Andrew Cunningham explains how Meta’s Muse joins a Tailscale network as a separately authenticated node, enabling access to self-hosted services and SSH-managed devices. The post details least-privilege controls, explicit access confirmation, outbound-only connections, encrypted communication, and tailnet policies for limiting agent risk.
Tailscale engineering blog
Tailscale details performance improvements across its networking data plane, including lower-memory packet handling, multi-queue processing, Linux writev support, and cached network maps. The changes improve throughput, latency, and startup times for subnet routers, app connectors, exit nodes, and clients operating under poor connectivity.
Andrew Cunningham examines why VPN servers built into consumer routers and NAS devices can suffer from NAT traversal failures, limited performance, uncertain security support, and administrative overhead. He contrasts these centralized setups with Tailscale’s peer-to-peer connections, identity-based access controls, split tunneling, and centralized policy management.
Tailscale’s Kubernetes Operator 1.102 introduces a PeerRelay custom resource for managing in-cluster relays, improving cross-cluster connectivity in restrictive VPC environments. It also adds IPv6 egress support and optimizes Let’s Encrypt certificate retries, issuance, and deletion handling to reduce deployment delays and rate-limit pressure.
Tailscale explains how to embed secure networking into applications with the Go-based tsnet library and provision isolated tailnets through APIs. It also covers automating certificates, sharing policies, ACLs, key rotation, and administrative workflows through code and GitOps.
Tailscale introduces tailcat, an open-source Go package and CLI that uses WireGuard, NAT traversal, and DERP without the Tailscale control plane or accounts. The post explains its address exchange, userspace TCP stack, direct and relayed connections, SOCKS mode, and self-hosted DERP options.
Tailscale integrates Control D DNS filtering directly into a tailnet, letting teams apply security rules to users, groups, tags, or devices through ACLs. The post explains nameserver setup, encrypted DNS queries, custom filtering rules, and user-based billing.
Tailscale introduces its PAM beta, combining private connectivity with identity-aware privileged access controls. The product supports just-in-time approvals, resource-level policies, connector-based access to infrastructure, and session logging or recording for audits and investigations.
Tailscale announces Aperture’s general availability as an AI gateway for managing model access, MCP endpoints, and agent tools. The release adds built-in model tokens, tailnet and Tailscale SSH controls, chat Projects, fine-grained permissions, and audit-friendly access controls.
Tailscale previews upcoming 2026 product updates focused on governing AI and agent access, time-bound privileged access, DNS-level Internet protection, and more programmable networking. The full technical details will be announced at TailscaleUp.
Tailscale and SQLite developers investigated 19 database corruption incidents and traced them to a rare race between WAL checkpointing and write transactions. The post explains the forensic telemetry, transaction replay, VFS tracing, SQLite fixes, and lessons about operating databases outside well-tested paths.
Keep AI agents useful without combining their riskiest capabilities.
Tailscale explains that it was not itself exploited during the Hugging Face intrusion, but argues it still should have prevented the incident. The post frames the event as a security and access-control failure worth learning from.
Mike Shaver joins Tailscale to scale engineering quality.
Someone's subsidizing your coding agent. Aperture shows whether it's you.
Take Home Assistant beyond your home network with Tailscale.
AI agents do a lot. Aperture keeps the audit trail.
Cut through the buzzwords with a clear explanation of the agentic AI stack.
Border0 ties every connection to a real person, securing databases, Kubernetes, SSH, and more.
Keep Tailscale logs with the rest of your security data.