Skip to content

Tailscale ACL: admit tag:dashboard to the dusk-1 serving API (tcp:8080) - #13613

Closed
briansrls wants to merge 1 commit into
mainfrom
tailscale/dusk-serving-api-grant
Closed

briansrls wants to merge 1 commit into
mainfrom
tailscale/dusk-serving-api-grant

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Models the grant the operator is adding in the admin console, so the repo's policy (extdeps.tailscale.acl operator_tailscale_acl_policy) matches live.

  • New grant tag_dashboard_to_dusk_serving_api_grant: src tag:dashboard → dst 100.127.39.77 (dusk-1) → tcp:8080.
  • operator_acl_security_spine_holds now also requires dusk_serving_reached_by_dashboard_api_only: exactly one grant reaches dusk-1, from tag:dashboard only, port 8080 only. tag:ci stays quarantined.
  • Witness witness_dusk_serving_api_only adds a red control: a tag:ci wildcard grant to dusk-1 refuses. Reference fixture updated.

Evidence: claim_batch --entry dag/test/claim/tailscale_acl_witness_test.dag --functions tailscale_acl_witnesses → PASS.

Not covered: there is still no apply route (tailscale_acl_upsert_wet is a declared scaffold with no definition), so live is edited in the console and this PR only records it. dusk-1 is addressed by IP because it is an untagged member device; tagging it would replace the IP.

🤖 Generated with Claude Code

…0) only

dusk-1 (operator desktop, WSL) serves an OpenAI-compatible API while the Sparks
are sold. It is an untagged member device, so no tag grant reached it and srv2
(tag:ci + tag:dashboard) timed out. The grant admits the dashboard plane to
tcp:8080 on its tailnet address only; tag:ci stays quarantined. The security
spine now requires exactly that one grant to reach dusk-1, and the witness
carries a red control (a tag:ci wildcard grant to dusk-1 refuses).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T04:21:14.322982Z 9532f16 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9532f164b5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +322 to +324
fn grant_reaches_dusk_serving(g: TailscaleGrant) -> Bool {
selector_list_contains(items: g.dst, needle: sel_ipv4(address: dusk_serving_ip))
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include wildcard destinations in the dusk reachability check

grant_reaches_dusk_serving recognizes only a literal 100.127.39.77 destination, but the existing member_baseline_grant uses dst: [sel_wildcard()] and ip: [sel_wildcard()]. Tailscale defines a destination wildcard as matching all tailnet IP addresses and an ip wildcard as matching every protocol and port (Tailscale selector reference), so the emitted policy lets every member reach dusk-1 on all ports while this new security-spine predicate reports that only tag:dashboard can reach TCP 8080. Account for wildcard destinations (and any modeled ranges containing this address) in this reachability check and its negative witness.

Useful? React with 👍 / 👎.

@gunbai-bot

gunbai-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Folded into #13641 (merge second parent = this head).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant