Compare commits

..
48 Commits
Author SHA1 Message Date
github-actions[bot] 6bdca7eadd Update Tailscale to v1.90.1 2025-10-23 20:07:52 +00:00
Weston BliedenandGitHub 8b941b08a5 Update README for Tailscale ACAP user space mode
Removed limitation note for Tailscale ACAP user space mode.
2025-10-22 21:36:54 +02:00
Weston BliedenandGitHub d157a91bae Fix build_needed flag logic in workflow 2025-10-22 21:31:29 +02:00
Weston BliedenandGitHub b35ed437b5 Fix build_needed condition in build workflow 2025-10-22 21:25:51 +02:00
Weston BliedenandGitHub cb390384a1 Update tailscaled command to include SOCKS5 server 2025-10-22 21:18:43 +02:00
Weston BliedenandGitHub 533fc53040 Update Tailscaled command to include SOCKS5 server 2025-10-22 21:17:11 +02:00
Weston BliedenandGitHub 0a85c286b4 Merge pull request #26 from kaleaht/SOCKS5-proxy
feat: ability to route traffic to other tailnet nodes using SOCKS5 proxy
2025-10-22 21:13:05 +02:00
Ahti Kalervo d7e7b63952 feat: ability to route traffic to other tailnet nodes using SOCKS5 proxy 2025-10-22 21:55:10 +03:00
Weston BliedenandGitHub ed7643b2eb Update README.md 2025-09-29 10:53:27 +02:00
Weston BliedenandGitHub c4b24aee40 Update README.md 2025-09-29 10:51:24 +02:00
Weston BliedenandGitHub bec473f0a8 Update README.md 2025-09-29 09:35:34 +02:00
Weston BliedenandGitHub 5278677098 Update README.md 2025-09-29 09:33:20 +02:00
github-actions[bot] c21f640622 Update Tailscale to v1.88.3 2025-09-29 03:38:36 +00:00
Weston BliedenandGitHub 83e108bb05 Update README.md 2025-09-15 13:49:03 +02:00
Weston BliedenandGitHub 38d7af6c86 Update build.yml 2025-09-15 07:58:02 +02:00
github-actions[bot] 51ead4a708 Update Tailscale to v1.88.1 2025-09-15 03:41:03 +00:00
Weston BliedenandGitHub 123906c98b Update README.md 2025-08-28 12:15:15 +02:00
Weston BliedenandGitHub f6999311b7 Update build.yml 2025-08-28 12:09:50 +02:00
Weston BliedenandGitHub a95415d687 Update build.yml 2025-08-28 12:04:18 +02:00
Weston BliedenandGitHub 7d584d1a22 Update build.yml 2025-08-28 11:50:02 +02:00
Weston BliedenandGitHub e27f0cdb34 Update build.yml 2025-08-28 11:45:27 +02:00
Weston BliedenandGitHub e5954eac52 Update build.yml 2025-08-28 11:41:17 +02:00
Weston BliedenandGitHub 91a45be400 Update build.yml 2025-08-28 11:35:04 +02:00
Weston BliedenandGitHub 9b06b49fef Update build.yml 2025-08-28 11:26:37 +02:00
Weston BliedenandGitHub 811aa9e2f5 Update README.md 2025-08-27 17:14:07 +02:00
Weston BliedenandGitHub f69a1971a2 Update README.md 2025-08-27 17:12:09 +02:00
github-actions[bot] e01a2ab95f Update Tailscale to v1.86.2 2025-08-27 15:08:38 +00:00
Weston BliedenandGitHub 5b87555295 Delete all directory 2025-08-27 17:04:51 +02:00
Weston BliedenandGitHub 4a4618344a Create build.yml 2025-08-27 17:04:08 +02:00
Weston BliedenandGitHub de739dec13 Update README.md 2025-05-26 18:25:20 +02:00
Weston BliedenandGitHub ef0cb156be Update README.md 2025-05-26 18:24:37 +02:00
Weston Blieden f3556d3e76 Merge branch 'main' of https://github.com/Mo3he/Axis_Cam_Tailscale 2025-05-26 15:18:51 +02:00
Weston Blieden d5e2be837f Update To Version 1.84.0
Updated Tailscale Binaries to version 1.84.0
2025-05-26 15:18:47 +02:00
Weston BliedenandGitHub 10f5cec1dd Update README.md 2025-04-30 08:59:39 +02:00
Weston BliedenandGitHub eb46f0f201 Update README.md 2025-04-30 08:56:54 +02:00
Weston BliedenandGitHub 5a6aada216 Update README.md 2025-04-30 08:54:08 +02:00
Weston BliedenandGitHub 65509f037e Update README.md 2025-04-30 08:40:22 +02:00
Weston BliedenandGitHub 5e27f2f6ca Update README.md 2025-04-30 08:20:02 +02:00
Weston Blieden f27769f415 Added "ROOT" versions 2025-04-25 13:34:46 +02:00
Weston BliedenandGitHub b8038797f3 Update README.md 2025-04-16 19:59:46 +02:00
Weston BliedenandGitHub 07f73648bf Update README.md 2025-04-16 18:41:39 +02:00
Weston BliedenandGitHub 108ea203b4 Update README.md 2025-04-16 18:40:32 +02:00
Weston BliedenandGitHub 4b282e81e6 Update README.md 2025-04-16 18:38:50 +02:00
Weston Blieden 34943f62b9 Added custom version 2025-04-16 18:35:38 +02:00
Weston Blieden 3d12e28a1f Update binaries to 1.82.0 2025-04-11 09:51:39 +02:00
Weston BliedenandGitHub b453bcb6f2 Update README.md 2025-03-24 10:02:25 +01:00
Weston Blieden 616d270350 Update Tailscale binaries to v1.80.3 2025-03-24 10:01:38 +01:00
Weston Blieden 17c2ae705c Update Tailscale binaries to v1.78.1 2025-01-13 08:19:57 +01:00
31 changed files with 804 additions and 123 deletions
+149
View File
@@ -0,0 +1,149 @@
name: Auto Build & Release Tailscale ACAP
on:
schedule:
- cron: "0 3 * * 1" # Every Monday at 03:00 UTC
