September 2025 Summaries
8 posts from Tailscale
Filter
Month:
Year:
Post Summaries
Back to Blog
Growing companies often face challenges in managing access and compliance due to the complexity and manual nature of tracking user permissions and deprovisioning former employees. To address these issues, a new integration between Tailscale and Vanta has been introduced, streamlining access management and compliance processes. This integration automatically syncs user and access data from Tailscale's network to Vanta, which then verifies account status, flags inconsistencies, and generates necessary compliance evidence without the need for manual interventions. Tailscale offers secure connectivity, while Vanta enhances visibility and audit readiness by performing automated compliance checks. The integration, which leverages Tailscale’s API with "Read Users" permission, ensures a robust security posture, facilitates smoother audits, and allows companies to allocate more resources towards growth. Notably, Vanta does not modify tailnets but provides comprehensive access insights by reading user data, ensuring that user access levels are appropriate and accounts are deactivated as needed.
Sep 29, 2025
288 words in the original blog post.
Tailscale has introduced a new windowed macOS UI in beta, designed to address the limitations of its existing menu bar app by providing more space for features like search, error handling, debugging, and feature discovery. The windowed app complements the menu bar app, which remains available, and is accessible for Tailscale v1.88 and later. Users can enable it via the admin console's Settings tab, and the app, still in beta, continues to receive updates for reliability and usability. The windowed UI offers a searchable list of devices and exit nodes, quick access to troubleshooting information, and a new mini player for a simplified experience. Tailscale is also preparing a similar UI for Windows devices and plans to refine the macOS version ahead of its General Availability release.
Sep 26, 2025
730 words in the original blog post.
Tailscale's latest updates focus on enhancing network reliability, manageability, and security across various platforms. This month's highlights include changes to exit node policies, improvements to Taildrive functionality, and the introduction of a windowed UI mode for macOS in beta, which features node search, TailDrop, and ping capabilities. Additionally, updates to DERP server IP addresses affect users with custom firewall settings, while enhancements in Tailscale v1.88.1 and 1.88.2 ensure better security and stability. These updates include confirmation prompts in the CLI, compatibility fixes for Tailscale SSH, and improved file accessibility in Taildrive. Platform-specific changes involve Linux GUI options, macOS system policy updates, and UI improvements for iOS and macOS 26 compatibility. For QNAP users, new builds are available, and the update can be manually downloaded. The release also addresses container, Kubernetes, and tsrecorder updates, fixing issues such as Kubernetes sidecar errors and multi-cluster ingress device certificate messages, while introducing new features like multiple replicas for high availability in Kubernetes.
Sep 26, 2025
588 words in the original blog post.
The blog post explores the advantages of using the GL-MT-3000, also known as the Beryl AX, a compact travel router with Tailscale integration, during vacations. It highlights how the router, which runs on firmware based on the open-source project OpenWRT, allows users to connect devices to a Tailscale network without needing Tailscale installed on each device. The integration, while still in beta, provides features such as accessing devices on a tailnet and using tailnet exit nodes, although it has limitations like a maximum speed of 300 Mbps due to its modest processor. The post also discusses additional benefits of travel routers, such as simplifying Wi-Fi logins, running ad blockers, and streaming media from USB-connected storage. It further details a modification to use a switch on the router to toggle Tailscale exit nodes, requiring some technical skills. The author encourages readers to share their own experiences with travel routers and Tailscale on various online platforms.
Sep 22, 2025
1,163 words in the original blog post.
Tsidp is a lightweight OIDC/OAuth server that integrates with Tailscale's identity-first networking to streamline authentication processes by eliminating the need for repeated login prompts while enhancing security. It uses cryptographically guaranteed identities to authenticate users without additional actions, making it appealing for enterprises seeking to simplify access to local, SaaS, and AI applications. By utilizing device postures and access policy rules, tsidp consolidates network and application access management, ensuring secure resource access based on device attributes. Moreover, tsidp supports less common OAuth specifications, facilitating compliance with Model Context Protocol (MCP) deployments without the need to switch identity providers. This approach addresses common frustrations with frequent logins while maintaining robust security measures, making it a valuable tool for improving user experience and operational efficiency in corporate and experimental environments.
Sep 22, 2025
1,008 words in the original blog post.
Tailscale offers a variety of ways to help users share resources with friends and family through its free plan, which can simplify their digital lives by reducing reliance on cloud services. With Tailscale, users can easily share files using Taildrop, set up persistent WebDAV folders with Taildrive, or even act as a VPN provider by configuring an exit node, such as an Apple TV, to provide privacy and security. Additionally, users can enable remote access to printers and other network devices by setting up a subnet router and sharing it with others on their Tailnet, though this requires a trust exercise due to potential logging. Tailscale also allows for the creation of simple file servers and the sharing of self-hosted web apps by using Docker and Tailscale Serve, which can enable friends and family to access various web services securely. However, users must exercise caution when exposing devices outside Tailscale’s encrypted environment to ensure security and privacy.
Sep 15, 2025
1,268 words in the original blog post.
Alex Kretzschmar discusses the benefits of using Forgejo and Tailscale to create a self-hosted code server that offers control and accessibility for developers who prefer managing their own infrastructure. Forgejo serves as a lightweight, self-hosted software forge that includes features such as repositories, issues, pull requests, CI/CD runners, and an often overlooked repository mirroring function, which allows automatic backups of public repositories. Tailscale simplifies the process of enabling secure SSH access without complex port forwarding or firewall adjustments, thanks to its peer-to-peer networking. This setup provides a straightforward and secure way to host a Git server, and further resources, including code snippets and upcoming tutorials on self-hosted CI/CD runners, are available through a GitHub repository and a YouTube channel.
Sep 15, 2025
317 words in the original blog post.
Security researchers from Cisco's Talos team discovered over 1,100 exposed AI servers, specifically Ollama endpoints, using the Shodan scanning tool, with 20% actively hosting models vulnerable to unauthorized access. The rapid rise in large language model (LLM) adoption has often surpassed the establishment of robust security measures, leading to servers going online with default settings and inadequate protection. This scenario poses risks such as unauthorized model usage, excessive resource consumption, and potential exploits like model poisoning. Tailscale CEO Avery Pennarun highlighted the common oversight of placing private API servers on the public internet, advocating for better security practices and mentioning the Model Context Protocol's complexity as a frequently overlooked challenge. Despite this, solutions exist, such as using Tailscale for secure AI hosting, which emphasizes access control and network isolation without exposing systems to the broader internet.
Sep 03, 2025
616 words in the original blog post.