{"repo":"patte/fly-tailscale-exit","free":true,"listed":false,"github":"https://github.com/patte/fly-tailscale-exit","clone":"git clone https://github.com/patte/fly-tailscale-exit.git","description":"Run a VPN with global exit nodes with fly.io, tailscale and github!","language":"Shell","stars":1659,"topics":["exitnode","flyio","tailscale","vpn"],"license":null,"category":"networking-infra","readme_excerpt":"fly-tailscale-exit ------------------ This repo shows how to run tailscale on fly, specifically to run exit nodes. If you want to add tailscale to a fly.io application, follow this guide instead: https://tailscale.com/kb/1132/flydotio/ Features: - [x] runs a Tailscale exit node on Fly.io microVMs (real kernel networking, not a userspace proxy) - [x] small docker image based on alpine:3.23 , pulls a pinned tailscale release - [x] auth via an OAuth client (mints a tagged, ephemeral, pre-approved key) or a plain auth key - [x] advertises --advertise-exit-node , hostname fly- - [x] IPv4 + IPv6 forwarding and MASQUERADE NAT for egress - [x] ephemeral, in-memory node state ( tailscaled --state=mem: ), auto-removed on shutdown - [x] health endpoint: busybox httpd serves /cgi-bin/healthz , wired to a Fly [checks] block - returns 200 when the node is connected to the tailnet, 503 otherwise - [x] self-healing: the container exits if tailscaled dies, so Fly restarts the machine - [x] CI: shellcheck , hadolint , image build, and a no-secrets healthz smoke test - [x] published to GHCR as a cosign-signed image (SLSA provenance + SBOM), so you can deploy without cloning - [x] weekly GitHub Action to auto-update tailscale , gated on CI, opening an issue on failure - [x] Dependabot for the base image and GitHub Actions [!WARNING] In September 2023 Tailscale and Mullvad announced to partner up: for $5/month you can use a mullvad exit node from up to 5 tailscale nodes. This is great news and I'","default_branch":null,"files":null,"tree":[],"storefront":"/r/patte","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/patte/fly-tailscale-exit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}