TailscaleUp is nearly here, and we have a lot to share in the next week. Here’s a preview of what we’re building—and one last call to join us in San Francisco.
The TailscaleUp-date
Author
Ross Kukulinski
I've spent most of my career in networking and infrastructure, and I joined Tailscale six months ago for a simple reason: this company takes things that are genuinely hard and makes them feel like magic. Customers tell us some version of “Wait, that's it?” every day.
Getting two things to communicate securely shouldn't require weeks of network design, a collection of overlapping security products, and a carefully maintained spreadsheet of firewall rules. Things should just connect with clear identity on each end and policy deciding what's allowed. Then the network should get out of the way.
That idea started with people and devices. But increasingly, the thing making the connection is software acting on someone’s behalf. That might be a service, an automation, or an AI agent, reaching into the systems it needs to do some work.
Giving everything access is easy. The hard part is how you give the right identity, access to the right thing, at the right time. You need controls you can actually trust, and a clear record of what happened.
That question sits at the center of what we’ll share at TailscaleUp this week. And if you want to join us, grab a ticket. If you can’t join us in person, you can register to watch the keynote and general sessions online.
We’ll share the full details of what’s new, and what’s changing, at the event. For now, here are a few of the areas we’ve been working on.
More control over how organizations use AI
AI systems are already reaching into repositories, internal tools, databases, and other private resources. They often rely on shared API keys and public endpoints that weren’t designed for this. That creates a new access problem: teams need to know which models, agents, and tools are in use, what they can reach, and what they’ve done.
We’re updating Aperture, our AI gateway and governance tool, to make it easier to use different models and agents with the tools and private systems they need. This gives organizations better control, and logs, around that access.
Privileged access when and where it’s needed
Some systems need tighter controls than others. Access to production databases, cloud consoles, and sensitive infrastructure often needs approval, a time limit, and a reliable record of the session.
We’re giving teams a simpler way to control that access. Teams will be able to grant approved, time-bound access to specific resources and review what happened afterward, without relying on permanent credentials or stitching together several disconnected products.
Protection for the tailnet, and beyond
Tailscale already protects access to your private resources. But people and agents spend most of their day on the public internet. We're extending protection there, too, with new DNS-level controls to reduce exposure to malicious or unwanted destinations.
A more programmable Tailscale
We’re also making Tailscale easier to build with and build on.
Developers and platform teams increasingly want networking to be something software can create and use directly, rather than something a person has to configure first.
That means better APIs, new ways to embed Tailscale into applications, and better primitives for programmable connectivity.
Later this week, we’ll show you a lot more of that.
One last call for TailscaleUp
If you’d like to see the announcements in person and spend the day with the Tailscale community, this is the last opportunity to get a ticket.
There’ll be technical sessions, hands-on workshops, a homelab help desk, customer stories, and more. The breakout sessions and workshops won’t be streamed or recorded, so joining us in person is the only way to take part in the full program.
If you can’t make it to San Francisco, you can still register for the free virtual pass to watch the keynote and general sessions.
I’m looking forward to showing you what we’ve built, and to hearing what you do with it.