Changelog

Updates to the Tailscale client and service.

View device posture status

  • When checking the device posture status of a machine on the Machines page of the admin console, you can see the assertions the posture requires, each machine's value, and whether it's passing. For each posture, you can also see a count of policy file rules that affect a machine and require this posture.

Tailscale GitHub Action v4.2.0

  • The Tailscale GitHub Action properly skips re-downloading binaries on linux if a file with a matching SHA already exists.
  • The Tailscale GitHub Action groups log output by default. Use the log-mode parameter to control whether the logging output is grouped, ungrouped, or run in "quiet" mode.

Tailscale v1.102.4

Update instructions
All Platforms
  • Resolved an issue that could cause a loss in connectivity when a netmap update occurs near the time of reauthentication.
macOS
  • Resolved an issue that could prevent exit nodes from appearing when using a custom coordination server.
iOS
  • Resolved an issue that could prevent exit nodes from appearing when using a custom coordination server.
tvOS
  • Resolved an issue that could prevent exit nodes from appearing when using a custom coordination server.
  • Resolved an issue that prevented the VPN tunnel from automatically starting on a cold boot.

Tailscale PAM

Read more

Use Tailscale Privileged Access Management (PAM) (beta) to provide application-aware access to resources in your Tailscale network.


Request access to join the Tailscale PAM beta.

Aperture by Tailscale GA

Read more

Use Aperture (generally available) to secure and manage AI agents and LLM sessions with cost controls, request and response hooks, guardrails, logging, MCP support, and API proxying.

  • A promotional model token credit is included for use with new and existing Aperture gateways.
  • Model tokens can be purchased directly in Aperture for major AI models.
  • With user approval, Aperture can add nodes to your tailnet with the Tailscale MCP endpoint for Aperture and coding agents.
  • Tailnet nodes can be accessed through Tailscale SSH with the SSH MCP endpoint after approval.
  • Chat Projects can be used to share instructions, tool access, and tailnet nodes in group chats.
  • Baseline tool access can be defined across Aperture chats with default tool permissions.

Tailscale v1.102.3

Update instructions
All Platforms
  • Go is updated to version 1.26.6.
  • Tailscale refuses host-scoped IPv4 destinations at every point that acts on an unmapped 4via6 address. This fix addresses a security vulnerability described in TS-2026-011.
  • When MagicDNS is disabled, unqualified hostnames are correctly forwarded to the configured nameservers.
  • Resolved an issue where nodes with Tailnet Lock enabled on large tailnets would experience startup failures.
Windows
  • Resolved an issue where the Windows installer would fail during an upgrade when the name of the user's home directory contained a space.
  • tailscaled returns an error instead of panicking on devices where IPv6 or NetBios over TCP/IP is disabled.
iOS
  • Memory usage is reduced for iOS devices on large tailnets.
tvOS
  • Memory usage is reduced for tvOS devices on large tailnets.

Tailscale container image v1.102.3

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository.

  • The container waits longer for its initial connection to the coordination server when you set the new TS_BOOT_TIMEOUT environment variable. It accepts a duration, such as 90s or 3m, and defaults to 60s.

Tailscale Kubernetes Operator v1.102.3

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

  • Peer relays on AWS are reachable regardless of the availability zone their pod is scheduled in. Pinning Elastic IPs also requires pinning the pods to the same zone using a ProxyClass.
  • Network Load Balancers fronting peer relays on AWS use HTTP instead of TCP for pod health checks. Peer relays listen only on UDP, so the default TCP health check could never succeed, causing every target to be reported as unhealthy.

Tailnet list API pagination

  • The list tailnets endpoint paginates results. By default, organizations with more than 100 tailnets now receive only the first 100 results, with totalCount and cursor parameters to retrieve additional results.
  • limit and cursor query parameters are supported on the list tailnets endpoint. If no limit is specified, the endpoint returns 100 results per page. Use the returned cursor value as the next request's cursor parameter to retrieve the next page until the returned cursor value is empty.

