tailscale/tailscale · error

error getting Tailscale Service %q: %w

Error message

error getting Tailscale Service %q: %w

What it means

Error "error getting Tailscale Service %q: %w" thrown in tailscale/tailscale.

Source

Thrown at cmd/k8s-operator/api-server-proxy-pg.go:166

	}

	if !slices.Contains(pg.Finalizers, proxyPGFinalizerName) {
		// This log line is printed exactly once during initial provisioning,
		// because once the finalizer is in place this block gets skipped. So,
		// this is a nice place to tell the operator that the high level,
		// multi-reconcile operation is underway.
		logger.Info("provisioning Tailscale Service for ProxyGroup")
		pg.Finalizers = append(pg.Finalizers, proxyPGFinalizerName)
		if err := r.Update(ctx, pg); err != nil {
			return fmt.Errorf("failed to add finalizer: %w", err)
		}
	}

	// 1. Check there isn't a Tailscale Service with the same hostname
	// already created and not owned by this ProxyGroup.
	existingTSSvc, err := tsClient.VIPServices().Get(ctx, serviceName.String())
	if err != nil && !tailscale.IsNotFound(err) {
		return fmt.Errorf("error getting Tailscale Service %q: %w", serviceName, err)
	}

	updatedAnnotations, err := exclusiveOwnerAnnotations(pg, r.operatorID, existingTSSvc)
	if err != nil {
		const instr = "To proceed, you can either manually delete the existing Tailscale Service or choose a different Service name in the ProxyGroup's spec.kubeAPIServer.serviceName field"
		msg := fmt.Sprintf("error ensuring exclusive ownership of Tailscale Service %s: %v. %s", serviceName, err, instr)
		logger.Warn(msg)
		r.recorder.Event(pg, corev1.EventTypeWarning, "InvalidTailscaleService", msg)
		tsoperator.SetProxyGroupCondition(pg, tsapi.KubeAPIServerProxyValid, metav1.ConditionFalse, reasonKubeAPIServerProxyInvalid, msg, pg.Generation, r.clock, logger)
		return nil
	}

	// After getting this far, we know the Tailscale Service is valid.
	tsoperator.SetProxyGroupCondition(pg, tsapi.KubeAPIServerProxyValid, metav1.ConditionTrue, reasonKubeAPIServerProxyValid, reasonKubeAPIServerProxyValid, pg.Generation, r.clock, logger)

	// Service tags are limited to matching the ProxyGroup's tags until we have
	// support for querying peer caps for a Service-bound request.
	serviceTags := r.defaultTags

View on GitHub (pinned to cfe32b8be6)

When it happens

Trigger: Thrown at cmd/k8s-operator/api-server-proxy-pg.go:166 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of tailscale/tailscale@cfe32b8be6 (2026-08-15). Data as JSON: /api/errors/e7273cd3b4c18358. Report an issue: GitHub.