#!/bin/sh # Joins the box it runs on to the fleet's tailnet. One script, two callers: a person pastes # the line `./fleet invite ` prints, which fetches this file from join.databob-labs.com # and runs it with sudo, and a cloud box runs it from cloud-init at first boot with the key # the tailscale root minted. Either way the arguments are the box's name, a machine in # fleet-config.yaml, and its key, which works once and dies within the hour: the one secret # here, and worth nothing once the join is done. It installs Tailscale when absent and # joins under the box's name, tagged tag:box by the key, with MagicDNS off so the box's # resolver stays as it is. POSIX sh, since the line runs it as `sh` on a box with nothing # installed yet; `set -e` ends it at the first failed step. set -eu fail() { echo "join.sh: $1" >&2 exit 1 } [ $# -eq 2 ] || fail "usage: join.sh " box=$1 key=$2 printf '%s' "$box" | grep -Eq '^[a-z][a-z0-9-]*$' || fail "$box is not a machine name from fleet-config.yaml" case $key in tskey-auth-*) ;; *) fail "the key is not a Tailscale auth key (tskey-auth-...)" ;; esac [ "$(id -u)" -eq 0 ] || fail "run it with sudo" if ! command -v tailscale >/dev/null; then curl -fsSL https://tailscale.com/install.sh | sh fi tailscale up --auth-key="$key" --hostname="$box" --accept-dns=false tailscale status --self --peers=false