1.9 KiB
tsrun
Single-binary temporary Tailscale client.
Build-time manifest
Use the build script. If secrets/tsrun.manifest.json does not exist yet, the
script will copy the example manifest into place, stop, and tell you to fill in
your real credentials before rerunning it.
./build-windows.sh
Manual blob generation is still available if needed:
go run ./cmd/buildblob -in secrets/tsrun.manifest.json -out internal/embedded/blob_gen.go
For Windows full-client mode, the build script will download wintun.dll once
and reuse it on later runs. Manual placement is still supported at:
internal/runtime/full/wintun.dll
It will be embedded into tsrun.exe and extracted at runtime automatically.
Run
go run ./cmd/tsrun
go run ./cmd/tsrun --proxy
go run ./cmd/tsrun clear
Default mode now supports:
- Windows: elevated Administrator shell required
- Linux: root required
--proxy remains the low-privilege fallback.
clear removes Tailscale DNS/router state and attempts to delete the local
TUN/interface state left behind by a bad run.
Bootstrap Server
The repo also contains a Bun bootstrap server that serves the built artifacts:
Linux: curl -L tsr.dgnr.us | bash
Windows: irm tsr.dgnr.us | iex
/auto-detect bootstrap script/linuxLinux UPX binary/windowsWindows UPX binary/linux-rawraw Linux binary/windows-rawraw Windows binary
Builds and deploys follow the GitOps Bun service pattern from deploy-docs:
- multi-stage Dockerfile
.gitea/workflows/deploy.ymlk8s/deployment, service, ingress, kustomization
Current deployment targets:
- image:
registry.neko-piranha.ts.net/astral/tsrun - namespace:
default - ingress host:
tsr.dgnr.us - CI kube auth:
ci-deployerservice account token stored as repo secretKUBE_TOKEN
Linux release build
./build-linux.sh
Windows release build
./build-windows.sh