workflow_dispatch:
jobs:
build-and-release:
runs-on: ubuntu-latest
steps:
# 1. Checkout repo
- uses: actions/checkout@v3
with:
persist-credentials: true
fetch-depth: 0
# 2. Get latest Tailscale version
- name: Get latest Tailscale version
id: tailscale_version
run: |
VERSION=$(curl -s https://api.github.com/repos/tailscale/tailscale/releases/latest | jq -r .tag_name)
VERSION=${VERSION#v} # remove leading 'v'
echo "RELEASE_VERSION=$VERSION" >> $GITHUB_ENV
echo "version=$VERSION" >> $GITHUB_OUTPUT
- name: Get current repo version
id: current
run: |
CURRENT=$(find . -path "*/app/manifest.json" -exec jq -r '.acapPackageConf.setup.version' {} \; | sort -u | head -n1)
echo "CURRENT_VERSION=$CURRENT" >> $GITHUB_ENV
echo "Current repo version: $CURRENT"
- name: Compare versions
id: compare
run: |
echo "Repo version: $CURRENT_VERSION"
echo "Latest Tailscale version: $RELEASE_VERSION"
if [ "$CURRENT_VERSION" = "$RELEASE_VERSION" ]; then
echo "build_needed=false" >> $GITHUB_ENV
echo "Already up to date. Skipping build."
else
echo "build_needed=true" >> $GITHUB_ENV
echo "New version detected. Will build."
fi
# 3. Download Tailscale binaries
- name: Download Tailscale binaries
if: env.build_needed == 'true'
run: |
mkdir -p tailscale_bins
curl -L "https://pkgs.tailscale.com/stable/tailscale_${RELEASE_VERSION}_arm.tgz" -o tailscale_arm.tgz
tar -xzf tailscale_arm.tgz -C tailscale_bins --strip-components=1
mv tailscale_bins/tailscale tailscale_bins/tailscale_arm
mv tailscale_bins/tailscaled tailscale_bins/tailscaled_arm
curl -L "https://pkgs.tailscale.com/stable/tailscale_${RELEASE_VERSION}_arm64.tgz" -o tailscale_arm64.tgz
tar -xzf tailscale_arm64.tgz -C tailscale_bins --strip-components=1
mv tailscale_bins/tailscale tailscale_bins/tailscale_arm64
mv tailscale_bins/tailscaled tailscale_bins/tailscaled_arm64
# 4. Build each folder, update manifest, and copy .eap files
- name: Build all folders
if: env.build_needed == 'true'
run: |
mkdir -p build
rm -rf releases
mkdir -p releases
for folder in */ ; do
[[ ! -d "$folder/app" ]] && continue
FOLDER_NAME="${folder%/}" # remove trailing slash
echo "Processing folder $FOLDER_NAME"
# Detect architecture
if [[ "$FOLDER_NAME" == arm* ]]; then
cp tailscale_bins/tailscale_arm "$folder/app/lib/tailscale"
cp tailscale_bins/tailscaled_arm "$folder/app/lib/tailscaled"
else
cp tailscale_bins/tailscale_arm64 "$folder/app/lib/tailscale"
cp tailscale_bins/tailscaled_arm64 "$folder/app/lib/tailscaled"
fi
# Stage updated binaries for commit
git add "$folder/app/lib/tailscale" "$folder/app/lib/tailscaled"
# Detect variant suffix for .eap naming
if [[ "$FOLDER_NAME" == *_ROOT ]]; then
VARIANT="_root"
elif [[ "$FOLDER_NAME" == *_custom ]]; then
VARIANT="_custom"
else
VARIANT=""
fi
# Update manifest version
sed -i "s/\"version\": \".*\"/\"version\": \"${RELEASE_VERSION}\"/" "$folder/app/manifest.json"
# Docker build
TAG_NAME=$(echo "$FOLDER_NAME" | tr '[:upper:]' '[:lower:]' | tr '/ ' '_') # lowercase and clean
echo "Building $TAG_NAME"
docker build -f "$folder/Dockerfile" --tag "$TAG_NAME" "$folder"
# Extract .eap files into build folder
EAP_OUTPUT="./build/${TAG_NAME}"
mkdir -p "$EAP_OUTPUT"
docker cp $(docker create "$TAG_NAME"):/opt/app "$EAP_OUTPUT"
# Move all .eap files to releases folder, append variant if needed
find "$EAP_OUTPUT" -type f -name "*.eap" | while read eap; do
BASENAME=$(basename "$eap" .eap)
if [[ -n "$VARIANT" ]]; then
mv "$eap" "releases/${BASENAME}${VARIANT}.eap"
else
mv "$eap" "releases/${BASENAME}.eap"
fi
done
done
# Clean up
rm -rf build tailscale_bins *.tgz
# 5. Commit updated manifests and .eap files directly to main
- name: Commit updates to main
if: env.build_needed == 'true'
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git add */app/manifest.json releases/*
if git diff --cached --quiet; then
echo "No changes to commit"
else
git commit -m "Update Tailscale to v${RELEASE_VERSION}"
git push https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/Mo3he/Axis_Cam_Tailscale.git main
fi
# 6. Create GitHub Release with all new .eap files
- name: Create GitHub Release
if: env.build_needed == 'true'
uses: softprops/action-gh-release@v1
with:
tag_name: v${{ env.RELEASE_VERSION }}
name: "Tailscale VPN ${{ env.RELEASE_VERSION }}"
files: releases/*
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+97 -53
View File
@@ -1,99 +1,143 @@
# The Tailscale installer ACAP
# Tailscale Installer ACAP for Axis Cameras
This ACAP packages the scripts and files required to install the Tailscale VPN client on Axis Cameras.
This repository contains an **ACAP package** that installs the [Tailscale VPN client](https://tailscale.com/) on Axis cameras.
Current version 1.76.1
- ✅ Secure remote access to cameras
- ✅ Easy to install via EAP package
- ✅ Works on **Axis OS 12+** (non-root version)
- ✅ Based on **WireGuard VPN** technology
https://tailscale.com/changelog/
[![Releases](https://img.shields.io/github/v/release/Mo3he/Axis_Cam_Tailscale)](https://github.com/Mo3he/Axis_Cam_Tailscale/releases)
[![License](https://img.shields.io/github/license/Mo3he/Axis_Cam_Tailscale)](LICENSE)
[![Sponsor](https://img.shields.io/badge/sponsor-%E2%9D%A4-lightgrey?logo=github)](https://github.com/sponsors/Mo3he)
---
The "Auto Update" version has been removed since it no longer works given the files are not stored in the default location.
## 📑 Table of Contents
## Good news, everyone!
- [📥 Installation](#-installation)
- [🚀 Usage](#-usage)
- [🔄 Updating Tailscale](#-updating-tailscale)
- [🧪 Testers Needed](#-testers-needed)
- [🎉 Good News](#-good-news)
- [🎯 Purpose](#-purpose)
- [🔗 Useful Links](#-useful-links)
- [🖥️ Compatibility](#️-compatibility)
- [⭐ Star History](#-star-history)
- [💖 Support](#-support)
We have found a way to run the Tailscale ACAP without root privileges allowing it to run on Axis OS 12.
---
The changes are implemented from version 1.68.1
## 📥 Installation
Thank you for your continued support.
The recommended way is to use the **prebuilt `.eap` file** from the [Releases page](https://github.com/Mo3he/Axis_Cam_Tailscale/releases).
## Purpose
1. Log into your Axis camera.
2. Go to **Apps → Add App**.
3. Upload the `.eap` file.
Adding a VPN client directly to the camera allows secure remote access to the device without requiring any other equipment or network configuration.
Tailscale achieves this in a secure, simple to setup and easy to use way.
Tailscale is based on WireGuard VPN tunneling technology.
Once installed:
- Start the app.
- Click **Open** to view logs and get your Tailscale authentication URL.
- On uninstall, all changes/files are removed.
https://tailscale.com/blog/how-tailscale-works/
> ⚠️ You’ll need a [Tailscale account](https://tailscale.com/) to authenticate.
## Links
---
https://tailscale.com/
## 🚀 Usage
https://github.com/tailscale/tailscale
- Runs a startup script to set permissions and launch Tailscale.
- View logs via the **Open** button in the app.
- Authenticate using the provided URL.
https://www.wireguard.com/
---
https://www.axis.com/
## 🔄 Updating Tailscale
## Compatibility
- New `.eap` files are auto-built and released **weekly** (if a new Tailscale version is available).
- To update, simply install the new `.eap` over the existing one.
The Tailscale ACAP is compatable with Axis cameras with arm and aarch64 based Soc's.
### Manual update (advanced)
```
curl --anyauth "*" -u <username>:<password> <device ip>/axis-cgi/basicdeviceinfo.cgi --data "{\"apiVersion\":\"1.0\",\"context\":\"Client defined request ID\",\"method\":\"getAllProperties\"}"
Replace the binaries in the `lib/` folder:
- `tailscale`
- `tailscaled`
Download the latest versions: [Tailscale static builds](https://pkgs.tailscale.com/stable/#static)
#### Build locally
From the main directory of the version you want (`arm` / `aarch64`):
```bash
docker build --tag <package_name> .
docker cp $(docker create <package_name>):/opt/app ./build
```
where `<device ip>` is the IP address of the Axis device, `<username>` is the root username and `<password>` is the root password. Please
note that you need to enclose your password with quotes (`'`) if it contains special characters.
