{"repo":"hellodword/tailscale-derp-client-verifier","free":true,"listed":false,"github":"https://github.com/hellodword/tailscale-derp-client-verifier","clone":"git clone https://github.com/hellodword/tailscale-derp-client-verifier.git","description":null,"language":"Go","stars":27,"topics":["derp","derper","self-hosted","tailscale"],"license":null,"category":"self-hosted-apps","readme_excerpt":"tailscale-derp-client-verifier tailscale-derp-client-verifier lets a custom Tailscale DERP server verify tailnet clients without enrolling the DERP host itself as a Tailscale node. Why 1. Tailscale traffic is end-to-end encrypted by design.[^1] 2. An untrusted DERP server cannot decrypt relayed traffic.[^2] 3. derper's --verify-clients mode requires a local Tailscale node on the DERP host. 4. --verify-client-url delegates client admission to an external HTTP service.[^3] This verifier implements that HTTP service and admits node public keys found in a local nodes.json file. Build Update nodes.json Generate the allowlist on a trusted machine that is already connected to the tailnet and can see every node that should use the DERP server. Tailscale documents tailscale status --json as machine-readable output suitable for automation.[^4] Review the generated keys, then deliver nodes.json.new to the DERP host using an authenticated mechanism already standard in your environment. Place the temporary file in the same directory as the live file and rename it there so readers see an atomic replacement: Run this update periodically and after adding, removing, or reauthenticating nodes. Node public keys can change when a device reauthenticates.[^5] The verifier reloads the file in the background every 30 seconds by default, even when it is not receiving requests. -path itself remains fixed for the lifetime of the process; replace the file at that path atomically, or restart the process ","default_branch":null,"files":null,"tree":[],"storefront":"/r/hellodword","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/hellodword/tailscale-derp-client-verifier/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}