megachangelog
Tailscale logo

Tailscale Changelog

Tailscale — Security, Developer Tools product updates and releases, tracked on megachangelog.


Feature1.102.2

Tailscale Kubernetes Operator v1.102.2

Tailscale Kubernetes Operator v1.102.2 adds support for in-cluster PeerRelays, Helm annotations, workload identity federation, 4via6 and IPv6 in egress resources, and includes multiple fixes for log output, MTU clamping, ProxyGroup reconciliation, DNS records, certificates, and rate-limit handling.

kubernetesoperatornetworkingcertificatesdns
Announcement1.102.2

Tailscale container image v1.102.2

A new release of the Tailscale container image is now available. This version contains library updates and no functional changes.

containerdockerreleasedependencies
Improvement1.102.1

Tailscale v1.102.1

Tailscale v1.102.1 introduces new CLI commands for getting preferences and user information, adds platform-specific improvements including protocol handlers on macOS and split-plane layout on iPad, and fixes multiple connectivity and performance issues across all platforms including a security vulnerability in Tailscale SSH (TS-2026-010).

clinetworkingperformancesecuritycross-platform
Feature

Tailnet Creation API

New API endpoints allow you to programmatically create, list, and delete API-only tailnets in your organization. This enables automation of tailnet management at scale.

apitailnetmanagementautomation
Security1.98.10

Tailscale SSH security fixes

Fixed security vulnerabilities in Tailscale SSH, including Unix socket forwarding symlink permission handling and additional UID/username validation checks across all platforms.

sshsecurityunix
Announcement

Admin console URL change

The Tailscale admin console has moved to console.tailscale.com with automatic redirects from the old login.tailscale.com/admin/ URL. Authentication continues to use login.tailscale.com.

adminconsoleurlmigration
Security1.98.9

Tailscale v1.98.9 Security and Stability Fixes

This release addresses six security vulnerabilities in Tailscale SSH, Serve, Funnel, and Services, plus fixes an issue where users could be unexpectedly logged out when changing device tags via CLI.

securitysshservefunnelauth
Feature

Nested group support for synced groups

Microsoft Entra ID and Google Workspace group sync now includes members of nested groups, allowing for more comprehensive user management and access control.

groupsentra-idgoogle-workspacesyncaccess-control
Feature

Self-serve identity provider changes

Owners can now switch their tailnet's identity provider directly from the admin console for supported providers, without requiring manual intervention.

identityadminauthself-serve
Feature

Device Provisioning with OAuth Apps

New OAuth Apps capability for Device Provisioning allows users to create and manage OAuth applications through the Tailscale API to automate device provisioning workflows.

oauthapidevice-provisioningauth
Feature

Public IP address device posture attribute

A new ip:publicAddress device posture attribute is now available for use in postures and can be viewed on the Machines page of the admin console, with the feature available as beta in settings.

device-postureadmin-consolebeta
Fix1.98.8

Tailscale v1.98.8

Fixed connectivity disruptions after OS wake from sleep, excessive WireGuard handshake retries, and connection leaks in SSH Session Recording across all platforms.

wireguardsshstabilityconnectivity
Feature

Log streaming integration with Azure Blob Storage

Tailscale network flow logs and configuration audit logs can now be streamed to Azure Blob Storage, enabling centralized log storage and analysis in Azure environments.

loggingazureintegrationaudit
Feature

Aperture chat, connectors, and sandboxes

Tailscale introduces Aperture chat interface with identity-aware MCP and API connectors, plus sandboxes for agents to perform chat-based tasks and coding. All features leverage tailnet access controls for unified identity management across chat, agents, and third-party integrations.

aperturechatconnectorsmcpsandboxes
Feature

Group visibility on Tailscale clients

Devices on your tailnet can now receive group membership information from the Tailscale control plane, enabling better access control and visibility across your network.

groupsaccess-controlclientsalpha
Improvement1.98.5

Apple platforms now built with Xcode 26.5

macOS and iOS clients are now built using the Xcode 26.5 toolchain, ensuring compatibility with the latest Apple development tools.

applexcodemacosiosbuild
Feature

Preset app support for Oracle Cloud Infrastructure

Preset apps are now available for Oracle Cloud Infrastructure, providing pre-configured integrations for compute, networking, Object Storage, and Oracle Services Network across regions.

ocicloudpreset-appsinfrastructure
Fix1.98.4

Tailscale Kubernetes Operator v1.98.4

This release fixes token exchange failures when using workload identity and corrects MTU value clamping in Ingress and Egress ProxyGroup pods.

