megachangelog
Announcement

Grants GA

Grants is now generally available for defining unified network and application layer access controls. The default tailnet policy file now uses grants syntax instead of ACL syntax with no effective permission changes, and the via feature lets you control traffic routing through specific exit nodes, subnet routers, or app connectors.

  • Changed: Use grants to define unified network and application layer access controls (generally available).
    • Note: The default tailnet policy file now uses grants syntax instead of the original ACL syntax, but makes no changes to the effective permissions. This applies to all new tailnets and any tailnet policy file that has never been edited.
  • Changed: Use via to control how traffic routes from a source to a destination, such as through specific exit nodes, subnet routers, or app connectors (generally available).
grantsaccess-controlpolicyrouting

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →