惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
博客园 - Franky
罗磊的独立博客
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
P
Proofpoint News Feed
Recent Announcements
Recent Announcements
V
V2EX
F
Fortinet All Blogs
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
U
Unit 42
GbyAI
GbyAI
A
About on SuperTechFans
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
Microsoft Azure Blog
Microsoft Azure Blog
Martin Fowler
Martin Fowler
D
DataBreaches.Net
The Cloudflare Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MongoDB | Blog
MongoDB | Blog

Blog on Tailscale

Why built-in router and NAS VPNs fall short Tailscale Kubernetes Operator 1.102: In-cluster relays, IPv6, and certificates Tailcat: An open-source CLI for Tailscale’s WireGuard®, NAT traversal, and DERP Build with Tailscale using tsnet, APIs, and automated sharing Tailscale and Control D: DNS filtering for your tailnet Tailscale PAM beta: Just-in-time access, session auditing, and more Aperture GA: model tokens, MCP controls, Projects, and custom permissions TailscaleUp 2026: a preview of Tailscale’s product updates How Tailscale helped find the SQLite WAL-Reset bug How Tailscale and Aperture mitigate the lethal trifecta for AI agents Tailscale in the Hugging Face intrusion: The good news and the bad news Mike Shaver joins Tailscale as VP of Engineering What a $20 Claude Code or Codex subscription actually buys, per Aperture Access Home Assistant Remotely with Tailscale | Guide Audit AI agent requests, logs, and access with Aperture A no-nonsense explainer to Agentic AI Database, Kubernetes, and SSH access without passwords | Border0 + Tailscale Tailscale adds log streaming for Azure Blob Storage Build a flexible AI stack with Aperture More Tailscale tricks for your jailbroken Kindle Redundancy only matters if you can reach it Fixing my ridiculous fridge with a tiny Funnel site Canada’s Bill C-22 and the security cost of collecting more data Introducing: Aperture CLI Five TailscaleUp sessions I’d attend if I didn’t work here Bambuddy: self-hosted 3D printing beyond the vendor cloud Fixing Headlamp OIDC login with Tailscale and tsidp How Cleric uses tsnet to securely automate software operations Tailscale + Paperless-ngx: scan everything, expose nothing Aperture, now in beta, adds the controls teams need for AI agents
This month at Tailscale for April 2026
Kevin Purdy · 2026-04-24 · via Blog on Tailscale

We continuously ship updates to make your network more reliable, manageable, and secure. Each month, we highlight some of the most impactful changes across clients, admin tools, integrations, and infrastructure—so you can stay on top of what’s new and what’s better.

Here's a rundown of what's changed in Tailscale's software since our last blog update in late March 2026. For instructions on how to update to the latest version, visit our update guide.

Aperture updates

  • New: Create custom guardrails with pre-LLM-call hooks to strip or block PII and restrict specific agent tools before requests reach the LLM.
  • New: Configure log retention time down to zero for request/response capture logs, with S3-compatible export supported.
  • New: Audit logs for configuration changes and when admins view logs owned by other users are available using a new API endpoint and UI.
  • Changed: Set customizable quotas across providers, models, users, agents, or individual agent runs.

API-only tailnets and Oauth clients

Client updates

v1.96.5

These notable changes are inclusive of all updates from versions 1.96.4 to 196.5 For detailed notes on each release, see our changelog.

Linux

  • Fixed: An issue on forks of Linux caused by fallback-on-ENOSYS logic is resolved. (Also on Synology)
  • Fixed: An issue that could cause a segmentation violation during startup on MIPS devices is resolved.

iOS/tvOS

  • Fixed: An issue that could cause the network extension to encounter an out of memory condition on large tailnets is resolved.

Android

  • Fixed: An issue causing a deadlock when disconnecting from a tailnet is resolved.

Container, Kubernetes, and tsrecorder updates

Container image v1.96.5

  • New: Services are now automatically advertised on startup. This can be disabled by setting the new environment variable, TS_EXPERIMENTAL_SERVICE_AUTO_ADVERTISEMENT, to false.
  • Fixed: The Tailscale container no longer tries to create a secret using TS_KUBE_SECRET when the variable is empty.

Kubernetes operator v1.96.5

  • New: Ingress and Egress ProxyGroup pods are able to request a new authkey when required.
  • New: Multiple tailnet access can be enabled with the use of the new Tailnet custom resource.
  • New: ProxyGroup creation controls can be managed by namespace with the new ProxyGroupPolicy custom resource.
  • Changed: The environment variable TS_EXPERIMENTAL_KUBE_API_EVENTS is removed. This can instead be set via Tailscale ACLs.
  • Fixed: The environment variable TS_LOCAL_ADDR_PORT no longer fails when it is populated with an IPv6 address without brackets.

tsrecorder v1.96.5

  • Changed: The Recorder CRD defaults to deploying a single replica StatefulSet, using the filesystem storage backend`.

Those are the highlights for recent weeks. If you have questions or feedback, we're here to help. Thank you for using Tailscale.