Tailscale Kubernetes Operator v1.102.2

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

  • PeerRelays are deployable in-cluster via a custom resource.
  • Annotations can now be applied to the operator's deployment resource via Helm.
  • Workload identity federation can now be configured for the Tailnet custom resource.
  • 4via6 is supported in connector and egress proxy resources when egressing from a dual-stack cluster.
  • IPv6 is supported in Egress ProxyGroups.
  • Operator log output excludes superfluous entries, such as entries for resources that do not contain annotations.
  • Several log lines have adjusted log levels.
  • MTU values are clamped on both the input and output interfaces, where previously only the output interface was clamped.
  • ProxyGroup services no longer fail to reconcile when using the same hostname across multiple tailnets.
  • ProxyGroup static endpoints no longer cause constant reconciliation loops due to non-deterministic ordering.
  • DNS reconciler no longer drops reconcile events, which left the dnsrecords ConfigMap stale.
  • EndpointSlices for Egress ProxyGroup are verified on every reconcile.
  • Cert renewal retries follow Let's Encrypt's recommended backoff schedule instead of a fixed interval.
  • Let's Encrypt Retry-After headers are honored by Kubernetes proxies when hitting rate limits, which avoids the tight retry loops that made rate-limit backoffs worse.
  • Per-attempt cert issuance timeout in Kubernetes proxies is increased to 30 minutes, giving ACME challenges room to complete under load without failing prematurely.
  • Cert issuance attempts no longer run against a VIPService that is being torn down during Ingress deletion, which wasted Let's Encrypt rate-limit quota.

Tailscale container image v1.102.2

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository.

This version contains no changes except for library updates.

Tailscale tsrecorder v1.102.2

A new release of the Tailscale tsrecorder is available. You can download it from Docker Hub.

  • Recorder does not attempt to index empty recording placeholder files on startup.

Tailscale v1.102.1

Update instructions
All Platforms
  • tailscaled_serve_outbound_bytes_total and tailscaled_serve_inbound_bytes_total client metrics report bytes sent to and received from peers on Tailscale Serve connections for Tailscale Services.
  • The tailscale get CLI command returns the current node's preferences.
  • The tailscale whoami CLI command displays information about the current user and device.
  • The tailscale service list CLI command displays Tailscale Services visible to the current node.
  • Node additions and removals are processed in constant time, significantly reducing CPU usage on large tailnets. This currently applies to all platforms except Windows.
  • Tailscale Funnel domains use TLS-ALPN-01 for faster HTTPS certificate renewals.
  • Deprecated formats for 4via6 MagicDNS names are no longer available to use.
  • TLS certificates on idle servers proactively auto-renew in the absence of traffic. Warnings are issued when there is no valid cached certificate.
  • Dials to dual-stack DNS names through an IPv4-only exit node connect to the correct address when using tailscaled in userspace mode.
  • Certificate issuance for multiple domains runs in parallel. Provisioning multiple domains does not stall each certificate behind the previous one.
  • Resolved an issue causing connectivity issues from the operating system waking from sleep in wireguard-go.
  • A node's home DERP region is reported to the coordination server after a profile switch or login, allowing for peers to immediately connect to the node.
  • A memory leak that occurred after a failed WireGuard handshake has been resolved.
  • tailscale status --peers=false command shows the current device name in the output.
  • Resolved an issue that prevented connectivity via Tailscale Peer Relays after a client restart.
  • Tailscale SSH passes environment variables to child processes via inherited file descriptors. This fix addresses a security vulnerability described in TS-2026-010.
Linux
  • Assembly crypto routines for 32-bit ARM are available, improving performance on these platforms.
  • Userspace TUN optimizations improve throughput and performance.
  • Resolved an issue impacting performance of UDP GSO on Linux v7.0.x through v7.1.4.
macOS
  • The Tailscale protocol handler supports deep-linking to devices, exit nodes, and settings panels in the application window.
  • The device list in the menu bar and Windowed UI loads more efficiently.
  • The client onboarding process is redesigned to match the style of the windowed UI.
  • Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.
  • The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.
  • Domain matching on-demand rules are evaluated in the correct order.
  • A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.
  • tailscale configure kubeconfig checks permissions on the $KUBECONFIG file before refusing to write to it when it's in a non-standard directory, fixing false rejections during Kubernetes API server access setup.
iOS
  • A new split-plane layout is used on iPad in both portrait and landscape orientation and on sufficiently wide iPhones in landscape.
  • The status widget supports toggling the active exit node inline.
  • Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.
  • The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.
  • Domain matching on-demand rules are evaluated in the correct order.
  • A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.
tvOS
Android
  • A single CGNAT route is created when no other interface is using CGNAT.
  • TCP connections do not reset when VPN routing changes due to a netmap update.
  • Health warnings are promptly cleared as soon as the underlying issue is resolved.
Synology
  • ARMv7 binaries with software floating point are produced for certain Synology NAS models, replacing older ARMv5 binaries.

