# tsrun Single-binary temporary Tailscale client. ## Build-time manifest Use the build script. If `secrets/tsrun.manifest.json` does not exist yet, the script will copy the example manifest into place, stop, and tell you to fill in your real credentials before rerunning it. ```bash ./build-windows.sh ``` Manual blob generation is still available if needed: ```bash go run ./cmd/buildblob -in secrets/tsrun.manifest.json -out internal/embedded/blob_gen.go ``` For Windows full-client mode, the build script will download `wintun.dll` once and reuse it on later runs. Manual placement is still supported at: ```text internal/runtime/full/wintun.dll ``` It will be embedded into `tsrun.exe` and extracted at runtime automatically. ## Run ```bash go run ./cmd/tsrun go run ./cmd/tsrun --proxy go run ./cmd/tsrun clear ``` Default mode now supports: - Windows: elevated Administrator shell required - Linux: root required `--proxy` remains the low-privilege fallback. `clear` removes Tailscale DNS/router state and attempts to delete the local TUN/interface state left behind by a bad run. ## Bootstrap Server The repo also contains a Bun bootstrap server that serves the built artifacts: ```text Linux: curl -L tsr.dgnr.us | bash Windows: irm tsr.dgnr.us | iex ``` 1. `/` auto-detect bootstrap script 2. `/linux` Linux UPX binary 3. `/windows` Windows UPX binary 4. `/linux-raw` raw Linux binary 5. `/windows-raw` raw Windows binary Builds and deploys follow the GitOps Bun service pattern from `deploy-docs`: 1. multi-stage Dockerfile 2. `.gitea/workflows/deploy.yml` 3. `k8s/` deployment, service, ingress, kustomization Current deployment targets: 1. image: `registry.neko-piranha.ts.net/astral/tsrun` 2. namespace: `default` 3. ingress host: `tsr.dgnr.us` 4. CI kube auth: `ci-deployer` service account token stored as repo secret `KUBE_TOKEN` ## Linux release build ```bash ./build-linux.sh ``` ## Windows release build ```bash ./build-windows.sh ```