This is the engineering blog of Tailscale, a company that builds a modern VPN alternative for secure, simple networking. The blog covers how they design features like Aperture for AI agent access, Kubernetes integrations, and macOS client improvements. It's great for developers and IT pros who want to see how a fast-moving startup approaches networking, security, and identity in practice.
TailscaleBlog on Tailscale
This is the engineering blog of Tailscale, a company that builds a modern VPN alternative for secure, simple networking. The blog covers how they design features like Aperture for AI agent access, Kubernetes integrations, and macOS client improvements. It's great for developers and IT pros who want to see how a fast-moving startup approaches networking, security, and identity in practice.
“Tailscale's engineering blog: practical networking and security for modern infrastructure.”
Read this when you want to understand real-world networking, access control, and identity patterns for distributed systems.
Skip it if you need deep dives into low-level kernel networking or large-scale cloud provider internals.
Compared to similar blogs like Cloudflare's, this one is more focused on practical, product-driven solutions and less on theoretical network architecture.
What this is
As told for the tourist
Start Here
A recommended reading path through the code
Start Here
A recommended reading path through the code
- 01
- 02
- 03
- 04
- 05
- 06
- 07
What's inside
8 sections of the codebase
Posting History
Activity over time
The Archive
Every post, searchable and filtered
Fixing Headlamp OIDC login with Tailscale and tsidp
5mHow to use Tailscale identity to log into Headlamp and manage Kubernetes RBAC.
How Cleric uses tsnet to securely automate software operations
6mCleric uses Tailscale's tsnet library to build a secure connectivity layer for automating software operations.
Tailscale + Paperless-ngx: scan everything, expose nothing
7mSetting up Paperless-ngx with Tailscale to securely store and access documents with optional AI tagging.
This month at Tailscale for April 2026
4mMonthly update on Tailscale clients including Aperture features, Kubernetes improvements, and API-only tailnet access.
Aperture beta: better controls for the AI agent era
5mAperture beta offers better controls and visibility for AI agents, now available on all plans.
Meet tailscale-rs, our new Rust library preview
4mPreview of tailscale-rs, a new Rust library, with a call for community testing.
Pricing v4: more value, more simply
3mTailscale's updated pricing plans offer more value, simpler pricing, and a more generous free tier.
Being the adult in the room
4mA reflection on maintaining stability and focus in a fast-moving industry.
The hidden costs of “good enough” network access
6mThe hidden costs of 'good enough' network access and how simplification benefits IT efficiency, productivity, and security.
This month at Tailscale for March 2026
4mMonthly update on Tailscale clients including Peer Relay, Services integrations, and macOS windowed UI.
Escaping the notch: Tailscale's new macOS home
5mHow Tailscale redesigned its macOS menu bar icon to handle the notch and improve user experience.
OpenClaw is fun. OpenClaw is dangerous. Here's where Tailscale helps.
6mHow Tailscale helps make OpenClaw setups safer by removing sharp edges without claiming to make it fully safe.
Aperture by Tailscale: More secure AI now available via self-serve
5mAperture by Tailscale is now available via self-serve for centralized AI control and visibility across organizations.
Border0 is joining Tailscale
4mBorder0, a PAM starter pack built on Tailscale, is joining Tailscale to enhance access controls and audit trails.
Behind the Winter Update: The team that made it work
5mBehind-the-scenes look at the team that turned product releases into real impact during the Winter Update.
Export & Share
Take the field notes with you