tailscale / tailscale/github-action

macOS: action unconditionally overrides system DNS (networksetup 100.100.100.100), breaking Actions broker resolution and cancelling jobs mid-run

Open
#315 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
938
Forks
137
PR merge metrics
No merged PRs in 30d

Description

What happens

On a GitHub-hosted macOS runner, a job that connects with tailscale/github-action@v4 and then runs for several minutes gets cancelled ~5 min in with the generic The operation was canceled. Runner diagnostic logs (ACTIONS_RUNNER_DEBUG=true) show repeated job-lease renewal failures:

WARN GitHubActionsService] Attempt N of POST .../renewjob failed (Socket Error: HostNotFound)
ERR  JobDispatcher] Catch exception during renew runner job ...
INFO JobDispatcher] Send job cancellation message to worker ...

The Actions broker hostname (run-actions-*.actions.githubusercontent.com) fails to resolve (HostNotFound), so the runner cannot renew its lease and the service cancels the healthy job.

Root cause

On join (macOS only), configureDNSOnMacOS in src/main.ts runs:

networksetup -setdnsservers Ethernet 100.100.100.100

repointing the runner's system DNS at the tailnet resolver, which intermittently fails to forward public queries — so the broker does not resolve, renewjob fails, and the job is cancelled. Three problems:

  1. Unconditional on macOS — gated only on the tailnet-wide MagicDNSEnabled flag, not on --accept-dns. Passing args: --accept-dns=false does not prevent it (that only affects tailscale up, not the action's own networksetup call).
  2. No input to disable the DNS configuration.
  3. The action never restores DNS, so the override persists for the whole job.

Introduced by #200.

Impact

Any macOS job that stays up long enough to hit a lease renewal while the tailnet resolver cannot forward the broker query is silently cancelled. Intermittent, so it reads as flaky infrastructure.

Workaround

Revert DNS immediately after the action (safe when you do not need MagicDNS name resolution — reach peers by Tailscale IP):

- run: sudo networksetup -setdnsservers Ethernet Empty
Request

Make the macOS DNS configuration opt-in (or skip it when --accept-dns=false), and/or restore the original DNS in the post step. An input such as set-dns: false would suffice.

Environment

GitHub-hosted macOS (arm64), tailscale/github-action@v4, Tailscale 1.94.2.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in src/main.ts at configureDNSOnMacOS and trace the macOS join and post-step flow introduced by #200. Verify how --accept-dns is handled relative to the action's networksetup call, then define the opt-in or --accept-dns=false behavior and DNS restoration; done means the action no longer unconditionally overrides the runner's DNS during a job.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, macos, typescript
Domain
ci-cd, devops, networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.