Workload identity federation
Workload identity federation (beta) enables creation of federated OIDC workload identities from third-party providers for Tailscale API authentication. Support added across tailscale-client-go-v2, Terraform provider, GitHub Action, and tailscale up command. OAuth client scopes and descriptions are now editable in the Trust credentials page of the admin console.
- New: Use workload identity federation (beta) for creation of federated OIDC workload identities from third-party providers to authenticate requests to the Tailscale API.
- New:
tailscale-client-go-v2can use workload identity federation for authentication. - New: The Tailscale Terraform provider can use workload identity federation for authentication.
- New: The Tailscale GitHub Action can use workload identity federation for auth key generation.
- New: The
tailscale upcommand can use workload identity federation for auth key generation. - New: OAuth client scopes and descriptions are editable in the Trust credentials page of the admin console.
- Changed: The Trust credentials page of the admin console replaces the OAuth clients page.
Source: original entry ↗
More from Tailscale
Follow Tailscale to get its new changes in your feed and email digest.
Tailscale v1.104.1 — Performance and Features Release
Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.
Declarative node sharing
Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.
Linux client reconnection stability fix
Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.