fix: use docker with host pid to install tailscale via nsenter
ts-install / install-tailscale (push) Successful in 8m7s

This commit is contained in:
2026-09-21 21:44:56 +08:00
parent d615a60bbd
commit fcab9ed0c3
+50 -58
View File
@@ -8,63 +8,55 @@ jobs:
install-tailscale:
runs-on: host
steps:
- name: Install Tailscale on build server host
- name: Install tailscale on host
run: |
set -ex
echo "=== Detect host OS ==="
# Use docker with host PID to inspect host
docker run --rm --privileged --pid=host alpine:latest sh -c '
# Access host filesystem via /proc/1/root
HOST_ROOT=/proc/1/root
# Detect OS
if [ -f $HOST_ROOT/etc/os-release ]; then
cat $HOST_ROOT/etc/os-release
OS_ID=$(grep ^ID= $HOST_ROOT/etc/os-release | cut -d= -f2 | tr -d ")
echo "Detected OS: $OS_ID"
else
echo "Cannot detect OS"
exit 1
fi
# Check if tailscale already installed
if chroot $HOST_ROOT which tailscale 2>/dev/null; then
echo "Tailscale already installed"
chroot $HOST_ROOT tailscale version
if chroot $HOST_ROOT tailscale status --json 2>/dev/null | grep -q "Running"; then
echo "Tailscale already running"
chroot $HOST_ROOT tailscale ip -4
exit 0
fi
fi
# Install based on OS
if [ "$OS_ID" = "ubuntu" ] || [ "$OS_ID" = "debian" ]; then
echo "Installing via apt..."
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
elif [ "$OS_ID" = "centos" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "alinux" ] || [ "$OS_ID" = "anolis" ]; then
echo "Installing via yum/dnf..."
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
else
echo "Attempting generic install..."
chroot $HOST_ROOT bash -c "curl -fsSL https://tailscale.com/install.sh | sh"
fi
# Enable and start tailscaled
chroot $HOST_ROOT systemctl enable --now tailscaled 2>/dev/null || \
chroot $HOST_ROOT service tailscaled start 2>/dev/null || \
echo "Could not start tailscaled via init system"
echo "=== Install completed ==="
'
# Write the host-install script to a file to avoid quoting issues
cat > /tmp/host-install.sh << 'ENDSCRIPT'
#!/bin/sh
set -e
echo "=== Getting Tailscale auth URL ==="
# Need to run tailscale up and get the auth URL
docker run --rm --privileged --pid=host --net=host alpine:latest sh -c '
HOST_ROOT=/proc/1/root
# Run tailscale up and capture the auth URL
chroot $HOST_ROOT tailscale up --ssh --timeout 30s 2>&1 | tee /tmp/ts-auth.log || true
echo "=== Tailscale status ==="
chroot $HOST_ROOT tailscale status 2>&1 || true
chroot $HOST_ROOT tailscale ip -4 2>&1 || true
'
# Check if we have nsenter
if ! command -v nsenter >/dev/null 2>&1; then
apt-get update -qq && apt-get install -y -qq util-linux curl ca-certificates
fi
TARGET_PID=1
NSENTER="nsenter -t $TARGET_PID -m -u -i -n -p"
echo "=== Host OS ==="
$NSENTER cat /etc/os-release 2>&1 | head -5
echo ""
echo "=== Check tailscale ==="
if $NSENTER sh -c 'command -v tailscale' >/dev/null 2>&1; then
echo "Tailscale already installed:"
$NSENTER tailscale version
else
echo "Installing Tailscale..."
$NSENTER sh -c 'curl -fsSL https://tailscale.com/install.sh | sh'
echo "Starting tailscaled..."
$NSENTER systemctl enable --now tailscaled 2>&1 || $NSENTER service tailscaled start 2>&1 || true
sleep 3
fi
echo ""
echo "=== Tailscale up (auth if needed) ==="
$NSENTER tailscale up --ssh --timeout 60s 2>&1 || true
echo ""
echo "=== Status ==="
$NSENTER tailscale status 2>&1 || true
echo ""
echo "=== Tailscale IPv4 ==="
$NSENTER tailscale ip -4 2>&1 || true
echo ""
echo "=== DONE ==="
ENDSCRIPT
chmod +x /tmp/host-install.sh
# Run an alpine container with host PID and privileged access,
# mount our script into it
docker run --rm --privileged --pid=host \
-v /tmp/host-install.sh:/host-install.sh:ro \
alpine:latest sh -c 'apk add --no-cache util-linux 2>/dev/null; sh /host-install.sh'