MagicRoute
MagicRoute is a tailnet-wide route selection option that selects among eligible subnet routers, app connectors, and Tailscale Service hosts for each client using a priority score. It also changes the algorithm for recommended exit nodes on supported clients. Premium and Enterprise tailnets eligible for regional routing can opt in to the beta.
Use cases
Use MagicRoute when you have multiple eligible resources for the same destination:
- Subnet routers: Select among routers advertising the same approved route prefixes, such as routers at different points of presence.
- App connectors: Select among connectors configured for the same apps, including apps with location-dependent DNS results.
- Tailscale Service hosts: Select among hosts for a Service, including backends for Kubernetes multi-cluster ingress.
For examples that also apply to regional routing, refer to Route selection use cases.
How it works
MagicRoute scores eligible candidates for each client using signals such as geolocation hints. Unlike regional routing, it does not group candidates by DERP region, and it supports custom DERP servers. Selection is per client, not per connection.
Switching to MagicRoute changes the selection method for existing Tailscale Service hosts from DERP-region grouping or active-passive failover to priority scoring. You do not need to recreate Services or Kubernetes Ingress resources. For host setup, refer to Tailscale Services.
MagicRoute also uses priority scoring for exit node recommendations on clients running Tailscale v1.86.0 or later. Earlier clients retain their existing recommendation behavior. It does not change whether recommended exit nodes are available to your tailnet or override an exit node that a user selected manually. Users can select a recommendation once or track recommendations automatically.
Prerequisites
Before you select MagicRoute, ensure that your tailnet and resources meet these requirements:
- Your tailnet is on a Premium or Enterprise plan, is eligible for regional routing, and has access to the MagicRoute beta. Existing regional routing customers must opt in.
- You must be an Owner, Admin, or IT admin to change the route selection option.
- For subnet routers and app connectors, deploy redundant connectors. Approve subnet routes and configure apps as needed. For Services, configure and approve the Service hosts.
- To use MagicRoute exit node recommendations, run Tailscale v1.86.0 or later on the client. Server-side selection among subnet routers, app connectors, and Service hosts works with all client versions.
Get started
Use the existing route selection procedure to change the tailnet-wide option. You do not need to reconfigure eligible resources when switching from another option.
- Set up the subnet routers, app connectors, or Tailscale Service hosts you want MagicRoute to select among. Approve their advertised routes or Service hosts as applicable.
- Select MagicRoute in the admin console or with the tailnet settings API. The change saves for the tailnet. Follow the linked procedure to read back the saved option.
- Check routing from your clients. A saved setting does not, by itself, establish that a particular request used a particular resource.
Limitations
MagicRoute does not guarantee equal traffic volume, capacity-based balancing, or selection of the geographically closest or fastest connector or Service host. For route eligibility, longest-prefix matching, and the absence of cross-prefix failover, refer to Route selection.
To report a problem with the beta, contact Tailscale Support.