Compare commits

..

52 Commits

Author SHA1 Message Date
gitea-admin a2c7345e43 feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-17 01:01:51 +00:00
gitea-admin 294fe564da Merge pull request 'feat: migrate tailscale-operator to OAuth auth mode' (#45) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778979641646 into main
Reviewed-on: #45
2026-05-17 01:01:11 +00:00
gitea-admin e39182ecbf feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-17 01:00:41 +00:00
gitea-admin f881ff31dc Merge pull request 'fix: migrate tailscale-operator to OAuth auth mode' (#44) from orion/auto/fix-migrate-tailscale-operator-to-oauth--1778979071556 into main
Reviewed-on: #44
2026-05-17 00:51:47 +00:00
gitea-admin dddd39e385 fix: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-17 00:51:11 +00:00
gitea-admin bf88086a3d Merge pull request 'fix: add OAuth config to tailscale-operator deployment' (#38) from orion/auto/fix-add-oauth-config-to-tailscale-operat-1778977929419 into main
Reviewed-on: #38
2026-05-17 00:32:28 +00:00
gitea-admin df571132b7 fix: add OAuth config to tailscale-operator deployment
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-17 00:32:09 +00:00
gitea-admin c4684fb0cf Merge pull request 'feat: migrate tailscale-operator to OAuth auth mode' (#37) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778968649055 into main
Reviewed-on: #37
2026-05-17 00:27:14 +00:00
gitea-admin 7217c9c9bf feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 21:57:29 +00:00
gitea-admin 406b643aaf Merge pull request 'fix: use OAuth auth mode for Tailscale operator' (#36) from orion/auto/fix-use-oauth-auth-mode-for-tailscale-op-1778968596436 into main
Auto-merged by ORION: fix: use OAuth auth mode for Tailscale operator
2026-05-16 21:56:37 +00:00
gitea-admin 5cbb25af84 fix: use OAuth auth mode for Tailscale operator
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 21:56:36 +00:00
gitea-admin efd3ccf0da Merge pull request 'feat: migrate tailscale operator to OAuth authentication' (#35) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778968460695 into main
Auto-merged by ORION: feat: migrate tailscale operator to OAuth authentication
2026-05-16 21:54:21 +00:00
gitea-admin 742cdf485f feat: migrate tailscale operator to OAuth authentication
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 21:54:20 +00:00
gitea-admin 28f608f0a1 Merge pull request 'feat: migrate tailscale-operator to OAuth auth mode' (#34) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778966778432 into main
Reviewed-on: #34
2026-05-16 21:26:32 +00:00
gitea-admin 6eaa4ea56f feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 21:26:18 +00:00
gitea-admin bdff8fa7f1 Merge pull request 'feat: migrate tailscale-operator to OAuth auth mode' (#33) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778963789752 into main
Auto-merged by ORION: feat: migrate tailscale-operator to OAuth auth mode
2026-05-16 20:36:30 +00:00
gitea-admin 5fd18fd952 feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 20:36:30 +00:00
gitea-admin 8ceed3a660 Merge pull request 'feat: migrate tailscale-operator to OAuth authentication' (#32) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778962040728 into main
Auto-merged by ORION: feat: migrate tailscale-operator to OAuth authentication
2026-05-16 20:07:21 +00:00
gitea-admin 088854fb98 feat: migrate tailscale-operator to OAuth authentication
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 20:07:20 +00:00
gitea-admin 5b3cd9145a Merge pull request 'feat: migrate tailscale-operator to OAuth auth mode' (#30) from orion/auto/feat-migrate-tailscale-operator-to-oauth-1778958534086 into main
Reviewed-on: #30
2026-05-16 19:09:07 +00:00
gitea-admin 0b4614f03b feat: migrate tailscale-operator to OAuth auth mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 19:08:54 +00:00
gitea-admin 4803fb2acc Merge pull request 'fix: update tailscale-operator to OAuth secrets mode' (#29) from orion/auto/fix-update-tailscale-operator-to-oauth-s-1778957203077 into main
Reviewed-on: #29
2026-05-16 18:47:08 +00:00
gitea-admin 1652b56287 fix: update tailscale-operator to OAuth secrets mode
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 18:46:43 +00:00
gitea-admin 9031a97bf9 Merge pull request 'fix: migrate tailscale operator to OAuth file-based auth' (#27) from orion/auto/fix-migrate-tailscale-operator-to-oauth--1778955313506 into main
Reviewed-on: #27
2026-05-16 18:17:07 +00:00
gitea-admin c645233fe4 fix: migrate tailscale operator to OAuth file-based auth
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-16 18:15:13 +00:00
gitea-admin 256db3f6ad Merge pull request 'fix: correctly reference existing tailscale-auth secret' (#25) from orion/auto/fix-correctly-reference-existing-tailsca-1778809478719 into main
Reviewed-on: #25
2026-05-15 02:05:16 +00:00
gitea-admin 149d883b8a chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:40 +00:00
gitea-admin 0049a65d61 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 20fa2bc6fb chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 3da23d5a39 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:39 +00:00