Admin console URL change

  • The Tailscale admin console is now available at console.tailscale.com. Authentication continues to use login.tailscale.com, and requests to login.tailscale.com/admin/ automatically redirect to the new subdomain.

Tailscale v1.98.9

Update instructions

All Platforms

  • Tailscale Serve Unix socket proxy targets are restricted to the root user. This fix addresses a security vulnerability described in TS-2026-005.
  • Tailscale SSH does not allow the use of UIDs or numeric-only usernames. This fix addresses a security vulnerability described in TS-2026-006.
  • Nodes advertising Tailscale Services filter and reject packets from service IPs on ports they do not advertise. This fix addresses a security vulnerability described in TS-2026-007.
  • Tailscale Serve and Tailscale Funnel terminate path walks for non-absolute paths, preventing CPU core pinning. This fix addresses a security vulnerability described in TS-2026-008.
  • Tailscale SSH does not allow the use of usernames with leading dashes. This fix addresses a security vulnerability described in TS-2026-009.
  • An issue where a user could be logged out of Tailscale when changing the tag on a device via CLI has been resolved.
  • An issue that could cause a crash on 32-bit ARM platforms is resolved.

Tailscale v1.98.8

Update instructions

Note: 1.98.6 and 1.98.7 were release candidates intended for testing only.

All Platforms

  • An issue causing connectivity disruptions when the operating system wakes from sleep in wireguard-go is resolved.
  • An issue causing excessive handshake initiation retries in wireguard-go is resolved.
  • An issue causing connection leaks in Tailscale SSH Session Recording is resolved.

Public IP address device posture attribute

  • ip:publicAddress device posture attribute is available for use in postures and viewable on the Machines page of the admin console. To test, go to the Settings page of the admin console and toggle Public IP addresses for device posture (beta).

Tailnet system policy values

  • The Tailnet system policy accepts a comma-separated list of tailnet IDs or organization IDs.

Aperture chat, connectors, and sandboxes

Read more
  • Use identity-aware connectors to let agents and users reach your data via MCP and API endpoints (alpha).
    • Tailnet access controls apply to every request, giving you one identity system across the chat interface and any agent connected to your tailnet.
  • Use Aperture chat, a mobile-responsive chat interface that enables switching between multiple LLMs with support for MCP, API connectors, and sandboxes (alpha).
  • Use sandboxes to let agents use a computer for chat-based tasks and coding, hosted by Tailscale or integrated with Tailscale identity from a third party (alpha).
    • Run sandboxes ephemerally from chat or as longer-running, workstation-like environments. Sandbox support is a private alpha. Request access to join.

Tailscale Kubernetes Operator v1.98.4

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

  • The operator no longer fails to perform token exchanges when using workload identity
  • Ingress & Egress ProxyGroup pods now correctly clamp their MTU values

Preset app support for Oracle Cloud Infrastructure (OCI)

Tailscale v1.98.4

Update instructions

All Platforms

  • An issue causing a deadlock when processing peer changes and disconnecting from the Tailscale control server is resolved.

