Tailscale Network Management
Quick Start
# Install (Linux)
curl -fsSL https://tailscale.com/install.sh | sh
# Install (macOS)
brew install tailscale
# Connect and authenticate
sudo tailscale up
# Check status
tailscale status
# Get your Tailscale IP
tailscale ip -4
Common Operations
Connection Management
tailscale up # Connect
tailscale down # Disconnect (daemon stays running)
tailscale status # View peers
tailscale status --json | jq # Detailed network map
tailscale ping machine-name # Test connectivity (ignores ACLs)
tailscale ping --icmp machine-name # Test with ACLs
tailscale set --exit-node=name # Use exit node
tailscale set --exit-node= # Stop using exit node
Use tailscale set to change settings without reconnecting. Use tailscale up for initial setup.
Subnet Router Setup
Run scripts/setup_subnet_router.sh <subnet_cidr> [auth_key] for automated setup.
Manual steps:
- Enable IP forwarding on the router device
sudo tailscale up --advertise-routes=192.168.1.0/24
- Approve routes in admin console (Machines > device > Edit route settings)
- Linux clients:
sudo tailscale up --accept-routes
Exit Node Setup
Run scripts/setup_exit_node.sh [auth_key] for automated setup.
Manual steps:
- Enable IP forwarding on the exit node
sudo tailscale up --advertise-exit-node
- Approve in admin console (Machines > device > Edit route settings > Use as exit node)
- Clients:
tailscale set --exit-node=node-name --exit-node-allow-lan-access
Tailscale SSH
# Enable on server
sudo tailscale set --ssh
# Connect from client (no special setup needed)
ssh machine-name
Requires both network access grant and SSH ACL rule. See acl-examples.md for SSH ACL patterns.
Serve and Funnel
# Serve locally to tailnet
tailscale serve 3000
# Expose to public internet (ports 443, 8443, or 10000 only)
tailscale funnel 3000
# TCP forwarding with TLS termination
tailscale serve --tls-terminated-tcp=5432 localhost:5432
# Check status / turn off
tailscale serve status
tailscale serve off
Access Control
Use Grants (modern, recommended) over ACLs (legacy). Both work, but Grants support application-layer capabilities.
{
"groups": {
"group:engineering": ["alice@example.com"]
},
"tagOwners": {
"tag:server": ["group:engineering"]
},
"grants": [
{
"src": ["group:engineering"],
"dst": ["tag:server"],
"ip": ["22", "443"]
}
]
}
Key patterns: Use groups for people, tags for machines. Always include both network grants and SSH rules for SSH access.
For detailed ACL scenarios, SSH access patterns, posture checks, auto-approvers, GitOps integration, and common mistakes, see acl-examples.md.
Reference Files
- cli-reference.md - Complete CLI command reference with all flags, target formats, and platform-specific notes
- acl-examples.md - Detailed ACL/grants configuration: team-based access, dev/staging/prod isolation, SSH patterns, posture checks, auto-approvers, GitOps, migration from ACLs to Grants
- api-usage.md - REST API, Terraform provider, Python SDK, webhooks, automation examples
- troubleshooting.md - Connectivity diagnostics, subnet router issues, exit node issues, SSH problems, MagicDNS, performance tuning, common error messages
- production-setup.md - Architecture patterns, HA setup, security hardening, IaC (Terraform/Ansible/K8s), monitoring, DR, operational procedures
Scripts
scripts/setup_subnet_router.sh <subnet_cidr> [auth_key] - Automated subnet router setup (installs Tailscale, enables IP forwarding, configures routes)
scripts/setup_exit_node.sh [auth_key] - Automated exit node setup (installs Tailscale, enables IP forwarding, advertises as exit node)
