Tailscale integration
Integrate Tailscale mesh VPN devices and access policies to build zero-trust network compliance and device lifecycle automation.
What it connects
- All connected devices with their IPs, hostnames, operating systems, and last-seen status
- Users and team members with their roles, device ownership counts, and online status
- Authentication keys including their expiry dates and revocation status for lifecycle tracking
- Network access control policies defining which devices and users can reach which resources
What it automates
- Authorize or revoke device access by updating device authorization state on the tailnet
- Update ACL tags on devices to enforce security policies and control network access
- Approve or modify subnet routes that devices are allowed to advertise within the network
- Manage DNS configuration by updating nameservers and search paths across the tailnet
In practice
When an employee is offboarded, STLabs automatically revokes their device from Tailscale and removes all associated auth keys, ensuring no stale access remains.
A new remote office opens; STLabs adds their subnet route to Tailscale, automatically making the office network accessible to all authorized team devices.
Compliance audits require devices to have specific security tags; STLabs scans connected devices and automatically applies the correct ACL tags based on device type and owner.
An engineer needs temporary access to production infrastructure; STLabs creates a time-limited auth key with the minimal required tags, expiring automatically after the maintenance window.