NVIDIA / NVIDIA/Personal-AI-Router
[Feature]: Support for Tailscale mesh network endpoints (CGNAT IPs and MagicDNS domain names)
まだ誰も着手していません。
- 主要言語
- Go
- スター
- 1.4k
- フォーク
- 250
- 平均マージ
- 23時間 27分
- マージ済み PR(30日)
- 1
説明
Area
Discovery or pairing
User problem
Note: This feature request includes AI generated suggestions (Google's Antigravity). I have marked
form sections where I lack context knowledge.
When attempting to connect a device (such as a MacBook Pro) located outside the local physical network using
Tailscale, PAIR is unable to connect to the remote LLM or register the remote machine as a node.
Specifically:
- Automatic Discovery Fails: mDNS discovery does not span across subnets or overlay networks without
explicit multicast forwarding. - Manual IP Addition Fails: Adding a node manually using its Tailscale IPv4 address (
100.64.x.xCGNAT
range) fails to establish pairing or route requests. - MagicDNS Hostnames Fail: Adding a node using its Tailscale domain name
(e.g.,macbook-pro.tailnet- name.ts.net) is either rejected by host validation or fails during probe/pairing.
As a result, users working remotely cannot access their home/office PAIR cluster's LLM resources or contribute remote nodes to an existing cluster.
Desired outcome
Tailscale & VPN Node Pairing: Users should be able to manually add out-of-network nodes by entering
either their Tailscale IP address (100.64.0.0/10) or MagicDNS domain name in the "Add Node" interface.
Alternatives considered
I tried an OpenVPN connection instead of Tailscale and had the same user problem.
Compatibility and security implications
Note: these are AI generated suggestions (Google's Antigravity) that I am not certain of.
- Address Scoring: Updating
services/shared/netpickso that explicit manual node additions for CGNAT
(100.64.0.0/10) and virtual interface addresses (tailscale0,utun) are not demoted below unreachable
physical LAN interfaces. - DNS & FQDN Support: Ensuring
nvpair-manual-nodesand cluster pairing clients perform asynchronous DNS
re-resolution for MagicDNS domain names (.ts.net). - mTLS & SANs: Ensuring TLS certificates issued during PIN pairing include MagicDNS hostnames and
Tailscale IP addresses in Subject Alternative Names (SANs). - Security: PAIR's PIN pairing, identity verification, and mTLS traffic encryption will protect
communication even over external overlay networks.
Validation approach
- Set up a PAIR host on a local network equipped with Tailscale.
- Connect a remote device (e.g., MacBook Pro on cellular/external Wi-Fi) to the same Tailscale network
(Tailnet). - Open PAIR UI on the host, select Add Node, and input the MacBook Pro's Tailscale IP (
100.64.x.y) or
MagicDNS domain. - Verify PIN pairing completes successfully, telemetry/node-info populates, and inference requests route to
the remote node.
Confirmations
- I searched existing issues for duplicates.
- I agree to follow the Code of Conduct.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
まず、手動アドレスとペアリングの Add Node フローを追跡し、次に services/shared/netpick と nvpair-manual-nodes を調べます。ノードエンドポイントに対して、ホスト検証、DNS 解決、PIN ペアリング、証明書 SANs がどのように処理されるかを確認します。Tailscale IP または MagicDNS 名でペアリングを完了し、ノード情報を登録し、検証環境で推論リクエストをルーティングできれば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- go
- 領域
- authentication, networking, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100