kubernetesoperatorworkload-identitynetworking
Fix0.29.2

Tailscale Terraform Provider v0.29.2

Fixed a regression in tailscale_tailnet_key resource where the recreate_if_invalid parameter was not being checked before recreating the resource when a key is not found.

terraformproviderregressiontailnet-key
Improvement1.98.3

Tailscale Kubernetes Operator v1.98.3

The Tailscale Kubernetes Operator v1.98.3 adds support for node affinity rules in DNSConfig, priority class names in the Helm chart, and fixes issues with long resource names, dual-stack IPv4/IPv6 addressing, and API server proxy auth key renewal.

kubernetesoperatordnsnetworkinghelm
Fix1.98.3

Tailscale tsrecorder v1.98.3

Fixed an issue where recorder pods can now request a new auth key when required, improving reliability of the tsrecorder service.

tsrecorderdockerauthfix
Improvement1.98.3

Tailscale container image v1.98.3

A new release of the Tailscale container image is available with library updates only.

containerdockerreleasedependencies
Fix1.98.3

Fixed netfilter rules inconsistency on Linux

Resolved an issue where netfilter rules could be applied inconsistently after a netfilter mode change failed. Connmark and CGNAT rules are now applied only after the active netfilter mode is successfully updated, matching the behavior of other netfilter paths.

linuxnetfilterbugstability
Feature

Aperture CLI for managing coding agents

Aperture CLI (alpha) lets you launch and manage coding agents with built-in guardrails, policy enforcement, and observability. It supports Claude Code, Gemini CLI, OpenCode, OpenAI Codex, Copilot CLI, and Claude Cowork on devices inside and outside your tailnet.

aperturecliagentsaisecurity
Fix0.29.1

Tailscale Terraform Provider v0.29.1

Fixed an issue where the tailscale_tailnet_key resource was incorrectly clearing the key attribute during state refresh, and fixed a panic that occurred when keys were removed outside of Terraform.

terraformprovidertailnet-keystability
Feature

Manage domain names in admin console

Added new Domains page in the admin console to manage domain verification and domain aliases for your tailnet in one place.

domainsadminconsoledns
Fix1.98.2

Tailscale v1.98.2

This release updates Go to 1.26.3 and fixes a regression from v1.98.0 where MagicDNS failed to resolve tailnet hostnames after network changes on non-Windows platforms.

dnsmagicdnsnetworkingbugfixstability
Feature0.29.0

Tailscale Terraform Provider v0.29.0

This release adds support for managing Tailscale Services via the tailscale_service resource and data source. It introduces new authentication features including OIDC identity token support from runtime environments and the ability to read credentials from disk. The provider has migrated to the Terraform plugin framework and tightened validation for the audience argument in federated identity configuration.

terraformprovideroidcauthenticationinfrastructure
Feature

Purchase additional tagged resources

All plans can now purchase additional tagged resources beyond the included 50-device limit and view their current tagged resource usage against the limit.

billingresourcesdevicespricing
Improvement1.98.1

Tailscale v1.98.1

This release fixes expired preferred peer address clearing to speed up alternative peer election, improves health checks for IP forwarding on Linux, adds device/exit node search on macOS, enables iOS devices as exit nodes, and resolves device list responsiveness issues across platforms.

stabilityperformancenetworkingexit-nodesmacos
Feature

View device posture status

Users can now view the device posture status of machines in their tailnet directly from the Machines page in the admin console, providing better visibility into device security and compliance.

admin-consoledevice-posturesecuritytailnetvisibility
Fix1.5.2

GitOps for Tailscale with GitHub Actions

Updated dependencies to remove Node 20 deprecation warning and ensure compatibility with current tooling.

github-actionsdependenciestoolinggitops
Feature

Aperture: LLM Agent Security and Management Control Plane

Aperture (beta) is a new control plane for securing and managing LLM agents across providers and models. It enables custom guardrails with pre-call hooks to strip PII and restrict agent tools, configurable log retention with S3 export, audit logging for configuration changes, and customizable quotas across providers, models, users, and agents.

llmsecurityagentsmanagementaudit
Feature

API-only tailnets accessible via OAuth clients

API-only tailnets can now be accessed by any OAuth client with the all scope in the creating tailnet, expanding programmatic access capabilities.

apioauthtailnetsaccess
Feature

Seat calculator

A new seat calculator tool is available to help users understand how many seats their account consumes before upgrading to a new plan.

billingseatsplanningaccount
Announcement

New pricing and packaging

Tailscale introduced new pricing that bills based on occupied user seats instead of monthly active users for new tailnets, increased free users on the Personal plan from three to six, made ephemeral node usage free within plan limits, and replaced the Starter plan with a new Standard plan. Existing legacy plans retain their previous billing model.