gitea-admin 861999433a chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin c605efa2d9 chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin 48ba9f258c chore: remove stale agent-generated files (wrong namespace, superseded by operator/) 2026-05-15 02:04:38 +00:00
gitea-admin e9e929f103 fix: correct Vault path to Talos Cluster/tailscale and ESO API version 2026-05-15 02:00:06 +00:00
gitea-admin 781496c02f chore: remove duplicate tailscale-operator dir, consolidated into deployments/tailscale/operator/ 2026-05-15 01:59:57 +00:00
gitea-admin b9ea102375 chore: remove duplicate tailscale-operator dir, consolidated into deployments/tailscale/operator/ 2026-05-15 01:59:57 +00:00
gitea-admin 241a4f4241 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:14 +00:00
gitea-admin fe3ae675c8 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:14 +00:00
gitea-admin df4ea9ec06 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin ed1becbf5f chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin 608e6776ce chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin da1315ce87 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:13 +00:00
gitea-admin ad014ea92e chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin 3cec68fdae chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin 0a87cf8a50 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:12 +00:00
gitea-admin fb670a1e64 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin d7f4545de5 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin b825855497 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin 935906c256 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:11 +00:00
gitea-admin 1dae3e4618 chore: remove files from wrong directory (ArgoCD does not watch this path) 2026-05-15 01:59:10 +00:00
gitea-admin ab6adebfb5 fix: correctly reference existing tailscale-auth secret
Validate Manifests / validate (pull_request) Has been cancelled
2026-05-15 01:44:38 +00:00
gitea-admin d763511a8a Merge pull request 'feat: deploy Tailscale Operator via GitOps' (#23) from orion/auto/feat-deploy-tailscale-operator-via-gitop-1778426037111 into main
Reviewed-on: #23
2026-05-10 15:15:07 +00:00
28 changed files with 220 additions and 270 deletions
+35 -25
View File
@@ -1,10 +1,10 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
name: tailscale-operator
namespace: tailscale
spec:
replicas: 1
selector:
@@ -18,28 +18,38 @@ spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.0
image: ghcr.io/tailscale/k8s-operator:v1.78.3
imagePullPolicy: IfNotPresent
env:
- name: TS_AUTHKEY
- name: POD_NAME
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: DEPLOYMENT_TYPE
value: "k8s"
ports:
- containerPort: 8080
name: http-metrics
readinessProbe:
httpGet:
path: /metrics
port: http-metrics
initialDelaySeconds: 10
periodSeconds: 15
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 200m
memory: 256Mi
fieldRef:
apiVersion: v1
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.namespace
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
resources: {}
terminationMessagePath: /dev/termination-log
terminationMessagePolicy: File
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret
defaultMode: 0600
dnsPolicy: ClusterFirst
restartPolicy: Always
terminationGracePeriodSeconds: 30
schedulerName: default
securityContext: {}
terminationGracePeriodSeconds: 30
@@ -0,0 +1,49 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale-operator
app.kubernetes.io/part-of: infrastructure
management: gitops
managed-by: orion
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale-operator
app.kubernetes.io/part-of: infrastructure
management: gitops
managed-by: orion
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: tailscale-operator
template:
metadata:
labels:
app.kubernetes.io/name: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:1.78.1
env:
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: TS_USERSPACE
value: "true"
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
-33
View File
@@ -1,33 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
rules:
- apiGroups: [""]
resources: ["secrets", "services", "endpoints", "namespaces", "nodes"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets", "daemonsets"]
verbs: ["get", "list", "watch", "update", "patch"]
- apiGroups: ["tailscale.com"]
resources: ["*"]
verbs: ["*"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
@@ -1,14 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: orion-vault
namespace: vault
spec:
provider:
vault:
server: "http://vault.vault.svc.cluster.local:8200"
path: "secret"
auth:
agentAuth:
path: "kubernetes"
namespace: "vault"
-19
View File
@@ -1,19 +0,0 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
labels:
app: tailscale-operator
rules:
- apiGroups: [""]
resources: ["pods", "services", "secrets", "configmaps"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["apps"]
resources: ["deployments", "statefulsets"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
- apiGroups: ["discovery.k8s.io"]
resources: ["endpointslices"]