---
## Installing
## 🧪 Testers Needed
The recommended way to install this ACAP is to use the pre built eap file.
Go to "Apps" on the camera and click "Add app".
A new **custom** version is available:
- Allows setting a custom server and auth key (for [Headscale](https://headscale.net/)).
- Go to **Settings (⋮ → Settings)** to add your details.
Please give it a try and share your feedback!
## Using the Tailscale ACAP
---
The Tailscale ACAP will run a script on startup that sets the required permissions and starts the service and app.
Once started click "Open" to see the output of the logs for further instructions and obtain the authetication URL.
## 🎉 Good News
When uninstalling the ACAP, all changes and files are removed from the camera.
Tailscale ACAP can now run **without root privileges**, making it compatible with **Axis OS 12+**.
You will need a tailscale.com account to use the ACAP
- Runs in **user space networking mode**.
## Updating Tailscale version
For **full networking features**, use the **ROOT** version on Axis OS < 12.
The eap files will be updated from time to time and simply installing the new version over the old will update all files.
---
It's also possible to build and use a locally built image as all necesary files are provided.
## 🎯 Purpose
Replace binaries "tailscale" and "tailscaled" in lib folder with new versions.
Make sure you use the files for the correct Soc.
Adding a VPN client directly to the camera enables:
- Secure remote access without additional hardware or complex network configuration.
- Easy setup through Tailscale’s lightweight WireGuard-based tunnel.
Latest versions can be found at
🔗 Learn more: [How Tailscale Works](https://tailscale.com/blog/how-tailscale-works/)
https://pkgs.tailscale.com/stable/#static
---
## 🔗 Useful Links
To build,
From main directory of the version you want (arm/aarch64)
- [Tailscale](https://tailscale.com/)
- [Tailscale GitHub](https://github.com/tailscale/tailscale)
- [WireGuard](https://www.wireguard.com/)
- [Axis Communications](https://www.axis.com/)
```
docker build --tag <package name> .
```
```
docker cp $(docker create <package name>):/opt/app ./build
---
## 🖥️ Compatibility
The Tailscale ACAP is compatible with Axis cameras with **ARM** and **AARCH64**-based SoCs.
You can verify your device details using the following command:
```bash
curl --anyauth "*" -u <username>:<password> <device_ip>/axis-cgi/basicdeviceinfo.cgi --data '{"apiVersion":"1.0","context":"Client defined request ID","method":"getAllProperties"}'
```
Thanks to wesQ3 there is now also a version in the "all" folder with a script that simplifies the build process with the following changes.
> Replace `<device_ip>`, `<username>`, and `<password>` with your device credentials.
> Enclose your password in quotes `' '` if it contains special characters.
1. Architecture specific build directories are not required, target arch is now an argument
2. manifest files are templated as part of the build
3. Tailscale binaries are downloaded as part of the build
---
## ⭐ Star History
[![Star History Chart](https://api.star-history.com/svg?repos=Mo3he/Axis_Cam_Tailscale&type=Date)](https://www.star-history.com/#Mo3he/Axis_Cam_Tailscale&Date)
---
## 💖 Support
If you like this project and want to support future updates:
👉 [Sponsor Me](https://github.com/sponsors/Mo3he)
+2 -2
View File
@@ -3,8 +3,8 @@
echo "Starting Service"
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscale
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscaled
/usr/local/packages/Tailscale_VPN/lib/tailscaled --tun=userspace-networking --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock &
/usr/local/packages/Tailscale_VPN/lib/tailscaled --socks5-server=localhost:1055 --tun=userspace-networking --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock &
echo "Service Started"
echo "Scroll to Bottom for link"
/usr/local/packages/Tailscale_VPN/lib/tailscale --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock up
wait
wait
+1 -1
View File
@@ -8,7 +8,7 @@
"embeddedSdkVersion": "3.0",
"vendorUrl": "https://www.tailscale.com",
"runMode": "once",
"version": "1.76.1",
"version": "1.90.1",
"architecture": "aarch64"
},
"configuration": {
+12
View File
@@ -0,0 +1,12 @@
ARG ARCH=aarch64
ARG VERSION=1.3
ARG UBUNTU_VERSION=22.04
ARG REPO=axisecp
ARG SDK=acap-native-sdk
FROM ${REPO}/${SDK}:${VERSION}-${ARCH}-ubuntu${UBUNTU_VERSION}
# Building the ACAP application
COPY ./app /opt/app/
WORKDIR /opt/app
RUN . /opt/axis/acapsdk/environment-setup* && acap-build ./
+5
View File
@@ -0,0 +1,5 @@
To build, from main directory
docker build --tag aarch64 .
