tailscale-derper custom image, turn off certificate validation
2.6K
The original tailscale-derper tool added the validation mechanism of the SSL certificate, which made the self-signed certificate unusable, and the following validation mechanism was turned off to make the Derper tool run normally.
https://github.com/tailscale/tailscale/blob/main/cmd/derper/cert.go#L91-L93
The image integrates the automatic certificate generator and automatically generates the SSL self-signed certificate of the corresponding configured domain name according to the CMD parameters in the Dokcerfile, and the default CMD parameters are:
You can control the working behavior of the derper through environment variables. By default, four environment variables are received, and the specific names and functions are as follows.
DOMAIN_NAME[dafault:derper.example.com]
DERPER_PORT[default:443]
COMMAND_LINE
ADVANCED_MODE[default:false]
example docker run command⌘
docker run -it --rm -e DOMAIN_NAME=test.com -e DERPER_PORT=2333 -p 2333:2333 tangcuyu/tailscale-derper
tailscale-derper 原始工具添加了 ssl 证书的验查机制,导致自签名证书无法使用,通过关闭下面的验查机制让 derper 工具能够正常运行。
https://github.com/tailscale/tailscale/blob/main/cmd/derper/cert.go#L91-L93
该镜像集成了证书自动生成程序,并根据所传入的环境变量自动生成对应配置域名的 ssl 自签证书,你可以通过环境变量来控制 derper 的工作行为。 默认接收四个环境变量具体的名称与作用如下
DOMAIN_NAME[默认值:derper.example.com]
/opt/ssl/ 你可以根据需要自己传入自己需要的证书DERPER_PORT[默认值:443]
COMMAND_LINE[默认为空]
ADVANCED_MODE[默认值:false]
docker 运行命令示例⌘
docker run -it --rm -e DOMAIN_NAME=test.com -e DERPER_PORT=2333 -p 2333:2333 tangcuyu/tailscale-derper
Content type
Image
Digest
sha256:2345cc41f…
Size
18.9 MB
Last updated
11 months ago
docker pull tangcuyu/tailscale-derper