← Back to all sparks
T

Tailscale

INFRA · APIS
Velocity6.3

Tailscale fills out enterprise plumbing while opening a new front in AI-agent control.

enterprise-readinessterraformai-agent-securitydevice-postureusage-billingmagicdns
Current state
The mainline Tailscale client and Terraform provider continue to ship steadily — v1.98 with MagicDNS and Linux subnet-router fixes, Terraform v0.29 adding first-class Tailscale Services support. Admin-console work (domain management, device posture visibility, paid-tier scaling for tagged resources) targets enterprise operability. Underneath the routine version cadence, the recent Aperture beta points the company up the stack into AI-agent governance.
Where it's heading
Two threads are running in parallel. The connectivity product is hardening for larger deployments: Terraform-native service modeling, posture surfacing in the console, and explicit billing levers for tagged resources past the 50-device line. The second thread, Aperture, repositions Tailscale's identity-and-policy primitives as a control plane for LLM calls and agent tools — same trust model, new target workload.
Prediction
Expect Aperture to graduate out of beta with broader provider coverage and tighter ties to Tailscale ACLs, while the core client continues a predictable point-release cadence. The enterprise plumbing improvements suggest paid-tier expansion (more usage-based dials) before the next big platform push.

Recent moves

  1. 1d ago

    Aperture CLI

  2. 2d ago

    Domain management in admin console + Terraform v0.29.1 fixes

    Admins can now verify domains and manage aliases from the console; the Terraform provider patches a key-clearing regression and a panic when keys are removed out-of-band. Operability and IaC reliability work, consistent with the enterprise-plumbing thread.

  3. 6d ago

    Tailscale Terraform Provider v0.29.0

    Adds tailscale_service resource/data source plus OIDC identity-token plumbing for GitHub Actions, AWS IMDSv2, ECS, and GCP. Brings the newer Services concept into IaC and makes the provider easier to wire up in CI/CD runtimes.

  4. 6d ago

    Tailscale v1.98.2

    Point release patches a MagicDNS regression that prevented tailnet hostname resolution after a network change, plus a Go toolchain bump. Routine but important — MagicDNS reliability is foundational to the product experience.

  5. 7d ago

    Purchase additional tagged resources

    All plans can now buy tagged-resource capacity above the 50-device included limit and see current usage. A monetization dial on a previously hard ceiling, aimed at workloads that mix many tagged ephemeral resources with human devices.

  6. 8d ago

    Tailscale v1.98.1

    Faster failover when preferred peer addresses expire, IP-forwarding misconfigurations surface as health-check warnings, and reverse-path filtering on Linux is tightened. Net: more self-diagnosing subnet routers and exit nodes for operators.