app-template: serviceAccount: name: tailscale controllers: tailscale: containers: app: image: repository: ghcr.io/tailscale/tailscale tag: latest env: TS_HOSTNAME: homelab-router TS_USERSPACE: false TS_KUBE_SECRET: tailscale TS_ROUTES: 192.168.1.224/27 TS_AUTHKEY: valueFrom: secretKeyRef: name: tailscale-auth key: TS_AUTHKEY securityContext: capabilities: add: - NET_ADMIN