Reading view

Tailscale Up 2026 - Keynote Replay

💾

What happens when writing the code becomes the easy part?

In the Tailscale Up 2026 keynote, Avery Pennarun, Ross Kukulinski, Sydney Rossman-Reich, Mike Shaver, and Remy Guercio from the Tailscale team look at what comes next as AI changes who can build software, and why networking, infrastructure, access, and security shouldn’t get in the way.

Along the way, you’ll see new ways to build with Tailscale, AI put to work in a homelab, projects from the Tailscale community, and the story of how something that started with a Minecraft server at home made its way into GoFundMe with John Downey.

It’s a look at what we’ve been building, what people are already building with Tailscale, and what happens when more people have the tools to turn an idea into something that works.

Watch the full Tailscale Up 2026 keynote.

*Key Moments*
0:00 Tailscale Up 2026
2:38 What if everyone could be a programmer?
7:04 Compute, storage, networking
10:31 Building on Tailscale
18:17 What comes after connectivity?
23:37 AI meets the homelab
30:51 What the Tailscale community is building
38:43 From the homelab to GoFundMe
49:43 Tailscale as a platform
59:13 What comes next
1:07:34 Go build something

So long, and thanks for all the fish.

💾

As they say, everything that has a beginning has an end, and today marks my last day as a Tailscalar. I always enjoyed that little nerdy math joke about this place.

https://tailscale.com

Please keep spreading the word. Tell your friends. Take Tailscale to work. That’s how the free tier stays free and we all get more cool homelab stuff. And check out the careers page for DevRel (and plenty of other roles). Tailscale is a fun place to work, and you’ll be surrounded by some of the best humans on the planet. I actually do mean that. It tells you a lot about the company that they asked me to make this video for you all.

I’m incredibly grateful to everyone who watched the videos, used the product, or came along for the ride, and to Tailscale for taking a chance on me in the first place.

I’m writing this from the airport after Tailscale Up wrapped yesterday, and after meeting so many of you in person, I’m more excited than ever about what comes next for Tailscale. The people here are building something genuinely special, and my departure doesn’t change that.

See you down the road, my lovely little velociraptors and noodlefishies.

You can find me at https://alex.ktz.me

And, as always, thank you so much for watching. I’ve been Alex.

Build isolated sandboxes with Tailscale

💾

AI can build an application in minutes. Deploying it securely is still the hard part.

In this update, Reza shows how to build secure development workflows where AI agents and applications can create isolated tailnets, embed networking directly into code, and automate infrastructure using the Tailscale API.

Instead of exposing services, managing temporary infrastructure by hand, or manually configuring sharing, you'll see how to make networking part of your application from the start.

## In this video you'll learn:
* How isolated tailnets create secure sandbox environments for AI agents
* When embedded networking is a better fit than running a Tailscale client
* How language libraries make networking part of your application
* How the upcoming Declarative Node Sharing feature simplifies access management through policy
* How to automate networking, infrastructure, and administration with the Tailscale API

Whether you're building AI applications, self-hosted services, developer tools, or modern infrastructure, these capabilities help make networking programmable from development through production.

## In this video:
00:00 Why AI can build apps faster than we can deploy them
01:10 Create isolated tailnets for AI agent workflows
02:20 Embed Tailscale networking into your application
03:47 Connect sandbox environments to real infrastructure
04:34 Simplify access with Declarative Node Sharing
05:58 Automate your infrastructure with the Tailscale API
06:39 Build secure infrastructure with code
07:03 Resources and next steps

## Resources:
🧑‍💻 Source code for this video: https://github.com/tailscale-dev/summer-with-tailscale
📖 Tailscale Documentation: https://tailscale.com/kb
⚙️ Tailscale API Documentation: https://tailscale.com/kb/api
💬 Join the Tailscale Discord: https://tailscale.com/discord

I replaced my Pi-hole with this

💾

DNS filtering by Control D is now available to Tailscale customers through the Tailscale sales team. It can block malware, phishing, ads, trackers, and other unwanted websites. You can apply different filtering rules to groups, tags, or individual devices across your tailnet.

Tailscale and Control D setup guide:
https://tailscale.com/docs/integrations/control-d

Control D’s Tailscale guide:
https://docs.controld.com/docs/tailscale-integration

Purchase through Tailscale:
https://tailscale.com/contact/sales

Control D:
https://controld.com/

In this video, I show you how to add Control D as a nameserver in Tailscale, create a filtering profile, and choose which users or devices should use it. Control D supports content categories, more than 1,000 services and apps, and custom rules to block, allow, or redirect domains.

Tailscale handles simple user-based billing, so you do not need to predict how many devices you will have. Your filtering rules are still managed through the Control D dashboard or API. Use the links below to learn more or talk to the Tailscale team.

A better way to manage privileged access

💾

Tailscale PAM is now available in beta, bringing privileged access management directly into Tailscale.

In this Summer Update, Alex takes a first look at Tailscale PAM: what it is, the problems it’s designed to solve, and how to get started. We’ll set up a PAM connector, add a PostgreSQL database as a service, connect through the Tailscale client and browser, and finish by accessing a Windows machine with Remote Desktop directly from the browser.

Tailscale PAM provides granular, identity-aware access to infrastructure while managing credentials behind the scenes. Admins can also audit access with logs and session playback.

Tailscale PAM beta is free for up to six users.

Join the Tailscale PAM beta:
https://tailscale.com/pam-selfserve-waitlist

Learn more about Tailscale PAM:
https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam


In this video:
00:00 Tailscale PAM is here
00:31 What is privileged access management?
00:53 What problems does PAM solve?
01:27 PAM vs network access policies
01:58 What’s included in the beta
02:36 Why Tailscale PAM uses connectors
02:58 Setting up Tailscale PAM
03:47 Adding a PAM connector
04:59 Adding a PostgreSQL service
06:40 Connecting to a database with PAM
07:24 Connecting through your browser
07:53 Remote Desktop with Tailscale PAM
09:10 Final thoughts

This will change how you homelab | Aperture GA announcement

💾

https://tailscale.com/blog/aperture-ga

Getting an AI agent to SSH into your server is easy. Giving it only the access it actually needs is the interesting part.

Aperture by Tailscale is now generally available, and it can give agents controlled SSH access to machines on your tailnet. In this Summer Update, Remy shows us how Aperture can set up real homelab services while keeping Tailscale identity and access controls in the loop.

We use a Raspberry Pi to see how an agent can install and configure services, add them to a tailnet, and work within the permissions you define. We also look at Aperture's mobile experience, LLM and MCP visibility, and how its SSH and node-management capabilities can be used from other agent workflows through MCP.

The goal isn't simply to let an agent onto your network. It's to make intentional decisions about what that agent can and can't access.

Learn more about Aperture: http://tailscale.com/blog/aperture-ga

Get started with Aperture: https://tailscale.com/docs/aperture/get-started

Watch the Tailscale Summer Update playlist: https://www.youtube.com/playlist?list=PLJW-_hiaseM8

In this video:
00:00 Why homelabbing is still too complicated
00:24 Aperture is now generally available
01:00 From LLM proxy to AI gateway
01:31 Why not just give an agent an SSH key?
02:03 Putting an agent to work in the homelab
02:57 Giving services their own Tailscale identity
03:12 Taking Aperture mobile
03:37 Seeing what your agents are doing
04:07 Using Aperture with other agents through MCP
04:34 Why the guardrails matter
05:03 Bringing Aperture tools to your existing workflow
05:15 Try Aperture

Smarter Tailscale Subnet Routing

💾

One of the biggest advantages of Tailscale is that your devices stay connected no matter where you are. But sometimes your location should change how your network behaves.
In this video, Jay demonstrates how to use IP source device posture to control access to a subnet router based on the public network your device is connected to. Instead of always routing through your subnet router, you'll learn how to automatically use your local network when you're home and Tailscale only when you're away.

Whether you're running printers, cameras, IoT devices, or other systems that can't run Tailscale themselves, this approach keeps your routing simple while avoiding unnecessary hops.
Documentation

Device posture: https://tailscale.com/docs/features/device-posture
Subnet routers:https://tailscale.com/docs/features/subnet-routers
Tailnet policy file: https://tailscale.com/docs/features/tailnet-policy-file

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com

00:00 Why location sometimes matters
00:29 The problem with always-on subnet routing
00:56 What device posture can do
01:30 Demo: Accessing a printer through a subnet router
02:05 Why routing locally is often better
02:41 Why broader routes aren't a great workaround
03:17 Using your public IP as the condition
03:56 Building the posture policy
05:08 Testing the policy at home and away
05:48 Security considerations
06:15 Final thoughts

DevRel Hot Takes

💾

From living like a “low-rent Tony Stark” to a few thoughts on Nano vs. Vim, last week’s DevRelCon had no shortage of hot takes. What are your devrel hot takes :face_with_monocle: ?

