Normal view

I replaced my Pi-hole with this

💾

DNS filtering by Control D is now available to Tailscale customers through the Tailscale sales team. It can block malware, phishing, ads, trackers, and other unwanted websites. You can apply different filtering rules to groups, tags, or individual devices across your tailnet.

Tailscale and Control D setup guide:
https://tailscale.com/docs/integrations/control-d

Control D’s Tailscale guide:
https://docs.controld.com/docs/tailscale-integration

Purchase through Tailscale:
https://tailscale.com/contact/sales

Control D:
https://controld.com/

In this video, I show you how to add Control D as a nameserver in Tailscale, create a filtering profile, and choose which users or devices should use it. Control D supports content categories, more than 1,000 services and apps, and custom rules to block, allow, or redirect domains.

Tailscale handles simple user-based billing, so you do not need to predict how many devices you will have. Your filtering rules are still managed through the Control D dashboard or API. Use the links below to learn more or talk to the Tailscale team.

A better way to manage privileged access

💾

Tailscale PAM is now available in beta, bringing privileged access management directly into Tailscale.

In this Summer Update, Alex takes a first look at Tailscale PAM: what it is, the problems it’s designed to solve, and how to get started. We’ll set up a PAM connector, add a PostgreSQL database as a service, connect through the Tailscale client and browser, and finish by accessing a Windows machine with Remote Desktop directly from the browser.

Tailscale PAM provides granular, identity-aware access to infrastructure while managing credentials behind the scenes. Admins can also audit access with logs and session playback.

Tailscale PAM beta is free for up to six users.

Join the Tailscale PAM beta:
https://tailscale.com/pam-selfserve-waitlist

Learn more about Tailscale PAM:
https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam


In this video:
00:00 Tailscale PAM is here
00:31 What is privileged access management?
00:53 What problems does PAM solve?
01:27 PAM vs network access policies
01:58 What’s included in the beta
02:36 Why Tailscale PAM uses connectors
02:58 Setting up Tailscale PAM
03:47 Adding a PAM connector
04:59 Adding a PostgreSQL service
06:40 Connecting to a database with PAM
07:24 Connecting through your browser
07:53 Remote Desktop with Tailscale PAM
09:10 Final thoughts

This will change how you homelab | Aperture GA announcement

💾

https://tailscale.com/blog/aperture-ga

Getting an AI agent to SSH into your server is easy. Giving it only the access it actually needs is the interesting part.

Aperture by Tailscale is now generally available, and it can give agents controlled SSH access to machines on your tailnet. In this Summer Update, Remy shows us how Aperture can set up real homelab services while keeping Tailscale identity and access controls in the loop.

We use a Raspberry Pi to see how an agent can install and configure services, add them to a tailnet, and work within the permissions you define. We also look at Aperture's mobile experience, LLM and MCP visibility, and how its SSH and node-management capabilities can be used from other agent workflows through MCP.

The goal isn't simply to let an agent onto your network. It's to make intentional decisions about what that agent can and can't access.

Learn more about Aperture: http://tailscale.com/blog/aperture-ga

Get started with Aperture: https://tailscale.com/docs/aperture/get-started

Watch the Tailscale Summer Update playlist: https://www.youtube.com/playlist?list=PLJW-_hiaseM8

In this video:
00:00 Why homelabbing is still too complicated
00:24 Aperture is now generally available
01:00 From LLM proxy to AI gateway
01:31 Why not just give an agent an SSH key?
02:03 Putting an agent to work in the homelab
02:57 Giving services their own Tailscale identity
03:12 Taking Aperture mobile
03:37 Seeing what your agents are doing
04:07 Using Aperture with other agents through MCP
04:34 Why the guardrails matter
05:03 Bringing Aperture tools to your existing workflow
05:15 Try Aperture

Smarter Tailscale Subnet Routing

💾

One of the biggest advantages of Tailscale is that your devices stay connected no matter where you are. But sometimes your location should change how your network behaves.
In this video, Jay demonstrates how to use IP source device posture to control access to a subnet router based on the public network your device is connected to. Instead of always routing through your subnet router, you'll learn how to automatically use your local network when you're home and Tailscale only when you're away.

