Compare commits

..
8 Commits
Author SHA1 Message Date
github-actions[bot] e17549fef0 Update Tailscale to v1.102.2 2026-08-05 03:36:20 +00:00
github-actions[bot] 3a71aba342 Update Tailscale to v1.102.1 2026-08-04 03:35:42 +00:00
github-actions[bot] dce8beaa1b Update Tailscale to v1.98.10 2026-07-29 06:32:18 +00:00
Weston Blieden b70d664f91 fix: use Mo3he vendor name in ROOT manifests to pass schema validation 2026-07-29 08:15:03 +02:00
Weston Blieden 9ea88ccd0d docs: extend verified OS range to 13 (intro + roadmap) 2026-07-24 13:06:32 +02:00
Weston Blieden f79f631d95 docs: note verified on AXIS OS 13 (13.0.0, aarch64) 2026-07-24 13:03:13 +02:00
Weston Blieden 835ccff82f docs: add Advertise Routes (Subnet Router) to README config table 2026-07-21 19:44:51 +02:00
Weston Blieden 92262bd16c Update vendor to moshe@mohome.net and vendorId for ACAP signing
Packages are now signed with the Axis ACAP signing service. Document the
signing change and the upgrade steps (back up config and uninstall the old
version to avoid the "Vendor ID in manifest does not match" install error)
in the README and changelog.
2026-07-21 19:35:05 +02:00
7 changed files with 38 additions and 14 deletions
+11
View File
@@ -5,6 +5,17 @@ links to its full release notes on GitHub.
The format is based on [Keep a Changelog](https://keepachangelog.com/). The format is based on [Keep a Changelog](https://keepachangelog.com/).
## [1.98.9-Signed] - 2026-07-21 - Tailscale VPN 1.98.9 (Signed)
- Packages are now signed with the Axis ACAP signing service and install
normally on AXIS OS 12.10 and later.
- Vendor updated to `moshe@mohome.net` with the registered vendor ID.
- `root` and `acap3` variants remain unsigned (manifest schema v1.x).
- Upgrading from an earlier unsigned version can fail with "Couldn't
install: app" (device log: "Vendor ID in manifest does not match the
vendor ID of the previous version"). Back up your config, uninstall the
old version, then install this one.
## [1.98.8-2] - 2026-07-03 - Tailscale VPN 1.98.8-2 ## [1.98.8-2] - 2026-07-03 - Tailscale VPN 1.98.8-2
## [1.98.8-subnet-routing] - 2026-07-01 - Tailscale VPN 1.98.8 - Subnet Routing ## [1.98.8-subnet-routing] - 2026-07-01 - Tailscale VPN 1.98.8 - Subnet Routing
+17 -4
View File
@@ -46,7 +46,7 @@ lightweight WireGuard-based tunnel.
- Secure remote access to cameras. - Secure remote access to cameras.
- Easy to install via EAP package. - Easy to install via EAP package.
- Works on **AXIS OS 10.12+** (non-root version, verified across 10.12–12.10). - Works on **AXIS OS 10.12+** (non-root version, verified across 10.12–13).
- Works on **legacy AXIS OS 9.x / 10.x** via the ACAP 3 variant. - Works on **legacy AXIS OS 9.x / 10.x** via the ACAP 3 variant.
- Based on **WireGuard VPN** technology. - Based on **WireGuard VPN** technology.
@@ -71,8 +71,19 @@ access for third-party applications). Learn more:
> root access for ACAPs). Use the **ACAP 3** build only on legacy cameras that > root access for ACAPs). Use the **ACAP 3** build only on legacy cameras that
> don't support ACAP 4 (AXIS OS 9–10). > don't support ACAP 4 (AXIS OS 9–10).
**Verified on AXIS OS 13** (13.0.0, aarch64).
## Installation ## Installation
> **Signed packages:** Release `.eap` files are signed with the Axis ACAP
> signing service and install normally on AXIS OS 12.10 and later.
>
> **Upgrading from an earlier version?** The signing vendor changed, so
> installing over a previously installed unsigned build can fail with
> **"Couldn't install: app"** (device log: *"Vendor ID in manifest does not
> match the vendor ID of the previous version"*). To upgrade: back up your app
> configuration, **uninstall** the old version, then install the signed one.
Get the **prebuilt `.eap` file** from the Get the **prebuilt `.eap` file** from the
[Releases page](https://github.com/Mo3he/Axis_Cam_Tailscale/releases). [Releases page](https://github.com/Mo3he/Axis_Cam_Tailscale/releases).
