Breakpoint

Tailscale engineering blog

Your agent, your network: How Meta’s Muse agent works with Tailscale
Andrew Cunningham explains how Meta’s Muse joins a Tailscale network as a separately authenticated node, enabling access to self-hosted services and SSH-managed devices. The post details least-privilege controls, explicit access confirmation, outbound-only connections, encrypted communication, and tailnet policies for limiting agent risk.
We're making Tailscale faster
Tailscale details performance improvements across its networking data plane, including lower-memory packet handling, multi-queue processing, Linux writev support, and cached network maps. The changes improve throughput, latency, and startup times for subnet routers, app connectors, exit nodes, and clients operating under poor connectivity.
Your built-in router VPN might be more trouble than it's worth
Andrew Cunningham examines why VPN servers built into consumer routers and NAS devices can suffer from NAT traversal failures, limited performance, uncertain security support, and administrative overhead. He contrasts these centralized setups with Tailscale’s peer-to-peer connections, identity-based access controls, split tunneling, and centralized policy management.
Build with Tailscale. Build on Tailscale.
Tailscale explains how to embed secure networking into applications with the Go-based tsnet library and provision isolated tailnets through APIs. It also covers automating certificates, sharing policies, ACLs, key rotation, and administrative workflows through code and GitOps.
Tailcat: Tailscale without Tailscale, by Tailscale
Tailscale introduces tailcat, an open-source Go package and CLI that uses WireGuard, NAT traversal, and DERP without the Tailscale control plane or accounts. The post explains its address exchange, userspace TCP stack, direct and relayed connections, SOCKS mode, and self-hosted DERP options.
Introducing DNS filtering by Control D
Tailscale integrates Control D DNS filtering directly into a tailnet, letting teams apply security rules to users, groups, tags, or devices through ACLs. The post explains nameserver setup, encrypted DNS queries, custom filtering rules, and user-based billing.
Aperture GA: Building a home(lab) for agentic AI
Tailscale announces Aperture’s general availability as an AI gateway for managing model access, MCP endpoints, and agent tools. The release adds built-in model tokens, tailnet and Tailscale SSH controls, chat Projects, fine-grained permissions, and audit-friendly access controls.
The TailscaleUp-date
Tailscale previews upcoming 2026 product updates focused on governing AI and agent access, time-bound privileged access, DNS-level Internet protection, and more programmable networking. The full technical details will be announced at TailscaleUp.
How we tracked down a 16-year-old SQLite bug
Tailscale and SQLite developers investigated 19 database corruption incidents and traced them to a rare race between WAL checkpointing and write transactions. The post explains the forensic telemetry, transaction replay, VFS tracing, SQLite fixes, and lessons about operating databases outside well-tested paths.
Tailscale didn’t stop the Hugging Face intrusion
Tailscale explains that it was not itself exploited during the Hugging Face intrusion, but argues it still should have prevented the incident. The post frames the event as a security and access-control failure worth learning from.