Skip to content

馃悶 Bug: Navidrome tailscale auth failure聽#342

Description

@dhndmn

Bug Description

I'm running the unmodified, currently published version of Navidrome. My TS_AUTHKEY is set and valid. The resulting tailscale-navidrome container continuously errors and restarts (healthcheck failing). The other container and the network are created successfully.

Also, "variable" is misspelled in the .env file line 22.

Expected Behavior

All containers start and I can view the new machine in my Tailscale dashboard.

Actual Behavior

A docker error-restart loop for the tailscale container.

Screenshots

No response

Operating System

Linux

Tailscale Version

1.102.3

Docker Version

28.4.0

Relevant Logs or Error Messages

2026-09-22T18:15:22.837865234Z boot: 2026/09/22 18:15:22 Running 'tailscale up'
2026-09-22T18:15:22.847120702Z 2026/09/22 18:15:22 localapi: [POST] /localapi/v0/check-prefs
2026-09-22T18:15:23.272487257Z Status: 400, Message: "requested tags [] are invalid or not permitted"
2026-09-22T18:15:23.276347566Z boot: 2026/09/22 18:15:23 HTTP server at 127.0.0.1:41234 closed
2026-09-22T18:15:23.277175544Z boot: 2026/09/22 18:15:23 Sending SIGTERM to tailscaled
2026-09-22T18:15:23.277215982Z boot: 2026/09/22 18:15:23 failed to auth tailscale: failed to auth tailscale: tailscale up failed: exit status 1

Docker Compose Configuration

configs:
  ts-serve:
    content: |
      {"TCP":{"443":{"HTTPS":true}},
      "Web":{"$${TS_CERT_DOMAIN}:443":
          {"Handlers":{"/":
          {"Proxy":"http://127.0.0.1:4533"}}}},
      "AllowFunnel":{"$${TS_CERT_DOMAIN}:443":false}}

services:
# Make sure you have updated/checked the .env file with the correct variables.
# All the ${ xx } need to be defined there.
  # Tailscale Sidecar Configuration
  tailscale:
    image: tailscale/tailscale:latest # Image to be used
    container_name: tailscale-${SERVICE} # Name for local container management
    hostname: ${SERVICE} # Name used within your Tailscale environment
    environment:
      - TS_AUTHKEY=${TS_AUTHKEY}
      - TS_STATE_DIR=/var/lib/tailscale
      - TS_SERVE_CONFIG=/config/serve.json # Tailscale Serve configuration to expose the web interface on your local Tailnet - remove this line if not required
      - TS_USERSPACE=false
      - TS_ENABLE_HEALTH_CHECK=true              # Enable healthcheck endpoint: "/healthz"
      - TS_LOCAL_ADDR_PORT=127.0.0.1:41234       # The <addr>:<port> for the healthz endpoint
      - TS_ACCEPT_DNS=true # Uncomment when using MagicDNS
      - TS_AUTH_ONCE=true
    configs:
      - source: ts-serve
        target: /config/serve.json
    volumes:
      - ./config:/config # Config folder used to store Tailscale files - you may need to change the path
      - ./ts/state:/var/lib/tailscale # Tailscale requirement - you may need to change the path
    devices:
      - /dev/net/tun:/dev/net/tun # Network configuration for Tailscale to work
    cap_add:
      - net_admin # Tailscale requirement
    #ports:
    #  - 0.0.0.0:${SERVICEPORT}:${SERVICEPORT} # Binding port ${SERVICE}PORT to the local network - may be removed if only exposure to your Tailnet is required
    # If any DNS issues arise, use your preferred DNS provider by uncommenting the config below
    #dns:
    #  - ${DNS_SERVER}
    healthcheck:
      test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:41234/healthz"] # Check Tailscale has a Tailnet IP and is operational
      interval: 1m # How often to perform the check
      timeout: 10s # Time to wait for the check to succeed
      retries: 3 # Number of retries before marking as unhealthy
      start_period: 10s # Time to wait before starting health checks
    restart: always

  # ${SERVICE}
  application:
    image: ${IMAGE_URL} # Image to be used
    network_mode: service:tailscale # Sidecar configuration to route ${SERVICE} through Tailscale
    container_name: app-${SERVICE} # Name for local container management
    environment:
      # Optional: put your config options customization here. Examples:
      # ND_LOGLEVEL: debug
      - PUID=1000
      - PGID=1000
      - TZ=${TZ}
    volumes:
      - ./${SERVICE}-data/data:/data
      - /path/to/your/music/folder:/music:ro # Adjust to your liking
    depends_on:
      tailscale:
        condition: service_healthy
    # healthcheck:
    #   test: ["CMD", "pgrep", "-f", "${SERVICE}"] # Check if ${SERVICE} process is running
    #   interval: 1m # How often to perform the check
    #   timeout: 10s # Time to wait for the check to succeed
    #   retries: 3 # Number of retries before marking as unhealthy
    #   start_period: 30s # Time to wait before starting health checks
    restart: always

Environment Configuration (.env file)

#version=1.1
#URL=https://github.com/tailscale-dev/ScaleTail
#COMPOSE_PROJECT_NAME= # Optional: only use when running multiple deployments on the same infrastructure.

# Service Configuration
SERVICE=navidrome
IMAGE_URL=deluan/navidrome

# Network Configuration
SERVICEPORT=4533
DNS_SERVER=9.9.9.9

# Tailscale Configuration
TS_AUTHKEY=${TS_AUTHKEY}

# Time Zone setting for containers
TZ=America/New_York # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones

# Optional Service variables
# PUID=1000

#EXAMPLE_VAR="Environment varibale"

Additional Context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions