Technology · Agentic → IAM · Open Core · wiki:deep
Tailscale is an identity-based WireGuard mesh (a tailnet): clients and tailscaled join via SSO, receive stable 100.x addresses and MagicDNS names, and connect peer-to-peer (DERP relay when NAT blocks). It is not a hub-and-spoke VPN appliance and not an application policy engine — it answers “which devices/users may open which ports on which nodes.” Node software is largely open source (BSD); the coordination service and some platform GUIs are commercial.
Agentic and local-AI installs need private paths to always-on hosts (Studio Ollama, remote Claude Code, IMAP boxes, research DBs) without publishing ports. Tailscale is the network access layer on the observe/admin path: mesh + ACL/grants + optional Tailscale SSH / Serve. Product authority (who may approve, spend, or mutate the ledger) stays in Keycloak / Open Policy Agent / Cedar — Tailscale only decides reachability.
A node authenticates to the control plane, downloads peer keys and the tailnet policy, then builds WireGuard sessions to peers (direct first, DERP fallback). Operators extend the mesh with subnet routers (advertise a CIDR for devices that cannot run Tailscale), exit nodes (default-route internet via a chosen node), Serve (HTTPS reverse-proxy to localhost for the tailnet, with identity headers), Funnel (same idea for the public internet — rarely correct for model/admin APIs), Tailscale SSH (identity-auth SSH on the Tailscale IP), and K8s sidecars/operator for cluster services.
tailscaled; tailscale up with SSO or auth key. tailscale serve (private) — avoid Funnel for secrets. Related: keycloak · open-policy-agent · cedar · kubernetes · ollama · usages _source/tailscale-usages.md
Named limits without a resolution are incomplete — full table: ../_source/tailscale-usages.md § Limits → resolutions.
| Limit | Resolution (this stack) |
|---|---|
| Coordination / join depends on control plane | Hosted Tailscale now; outage = no new nodes/ACL, peers keep working; Tailnet Lock when mesh stabilizes; Headscale only when control plane must be local |
| DERP relay latency | Design for direct Studio↔server; measure with tailscale ping; fix NAT before blaming the app |
| Funnel exposes localhost | Funnel denied on tag:studio / tag:server / tag:agent; Serve only; optional tag:demo |
| Default allow-all ACL | Day-one deny-by-default grants + tags; GitOps policy.hujson |
| Mesh ≠ authority | Tailscale = ports; Open Policy Agent / Cedar / Keycloak = actions |
Linux --accept-routes off |
Enable on nodes that use subnet routers / app connectors |
| macOS App Store limits | Studio/Mac needing Serve or Tailscale SSH → OSS/CLI tailscaled |
Operator checklist (live proofs still open): CHECKLIST.md.
Cite: How Tailscale works · Tailnet Lock · policy file syntax · macOS variants · Serve/Funnel docs · science/sources/.
Claims below are backed by science sources on disk.
WireGuard mesh + coordination model
How Tailscale works (blog) · STRONG
“Our base layer is the increasingly popular and excellent open source WireGuard package (specifically the userspace Go variant, wireguard-go).”
Serve vs Funnel / identity headers
Tailscale Serve & Funnel docs · STRONG
“Tailscale Serve lets you route traffic from other devices on your Tailscale network (known as a tailnet) to a local service running on your device.”
Repo / OSS boundary
tailscale/tailscale README · STRONG
“Private WireGuard® networks made easy”
9 tags · 14 out · 15 in · 3 artifacts · 1 gaps · 0 corpus docs