docker cp $(docker create aarch64):/opt/app ./build
+10
View File
@@ -0,0 +1,10 @@
#!/bin/sh
echo "Starting Service"
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscale
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscaled
/usr/local/packages/Tailscale_VPN/lib/tailscaled &
echo "Service Started"
echo "Scroll to Bottom for link"
/usr/local/packages/Tailscale_VPN/lib/tailscale up --accept-routes
wait
@@ -16,4 +16,4 @@
</body>
</body>
</html>
</html>
@@ -6,13 +6,17 @@
"friendlyName": "Tailscale VPN",
"vendor": "Tailscale - Packaged by Mo3he",
"embeddedSdkVersion": "3.0",
"user": {
"group": "root",
"username": "root"
},
"vendorUrl": "https://www.tailscale.com",
"runMode": "once",
"version": "@@TAILSCALE_VERSION@@",
"architecture": "@@ARCH@@"
"version": "1.90.1",
"architecture": "aarch64"
},
"configuration": {
"settingPage": "index.html"
}
}
}
}
+12
View File
@@ -0,0 +1,12 @@
ARG ARCH=aarch64
ARG VERSION=12.3.0
ARG UBUNTU_VERSION=24.04
ARG REPO=axisecp
ARG SDK=acap-native-sdk
FROM ${REPO}/${SDK}:${VERSION}-${ARCH}-ubuntu${UBUNTU_VERSION}
# Building the ACAP application
COPY ./app /opt/app/
WORKDIR /opt/app
RUN . /opt/axis/acapsdk/environment-setup* && acap-build .
+5
View File
@@ -0,0 +1,5 @@
To build, from main directory
docker build --tag aarch64 .
docker cp $(docker create aarch64):/opt/app ./build
+29
View File
@@ -0,0 +1,29 @@
BSD 3-Clause License
Copyright (c) 2020 Tailscale & AUTHORS.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
1. Redistributions of source code must retain the above copyright notice, this
list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright notice,
this list of conditions and the following disclaimer in the documentation
and/or other materials provided with the distribution.
3. Neither the name of the copyright holder nor the names of its
contributors may be used to endorse or promote products derived from
this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+29
View File
@@ -0,0 +1,29 @@
PROGS = serverconfig
SRCS = config_updater.c
OBJS = $(SRCS:.c=.o)
PKGS = glib-2.0 gio-2.0 axparameter
CFLAGS += $(shell PKG_CONFIG_PATH=$(PKG_CONFIG_PATH) pkg-config --cflags $(PKGS))
LDLIBS += $(shell PKG_CONFIG_PATH=$(PKG_CONFIG_PATH) pkg-config --libs $(PKGS))
CFLAGS += -Wall \
-Wextra \
-Wformat=2 \
-Wpointer-arith \
-Wbad-function-cast \
-Wstrict-prototypes \
-Wmissing-prototypes \
-Winline \
-Wdisabled-optimization \
-Wfloat-equal \
-W \
-Werror
all: $(PROGS)
$(PROGS): $(OBJS)
$(CC) $(LDFLAGS) $^ $(LIBS) $(LDLIBS) -o $@
clean:
rm -f $(PROGS) *.o *.eap* *_LICENSE.txt package.conf* param.conf tmp*
+232
View File
@@ -0,0 +1,232 @@
/**
* Simple file-based configuration updater for Tailscale
* This avoids the AXParameter system and just writes directly to a config file
*/
#include <axsdk/axparameter.h>
#include <glib-unix.h>
#include <stdbool.h>
#include <syslog.h>
#include <string.h>
#include <stdlib.h>
#include <stdio.h>
#include <unistd.h>
#include <sys/types.h>
#include <sys/wait.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <errno.h>
#define APP_NAME "serverconfig"
#define CONFIG_FILE "/usr/local/packages/serverconfig/config.txt"
#define SCRIPT_PATH "/usr/local/packages/serverconfig/start_tailscale.sh"
#define SCRIPT_SOURCE "/usr/local/packages/serverconfig/lib/start_tailscale.sh"
static gboolean signal_handler(gpointer loop) {
g_main_loop_quit((GMainLoop*)loop);
syslog(LOG_INFO, "Configuration updater stopping.");
return G_SOURCE_REMOVE;
}
// Copy script from lib folder to main directory
static void copy_script_file(void) {
char buffer[4096];
ssize_t bytes_read, bytes_written;
int source_fd, dest_fd;
syslog(LOG_INFO, "Copying script from %s to %s", SCRIPT_SOURCE, SCRIPT_PATH);
// Open source file
source_fd = open(SCRIPT_SOURCE, O_RDONLY);
if (source_fd < 0) {
syslog(LOG_ERR, "Failed to open source script: %s", strerror(errno));
return;
}
// Open destination file (create if doesn't exist, truncate if exists)
dest_fd = open(SCRIPT_PATH, O_WRONLY | O_CREAT | O_TRUNC, 0755);
if (dest_fd < 0) {
syslog(LOG_ERR, "Failed to open destination script: %s", strerror(errno));
close(source_fd);
return;
}
// Copy the file
while ((bytes_read = read(source_fd, buffer, sizeof(buffer))) > 0) {
bytes_written = write(dest_fd, buffer, bytes_read);
if (bytes_written != bytes_read) {
syslog(LOG_ERR, "Error writing to destination file: %s", strerror(errno));
close(source_fd);
close(dest_fd);
return;
}
}
// Close file descriptors
close(source_fd);
close(dest_fd);
// Make the script executable
if (chmod(SCRIPT_PATH, 0755) != 0) {
syslog(LOG_ERR, "Failed to make script executable: %s", strerror(errno));
return;
}
syslog(LOG_INFO, "Script copied and made executable successfully");
}
// Execute the Tailscale script
static void start_tailscale(void) {
syslog(LOG_INFO, "Starting Tailscale VPN script");
// Check if script exists, if not, copy it
struct stat st;
if (stat(SCRIPT_PATH, &st) != 0) {
syslog(LOG_INFO, "Script not found at %s, copying from lib folder", SCRIPT_PATH);
copy_script_file();
}
// Fork and execute the script
pid_t pid = fork();
if (pid < 0) {
syslog(LOG_ERR, "Failed to fork for Tailscale script: %s", strerror(errno));
return;
} else if (pid == 0) {
// Child process - execute the script
execl(SCRIPT_PATH, "start_tailscale.sh", NULL);
// If we get here, execl failed
syslog(LOG_ERR, "Failed to execute Tailscale script: %s", strerror(errno));
_exit(1);
}
syslog(LOG_INFO, "Tailscale script started with PID: %d", pid);
}
// Update the configuration file with current parameter values
static void update_config_file(AXParameter* handle) {
GError* error = NULL;
gchar* server_value = NULL;
gchar* key_value = NULL;
FILE* file;
// Get parameter values
if (!ax_parameter_get(handle, "CustomServer", &server_value, &error)) {
syslog(LOG_ERR, "Failed to get CustomServer: %s",
error ? error->message : "unknown error");
if (error) g_error_free(error);
error = NULL;
server_value = g_strdup("");
}
if (!ax_parameter_get(handle, "AuthKey", &key_value, &error)) {
syslog(LOG_ERR, "Failed to get AuthKey: %s",
error ? error->message : "unknown error");
if (error) g_error_free(error);
key_value = g_strdup("");
}
// Write to config file
file = fopen(CONFIG_FILE, "w");
if (file) {
fprintf(file, "custom_server=%s\n", server_value ? server_value : "");
fprintf(file, "auth_key=%s\n", key_value ? key_value : "");
fclose(file);
// Set permissions to ensure the file is readable
chmod(CONFIG_FILE, 0644);
syslog(LOG_INFO, "Updated configuration file: custom_server=%s",
server_value ? server_value : "");
syslog(LOG_INFO, "Updated configuration file: auth_key=%s",
key_value && strlen(key_value) > 0 ? "(set)" : "(empty)");
} else {
syslog(LOG_ERR, "Failed to open config file for writing");
}
// Clean up
g_free(server_value);
g_free(key_value);
}
// Handle parameter changes
static void parameter_changed(const gchar* name, const gchar* value, gpointer handle_void_ptr) {
AXParameter* handle = handle_void_ptr;
// Extract simple parameter name from the fully qualified name
const char* simple_name = name;
const char* prefix = "root." APP_NAME ".";
if (strncmp(name, prefix, strlen(prefix)) == 0) {
simple_name = name + strlen(prefix);
}
syslog(LOG_INFO, "Parameter changed: %s = %s", simple_name, value);
// Update config file whenever any parameter changes
update_config_file(handle);
// Restart Tailscale to apply the new settings
start_tailscale();
}
int main(void) {
GError* error = NULL;
GMainLoop* loop = NULL;
// Open syslog for logging
openlog(APP_NAME, LOG_PID, LOG_USER);
syslog(LOG_INFO, "Config updater starting");
// Initialize parameter handling
AXParameter* handle = ax_parameter_new(APP_NAME, &error);
if (handle == NULL) {
syslog(LOG_ERR, "Failed to initialize parameters: %s",
error ? error->message : "unknown error");
if (error) g_error_free(error);
exit(1);
}
// Ensure script is copied from lib folder
copy_script_file();
// Create initial config file
update_config_file(handle);
// Start Tailscale VPN script
start_tailscale();
// Register for parameter changes
if (!ax_parameter_register_callback(handle, "CustomServer", parameter_changed, handle, &error)) {
syslog(LOG_ERR, "Failed to register CustomServer callback: %s",
error ? error->message : "unknown error");
if (error) g_error_free(error);
error = NULL;
}
if (!ax_parameter_register_callback(handle, "AuthKey", parameter_changed, handle, &error)) {
syslog(LOG_ERR, "Failed to register AuthKey callback: %s",
error ? error->message : "unknown error");
if (error) g_error_free(error);
}
// Register for parameter changes with fully qualified names as fallback
if (!ax_parameter_register_callback(handle, "root." APP_NAME ".CustomServer", parameter_changed, handle, NULL)) {
syslog(LOG_INFO, "Fallback CustomServer registration failed (this may be normal)");
}
if (!ax_parameter_register_callback(handle, "root." APP_NAME ".AuthKey", parameter_changed, handle, NULL)) {
syslog(LOG_INFO, "Fallback AuthKey registration failed (this may be normal)");
}
// Set up main loop
loop = g_main_loop_new(NULL, FALSE);
g_unix_signal_add(SIGTERM, signal_handler, loop);
g_unix_signal_add(SIGINT, signal_handler, loop);
