TSLinkTSLink Docs

Experimental & Roadmap

Features under development or not yet production-ready

View as Markdown

The remaining areas below are roadmap directions, not runtime packages or registry settings that can be enabled. Use the CLI and optional tailnet-only scoped MCP for shipped management.

Shipped access workflows and remaining plans

Guest links, per-host portal, requests and QR, MCP roles and receipts, access history and flexible durations are shipped. Multi-host inventory remains planned. Health/upload limits do not implement requests-per-second middleware.

Middleware

Overview

Configurable rate limiting, Basic Auth, IP allow lists, and CORS are not implemented. The middleware registry key has been removed. It is rejected with unknown_config_key even when its value is {}. The shipped HTTP --allow filter still applies to proxy/file services; raw TCP uses tailnet policy and target authentication.

Registry Configuration

This is a rejected legacy example, kept to help identify configuration that needs migration. Remove the entire middleware key:

json
{
  "middleware": {
    "rate_limit": 100
  }
}

Strict registry mutation commands reject the key. The daemon skips invalid service entries while continuing healthy entries; a reload that makes a public Funnel service invalid closes its public listener. Check tslink registry check --json and diagnostics before retrying.

Docker Auto-Discovery

Overview

Docker label discovery is not implemented, and the current TSLink has no Docker discovery package. Labels such as tslink.enable do not register services. Register container-backed services explicitly with tslink add using the backend's reachable host and port.

FAQ

  • Does TSLink need access to the Docker socket? No shipped flow uses it. A future discovery implementation would need its own access and authorization design.

Cluster Support

Overview

Cluster synchronization is not implemented. There is no cluster package, peer transport, membership model, or shared-registry protocol. Each installation manages its local registry; do not treat separate TSLink instances as a synchronized cluster.

FAQ

  • Can I run multiple TSLink instances? Separate installations can manage their own services, but cluster synchronization is roadmap/experimental. See the TSLink multi-machine documentation for local ownership limits.
  • What happens if a cluster node goes down? No cluster failover contract exists in the current TSLink.

Admin Dashboard & REST API

Overview

No admin dashboard or REST handler is shipped. The optional tailnet-only MCP control plane (tslink serve --mcp) is the remote management surface and requires explicit owner entries or scoped bindings. Use the CLI with --json or MCP for shipped automation.

FAQ

  • Is there a web dashboard? There is a shipped private per-host app portal with request forms. An admin management dashboard/REST API remains planned. TSLink Web is the documentation site.
  • Can I manage services via REST API? No shipped admin REST API exists; dashboard/REST work remains roadmap/experimental.

Custom Domains & ACME

Overview

Custom-domain TLS and ACME are not implemented. There are no --domain / --acme-email flags or accepted domain / acme_email registry fields. CLI use fails as an unknown flag; old registry keys fail with unknown_config_key, even when empty. Delete those keys and use the default <service>.<tailnet>.ts.net hostname.

Prometheus Metrics

Overview

Prometheus support is not implemented. The current TSLink has neither HTTP metrics instrumentation nor a /metrics scrape endpoint. Use daemon logs and CLI diagnostics for available evidence.

Roadmap Configuration Fields

AreaStatus
middlewareRemoved registry key; all values, including {}, are rejected with unknown_config_key.
Docker labelsNot implemented; labels do not register services.
Prometheus /metricsNo instrumentation or scrape endpoint.
domain / acme_emailRemoved registry keys; even empty values are rejected with unknown_config_key.

Roadmap Commands

AreaStatus
MiddlewareNot implemented; HTTP --allow remains available for proxy/file services.
Docker IntegrationNot implemented; register container-backed services explicitly.
Admin REST APINo handler; use CLI --json or the optional tailnet-only MCP control plane.
Custom domain / ACMENot implemented; no CLI flags or registry fields.
Cluster syncNot implemented; installations have separate local registries.

Table of Contents