Tailscale Kubernetes Operator v1.98.3

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

  • New: The DNSConfig custom resource supports specifying node affinity rules and node selectors for nameserver pods.
  • The operator Helm chart supports priority class names for operator pods.
  • The operator now reconciles Services and Ingresses with names longer than 63 characters.
  • ProxyGroup egress services now obtain an IPv4 address in addition to a IPv6 address on dual-stack clusters.
  • API server proxy ProxyGroup pods request a new auth key when required.

Tailscale tsrecorder v1.98.3

A new release of the Tailscale tsrecorder is available. You can download it from Docker Hub.

Tailscale v1.98.3

Update instructions
Linux
  • An issue where netfilter rules could be applied inconsistently after a netfilter mode change failed has been resolved. Connmark and CGNAT rules are applied after the active netfilter mode is successfully updated, matching the behavior of other netfilter paths.

Tailscale container image v1.98.3

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository.

This version contains no changes except for library updates.

Aperture CLI

Read more

Use Aperture CLI (alpha) to launch and manage coding agents with Aperture's built in guardrails, policy enforcement, and observability. Aperture CLI supports Claude Code, Gemini CLI, OpenCode, OpenAI Codex, Copilot CLI, and Claude Cowork, on devices both inside and outside your tailnet.

Manage domain names

Tailscale Terraform Provider v0.29.1

v0.29.1 of the Tailscale Terraform Provider has been released with the following changes:

  • The tailscale_tailnet_key resource no longer clears the key attribute when Terraform state is refreshed. tailscale_tailnet_key values that are already cleared should be recreated to generate a new key in state. This issue only affects tailscale_tailnet_key resources that were refreshed on v0.29.0 of the Tailscale Terraform provider.
  • The tailscale_tailnet_key resource no longer causes a panic when a key has been removed outside of Terraform.

Tailscale v1.98.2

Update instructions
All Platforms
  • Go is updated to 1.26.3.
  • A regression from 1.98.0 is patched, ensuring MagicDNS resolves tailnet hostnames after a network change. Windows clients are unaffected.

Tailscale Terraform Provider v0.29.0

v0.29.0 of the Tailscale Terraform Provider has been released with the following changes:

  • Use the tailscale_service resource and tailscale_service data source to manage Tailscale Services.
  • Set identity_token_environment_variable_name in the provider to specify the environment variable to read an identity token from. This is useful for platforms like HCP Cloud that have well-known environment variable names for the identity token.
  • Obtain an OIDC identity token from the runtime environment by setting audience in the provider. This is useful for runtimes like GitHub Actions, AWS via EC2 IMDSv2 or ECS, or GCP via Metadata Server.
  • Read credential related provider argument values from disk by supplying paths prefixed with file:.
  • The provider has migrated from Terraform Plugin SDKv2 to the Terraform plugin framework.
  • The tailscale_federated_identity resource no longer accepts an empty string ("") for the audience argument, to match the server-side validation for it. Omit the audience argument or set it to null to let Tailscale generate the audience (recommended), or set it to a non-empty string to specify it yourself.

Tailscale v1.98.1

Update instructions

Note: 1.98.0 was a release candidate intended for testing only.

All Platforms
Linux

Note: 1.98.1 introduced a regression in the interaction between Tailscale and MagicDNS on Linux. The Linux release has been withdrawn pending a fix.

macOS
  • Devices and exit nodes can be searched from the application's main menu on macOS Tahoe 26 or later.
  • The AppIntroShown system policy disables the Welcome to the Tailscale app modal window introduction that appears when you log in to Tailscale on a device for the first time.
  • The Hide Dock Icon checkbox in Settings is available when Tailscale is disconnected.
  • The tailscale drive CLI command directs users to configure Taildrive through the client GUI instead of returning an error.
  • Device list is more responsive, especially for larger tailnets.
iOS
  • iOS devices can be used as exit nodes.
  • Device list is more responsive, especially for larger tailnets.

Aperture

Read more

Use Aperture (beta) to secure and manage your LLM agents with a single control plane across all your providers and models.

Access API-only tailnets with OAuth clients

Seat calculator

  • A seat calculator is available to help you understand seat consumption on your account before upgrading to a new plan.