verbs: ["get", "list", "watch"]
- apiGroups: ["coordination.k8s.io"]
resources: ["leases"]
verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
@@ -1,14 +0,0 @@
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
labels:
app: tailscale-operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: apps
-9
View File
@@ -1,9 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: tailscale-operator
namespace: apps
labels:
app: tailscale-operator
data:
TS_KUBE_OBJECT_STORE: "true"
+5 -5
View File
@@ -1,4 +1,4 @@
apiVersion: external-secrets.io/v1
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: tailscale-auth
@@ -12,7 +12,7 @@ spec:
name: tailscale-auth
creationPolicy: Owner
data:
- secretKey: TS_AUTH_KEY
remoteRef:
key: tailscale
property: TS_AUTH_KEY
- secretKey: TS_AUTH_KEY
remoteRef:
key: Talos Cluster/tailscale
property: TS_AUTH_KEY
-6
View File
@@ -1,6 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: apps
labels:
name: apps
+14 -5
View File
@@ -23,13 +23,22 @@ spec:
- name: POD_NAME
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
apiVersion: v1
fieldPath: metadata.namespace
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret
@@ -1,7 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: apps
labels:
app: tailscale-operator
@@ -0,0 +1,37 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:latest
env:
- name: TS_K8S_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TS_K8S_SECRET
value: tailscale-operator-secret
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret
-12
View File
@@ -1,12 +0,0 @@
apiVersion: v1
kind: Secret
metadata:
name: tailscale-operator-secret
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
type: Opaque
data:
# TODO: Fill in the Tailscale auth key (base64 encoded)
authkey: PLACEHOLDER
+24 -16
View File
@@ -17,19 +17,27 @@ spec:
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
key: TS_AUTH_KEY
name: tailscale-auth
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: CLIENT_ID_FILE
value: /etc/tailscale/operator/client-id
- name: CLIENT_SECRET_FILE
value: /etc/tailscale/operator/client-secret
volumeMounts:
- name: operator-secret
mountPath: /etc/tailscale/operator
readOnly: true
resources: {}
volumes:
- name: operator-secret
secret:
secretName: tailscale-operator-secret
@@ -1,18 +0,0 @@
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: tailscale-auth
namespace: tailscale
spec:
refreshInterval: 1h
secretStoreRef:
name: orion-vault
kind: ClusterSecretStore
target:
name: tailscale-auth
creationPolicy: Owner
data:
- secretKey: TS_AUTH_KEY
remoteRef:
key: secret/tailscale
property: TS_AUTH_KEY
-7
View File
@@ -1,7 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
@@ -2,7 +2,7 @@ apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: apps
namespace: tailscale
labels:
app: tailscale-operator
spec:
@@ -18,13 +18,8 @@ spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:1.72.0
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: TS_AUTH_KEY
valueFrom:
secretKeyRef:
name: tailscale-auth
key: TS_AUTH_KEY
- name: POD_NAME
valueFrom:
fieldRef:
@@ -33,10 +28,15 @@ spec:
valueFrom:
fieldRef:
fieldPath: metadata.namespace
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 100m
memory: 128Mi
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret
-48
View File
@@ -1,48 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
rules:
- apiGroups: ['']
resources: ['secrets', 'services', 'endpoints']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['']
resources: ['nodes']
verbs: ['get', 'list', 'update', 'patch']
- apiGroups: ['apps']
resources: ['daemonsets']
verbs: ['get', 'list', 'watch']
- apiGroups: ['tailscale.com']
resources: ['*']
verbs: ['get', 'list', 'watch', 'create', 'update', 'patch', 'delete']
- apiGroups: ['coordination.k8s.io']
resources: ['leases']
verbs: ['get', 'create', 'update']
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: tailscale-operator
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: tailscale-operator
subjects:
- kind: ServiceAccount
name: tailscale-operator
namespace: tailscale
-18
View File
@@ -1,18 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
spec:
type: ClusterIP
ports:
- name: metrics
port: 8080
targetPort: 8080
protocol: TCP
selector:
app.kubernetes.io/name: tailscale
app.kubernetes.io/component: operator
@@ -0,0 +1,42 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: tailscale-operator
namespace: tailscale
labels:
app: tailscale-operator
spec:
replicas: 1
selector:
matchLabels:
app: tailscale-operator
template:
metadata:
labels:
app: tailscale-operator
spec:
serviceAccountName: tailscale-operator
containers:
- name: operator
image: ghcr.io/tailscale/k8s-operator:v1.78.3
env:
- name: POD_NAME
valueFrom:
fieldRef:
fieldPath: metadata.name
- name: POD_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: TS_CLIENT_ID_FILE
value: /etc/tailscale/oauth/client-id
- name: TS_CLIENT_SECRET_FILE
value: /etc/tailscale/oauth/client-secret
volumeMounts:
- name: oauth-secret
mountPath: /etc/tailscale/oauth
readOnly: true
volumes:
- name: oauth-secret
secret:
secretName: tailscale-operator-secret