Skip to content

darwin: share declarative Tailscale setup with the MacBook Air - #37

Open
alexmalison wants to merge 2 commits into
colonelpanic8:masterfrom
alexmalison:darwin/declarative-tailscale
Open

alexmalison wants to merge 2 commits into
colonelpanic8:masterfrom
alexmalison:darwin/declarative-tailscale

Conversation

@alexmalison

@alexmalison alexmalison commented Oct 10, 2026 •

Copy link
Copy Markdown

The MacBook Air currently relies on Tailscale.app, while the Mac Mini has a Nix-managed system daemon. Extract the Darwin Tailscale setup into a shared module and enable it for both hosts, reconciling DNS acceptance, hostname, and operator access.

The Mini keeps its existing agenix enrollment key. The Air enrolls automatically with its own reusable Tailscale auth key, encrypted only to the Air SSH host key. Agenix decrypts it with the system host identity into a root-only file; the daemon receives the file path rather than a plaintext key in its arguments. The key expires January 7, 2027 and must be rotated for enrollment or reauthentication after that date.

Document the app-to-daemon migration, CLI-only client limitations, and automatic enrollment. Refuse activation while Tailscale.app remains installed to avoid overlapping VPN clients.

Validation:

  • Built the Air system with automatic enrollment configured.
  • Evaluated the Mini system derivation and both hosts' generated scripts and secret lists.
  • Passed seven mocked shell scenarios covering preference reconciliation, manual enrollment, an authenticated daemon, missing/empty/DISABLED auth keys, and enrollment through a key file.
  • Verified the actual Air auth key decrypts using its SSH host identity and that its age file has exactly one SSH recipient, without printing or writing plaintext.
  • Alejandra formatting and git diff --check passed.

Not activated on the Air: migration disconnects its current VPN and requires removing Tailscale.app and rebooting. Enrollment then runs automatically after just switch. See nix-darwin/README.md.

Separate local Paseo secret edits remain outside this PR.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant