From 3b3085a44d793e6abf699580c39c48da40a4a311 Mon Sep 17 00:00:00 2001 From: val Date: Sat, 29 Aug 2026 11:27:29 +0200 Subject: [PATCH] expiry moved from oidc to node --- abra.sh | 2 +- config.yaml.tmpl | 48 ++++++++++++++++++++++++++++++++++++++++-------- 2 files changed, 41 insertions(+), 9 deletions(-) diff --git a/abra.sh b/abra.sh index 37cb80a..9b619ec 100755 --- a/abra.sh +++ b/abra.sh @@ -1,3 +1,3 @@ # Set any config versions here # Docs: https://docs.coopcloud.tech/maintainers/handbook/#manage-configs -export CONFIG_YAML_VERSION=v6 +export CONFIG_YAML_VERSION=v7 diff --git a/config.yaml.tmpl b/config.yaml.tmpl index b3a1861..78eee9c 100644 --- a/config.yaml.tmpl +++ b/config.yaml.tmpl @@ -134,8 +134,45 @@ derp: # Disables the automatic check for headscale updates on startup disable_check_updates: false -# Time before an inactive ephemeral node is deleted? -ephemeral_node_inactivity_timeout: 30m +# Node lifecycle configuration. +node: + # Default key expiry for non-tagged nodes, regardless of registration method + # (auth key, CLI, web auth). Tagged nodes are exempt and never expire. + # + # This is the base default. OIDC can override this via oidc.expiry. + # If a client explicitly requests a specific expiry, the client value is used. + # + # Setting the value to "0" means no default expiry (nodes never expire unless + # explicitly expired via `headscale nodes expire`). + # + # Tailscale SaaS uses 180d; set to a positive duration to match that behaviour. + # + # Default: 0 (no default expiry) + expiry: {{ env "EXPIRY" }} + + ephemeral: + # Time before an inactive ephemeral node is deleted. + inactivity_timeout: 30m + + # HA subnet router health probing. + # + # When HA routes exist (2+ nodes advertising the same prefix), headscale + # pings each HA node every probe_interval via the Noise channel. If a node + # fails to respond within probe_timeout it is marked unhealthy and the + # primary role moves to the next healthy node. A node that later responds + # is marked healthy again but does NOT reclaim primary (avoids flapping). + # + # Worst-case detection time is probe_interval + probe_timeout (15s default). + # No-op when no HA routes exist. Set probe_interval to 0 to disable. + routes: + ha: + # How often to ping HA subnet routers. Set to 0 to disable probing. + # Must be >= 2s when enabled. + probe_interval: 10s + + # How long to wait for a ping response before marking a node unhealthy. + # Must be >= 1s and less than probe_interval. + probe_timeout: 5s database: # Database type. Available options: sqlite, postgres @@ -345,15 +382,10 @@ oidc: # `LoadCredential` straightforward: client_secret_path: "/run/secrets/oidc_client_key" - # The amount of time a node is authenticated with OpenID until it expires - # and needs to reauthenticate. - # Setting the value to "0" will mean no expiry. - expiry: {{ env "EXPIRY" }} - # Use the expiry from the token received from OpenID when the user logged # in. This will typically lead to frequent need to reauthenticate and should # only be enabled if you know what you are doing. - # Note: enabling this will cause `oidc.expiry` to be ignored. + # Note: enabling this will cause `node.expiry` to be ignored for use_expiry_from_token: false # The OIDC scopes to use, defaults to "openid", "profile" and "email". -- 2.54.0