix(ui): fix assigning ACL tags to non-user nodes
2026-07-04 00:50:57 -04:00
Aarnav Tale
948cfad58c
fix: handle registration keys on headscale 0.29+
...
Closes HP-555.
2026-07-04 00:07:53 -04:00
Aarnav Tale
990e1e9ff5
chore(ssh): warn about broken SSH on certain versions
2026-07-01 11:23:35 -04:00
Aarnav Tale
18263e4878
fix(ui): show display names in lists
...
Closes HP-549.
2026-06-22 20:23:41 -04:00
Aarnav Tale
12cee9763e
fix(ui): stop split DNS from crashing the page when undefined
...
Closes HP-548.
2026-06-22 20:23:40 -04:00
github-actions[bot]
4d0c0cacca
chore: update nix pnpm deps hash
2026-06-22 20:44:09 +00:00
Aarnav Tale
83671ff3b0
chore: add audit fix
2026-06-22 16:42:10 -04:00
Aarnav Tale
476a0419f1
chore: update dev stuff
2026-06-22 16:40:29 -04:00
Aarnav Tale
0439175e73
feat(auth): support role sync on re-login
2026-06-22 16:40:29 -04:00
Aarnav Tale
a3cd8444a3
chore(auth): add more informative logs
2026-06-22 16:40:29 -04:00
Aarnav Tale
10055541cc
feat(config): simplify required headscale config
2026-06-22 16:40:29 -04:00
Aarnav Tale
dc32427cff
feat(config): use minimal headscale config
2026-06-22 16:40:28 -04:00
github-actions[bot]
5aebc6d932
chore: update nix pnpm deps hash
2026-06-20 22:14:47 +00:00
Aarnav Tale
e29221e5f7
feat: add support for headscale 0.29+
2026-06-20 18:03:14 -04:00
Aarnav Tale
846c030bc1
chore: update to react router v8
2026-06-20 13:33:24 -04:00
Aarnav Tale
5d6eef5843
feat: update to the v8 middleware api
2026-06-20 12:38:09 -04:00
Aarnav Tale
3f9dcd5eb4
feat: update build for react router v8
2026-06-20 12:09:42 -04:00
Aarnav Tale
0c4d175eb7
feat(auth): support deriving roles from the IDP
...
Closes HP-352.
2026-06-20 11:53:09 -04:00
Aarnav Tale
96f2721272
feat(auth): support reverse-proxy driven proxy auth
...
Closes HP-353.
2026-06-20 11:41:44 -04:00
eccgecko
c7822e3ec2
fix(wasm): make whole vendored tailscale tree writable before patching ( #567 )
2026-06-18 10:53:21 -04:00
github-actions[bot]
4179e3e604
chore: update nix pnpm deps hash
2026-06-17 20:06:57 +00:00
Aarnav Tale
f00d8ab87e
chore: changelog
2026-06-17 16:05:21 -04:00
Aarnav Tale
3252482e0b
feat: switch logging to pino
...
Closes HP-279
2026-06-17 15:58:48 -04:00
Aarnav Tale
57c8046f99
feat(ui): add support for showing existing tag options
2026-06-17 11:35:38 -04:00
Aarnav Tale
c8b1a30f34
fix(wasm): account for custom DERP ports when checking the probe
...
Closes HP-540
2026-06-17 11:30:34 -04:00
Aarnav Tale
8017436bb6
fix(ui): increase ssh pre-auth key expiry time and present errors
...
Closes HP-546
2026-06-17 11:27:07 -04:00
Aarnav Tale
dea19f9330
fix(ui): validate machine names before rename submission
...
Closes HP-545
2026-06-17 11:15:30 -04:00
Aarnav Tale
21806caa05
fix(oidc): correctly handle client_secret_basic fallback
2026-06-17 11:13:46 -04:00
Aarnav Tale
2f3a440de5
fix: auto read dns.extra_records_path instead of making it required
...
Closes HP-538
2026-06-17 11:11:20 -04:00
Aarnav Tale
e74e0d4542
fix: don't require postgres pass when password_file is supplied
...
Closes HP-528
2026-06-17 11:09:12 -04:00
Aarnav Tale
db39b5f2bd
chore: add pullfrog.yml workflow
2026-06-17 10:26:20 -04:00
Aarnav Tale
262c7bf82a
chore: v0.7.0-beta.4
v0.7.0-beta.4
2026-05-31 14:46:03 -04:00
Aarnav Tale
f8b23a5c89
chore: changelog
2026-05-31 14:39:53 -04:00
Aarnav Tale
775b81a7fa
feat: support multiple CAs through documentation
2026-05-31 14:38:10 -04:00
Aarnav Tale
62817efa6e
feat: gate the healthcheck listen file to docker only
2026-05-30 20:46:32 -04:00
Aarnav Tale
b95d601ff6
feat: automate health check with a written file
2026-05-30 20:45:15 -04:00
Aarnav Tale
ea27c846e2
feat: add support for https
2026-05-30 19:39:02 -04:00
Aarnav Tale
8c508e0602
feat(users): expose rename and delete for unlinked Headscale users
...
The user-actions handler already supported `rename_user` and
`delete_user` (both keyed by headscale_user_id), but the Unlinked
Headscale Users table had no menu to invoke them. That left admins
with no UI path to remove or rename Headscale users that have no
Headplane counterpart — e.g. users created via the Headscale CLI
before an OIDC migration.
Wire the existing dialogs into a new HeadscaleUserMenu rendered in
the row's actions column. OIDC-managed users still can't be renamed
(Headscale rejects it), so the Rename item hides for those.
Closes #525
Amp-Thread-ID: https://ampcode.com/threads/T-019e7ae4-6862-760c-a3e7-239350eab71d
Co-authored-by: Amp <amp@ampcode.com >
2026-05-30 18:49:27 -04:00
Aarnav Tale
0a51182eed
fix(pre-auth-keys): pass Headscale numeric user id when expiring on 0.27.x
...
The pre-0.28 ExpirePreAuthKey RPC takes a uint64 `user` field plus the
key string. The API layer reads that uint64 from `key.user?.id`, but
the action was wrapping the form's user_id as `{ name: user }` — so
.id was always undefined and the wire request sent an empty string,
which Headscale rejects with "proto: invalid value for uint64 field
user". 0.28+ is unaffected because the new expire endpoint only reads
`key.id` (the stable preauthkey id).
Pass `{ id: user }` so the numeric Headscale user id reaches the wire.
Amp-Thread-ID: https://ampcode.com/threads/T-019e7ae4-6862-760c-a3e7-239350eab71d
Co-authored-by: Amp <amp@ampcode.com >
2026-05-30 18:49:11 -04:00