Unify VNet status and control across Teleport Connect and the CLI
What would you like Teleport to do? Provide one authoritative VNet status and on/off control across Teleport Connect and tsh vnet for the same user on the same device. Connect should reflect VNet started through the CLI, and turning VNet off in Connect should stop active VNet connectivity regardless of which client started it. Starting or stopping VNet through either client should keep the displayed status consistent. If stopping VNet fails, Connect should clearly report that failure instead of showing VNet as disabled.
What problem does this solve? Connect can show VNet as off while CLI-managed VNet remains active and connectivity continues. The reported sequence is to leave CLI-managed VNet running, turn VNet off in Connect, and observe that connectivity remains available. There was no connectivity failure in this case. This makes the UI unreliable as an indicator of whether VNet is active, complicates troubleshooting, and can lead users to believe they have disabled VNet connectivity when they have not.
If a workaround exists, please include it. Use one client to manage VNet and stop it through the client that started it. When switching to Connect, first stop CLI-managed VNet. This requires users to track ownership manually and does not provide shared status or control.
Source: gravitational/teleport