Whether you're running printers, cameras, IoT devices, or other systems that can't run Tailscale themselves, this approach keeps your routing simple while avoiding unnecessary hops.
Documentation

Device posture: https://tailscale.com/docs/features/device-posture
Subnet routers:https://tailscale.com/docs/features/subnet-routers
Tailnet policy file: https://tailscale.com/docs/features/tailnet-policy-file

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com

00:00 Why location sometimes matters
00:29 The problem with always-on subnet routing
00:56 What device posture can do
01:30 Demo: Accessing a printer through a subnet router
02:05 Why routing locally is often better
02:41 Why broader routes aren't a great workaround
03:17 Using your public IP as the condition
03:56 Building the posture policy
05:08 Testing the policy at home and away
05:48 Security considerations
06:15 Final thoughts

DevRel Hot Takes

💾

From living like a “low-rent Tony Stark” to a few thoughts on Nano vs. Vim, last week’s DevRelCon had no shortage of hot takes. What are your devrel hot takes :face_with_monocle: ?

Meet Tailscale’s DevRel team - A chat about what we’re doing next on this channel

💾

Tailscale’s DevRel team is normally spread across different time zones, so Alex sat down with Kevin Purdy and Ryan Wuller while everyone was together at DevRelCon in Brooklyn. Ryan explains how a career in video production brought him to Tailscale, while Kevin looks back on more than 15 years of technology journalism, open source rabbit holes, and difficult projects that eventually became stories.

Ryan is beginning his journey into self-hosting with a 3D-printed ThinkCenter NAS, while Kevin wants to explore local AI, privacy, and building useful software for yourself. Tell us in the comments what tutorials, projects, and experiments you want the team to make next.

Get Tailscale:
https://tailscale.com/

Join us at TailscaleUp:
https://tailscaleup.com/
Get 20% off in-person tickets with code ALEXSENTME

Follow Tailscale:

Bluesky:
https://bsky.app/profile/tailscale.com

X:
https://twitter.com/tailscale

LinkedIn:
https://www.linkedin.com/company/tailscale

Mastodon:
https://hachyderm.io/@tailscale

Reddit:
https://www.reddit.com/r/Tailscale/

Discord:
https://discord.gg/tailscale

GitHub:
https://github.com/tailscale

A Quick Look into Aperture

💾

There's no shortage of talk about AI. The harder part is what comes after your teams start using it: who's using what, how much of it, and how it's made secure.

Over the next few weeks, we'll be sharing a series of short demos exploring how our centralized AI gateway, Aperture, gives organizations visibility into AI adoption while making it easier to securely connect people to the models and tools they need.

First up: a quick look at what Aperture is, and what it brings to your AI stack.

Free and Easy Home Assistant Remote Access with Tailscale!

💾

Learn how to access Home Assistant remotely with Tailscale https://tailscale.com/blog/remotely-access-home-assistant

This step-by-step guide shows you how to install Tailscale on Home Assistant, enable MagicDNS and HTTPS, and securely connect to your smart home from anywhere without opening ports.

We also cover Tailscale Serve, exit nodes, and subnet routes. Tailscale is free for home users and makes secure remote access to Home Assistant simple.

00:00 - Start
01:15 - Installing Tailscale
05:25 - Configuring Tailscale Serve
08:56 - Mobile
10:01 - Advanced configuration

I’m Running Docker Apps Differently Now

💾

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com.

In this video, Alex shows how to use the community project DockTail, to turn Docker labels into native Tailscale Services. DockTail watches your Docker containers, reads their labels, and automatically exposes matching containers as private Tailscale Services without publishing ports directly on the host. It is a bit like a Tailscale-native workflow for Docker apps, especially if you are used to tools like Traefik.

DockTail docs: https://docktail.org/docs/#why-docktail
DockTail project: https://github.com/marvinvr/docktail
Code snippets: https://github.com/tailscale-dev/video-code-snippets/tree/docktail-vid/2026/2026-07-docktail

How I Control Home Assistant with Hermes Agent

💾

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com.

To clarify, I did, in fact, actually put on an actual suit for this thumbnail. The first time in many years. The sacrifices one makes for their art!

AI agents are everywhere right now but what actually makes something an agent? In this video I break down the agentic AI stack in simple terms, covering models, tools, harnesses, sandboxes, memory, context, and permissions without all the confusing buzzwords.

Towards the end of the video, I also share my self-hosted Hermes and Home Assistant setup, showing how I use Tailscale to securely connect everything together. From fixing Jellyfin over SSH to controlling my smart home with natural language, these real world examples show why agentic workflows are such an exciting step forward. If you want to learn more about AI agents, check out the Tailscale blog post here: https://tailscale.com/blog/agents-are-coming

00:00 - Start
00:48 - What’s an LLM?
05:35 - Aperture
06:24 - Hermes + Home Assistant

Fixing my ridiculous fridge with a tiny Funnel site

💾

Websites—just websites—can still be pretty amazing. I recently rediscovered the joy of a little page with just one job, thanks to Tailscale Funnel. And all it took was reaching a breaking point with my stupid fridge.
❌