Announcement
Tailscale PAM (Privileged Access Management) Beta
Tailscale announces a beta release of Privileged Access Management (PAM) enabling application-aware access control for SSH, databases, RDP, HTTPS, Kubernetes, and S3 resources. Features include session recording, policy-based access grants, credential injection, audit logs, and browser-based access without requiring a client download.
Use Tailscale Privileged Access Management (PAM) (beta) to provide application-aware access to resources in your Tailscale network.
- New: Services can be defined for privileged access, including SSH, database, RDP, HTTPS, Kubernetes, and Amazon S3 types.
- New: Sessions can be recorded for SSH, database, HTTPS, and Kubernetes Service types.
- New: Policies can be set for user access and in-service permissions through grants.
- New: Secrets store can be linked for credential injection.
- New: Logs of user access can be viewed, and session recordings can be played back.
- New: Connectors can be managed and deployed to provide connectivity to services.
- New: Browser client permits access to services without requiring a Tailscale client download.
- New: Custom domain management can be used for public HTTP PAM services.
- New: Custom Amazon S3 bucket can be configured for PAM recording storage.
- New: Service accounts can be created for machine identities to interact with the PAM API.
Request access to join the Tailscale PAM beta.
pamsecurityaccess-controlbetanetworkaudit
Source: original entry ↗