1---2name: tailscale3description: Comprehensive Tailscale VPN setup, configuration, and management for mesh networking, secure access, and zero-trust infrastructure. Covers installation, CLI commands, subnet routers, exit nodes, Tailscale SSH, ACL/grants configuration, MagicDNS, Tailscale Serve/Funnel, API automation, and production deployment best practices. Use when setting up Tailscale, configuring tailnet access controls, deploying subnet routers or exit nodes, enabling Tailscale SSH, exposing services with Serve/Funnel, automating via the Tailscale API, troubleshooting connectivity, or planning production Tailscale deployments.4---56# Tailscale Network Management78## Quick Start910```bash11# Install (Linux)12curl -fsSL https://tailscale.com/install.sh | sh1314# Install (macOS)15brew install tailscale1617# Connect and authenticate18sudo tailscale up1920# Check status21tailscale status2223# Get your Tailscale IP24tailscale ip -425```2627## Common Operations2829### Connection Management3031```bash32tailscale up # Connect33tailscale down # Disconnect (daemon stays running)34tailscale status # View peers35tailscale status --json | jq # Detailed network map36tailscale ping machine-name # Test connectivity (ignores ACLs)37tailscale ping --icmp machine-name # Test with ACLs38tailscale set --exit-node=name # Use exit node39tailscale set --exit-node= # Stop using exit node40```4142Use `tailscale set` to change settings without reconnecting. Use `tailscale up` for initial setup.4344### Subnet Router Setup4546Run `scripts/setup_subnet_router.sh <subnet_cidr> [auth_key]` for automated setup.4748**Manual steps:**491. Enable IP forwarding on the router device502. `sudo tailscale up --advertise-routes=192.168.1.0/24`513. Approve routes in admin console (Machines > device > Edit route settings)524. Linux clients: `sudo tailscale up --accept-routes`5354### Exit Node Setup5556Run `scripts/setup_exit_node.sh [auth_key]` for automated setup.5758**Manual steps:**591. Enable IP forwarding on the exit node602. `sudo tailscale up --advertise-exit-node`613. Approve in admin console (Machines > device > Edit route settings > Use as exit node)624. Clients: `tailscale set --exit-node=node-name --exit-node-allow-lan-access`6364### Tailscale SSH6566```bash67# Enable on server68sudo tailscale set --ssh6970# Connect from client (no special setup needed)71ssh machine-name72```7374Requires both network access grant and SSH ACL rule. See [acl-examples.md](references/acl-examples.md) for SSH ACL patterns.7576### Serve and Funnel7778```bash79# Serve locally to tailnet80tailscale serve 30008182# Expose to public internet (ports 443, 8443, or 10000 only)83tailscale funnel 30008485# TCP forwarding with TLS termination86tailscale serve --tls-terminated-tcp=5432 localhost:54328788# Check status / turn off89tailscale serve status90tailscale serve off91```9293## Access Control9495Use **Grants** (modern, recommended) over ACLs (legacy). Both work, but Grants support application-layer capabilities.9697```json98{99 "groups": {100 "group:engineering": ["alice@example.com"]101 },102 "tagOwners": {103 "tag:server": ["group:engineering"]104 },105 "grants": [106 {107 "src": ["group:engineering"],108 "dst": ["tag:server"],109 "ip": ["22", "443"]110 }111 ]112}113```114115**Key patterns:** Use groups for people, tags for machines. Always include both network grants and SSH rules for SSH access.116117For detailed ACL scenarios, SSH access patterns, posture checks, auto-approvers, GitOps integration, and common mistakes, see [acl-examples.md](references/acl-examples.md).118119## Reference Files120121- **[cli-reference.md](references/cli-reference.md)** - Complete CLI command reference with all flags, target formats, and platform-specific notes122- **[acl-examples.md](references/acl-examples.md)** - Detailed ACL/grants configuration: team-based access, dev/staging/prod isolation, SSH patterns, posture checks, auto-approvers, GitOps, migration from ACLs to Grants123- **[api-usage.md](references/api-usage.md)** - REST API, Terraform provider, Python SDK, webhooks, automation examples124- **[troubleshooting.md](references/troubleshooting.md)** - Connectivity diagnostics, subnet router issues, exit node issues, SSH problems, MagicDNS, performance tuning, common error messages125- **[production-setup.md](references/production-setup.md)** - Architecture patterns, HA setup, security hardening, IaC (Terraform/Ansible/K8s), monitoring, DR, operational procedures126127## Scripts128129- **`scripts/setup_subnet_router.sh <subnet_cidr> [auth_key]`** - Automated subnet router setup (installs Tailscale, enables IP forwarding, configures routes)130- **`scripts/setup_exit_node.sh [auth_key]`** - Automated exit node setup (installs Tailscale, enables IP forwarding, advertises as exit node)