Tailscale Kubernetes Operator
The Tailscale operator enables Kubernetes services to be exposed directly on the Tailscale network via Ingress resources.
Quick Reference
| Property | Value |
|---|---|
| Namespace | tailscale |
| Helm Chart | tailscale/tailscale-operator |
| ArgoCD App | tailscale-operator |
How It Works
When you create an Ingress with ingressClassName: tailscale:
- Operator provisions a Tailscale node for the service
- Service becomes accessible at
<hostname>.tail8d86e.ts.net - TLS is handled automatically via Tailscale
Limitations
Services exposed via Tailscale Ingress are not accessible from:
- Other Kubernetes pods (they’re not Tailscale clients)
- Docker containers on indri
For pod-to-service communication, use Caddy (*.ops.eblu.me) instead.