New pricing and packaging

Read more
  • New tailnet plan signups are billed based on occupied user seats instead of monthly active users. Existing tailnets on a legacy plan will continue to be billed based on monthly active users.
  • All plans can have an unlimited number of user devices in a tailnet.
  • The Personal plan provides up to six free users instead of the previous three users.
  • Ephemeral node usage is free up to a monthly limit, by pricing plan. After four hours in the tailnet, nodes are treated as standard tagged devices and stop consuming ephemeral minutes.
  • As part of the Personal plan change, Aperture by Tailscale also provides for up to six free users during the alpha testing phase.
  • The Starter plan is no longer available as a plan option for new signups. The new Standard plan is the closest equivalent option.
  • Promo codes can be applied to existing plans. Previously, promo codes could only be applied when upgrading to a new plan.

For more information about our pricing plans and the features available for each plan, refer to Pricing and Pricing FAQs.

Tailscale container image v1.96.5

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository.

  • Services are now automatically advertised on startup. This can be disabled by setting the new environment variable, TS_EXPERIMENTAL_SERVICE_AUTO_ADVERTISEMENT, to false.
  • The Tailscale container no longer tries to create a secret using TS_KUBE_SECRET when the variable is empty.

Tailscale Kubernetes Operator v1.96.5

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

  • Ingress and Egress ProxyGroup pods are able to request a new authkey when required.
  • Multiple tailnet access can be enabled with the use of the new Tailnet custom resource.
  • ProxyGroup creation controls can be managed by namespace with the new ProxyGroupPolicy custom resource.
  • The environment variable TS_EXPERIMENTAL_KUBE_API_EVENTS is removed. This can instead be set via Tailscale ACLs.
  • The environment variable TS_LOCAL_ADDR_PORT no longer fails when it is populated with an IPv6 address without brackets.

Tailscale tsrecorder v1.96.5

A new release of the Tailscale tsrecorder is available. You can download it from Docker Hub.

  • The Recorder CRD defaults to deploying a single replica StatefulSet, using the filesystem storage backend`.

Tailscale v1.96.5

Update instructions
iOS
  • An issue that could cause the network extension to encounter an out of memory condition on large tailnets is resolved.

tvOS

  • An issue that could cause the network extension to encounter an out of memory condition on large tailnets is resolved.

Tailscale v1.96.4

Update instructions

Linux

  • An issue on forks of Linux caused by fallback-on-ENOSYS logic is resolved.
  • An issue that could cause a segmentation violation during startup on MIPS devices is resolved.

Android

  • An issue causing a deadlock when disconnecting from a tailnet is resolved.

Synology

  • An issue on forks of Synology Linux caused by fallback-on-ENOSYS logic is resolved.

Tailscale v1.96.2

Update instructions

Note: 1.96.0 and 1.96.1 were release candidates intended for testing only.

All Platforms
Linux
  • Launch the systray application on startup using autostart file with the tailscale configure systray --enable-startup=freedesktop command.
  • Scaling of Tailscale Peer Relays UDP sockets is gated by container-aware GOMAXPROCS defaults.
  • Firewall rules created on Linux platforms correctly mark their traffic, avoiding reverse path filtering dropping connections and producing health warnings and risk prompts.
  • OpenWrt versions 25.12.0 or later using apk as a package manager supports Tailscale updates.
macOS
  • Windowed UI mode for macOS is generally available.
  • Double-click an account in the Accounts section to switch to that account.
  • A progress dialog indicates Tailscale is waiting on the browser to complete reauthentication.
  • The open source variant of Tailscale on macOS sets the node:osVersion attribute.
  • The Taildrop Send File action and shortcut do not transmit empty files on macOS Tahoe (version 26) or later.
  • Tailscale data directories for the macOS standalone version are excluded from Time Machine backups.
  • An issue that required a machine reboot after installing a Tailscale update is resolved.
iOS
  • iOS bug report ID displays in its entirety instead of being truncated.
  • The Taildrop Send File action and shortcut do not transmit empty files on iOS version 26 or later.