Meet Tailscale’s DevRel team - A chat about what we’re doing next on this channel

💾

Tailscale’s DevRel team is normally spread across different time zones, so Alex sat down with Kevin Purdy and Ryan Wuller while everyone was together at DevRelCon in Brooklyn. Ryan explains how a career in video production brought him to Tailscale, while Kevin looks back on more than 15 years of technology journalism, open source rabbit holes, and difficult projects that eventually became stories.

Ryan is beginning his journey into self-hosting with a 3D-printed ThinkCenter NAS, while Kevin wants to explore local AI, privacy, and building useful software for yourself. Tell us in the comments what tutorials, projects, and experiments you want the team to make next.

Get Tailscale:
https://tailscale.com/

Join us at TailscaleUp:
https://tailscaleup.com/
Get 20% off in-person tickets with code ALEXSENTME

Follow Tailscale:

Bluesky:
https://bsky.app/profile/tailscale.com

X:
https://twitter.com/tailscale

LinkedIn:
https://www.linkedin.com/company/tailscale

Mastodon:
https://hachyderm.io/@tailscale

Reddit:
https://www.reddit.com/r/Tailscale/

Discord:
https://discord.gg/tailscale

GitHub:
https://github.com/tailscale

A Quick Look into Aperture

💾

There's no shortage of talk about AI. The harder part is what comes after your teams start using it: who's using what, how much of it, and how it's made secure.

Over the next few weeks, we'll be sharing a series of short demos exploring how our centralized AI gateway, Aperture, gives organizations visibility into AI adoption while making it easier to securely connect people to the models and tools they need.

First up: a quick look at what Aperture is, and what it brings to your AI stack.

Free and Easy Home Assistant Remote Access with Tailscale!

💾

Learn how to access Home Assistant remotely with Tailscale https://tailscale.com/blog/remotely-access-home-assistant

This step-by-step guide shows you how to install Tailscale on Home Assistant, enable MagicDNS and HTTPS, and securely connect to your smart home from anywhere without opening ports.

We also cover Tailscale Serve, exit nodes, and subnet routes. Tailscale is free for home users and makes secure remote access to Home Assistant simple.

00:00 - Start
01:15 - Installing Tailscale
05:25 - Configuring Tailscale Serve
08:56 - Mobile
10:01 - Advanced configuration

I’m Running Docker Apps Differently Now

💾

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com.

In this video, Alex shows how to use the community project DockTail, to turn Docker labels into native Tailscale Services. DockTail watches your Docker containers, reads their labels, and automatically exposes matching containers as private Tailscale Services without publishing ports directly on the host. It is a bit like a Tailscale-native workflow for Docker apps, especially if you are used to tools like Traefik.

DockTail docs: https://docktail.org/docs/#why-docktail
DockTail project: https://github.com/marvinvr/docktail
Code snippets: https://github.com/tailscale-dev/video-code-snippets/tree/docktail-vid/2026/2026-07-docktail

How I Control Home Assistant with Hermes Agent

💾

Want to learn more about self hosting, AI, Kubernetes, and modern infrastructure? Come to Tailscale Up and join us in person. Get 20% off IRL tickets with the code ALEXSENTME at https://tailscaleup.com.

To clarify, I did, in fact, actually put on an actual suit for this thumbnail. The first time in many years. The sacrifices one makes for their art!

AI agents are everywhere right now but what actually makes something an agent? In this video I break down the agentic AI stack in simple terms, covering models, tools, harnesses, sandboxes, memory, context, and permissions without all the confusing buzzwords.

Towards the end of the video, I also share my self-hosted Hermes and Home Assistant setup, showing how I use Tailscale to securely connect everything together. From fixing Jellyfin over SSH to controlling my smart home with natural language, these real world examples show why agentic workflows are such an exciting step forward. If you want to learn more about AI agents, check out the Tailscale blog post here: https://tailscale.com/blog/agents-are-coming

00:00 - Start
00:48 - What’s an LLM?
05:35 - Aperture
06:24 - Hermes + Home Assistant

Fixing my ridiculous fridge with a tiny Funnel site

💾

Websites—just websites—can still be pretty amazing. I recently rediscovered the joy of a little page with just one job, thanks to Tailscale Funnel. And all it took was reaching a breaking point with my stupid fridge.
❌