NVIDIA / NVIDIA/Personal-AI-Router
[Feature]: Support for Tailscale mesh network endpoints (CGNAT IPs and MagicDNS domain names)
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Go
- Star
- 1.4k
- Fork
- 250
- Merge trung bình
- 23 giờ 27 phút
- Pull request đã merge (30 ngày)
- 1
Mô tả
Area
Discovery or pairing
User problem
Note: This feature request includes AI generated suggestions (Google's Antigravity). I have marked
form sections where I lack context knowledge.
When attempting to connect a device (such as a MacBook Pro) located outside the local physical network using
Tailscale, PAIR is unable to connect to the remote LLM or register the remote machine as a node.
Specifically:
- Automatic Discovery Fails: mDNS discovery does not span across subnets or overlay networks without
explicit multicast forwarding. - Manual IP Addition Fails: Adding a node manually using its Tailscale IPv4 address (
100.64.x.xCGNAT
range) fails to establish pairing or route requests. - MagicDNS Hostnames Fail: Adding a node using its Tailscale domain name
(e.g.,macbook-pro.tailnet- name.ts.net) is either rejected by host validation or fails during probe/pairing.
As a result, users working remotely cannot access their home/office PAIR cluster's LLM resources or contribute remote nodes to an existing cluster.
Desired outcome
Tailscale & VPN Node Pairing: Users should be able to manually add out-of-network nodes by entering
either their Tailscale IP address (100.64.0.0/10) or MagicDNS domain name in the "Add Node" interface.
Alternatives considered
I tried an OpenVPN connection instead of Tailscale and had the same user problem.
Compatibility and security implications
Note: these are AI generated suggestions (Google's Antigravity) that I am not certain of.
- Address Scoring: Updating
services/shared/netpickso that explicit manual node additions for CGNAT
(100.64.0.0/10) and virtual interface addresses (tailscale0,utun) are not demoted below unreachable
physical LAN interfaces. - DNS & FQDN Support: Ensuring
nvpair-manual-nodesand cluster pairing clients perform asynchronous DNS
re-resolution for MagicDNS domain names (.ts.net). - mTLS & SANs: Ensuring TLS certificates issued during PIN pairing include MagicDNS hostnames and
Tailscale IP addresses in Subject Alternative Names (SANs). - Security: PAIR's PIN pairing, identity verification, and mTLS traffic encryption will protect
communication even over external overlay networks.
Validation approach
- Set up a PAIR host on a local network equipped with Tailscale.
- Connect a remote device (e.g., MacBook Pro on cellular/external Wi-Fi) to the same Tailscale network
(Tailnet). - Open PAIR UI on the host, select Add Node, and input the MacBook Pro's Tailscale IP (
100.64.x.y) or
MagicDNS domain. - Verify PIN pairing completes successfully, telemetry/node-info populates, and inference requests route to
the remote node.
Confirmations
- I searched existing issues for duplicates.
- I agree to follow the Code of Conduct.
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Bắt đầu bằng cách lần theo flow Add Node cho các địa chỉ thủ công và pairing, sau đó kiểm tra services/shared/netpick và nvpair-manual-nodes. Kiểm tra cách validation host, phân giải DNS, pairing bằng PIN và certificate SANs được xử lý cho các node endpoint. Hoàn thành khi một Tailscale IP hoặc tên MagicDNS có thể hoàn tất pairing, điền thông tin node và định tuyến các yêu cầu inference trong thiết lập validation.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- go
- Lĩnh vực
- authentication, networking, security
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 45/100