Skip to content

Instantly share code, notes, and snippets.

@cerebrate
Created January 27, 2026 20:18
Show Gist options
  • Select an option

  • Save cerebrate/d8e63b5638c753862b37c49bb1aca35c to your computer and use it in GitHub Desktop.

Select an option

Save cerebrate/d8e63b5638c753862b37c49bb1aca35c to your computer and use it in GitHub Desktop.
Configure a peer relay for Tailscale containers on k8s
---
apiVersion: v1
kind: Secret
metadata:
name: tailscale-peer-relay-state
namespace: kube-public
stringData:
TS_AUTHKEY: tskey-auth-REDACTED_NOT_THAT_IT_MATTERS
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: tailscale-peer-relay
namespace: kube-public
rules:
- apiGroups: [""] # "" indicates the core API group
resources: ["secrets"]
# Create can not be restricted to a resource name.
verbs: ["create"]
- apiGroups: [""] # "" indicates the core API group
resourceNames: ["tailscale-peer-relay-state"]
resources: ["secrets"]
verbs: ["get", "update", "patch"]
- apiGroups: [""] # "" indicates the core API group
resources: ["events"]
verbs: ["get", "create", "patch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: tailscale-peer-relay
namespace: kube-public
subjects:
- kind: ServiceAccount
name: "tailscale-peer-relay"
roleRef:
kind: Role
name: tailscale-peer-relay
apiGroup: rbac.authorization.k8s.io
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-peer-relay
namespace: kube-public
---
apiVersion: v1
kind: Service
metadata:
name: tailscale-peer-relay
namespace: kube-public
labels:
app: tailscale-peer-relay
annotations:
metallb.io/loadBalancerIPs: fdc9:b01a:9d26:0:2::3,172.16.2.3
spec:
type: LoadBalancer
ipFamilyPolicy: RequireDualStack
ports:
- name: peer-relay
protocol: UDP
port: 61441
targetPort: 61441
selector:
app: tailscale-peer-relay
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-peer-relay
namespace: kube-public
labels:
app: tailscale-peer-relay
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-peer-relay
template:
metadata:
labels:
app: tailscale-peer-relay
spec:
serviceAccountName: tailscale-peer-relay
containers:
- name: tailscale
imagePullPolicy: Always
image: "ghcr.io/tailscale/tailscale:latest"
env:
- name: TS_KUBE_SECRET
value: "tailscale-peer-relay-state"
- name: TS_USERSPACE
value: "false"
- name: TS_DEBUG_FIREWALL_MODE
value: auto
- name: TS_AUTHKEY
valueFrom:
secretKeyRef:
name: tailscale-peer-relay-state
key: TS_AUTHKEY
optional: true
- name: TS_EXTRA_ARGS
value: "--hostname=k8s-peer-relay" # --relay-server-port=61441 --relay-server-static-endpoints=\"[fdc9:b01a:9d26:0:2::3]:81441,172.16.2.3:61441\""
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_UID
valueFrom:
fieldRef:
fieldPath: metadata.uid
securityContext:
privileged: true
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment