Home / Companies / Tailscale / Blog / October 2025

October 2025 Summaries

13 posts from Tailscale

Filter
Month: Year:
Post Summaries Back to Blog
Tailscale's Fall Update Week introduced a range of new features aimed at enhancing the product's simplicity, intelligence, and connectivity, including the debut of Services for flexible resource allocation, Tailscale Peer Relays for efficient traffic routing, and the ability to manage multiple tailnets with the same identity provider. The update also showcased workload identity federation to streamline authentication processes, and app capabilities that grant third-party applications access to Tailscale features. Additionally, a new windowed macOS UI in beta was highlighted, along with the introduction of tsidp, a lightweight identity tool. These developments stem from collaborative efforts across various Tailscale teams, aiming to simplify networking processes.
Oct 31, 2025 500 words in the original blog post.
Tailscale's latest updates focus on enhancing network reliability, management, and security through various improvements across clients, admin tools, integrations, and infrastructure. Key highlights include the rewritten Tailscale GitHub Action in TypeScript, supporting features like a ping parameter and improved logging, and the introduction of Tailscale Services for creating and managing applications independently of devices. New offerings like Tailscale Peer Relays and multiple tailnets provide advanced traffic routing and organizational flexibility, while workload identity federation simplifies agent and workload creation. The visual policy editor is now generally available, facilitating policy creation and editing through browser-based controls. Updates to the admin console include new naming tools and better support for multiple tailnets. Client updates address security and stability across platforms, with notable changes in Linux, Windows, macOS, iOS, Android, and more, including seamless node key renewal and improved DNS resolver configurations. Additionally, Kubernetes updates enhance DNS support and logging capabilities, and tsrecorder features a refreshed web interface and improved session recording.
Oct 31, 2025 992 words in the original blog post.
Tailscale, widely recognized for its VPN capabilities, can be leveraged to build applications directly on its platform, as demonstrated by the creation of tsidp, a lightweight identity provider. This development was facilitated by three key Tailscale features: tsnet, application capability grants, and Funnel. Tsnet allows embedding Tailscale connectivity within a Go program, enabling secure communication by using a hostname and an auth key. It also provides user identity information through its .WhoIs call, which tsidp uses for authorization processes. Application capability grants provide customizable access controls through JSON configurations, enhancing the flexibility of user and group permissions. Funnel allows applications within a tailnet to be exposed globally while maintaining private access to specific endpoints, supporting seamless login experiences for public SaaS apps. The article also encourages exploring the potential of tsnet for creating a variety of applications, showcasing its versatility and inviting developers to delve into its documentation and community projects.
Oct 30, 2025 838 words in the original blog post.
Workload identity federation is a new feature introduced by Tailscale that enhances the security and automation of infrastructure and CI/CD systems by replacing static credentials like API keys with signed, short-lived OpenID Connect (OIDC) tokens. This approach leverages existing identity systems in cloud providers, allowing workloads to authenticate with Tailscale without manually managing secrets. The system supports various cloud platforms such as GitHub Actions, Google Cloud, and Microsoft Azure, and it is designed to facilitate secure, automated access to resources by using verifiable tokens. The feature is particularly beneficial for environments that prioritize automation and security, enabling ephemeral workloads to access networks with minimal permissions and reducing the complexity of credential management. The Tailscale admin console has been updated to simplify the management of OAuth clients and federated identities, and workload identity federation is now available in public beta across all Tailscale plans.
Oct 30, 2025 725 words in the original blog post.
Tailscale has announced the availability of app capabilities and user identities in HTTP headers for all applications connected to a tailnet, facilitating the development of identity and capability-aware applications. This enhancement builds on Tailscale's existing identity-based access controls, allowing developers to create powerful, secure apps without being restricted to specific coding languages or needing custom code. By utilizing HTTP headers, Tailscale expands its compatibility with various applications and simplifies future-proofing for developers, as apps using these headers will not require re-engineering even if new tools are released in other languages. The serve function can now accept app capability grants through a command-line flag, enabling applications to use Tailscale's identity features in a language-independent manner. While currently available through a command-line interface, a declarative configuration option is planned for the future. These capabilities are included in the latest unstable builds and will be part of the upcoming 1.92 stable release, with feedback encouraged through GitHub, Reddit, or Discord.
Oct 30, 2025 672 words in the original blog post.
Tailscale has launched its visual policy editor, previously in beta, to general availability, providing a user-friendly tabular and graphical interface for managing Tailscale network (tailnet) policy files. This tool is designed to complement the existing JSON-based configuration by allowing users to control access to nodes and machines through an intuitive interface that includes features like buttons, live previews, and auto-completing search. Users can still edit the HuJSON text file or use Terraform and the REST API if preferred. The visual editor is intended to simplify network access management for non-technical users, as illustrated by Chris Foster from DEEL Media, who noted its significant impact in reducing the time and technical explanation required for network permissions. The editor is accessible to all Tailscale users, including those on the free tier, enhancing its offering across various environments, such as IT, development, and security.
Oct 29, 2025 245 words in the original blog post.
Tailscale has introduced Tailscale Peer Relays, a customer-managed traffic relaying solution that allows any Tailscale node to act as a relay for peer nodes within the same tailnet, offering an alternative to the company's managed DERP servers. This new feature is integrated into the Tailscale client and aims to provide higher throughput connections, particularly beneficial for locked-down cloud infrastructures or environments with strict network firewalls. Tailscale Peer Relays are designed to address limitations in network address translation (NAT) traversal by enabling high-throughput relay topologies that approach direct connection speeds. This solution is part of Tailscale's ongoing efforts to enhance connectivity and performance, addressing customer feedback regarding the constraints of the existing DERP relay fleet. The peer relays can be easily enabled via a command in the Tailscale CLI, and all traffic remains end-to-end encrypted using WireGuard®. Currently available as a public beta, Tailscale Peer Relays offer flexibility and scalability for various network environments, allowing customers to maintain performance benchmarks and streamline connectivity in complex network scenarios.
Oct 29, 2025 1,037 words in the original blog post.
Tailscale has introduced a feature allowing organizations to create multiple tailnets under a single identity provider, providing flexibility for teams needing separation for testing, development, or customer management without adding complexity. Each tailnet can be customized with unique policies, tags, devices, and specific admin assignments, and they can be marked as "unlisted" to control visibility within the organization. This feature caters to enterprises using services like Google Workspace, Okta, or Microsoft Entra ID by allowing group references across tailnets without additional syncing. Additionally, Tailscale has launched an API for programmatically creating tailnets, which is ideal for developers looking to integrate Tailscale connectivity into applications securely. This API-generated tailnet, distinct from user-managed ones, is primarily for automation and integration scenarios. Both the multiple tailnets feature and the tailnet creation API are available through an alpha program, with plans for further enhancements like user assignments based on groups and self-serve tailnet creation in the admin console.
Oct 29, 2025 837 words in the original blog post.
Tailscale Services, a recent innovation from Tailscale, enables users to define network resources with greater precision and flexibility, offering virtual IPv4 and IPv6 addresses (TailVIPs) and MagicDNS names for easy reference and access control. This service is designed to accommodate complex networking scenarios, such as dynamic IP addresses or ephemeral environments, without requiring direct installation on the resources. It acts similarly to traditional Tailscale nodes but is not hardware-bound, allowing for intelligent routing and high availability, potentially eliminating the need for traditional load balancing setups. Tailscale Services supports a wide range of applications, from CI pipeline connectivity to secure internal application access, utilizing a repeatable API-driven interface that simplifies scaling and infrastructure management. In its public beta phase, Tailscale Services is free, with future improvements planned, including enhanced state validation, third-party proxy integration, and broader service discovery capabilities.
Oct 28, 2025 1,578 words in the original blog post.
The Fall Update Week, spanning October 27-30, 2025, focuses on simplifying and enhancing network connectivity across people, services, and systems, aiming to make secure networking intuitive and less cumbersome. The event emphasizes reducing policy-related stress, minimizing the need for firewall adjustments, and improving network configurations to be predictable and hassle-free. This week-long initiative is not a single grand event but a culmination of carefully integrated developments that have been in progress throughout the year. It includes a series of webinars, videos, blog posts, and talks, with a recap and future outlook scheduled for Friday. The updates are being shared through various platforms, including YouTube and social media, with interactive sessions such as a webinar and a Discord fireside chat planned to engage the community. The overarching goal is to transform networking into a straightforward, reliable process, likened to managing meaningful relationships rather than navigating complex systems.
Oct 26, 2025 478 words in the original blog post.
Tailscale's recent blog post explores ongoing improvements in NAT traversal, focusing on enhancing direct connectivity between devices by addressing challenges such as locked-down networks that require relays like Tailscale's DERP. While DERP reliably forwards encrypted packets over TCP, it is not optimized for performance, prompting discussions about using a UDP-based relay to improve throughput and reduce latency in challenging connectivity scenarios. As peer-to-peer communication becomes mainstream due to tools like WebRTC and VPNs, there is a shift in equipment defaults and enterprise policies, paving the way for easier NAT traversal. Tailscale's multi-strategy approach, including STUN, hole punching, and DERP relays, aims to make VPN networking more reliable, envisioning a future where encrypted packets take the most direct path possible. The blog also highlights the potential impact of IPv6 adoption in simplifying connectivity issues by allowing peers to communicate directly without NAT. The overarching trend indicates a move towards more efficient, peer-to-peer, and direct connectivity, with Tailscale continuing to refine its solutions to ensure seamless communication in varied network environments.
Oct 24, 2025 795 words in the original blog post.
In the second installment of a series on NAT traversal improvements, the focus is on the challenges faced when establishing secure connections in public cloud environments, particularly with Tailscale. The major cloud providers, such as AWS, Azure, and Google Cloud, offer NAT solutions that are optimized for outbound traffic but present obstacles for peer-to-peer connectivity due to their symmetric design and randomized port assignments. To address these challenges, various strategies are discussed, including assigning public IPs to cloud instances, using custom NAT instances or firewalls, leveraging specific cloud provider features, and employing subnet routers or exit nodes for traffic routing. The article suggests that while public IPs simplify direct connections, alternative configurations can mitigate NAT constraints, with the promise of future enhancements as cloud networks slowly adapt to these connectivity needs.
Oct 21, 2025 1,430 words in the original blog post.
Tailscale is enhancing its NAT traversal techniques to facilitate secure peer-to-peer (P2P) connections, focusing on improving direct connections between devices while minimizing reliance on DERP relay servers. Direct P2P connections, which bypass central servers and offer better performance, account for over 90% of Tailscale's traffic under normal conditions. However, challenges arise from symmetric or "hard" NATs, multiple NAT layers, strict firewalls, carrier-grade NAT, and restrictive endpoint configurations, often necessitating DERP's assistance. Tailscale is actively working to overcome these obstacles, including sponsoring a patch for FreeBSD's firewall to support endpoint-independent NAT mapping for UDP traffic, enhancing connectivity for P2P applications. This approach is considered safer and more effective than protocols like UPnP or NAT-PMP, which can pose security risks and are not universally supported. Tailscale continues to refine its client software to handle NAT traversal complexities, optimize connection paths, and improve diagnostics, all while preparing for future connectivity advancements, including expanding IPv6 support.
Oct 15, 2025 2,728 words in the original blog post.