syslog(LOG_INFO, "Config updater running. Waiting for parameter changes...");
g_main_loop_run(loop);
// Clean up
g_main_loop_unref(loop);
ax_parameter_free(handle);
return 0;
}
+19
View File
@@ -0,0 +1,19 @@
<!DOCTYPE html>
<html>
<body>
<head>
<h1 style="color:red;">Scroll to the bottom to find authentication URL</h1>
<script>
function refreshIFrame() {
var x = document.getElementById("*Your_iframe_id*");
x.contentWindow.location.reload();
var t = setTimeout(refreshIFrame, 5000);
}
</script>
</head>
<body onload="refreshIFrame()">
<iframe id="*Your_iframe_id*" src= "/axis-cgi/admin/systemlog.cgi?appname=serverconfig" style="height:600px;width:100%;border: none;" ></iframe>
</body>
</body>
</html>
+64
View File
@@ -0,0 +1,64 @@
#!/bin/sh
# Make sure this script terminates any existing Tailscale processes before starting new ones
# Kill any existing tailscaled processes
pkill -f tailscaled || true
# Simple script to start Tailscale with custom configuration
CONFIG_FILE="/usr/local/packages/serverconfig/config.txt"
TAILSCALED_PATH="/usr/local/packages/serverconfig/lib/tailscaled"
TAILSCALE_PATH="/usr/local/packages/serverconfig/lib/tailscale"
SOCKET_PATH="/usr/local/packages/serverconfig/tailscaled.sock"
# Log to syslog
logger -t "tailscale_script" "Starting Tailscale VPN service"
# Set execute permissions
chmod 755 $TAILSCALED_PATH
chmod 755 $TAILSCALE_PATH
# Read configuration (if exists)
CUSTOM_SERVER=""
AUTH_KEY=""
if [ -f "$CONFIG_FILE" ]; then
logger -t "tailscale_script" "Reading configuration from $CONFIG_FILE"
# Read values from config file
while IFS='=' read -r key value; do
case "$key" in
"custom_server") CUSTOM_SERVER="$value" ;;
"auth_key") AUTH_KEY="$value" ;;
esac
done < "$CONFIG_FILE"
fi
# Start tailscaled
logger -t "tailscale_script" "Starting tailscaled daemon"
$TAILSCALED_PATH --socks5-server=localhost:1055 --tun=userspace-networking --socket=$SOCKET_PATH &
TAILSCALED_PID=$!
# Wait for tailscaled to initialize
sleep 2
# Build up the command based on available parameters
TAILSCALE_CMD="$TAILSCALE_PATH --socket=$SOCKET_PATH up"
if [ -n "$CUSTOM_SERVER" ]; then
logger -t "tailscale_script" "Using custom server: $CUSTOM_SERVER"
TAILSCALE_CMD="$TAILSCALE_CMD --login-server $CUSTOM_SERVER"
fi
if [ -n "$AUTH_KEY" ]; then
logger -t "tailscale_script" "Using authentication key"
TAILSCALE_CMD="$TAILSCALE_CMD --authkey $AUTH_KEY"
fi
# Connect to Tailscale network
logger -t "tailscale_script" "Running: $TAILSCALE_CMD"
eval $TAILSCALE_CMD
# Keep the script running to maintain the tailscaled process
logger -t "tailscale_script" "Tailscale VPN is running"
logger -t "tailscale_script" "To change settings, modify parameters in ACAP web interface"
# Wait for tailscaled process to exit
wait $TAILSCALED_PID
+29
View File
@@ -0,0 +1,29 @@
{
"schemaVersion": "1.7.3",
"acapPackageConf": {
"setup": {
"friendlyName": "Tailscale VPN",
"appName": "serverconfig",
"vendor": "Tailscale - Packaged by Mo3he",
"embeddedSdkVersion": "3.0",
"vendorUrl": "https://www.tailscale.com",
"runMode": "respawn",
"version": "1.90.1"
},
"configuration": {
"settingPage": "index.html",
"paramConfig": [
{
"name": "CustomServer",
"default": "",
"type": "string"
},
{
"name": "AuthKey",
"default": "",
"type": "string"
}
]
}
}
}
-32
View File
@@ -1,32 +0,0 @@
# example usage:
# docker build --build-arg ARCH=armv7hf --build-arg TAILSCALE_VERSION=1.70.0 -t axis_tailscale:latest .
# docker cp $(docker create axis_tailscale):/opt/app ./build
ARG REPO=axisecp
ARG SDK=acap-native-sdk
ARG VERSION=1.3
ARG ARCH=armv7hf
ARG UBUNTU_VERSION=22.04
FROM ${REPO}/${SDK}:${VERSION}-${ARCH}-ubuntu${UBUNTU_VERSION}
WORKDIR /opt/app
COPY ./app /opt/app/
ARG ARCH=armv7hf
ARG TAILSCALE_VERSION=1.68.1
# template files
RUN sed -i "s/@@ARCH@@/${ARCH}/g" /opt/app/manifest.json \
&& sed -i "s/@@TAILSCALE_VERSION@@/${TAILSCALE_VERSION}/g" /opt/app/manifest.json
# tailscale uses "arm(64)" instead of the more specific arm arch names
RUN \
if [ "${ARCH}" = "armv7hf" ]; then TAILSCALE_ARCH="arm"; \
elif [ "${ARCH}" = "aarch64" ]; then TAILSCALE_ARCH="arm64"; \
else TAILSCALE_ARCH="${ARCH}"; fi \
&& curl -sS --fail -L -o /tmp/tailscale.tgz https://pkgs.tailscale.com/stable/tailscale_${TAILSCALE_VERSION}_${TAILSCALE_ARCH}.tgz \
&& mkdir -p /opt/app/lib \
&& tar xzf /tmp/tailscale.tgz -C /opt/app/lib --strip-components=1 --wildcards --no-anchored '*/tailscale' '*/tailscaled' \
&& rm /tmp/tailscale.tgz
RUN . /opt/axis/acapsdk/environment-setup* && acap-build ./
-18
View File
@@ -1,18 +0,0 @@
# Building
Set your preferred build parameters via the docker build command.