@@ -107,6 +118,7 @@ take effect immediately:
| SOCKS5 Proxy Port | `1080` | Port for the outbound SOCKS5 proxy. | | SOCKS5 Proxy Port | `1080` | Port for the outbound SOCKS5 proxy. |
| Accept DNS | `off` | Passes `--accept-dns=true` to `tailscale up`. Allows the tailnet to push DNS settings to the camera. Not available on `armv7hf_acap3`. | | Accept DNS | `off` | Passes `--accept-dns=true` to `tailscale up`. Allows the tailnet to push DNS settings to the camera. Not available on `armv7hf_acap3`. |
| Accept Routes | `off` | Passes `--accept-routes=true` to `tailscale up`. Allows the camera to use subnet routes advertised by other nodes. Not available on `armv7hf_acap3`. | | Accept Routes | `off` | Passes `--accept-routes=true` to `tailscale up`. Allows the camera to use subnet routes advertised by other nodes. Not available on `armv7hf_acap3`. |
| Advertise Routes (Subnet Router) | *(empty)* | Comma-separated CIDRs (e.g. `192.168.1.0/24,10.0.0.0/8`) this camera will route for the tailnet, turning it into a subnet router. Approve the routes in the Tailscale admin console after saving. Leave blank to disable. |
## Ports & security ## Ports & security
@@ -209,14 +221,15 @@ announcement for details.
supports root third-party apps. supports root third-party apps.
- [x] **Migrate to Manifest Schema v2** - Done for `aarch64`/`armv7hf` (schema - [x] **Migrate to Manifest Schema v2** - Done for `aarch64`/`armv7hf` (schema
2.0.0, `compatibleOsVersions` declared); verified installability on OS 2.0.0, `compatibleOsVersions` declared); verified installability on OS
10.12–12.10. 10.12–13.
- [x] **Audit for executable stack usage** - All compiled binaries report - [x] **Audit for executable stack usage** - All compiled binaries report
`flags rw-` (no executable stack) on every architecture and variant. `flags rw-` (no executable stack) on every architecture and variant.
- [x] **Verify web UI works over HTTPS** - Verified live; the UI only issues - [x] **Verify web UI works over HTTPS** - Verified live; the UI only issues
relative-path requests, so it inherits the page's protocol with no relative-path requests, so it inherits the page's protocol with no
mixed-content risk. mixed-content risk.
- [ ] **Sign the ACAP via the Axis ACAP Portal** - Deferred; the manifest's - [x] **Sign the ACAP via the Axis ACAP Portal** - Done; `aarch64`/`armv7hf`
`vendorId` is a placeholder value, not yet portal-registered. packages are signed with the Axis ACAP signing service. The `root` and
`acap3` variants use manifest schema v1.x and are distributed unsigned.
### General Improvements ### General Improvements
+3 -3
View File
@@ -4,10 +4,10 @@
"setup": { "setup": {
"appName": "Tailscale_VPN", "appName": "Tailscale_VPN",
"friendlyName": "Tailscale VPN", "friendlyName": "Tailscale VPN",
"vendor": "Mo3he", "vendor": "moshe@mohome.net",
"vendorId": "5741c1fb91", "vendorId": "70ee172dd9",
"vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale", "vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale",
"version": "1.98.9", "version": "1.102.2",
"architecture": "aarch64", "architecture": "aarch64",
"runMode": "respawn", "runMode": "respawn",
"compatibleOsVersions": [ "compatibleOsVersions": [
+1 -1
View File
@@ -12,7 +12,7 @@
}, },
"vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale", "vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale",
"runMode": "respawn", "runMode": "respawn",
"version": "1.98.9", "version": "1.102.2",
"architecture": "aarch64" "architecture": "aarch64"
}, },
"configuration": { "configuration": {
+3 -3
View File
@@ -4,10 +4,10 @@
"setup": { "setup": {
"appName": "Tailscale_VPN", "appName": "Tailscale_VPN",
"friendlyName": "Tailscale VPN", "friendlyName": "Tailscale VPN",
"vendor": "Mo3he", "vendor": "moshe@mohome.net",
"vendorId": "5741c1fb91", "vendorId": "70ee172dd9",
"vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale", "vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale",
"version": "1.98.9", "version": "1.102.2",
"architecture": "armv7hf", "architecture": "armv7hf",
"runMode": "respawn", "runMode": "respawn",
"compatibleOsVersions": [ "compatibleOsVersions": [
+1 -1
View File
@@ -12,7 +12,7 @@
}, },
"vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale", "vendorUrl": "https://github.com/Mo3he/Axis_Cam_Tailscale",
"runMode": "respawn", "runMode": "respawn",
"version": "1.98.9", "version": "1.102.2",
"architecture": "armv7hf" "architecture": "armv7hf"
}, },
"configuration": { "configuration": {
+2 -2
View File
@@ -2,8 +2,8 @@ PACKAGENAME=Tailscale_VPN
MENUNAME="Tailscale VPN" MENUNAME="Tailscale VPN"
VENDOR="Mo3he" VENDOR="Mo3he"
APPMAJORVERSION=1 APPMAJORVERSION=1
APPMINORVERSION=98 APPMINORVERSION=102
APPMICROVERSION=9 APPMICROVERSION=2
APPTYPE=armv7hf APPTYPE=armv7hf
APPNAME=Tailscale_VPN APPNAME=Tailscale_VPN
APPOPTS="" APPOPTS=""