pricingbillingplanspolicy
Improvement1.96.5

Tailscale Kubernetes Operator v1.96.5

New features include authkey refresh for Ingress/Egress ProxyGroup pods, multiple tailnet access via new Tailnet custom resource, and namespace-level ProxyGroup creation controls via ProxyGroupPolicy. Removed TS_EXPERIMENTAL_KUBE_API_EVENTS variable and fixed TS_LOCAL_ADDR_PORT handling for IPv6 addresses.

kubernetesoperatornetworkingproxy
Improvement1.96.5

tsrecorder v1.96.5

The Recorder CRD now defaults to deploying a single replica StatefulSet with filesystem storage backend, simplifying default deployment configuration.

recorderkubernetesdeploymentstorage
Improvement1.96.5

Tailscale container image v1.96.5

Services are now automatically advertised on startup with a new TS_EXPERIMENTAL_SERVICE_AUTO_ADVERTISEMENT environment variable to control this behavior. Fixed an issue where the container would attempt to create a secret even when TS_KUBE_SECRET was empty.

containerdockerkubernetesservices
Fix1.96.4

Tailscale v1.96.4

Resolved stability issues on Linux and Synology including ENOSYS fallback handling, a segmentation fault on MIPS devices, and an Android disconnection deadlock.

linuxandroidstabilitymipssynology
Feature1.96.2

Tailscale v1.96.2

Tailscale v1.96.2 adds new CLI commands for DNS queries with JSON output, resource waiting, and IP assertion, introduces generally available windowed UI mode on macOS, and fixes multiple bugs across platforms including firewall rule marking on Linux, empty file transmission on macOS and iOS, and UPnP routing issues. Go has been updated to 1.26.

clidnsmacoslinuxios
Announcement

Workload identity federation GA

Workload identity federation is now generally available, allowing you to authenticate Tailscale API requests using federated OIDC workload identities from third-party providers.

apiauthidentityoidcsecurity
Announcement

Tailscale Peer Relays GA

Tailscale Peer Relays are now generally available, allowing users to set up self-hosted high-throughput relay servers for cases where direct connections aren't possible.

peer-relaysnetworkinginfrastructureavailability
Feature

Huntress device posture integration

Tailscale now integrates with Huntress Managed EDR to collect device posture signals from devices in your tailnet, enabling better security visibility and policy enforcement.

securitydevice-postureintegrationshuntress
Feature

Fleet device posture integration

Tailscale now integrates with Fleet Device Management to collect device posture signals from devices in your tailnet, enabling better visibility into device compliance and security status.

device-managementposturefleetsecurityintegration
Fix1.94.2

Tailscale Kubernetes Operator v1.94.2

Fixed a crash when configuring an invalid Tailscale FQDN for an egress. The operator now logs errors gracefully and continues serving traffic instead of crashing.

kubernetesoperatoregressstability
Feature1.94.1

Tailscale container image v1.94.1

Container image v1.94.1 adds OAuth and workload identity federation support, enabling improved authentication for containerized deployments.

containersoauthidentity-federationauth
Improvement1.94.1

Tailscale Kubernetes Operator v1.94.1

This release adds egress proxy support for Tailscale service VIPs and introduces Kubernetes API server proxy audit logging (beta). It also fixes stale TLS certificate serving in HA mode and resolves container resource configuration validation errors.

kubernetesoperatorproxyaudit-loggingtls
Announcement1.94.1

Tailscale tsrecorder v1.94.1

New release of Tailscale tsrecorder with library updates. Available on Docker Hub.

tsrecorderreleasedependencies
Feature

Log streaming integration with Google Cloud Storage

Tailscale network flow logs and configuration audit logs can now be streamed to Google Cloud Storage, enabling centralized log collection and archival.

logsgcsgoogle-cloudauditintegration
Feature

Workload identity federation updates

Workload identity federation now supports provider-native identity token authentication for GitOps with GitHub Actions and GitLab CI. Token exchange error details are available in the Trust credentials page of the admin console.

identityfederationgitopsgithubgitlab
Feature

tsnet integration for Tailscale Services

Added tsnet application support for Tailscale Services hosts, enabling new deployment capabilities on the Tailscale network.

tsnetservicesnetworkintegration
Announcement

Tailscale Services GA

Tailscale Services is now generally available, allowing you to decouple applications and services from the devices that host them for more flexible service management.

servicesnetworkingarchitecturegeneral-availability
Feature1.94.1

Tailscale v1.94.1

Tailscale v1.94.1 introduces new client metrics for DERP regions and peer relays, automatic identity token generation for workload identities, and tsnet support for hosting Tailscale Services. It includes multiple fixes across platforms including DNS resolution on Linux, security vulnerability fixes on macOS, and improved relay throughput optimizations.

peer-relaymetricsworkload-identitysecurityperformance
Feature

IS SET and NOT SET device posture operators

Added IS SET and NOT SET operators for device posture checks, allowing more flexible policy conditions based on whether posture attributes are set or unset.

device-posturepolicyoperatorsaccess-control
Improvement

India DERP region city name updated to Bengaluru

The city name for Tailscale's India DERP server has been updated to Bengaluru to reflect the official name. Hosting provider and IP addresses remain unchanged.

derpinfrastructureindiaregions
Fix1.92.5

Tailscale v1.92.5

State file encryption and hardware attestation keys are no longer enabled by default on Linux and Windows. Fixed a crash that occurred when the client failed to load hardware attestation keys due to TPM device reset or replacement.

securityhardware-attestationlinuxwindows
Fix1.92.5

Tailscale container image v1.92.5

Fixed an issue where hardware attestation keys were added to Kubernetes state Secrets, which prevented changing the Kubernetes node where Tailscale containers are deployed.

containerkuberneteshardware-attestationsecurity
Improvement1.92.5

Tailscale Kubernetes Operator v1.92.5

Certificate renewal now avoids ARI orders by default to prevent failures when ACME account keys are recreated. Hardware attestation keys are no longer stored in Kubernetes Secrets, enabling node migration for the operator.

kubernetesoperatorcertificatessecurityreliability
Announcement1.92.5

Tailscale tsrecorder v1.92.5

A new release of Tailscale tsrecorder is available with library updates only. Download it from Docker Hub.

tsrecorderreleasedockerlibrary-updates
Feature

Workload identity federation API

The Tailscale API now supports creating, reading, updating, and deleting federated identities. The Go client library and Terraform provider can also configure federated identities.

apiidentityfederationterraformgo-client
Fix4.1.1

Tailscale GitHub Action v4.1.1

Fixed the Tailscale GitHub Action to use the correct architecture for storing and retrieving caches on macOS-based GitHub runners.

github-actionmacoscachingci-cd
Fix1.92.4

Tailscale container image v1.92.4

Released Tailscale container image v1.92.4 with a fix to ensure errors from background certificate renewal failures are properly logged.

containerdockercertificateslogging
Announcement1.92.4

Tailscale tsrecorder v1.92.4

A new release of Tailscale tsrecorder is available on Docker Hub with library updates only.

tsrecorderreleasedockerdependencies
Feature1.92.3

tsrecorder v1.92.3 — File-based auth key support

tsrecorder now supports authentication via a file-based auth key using the TS_AUTHKEY_FILE environment variable, providing more secure credential management for containerized deployments.

tsrecorderauthenticationdockerauth-key
Fix1.92.3

Tailscale container image v1.92.3

Fixed an issue where iptables could not be used on hosts that don't support nftables. The container image now works correctly on systems using iptables instead of nftables.

containerdockeriptablesnetworking
Improvement1.92.3

Tailscale Kubernetes Operator v1.92.3

This release adds workload identity federation support for tailnet authentication and HTTP-to-HTTPS redirect annotations for Ingress resources. It also improves operator defaults, enables multi-replica Recorder deployments, fixes ArgoCD compatibility, and resolves issues with managed Ingress reconciliation and ProxyGroup-backed Ingress deletion.

kubernetesoperatoridentityingressdns
Fix1.92.3

Tailscale v1.92.3

Fixed a panic caused by automatic WireGuard configuration on all platforms, and resolved a system extension installation failure during macOS upgrades.

wireguardstabilitymacosinstallation
Announcement1.92.1

Tailscale v1.92.1

Tailscale v1.92.1 introduces support for the PROXY protocol in Funnel and Serve, static endpoints for Peer Relays, remote service destinations, workload identity federation, and improved network flow logs. The release also fixes Peer Relay handshake improvements and accessibility issues on macOS and iOS.

networkingrelayauthenticationfunnelaccessibility
Fix1.92.2

Tailscale v1.92.2

Fixes Taildrop functionality on macOS via the Share option and resolves a connectivity issue on Android when using custom control servers like Headscale.

macosandroidtaildropheadscalebug-fix
Fix1.90.9

Tailscale v1.90.9

Fixed tailscaled deadlocks during event bursts and client hangs after wake up with port mapping. Fixed DNS issues when switching between cellular and Wi-Fi connections on Android.