* `ARCH` - use the Axis architecture string you can fetch from `/axis-cgi/param.cgi?action=list&group=Properties.System.Architecture`
* `TAILSCALE_VERSION` - Specify the version string as it appears on the [Tailscale archive](https://pkgs.tailscale.com/stable/#static)
Tailscale arm arch strings are different than the axis format. The Dockerfile has some mappings for common strings.
```
docker build --build-arg ARCH=armv7hf --build-arg TAILSCALE_VERSION=1.70.0 -t axis_tailscale:latest .
```
Then copy out the build artifacts:
```
docker cp $(docker create axis_tailscale):/opt/app ./build
```
-10
View File
@@ -1,10 +0,0 @@
#!/bin/sh
echo "Starting Service"
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscale
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscaled
/usr/local/packages/Tailscale_VPN/lib/tailscaled --tun=userspace-networking --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock &
echo "Service Started"
echo "Scroll to Bottom for link"
/usr/local/packages/Tailscale_VPN/lib/tailscale --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock up
wait
+2 -2
View File
@@ -3,8 +3,8 @@
echo "Starting Service"
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscale
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscaled
/usr/local/packages/Tailscale_VPN/lib/tailscaled --tun=userspace-networking --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock &
/usr/local/packages/Tailscale_VPN/lib/tailscaled --socks5-server=localhost:1055 --tun=userspace-networking --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock &
echo "Service Started"
echo "Scroll to Bottom for link"
/usr/local/packages/Tailscale_VPN/lib/tailscale --socket=/usr/local/packages/Tailscale_VPN/tailscaled.sock up
wait
wait
+1 -1
View File
@@ -8,7 +8,7 @@
"embeddedSdkVersion": "3.0",
"vendorUrl": "https://www.tailscale.com",
"runMode": "once",
"version": "1.76.1",
"version": "1.90.1",
"architecture": "armv7hf"
},
"configuration": {
+12
View File
@@ -0,0 +1,12 @@
ARG ARCH=armv7hf
ARG VERSION=1.3
ARG UBUNTU_VERSION=22.04
ARG REPO=axisecp
ARG SDK=acap-native-sdk
FROM ${REPO}/${SDK}:${VERSION}-${ARCH}-ubuntu${UBUNTU_VERSION}
# Building the ACAP application
COPY ./app /opt/app/
WORKDIR /opt/app
RUN . /opt/axis/acapsdk/environment-setup* && acap-build ./
+5
View File
@@ -0,0 +1,5 @@
To build from main directory
docker build --tag arm .
docker cp $(docker create arm):/opt/app ./build
+29
View File
@@ -0,0 +1,29 @@
BSD 3-Clause License
Copyright (c) 2020 Tailscale & AUTHORS.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
1. Redistributions of source code must retain the above copyright notice, this
list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright notice,
this list of conditions and the following disclaimer in the documentation
and/or other materials provided with the distribution.
3. Neither the name of the copyright holder nor the names of its
contributors may be used to endorse or promote products derived from
this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+1
View File
@@ -0,0 +1 @@
nop:
+10
View File
@@ -0,0 +1,10 @@
#!/bin/sh
echo "Starting Service"
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscale
chmod 777 /usr/local/packages/Tailscale_VPN/lib/tailscaled
/usr/local/packages/Tailscale_VPN/lib/tailscaled &
echo "Service Started"
echo "Scroll to Bottom for link"
/usr/local/packages/Tailscale_VPN/lib/tailscale up --accept-routes
wait
+19
View File
@@ -0,0 +1,19 @@
<!DOCTYPE html>
<html>
<body>
<head>
<h1 style="color:red;">Scroll to the bottom to find authentication URL</h1>
<script>
function refreshIFrame() {
var x = document.getElementById("*Your_iframe_id*");
x.contentWindow.location.reload();
var t = setTimeout(refreshIFrame, 5000);
}
</script>
</head>
<body onload="refreshIFrame()">
<iframe id="*Your_iframe_id*" src= "/axis-cgi/admin/systemlog.cgi?appname=Tailscale_VPN" style="height:600px;width:100%;border: none;" ></iframe>
</body>
</body>
</html>
+22
View File
@@ -0,0 +1,22 @@
{
"schemaVersion": "1.3",
"acapPackageConf": {
"setup": {
"appName": "Tailscale_VPN",
"friendlyName": "Tailscale VPN",
"vendor": "Tailscale - Packaged by Mo3he",
"embeddedSdkVersion": "3.0",
"user": {
"group": "root",
"username": "root"
},
"vendorUrl": "https://www.tailscale.com",
"runMode": "once",
"version": "1.90.1",
"architecture": "armv7hf"
},
"configuration": {
"settingPage": "index.html"
}
}
}