Experimental & Roadmap
Features under development or not yet production-ready
The remaining areas below are roadmap directions, not runtime packages or registry settings that can be enabled. Use the CLI and optional tailnet-only scoped MCP for shipped management.
Shipped access workflows and remaining plans
Guest links, per-host portal, requests and QR, MCP roles and receipts, access history and flexible durations are shipped. Multi-host inventory remains planned. Health/upload limits do not implement requests-per-second middleware.
Middleware
Overview
Configurable rate limiting, Basic Auth, IP allow lists, and CORS are not implemented. The middleware registry key has been removed. It is rejected with unknown_config_key even when its value is {}. The shipped HTTP --allow filter still applies to proxy/file services; raw TCP uses tailnet policy and target authentication.
Registry Configuration
This is a rejected legacy example, kept to help identify configuration that needs migration. Remove the entire middleware key:
{
"middleware": {
"rate_limit": 100
}
}Strict registry mutation commands reject the key. The daemon skips invalid service entries while continuing healthy entries; a reload that makes a public Funnel service invalid closes its public listener. Check tslink registry check --json and diagnostics before retrying.
Docker Auto-Discovery
Overview
Docker label discovery is not implemented, and the current TSLink has no Docker discovery package. Labels such as tslink.enable do not register services. Register container-backed services explicitly with tslink add using the backend's reachable host and port.
FAQ
- Does TSLink need access to the Docker socket? No shipped flow uses it. A future discovery implementation would need its own access and authorization design.
Cluster Support
Overview
Cluster synchronization is not implemented. There is no cluster package, peer transport, membership model, or shared-registry protocol. Each installation manages its local registry; do not treat separate TSLink instances as a synchronized cluster.
FAQ
- Can I run multiple TSLink instances? Separate installations can manage their own services, but cluster synchronization is roadmap/experimental. See the TSLink multi-machine documentation for local ownership limits.
- What happens if a cluster node goes down? No cluster failover contract exists in the current TSLink.
Admin Dashboard & REST API
Overview
No admin dashboard or REST handler is shipped. The optional tailnet-only MCP control plane (tslink serve --mcp) is the remote management surface and requires explicit owner entries or scoped bindings. Use the CLI with --json or MCP for shipped automation.
FAQ
- Is there a web dashboard? There is a shipped private per-host app portal with request forms. An admin management dashboard/REST API remains planned. TSLink Web is the documentation site.
- Can I manage services via REST API? No shipped admin REST API exists; dashboard/REST work remains roadmap/experimental.
Custom Domains & ACME
Overview
Custom-domain TLS and ACME are not implemented. There are no --domain / --acme-email flags or accepted domain / acme_email registry fields. CLI use fails as an unknown flag; old registry keys fail with unknown_config_key, even when empty. Delete those keys and use the default <service>.<tailnet>.ts.net hostname.
Prometheus Metrics
Overview
Prometheus support is not implemented. The current TSLink has neither HTTP metrics instrumentation nor a /metrics scrape endpoint. Use daemon logs and CLI diagnostics for available evidence.
Roadmap Configuration Fields
| Area | Status |
|---|---|
middleware | Removed registry key; all values, including {}, are rejected with unknown_config_key. |
| Docker labels | Not implemented; labels do not register services. |
Prometheus /metrics | No instrumentation or scrape endpoint. |
domain / acme_email | Removed registry keys; even empty values are rejected with unknown_config_key. |
Roadmap Commands
| Area | Status |
|---|---|
| Middleware | Not implemented; HTTP --allow remains available for proxy/file services. |
| Docker Integration | Not implemented; register container-backed services explicitly. |
| Admin REST API | No handler; use CLI --json or the optional tailnet-only MCP control plane. |
| Custom domain / ACME | Not implemented; no CLI flags or registry fields. |
| Cluster sync | Not implemented; installations have separate local registries. |