Tailscale settings lost on reboot

I asked the same of my ddns client when I’m benind addn’l upstream routers:

root@GL-AX1800:~# cat /etc/rc.local
# Put your custom commands here that should be executed once
# the system init finished. By default this file does nothing.

. /lib/functions/gl_util.sh

/usr/lib/ddns/dynamic_dns_updater.sh -S desec_ipv4 start &

exit 0
root@GL-AX1800:~# ps -w | grep ddns
19182 root      1376 S    /bin/sh /usr/lib/ddns/dynamic_dns_updater.sh -S desec_ipv4 start

You run the risk of it choking in rc.local & inadvertently stalling the full boot process. If it’s a true ‘one shot’ as you describe it’ll exit fr the bg processes automatically anyways.

It’s a workaround not a solution. 4 days ago:

Adding the “&” to fork to background didn’t work on reboot. Routes and exit node config still overwritten.

Do you know the file location for the conf? It can be checked for its existence & if so, deleted/moved/renamed/whatever before launching w/ your specific string.

No, haven’t found it. The /etc/init.d/tailscale file has the tailscaled startup but I can’t find the tailscale up xxxx config anywhere.

The params might be being passed by /etc/init.d/tailscale; reboot it as if using TS via GL GUI & chk ps -w | grep tail

Its exactly as per the init.d file:

root@GL-AX1800:/# ps -w | grep tail
12659 root      670m S    /usr/sbin/tailscaled --port 41641 --state /etc/tailscale/tailscaled.state

tailscale up xxxx is never called. Not sure how the UI passes the selections re. routes that it configures.

Ohh… that’s interesting; cat & post the output, pls.

That file contains the hashed connection info so probably shouldn’t post! But no config in that file.

You can always redact details as needed before posting.

I think at this stage I need a way to run the tailscale up command after tailscaled has come up. That /etc/rc.local is not working for me…

I added this to the startup script to find whats running at start:

ps -w | grep tail > /tmp/tailscale.info &

root@GL-AX1800:~# cat /tmp/tailscale.info
 4750 root      1176 S    /bin/sh /usr/bin/gl_tailscale restart
 4752 root      1312 S    /bin/sh /etc/rc.common /etc/init.d/tailscale restart
 4776 root      794m S    /usr/sbin/tailscaled --port 41641 --state /etc/tailscale/tailscaled.state
 4777 root      1304 S    /bin/sh /etc/rc.common /etc/init.d/tailscale running
 4797 root      794m S    /usr/sbin/tailscaled --cleanup
 4879 root      1172 S    /bin/sh /usr/bin/gl_tailscale set_route
 5313 root      1172 S    grep tail

It looks as though its being configured via:

/bin/sh /usr/bin/gl_tailscale set_route

My Flint is running f/w 4.2.3-release5. Try adding some custom params to the launching shell script. You might not even need rc.local:

root@GL-AX1800:~# cat /etc/init.d/tailscale
#!/bin/sh /etc/rc.common

# Copyright 2020 Google LLC.
# Copyright (C) 2021 CZ.NIC z.s.p.o. (https://www.nic.cz/)
# SPDX-License-Identifier: Apache-2.0


start_service() {
  local state_file
  local port
  local std_err std_out

  config_load tailscale
  config_get_bool std_out "settings" log_stdout 1
  config_get_bool std_err "settings" log_stderr 1
  config_get port "settings" port 41641
  config_get state_file "settings" state_file /etc/tailscale/tailscaled.state

  /usr/sbin/tailscaled --cleanup
  config_get enabled "settings" enabled 0
  if [ "$enabled" -eq "1" ];then
        procd_set_param command /usr/sbin/tailscaled

        # Set the port to listen on for incoming VPN packets.
        # Remote nodes will automatically be informed about the new port number,
        # but you might want to configure this in order to set external firewall
        # settings.
        procd_append_param command --port "$port"
        procd_append_param command --state "$state_file"

        # my custom params
        procd_append_param command --advertise-routes ""
        # ... & so on, & so forth....
        # // end my custom params

        procd_set_param respawn
        procd_set_param stdout "$std_out"
        procd_set_param stderr "$std_err"


That wont work unfortunately… The init.d file runs tailscaled not tailscale - there is no --advertise-routes etc for the daemon process. The tailscale binary is the cli interface to the tailscale daemon process.

/usr/bin/gl_tailscale must be running the tailscale up xxxx command after it pulls config info that has been set via the UI.

Yeah I see that now after you posted that dir list. The more I look at this the more it seems all so familar:

This is untested code to enable exit nodes I never got feedback on from someone else but here:

sed '/param="$param --exit-node-allow-lan-access --exit-node=$exit_node_ip"/a\                        param=“$param --advertise-exit-node --allow-exit-node --allow-routes”' /usr/bin/gl_tailscale >> \
 /usr/bin/gl_tailscale.new && mv /usr/bin/gl_tailscale /usr/bin/gl_tailscale.stock \
&& mv /usr/bin/gl_tailscale.new /usr/bin/gl_tailscale && chmod +x /usr/bin/gl_tailscale

It’ll add more the launch string of /usr/bin/gl_tailscale @ this if statement/code block:

                if [ -n "$exit_node_ip" ];then
                        param="$param --exit-node-allow-lan-access --exit-node=$exit_node_ip"
                        # new params added here by the `sed` search & replace

You can add your params there or by adding more to the second half of that above sed command.

I hadn’t realised /usr/bin/gl_tailscale was a script! I assumed it was a binary - I’ll check out what you have posted above but this will definitely fix things for me.

This fixed it for me! I ended up just hardcoding my tailscale up command line into /usr/sbin/gl_tailscale and it now works on reboot.

I’m glad you got it sorted… I was always curious if such a simple edit would work (I don’t use Tailscale). I look forward to you marking my post as the ‘Solution’.

There’s no --allow-routes as I see, you mean --accept-routes surely?

Damned if I know. That param was copied fr some one else. Like I said, I don’t use Tailscale.