megachangelog
Announcement1.86.0

Tailscale v1.86.0

Version 1.86.0 introduces device posture checks for encrypted client state, automatic exit node selection across platforms, state encryption via TPM/Keychain, and multiple fixes for CSRF, proxy detection, system policies, and platform-specific issues. Note: This version was rolled back due to regressions on July 25 (macOS) and July 28 (all platforms).

Note: Tailscale halted the rollout of version 1.86.0 for macOS on July 25, 2025, and for all other platforms on July 28, 2025, due to multiple regressions.

All platforms Linux Windows
  • New: tailscale up --exit-node=auto:any and tailscale set --exit-node=auto:any CLI commands track the recommended exit node and automatically switches to it when available exit nodes or network conditions change.
  • New: EncryptState system policy enforces storing the node state file in encrypted format on disk using trusted platform module (TPM).
  • Changed: Selecting Recommended from the exit node picker makes the Tailscale client track the recommended exit node and automatically switch to it when available exit nodes or network conditions change.
  • Fixed: AlwaysOn system policy is enforced as expected.
  • Fixed: System tray icon display a notification when the selected exit node is unavailable.
  • Fixed: Mullvad exit node picker hides after switching from a profile with Mullvad exit nodes to one without any exit nodes.
  • Fixed: WDAP/PAC proxy detection on Windows 10 1607 and earlier to ensure successful connectivity when a proxy is required.
macOS
  • New: tailscale up --exit-node=auto:any and tailscale set --exit-node=auto:any CLI commands track the recommended exit node and automatically switches to it when available exit nodes or network conditions change.
  • New: ReconnectAfter system policy setting, which configures the maximum period of time between a user disconnecting Tailscale and the client automatically reconnecting.
  • New: EncryptState system policy enforces storing the node state file in the Keychain. The App Store variant of the client always uses the Keychain regardless of this setting.
  • New: OnboardingFlow system policy enforces the suppression of the onboarding flow that displays when the client is installed. This replaces the deprecated TailscaleOnboardingSeen system policy.
  • New: Remove all accounts option in the Debug menu.
  • Changed: TailscaleOnboardingSeen system policy is deprecated. Use the new OnboardingFlow system policy instead.
  • Changed: Selecting Recommended from the exit node picker makes the Tailscale client track the recommended exit node and automatically switch to it when available exit nodes or network conditions change.
  • Fixed: AlwaysOn system policy is enforced as expected.
  • Fixed: Shortcut action issues.
iOS
  • Changed: Selecting Recommended from the exit node picker makes the Tailscale client track the recommended exit node and automatically switches to it when available exit nodes or network conditions change.
  • Fixed: Reset keychain option issues.
  • Fixed: Shortcut action issues.
  • Fixed: Taildrop resending issues.
tvOS
  • Changed: Selecting Recommended from the exit node picker makes the Tailscale client track the recommended exit node and automatically switch to it when available exit nodes or network conditions change.
exit-nodessecurityencryptionsystem-policymulti-platformfixes

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →