-
Notifications
You must be signed in to change notification settings - Fork 16
Expand file tree
/
Copy pathesp32-ts.yaml
More file actions
112 lines (95 loc) · 3.52 KB
/
Copy pathesp32-ts.yaml
File metadata and controls
112 lines (95 loc) · 3.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
esphome:
name: esp32-ts
friendly_name: ESP32 Tailscale
esp32:
board: esp32-c3-devkitm-1
framework:
type: esp-idf
version: recommended
sdkconfig_options:
# LwIP Debugging (uncomment when needed)
# CONFIG_LWIP_DEBUG: y
# CONFIG_LWIP_TCP_DEBUG: y
# CONFIG_LWIP_TCP_INPUT_DEBUG: y
# CONFIG_LWIP_TCP_OUTPUT_DEBUG: y
# CONFIG_LWIP_IP_DEBUG: y
# Ensure LwIP calculates checksums (we have no HW offload for the tunnel)
CONFIG_LWIP_CHECKSUM_GEN_IP: y
CONFIG_LWIP_CHECKSUM_GEN_UDP: y
CONFIG_LWIP_CHECKSUM_GEN_TCP: y
CONFIG_LWIP_CHECKSUM_GEN_ICMP: y
# Increase TCP limits to prevent PCB exhaustion
CONFIG_LWIP_MAX_ACTIVE_TCP: "16"
CONFIG_LWIP_MAX_LISTENING_TCP: "16"
# Increase LwIP Task Stack Size to prevent overflows
CONFIG_LWIP_TCPIP_TASK_STACK_SIZE: "4096"
# Increase task watchdog timeout from default 5s to 30s
CONFIG_ESP_TASK_WDT_TIMEOUT_S: "30"
# Aggressive mbedTLS Memory Optimization (The "320KB RAM" survival kit)
# 1. Reduce Buffer Sizes:
# Standard TLS requires 16KB. We force 4KB.
# This saves ~24KB PER CONNECTION (RX+TX).
# Headscale/DERP payloads are small (JSON or <1.5KB WG packets).
CONFIG_MBEDTLS_SSL_MAX_CONTENT_LEN: "4096"
CONFIG_MBEDTLS_SSL_IN_CONTENT_LEN: "4096"
CONFIG_MBEDTLS_SSL_OUT_CONTENT_LEN: "4096"
# 2. Dynamic Allocation:
# Only allocate buffers when processing records, free immediately after.
CONFIG_MBEDTLS_DYNAMIC_BUFFER: y
CONFIG_MBEDTLS_DYNAMIC_FREE_CONFIG_DATA: y
CONFIG_MBEDTLS_DYNAMIC_FREE_CA_CERT: y
# 3. Discard Certificate Data:
# Don't store the peer certificate after verification. Saves ~2-4KB.
CONFIG_MBEDTLS_SSL_KEEP_PEER_CERTIFICATE: n
# 4. Certificate Bundle:
# Use custom bundle with only Let's Encrypt certificates instead of full bundle
# This saves ~145KB flash and reduces RAM usage during TLS verification
CONFIG_MBEDTLS_CERTIFICATE_BUNDLE: y
CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_DEFAULT_FULL: n
CONFIG_MBEDTLS_CERTIFICATE_BUNDLE_CUSTOM: y
CONFIG_MBEDTLS_CUSTOM_CERTIFICATE_BUNDLE_PATH: "certs"
# Enable variable-length buffers (saves 1KB)
CONFIG_MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH: y
# WiFi configuration
wifi:
ssid: !secret wifi_ssid
password: !secret wifi_password
power_save_mode: NONE
# Enable logging
logger:
#level: INFO
#level: DEBUG
level: VERBOSE
logs:
tailscale.wireguard: VERBOSE
# Time source (required)
time:
- platform: sntp
id: sntp_time
# Can probably be removed in your config.
# tz is needed docker build environment
timezone: Europe/Stockholm
external_components:
- source:
type: local
path: components
components: [ tailscale ]
tailscale:
id: tailscale_client
auth_key: !secret tailscale_auth_key
control_url: !secret headscale_url
device_name: "esp"
time_id: sntp_time
update_interval: 5s # Reduced from 5s to 2s for faster reconnection checks
allowed_peers: !secret allowed_peers
preferred_derp: 999
prefer_direct_udp: true # Prefer direct UDP routing after Disco PONG confirmation, else use DERP
# LED status indicator (WS2812 addressable LED)
# Orange (20%) - Connecting
# Green (20%) - Connected/OK
# Red (20%) - Error
# Blue blink - Control packets (disco, wireguard handshake)
# Orange blink - Data packets (ICMP, TCP)
status_led:
enabled: false
pin: 10 # GPIO10 for ESP32-C3 Zero onboard WS2812