stabilitynetworkingport-mappingdnsandroid
Fix1.90.9

Tailscale container image v1.90.9

Fixed deadlock in tailscaled during event bursts and resolved client hang after wake-up when port mapping is enabled with slow interface initialization.

containerstabilityport-mappingdocker
Improvement1.90.9

Tailscale Kubernetes operator v1.90.9

A new release of the Tailscale Kubernetes operator is available with library updates. No functional changes are included in this version.

kubernetesoperatordependencies
Improvement1.90.9

Tailscale tsrecorder v1.90.9

A new release of Tailscale tsrecorder is available with library updates only, no functional changes.

tsrecorderlibraryreleasedependencies
Improvement1.90.8

Tailscale Kubernetes operator v1.90.8

A new release of the Tailscale Kubernetes operator is available with library updates. Refer to installation instructions for guidance on installing and updating.

kubernetesoperatordependencies
Fix1.90.8

Tailscale v1.90.8

This release fixes multiple critical issues including panic and deadlock problems in Peer Relays, a memory leak, a security vulnerability affecting Linux nodes with Tailnet Lock, and a macOS sleep/wake connectivity issue.

peer-relaysstabilitysecuritymemorymacos
Security1.90.8

Container image v1.90.8 released

Fixed a security vulnerability (TS-2025-008) where nodes without the tailscaled --statedir flag or TS_STATE_DIR environment variable failed to enforce signing checks in tailnets with Tailnet Lock enabled.

securitycontainertailnet-lockvulnerability
Announcement1.90.8

Tailscale tsrecorder v1.90.8

A new release of Tailscale tsrecorder is available on Docker Hub with library updates.

tsrecorderreleasedependencies
Announcement

IP changes to Tailscale's logging infrastructure

The domain log.tailscale.com now resolves to static IP address ranges managed by Tailscale. Users requiring IP-based firewall rules should use the IPv4 range 199.165.136.0/24 and IPv6 range 2606:B740:1::/48.

infrastructurenetworkingloggingfirewall
Fix1.90.6

Tailscale container image v1.90.6

Fixed a bug where app connector routes would stall and fail to apply when updated repeatedly in a short period of time. This release is available on Docker Hub and GitHub packages.

containerdockerapp-connectorrouting
Improvement1.90.6

Tailscale Kubernetes operator v1.90.6

New release of the Tailscale Kubernetes operator with library updates. Refer to installation instructions for guidance on installing and updating.

kubernetesoperatordependencies
Announcement1.90.6

Tailscale tsrecorder v1.90.6

A new release of tsrecorder is available on Docker Hub with library dependency updates.

tsrecorderreleasedependencies
Improvement1.90.5

tsrecorder v1.90.5

tsrecorder v1.90.5 adds web interface search and filtering capabilities for metadata queries, fixes kubectl exec session recording, and resolves issues with cached recordings and sessions on large datasets.

tsrecorderweb-interfacekubectlrecording
Improvement1.90.5

Tailscale container image v1.90.5

A new release of the Tailscale container image is available on Docker Hub and GitHub packages. This version includes library updates with no other changes.

containerdockerreleasedependencies
Feature1.90.5

Tailscale Kubernetes operator v1.90.5

The Tailscale Kubernetes operator adds IPv6 support and high-availability features to DNSConfig nameserver, including replica count configuration and pod tolerations. ProxyClass now supports dnsConfig and dnsPolicy fields for refined DNS specifications, and reconciler logs are now sent to the control plane.

kubernetesdnsoperatoripv6ha
Feature

Workload identity federation

Workload identity federation (beta) enables creation of federated OIDC workload identities from third-party providers for Tailscale API authentication. Support added across tailscale-client-go-v2, Terraform provider, GitHub Action, and tailscale up command. OAuth client scopes and descriptions are now editable in the Trust credentials page of the admin console.

authapioidcidentityfederation
Feature

Multiple tailnets for a single organization

Organizations can now administer multiple tailnets under a single identity provider and domain. This alpha feature enables unified management across multiple networks while sharing authentication infrastructure.

adminorganizationtailnetsidentity
Feature

Tailscale Peer Relays

Tailscale Peer Relays enable client-to-client connections through relay servers when direct peer-to-peer connections aren't possible, improving connectivity in restrictive network environments. This feature is currently in beta.

relaysnetworkingconnectivityp2pbeta
Announcement

Visual policy editor (GA)

The visual policy editor for creating and managing tailnet policy files is now generally available, allowing users to edit policies through an intuitive interface.

policyeditoruinetworking

Sign up to see more

97 more changes from Tailscale. Sign up to read the whole changelog.

Sign up free

GitHub or email — no card needed.