Traditional VPNs are all-or-nothing: connect to the VPN and you can reach everything on the network. Tailscale creates a mesh network where every device connects directly to every other device, and access is controlled per-device and per-service.
How Tailscale Works
Laptop ←── WireGuard tunnel ──→ Production Server
Laptop ←── WireGuard tunnel ──→ Kubernetes Cluster
Phone ←── WireGuard tunnel ──→ Home NASEvery device gets a stable IP (100.x.y.z) in your tailnet. Connections are peer-to-peer, encrypted with WireGuard. No traffic flows through a central server.
Setup
# Install on any device
curl -fsSL https://tailscale.com/install.sh | sh
# Connect
sudo tailscale up
# Check your IP
tailscale ip -4
# 100.64.0.1Repeat on every device. They automatically discover each other and establish encrypted connections.
Access Control Lists
Control who can reach what:
{
"acls": [
{
"action": "accept",
"src": ["group:developers"],
"dst": ["tag:dev-servers:*"]
},
{
"action": "accept",
"src": ["group:sre"],
"dst": ["tag:production:*"]
},
{
"action": "accept",
"src": ["group:developers"],
"dst": ["tag:production:443"]
}
],
"groups": {
"group:developers": ["alice@myorg.com", "bob@myorg.com"],
"group:sre": ["charlie@myorg.com"]
},
"tagOwners": {
"tag:dev-servers": ["group:sre"],
"tag:production": ["group:sre"]
}
}Developers can reach dev servers on all ports. SREs can reach production on all ports. Developers can only reach production on port 443 (HTTPS).
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Kubernetes Access
Tailscale as a Kubernetes Operator
helm install tailscale-operator tailscale/tailscale-operator \
--namespace tailscale --create-namespace \
--set oauth.clientId=$TS_CLIENT_ID \
--set oauth.clientSecret=$TS_CLIENT_SECRETExpose a Kubernetes service on your tailnet:
apiVersion: v1
kind: Service
metadata:
name: grafana
annotations:
tailscale.com/expose: "true"
tailscale.com/hostname: "grafana-prod"
spec:
selector:
app: grafana
ports:
- port: 3000Now grafana-prod is accessible on your tailnet at http://grafana-prod:3000. No Ingress, no LoadBalancer, no public IP.
kubectl Access
# Register the API server on your tailnet
tailscale.com/expose: "true" # On the API server service
# Access from any device on the tailnet
kubectl --server=https://k8s-prod:6443 get podsSSH over Tailscale
# Enable Tailscale SSH on a server
tailscale up --ssh
# SSH from any device on the tailnet
ssh user@100.64.0.2
# Or use the MagicDNS name
ssh user@prod-serverNo SSH key management. Authentication uses your identity provider (Google, Okta, etc.). Access is logged and auditable.
Database Access
# Tag the database server
tailscale up --advertise-tags=tag:database
# ACL: only backend services can reach databases
{
"action": "accept",
"src": ["tag:backend"],
"dst": ["tag:database:5432"]
}The database is never exposed to the public internet. Only tagged backend services can connect, and only on port 5432.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Subnet Router
Access entire networks through a single Tailscale node:
# On a node in the target network
tailscale up --advertise-routes=10.0.0.0/24,192.168.1.0/24
# Approve in admin console
# Now all tailnet devices can reach 10.0.0.0/24Access on-premises networks from anywhere without a traditional VPN concentrator.
Tailscale vs Traditional VPN
| Feature | Tailscale | Traditional VPN |
|---|---|---|
| Architecture | Mesh (peer-to-peer) | Hub-and-spoke |
| Encryption | WireGuard | IPSec/OpenVPN |
| Access control | Per-device, per-port | Network-level |
| NAT traversal | Automatic | Complex |
| Setup | Minutes | Hours/days |
| Performance | Direct connections | All traffic through VPN server |
| SSO integration | Built-in (OIDC) | Separate config |
When to Use Tailscale
Good fit: - Remote access to servers and databases - Connecting cloud and on-premises networks - Zero trust access to Kubernetes clusters - Replacing traditional VPNs - Dev environments accessing shared resources
Not suited for: - High-bandwidth data transfer between data centers (use dedicated links) - Environments requiring FIPS-validated encryption - Organizations that need full network inspection (DPI)
---
Ready to go deeper? Master networking and security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Boundary Zero Trust Access Manager
HashiCorp Boundary provides identity-based access to infrastructure without VPNs or SSH keys. Learn how Boundary replaces bastion hosts and VPNs.
Ubuntu 26.04 Makes sudo-rs Default
Ubuntu 26.04 LTS replaces the 44-year-old C sudo with sudo-rs, a Rust rewrite. Learn what changes, why it matters for security, and what else ships.
Quality vs Safety in Engineering
Quality and safety are not the same thing in software engineering. Learn when to prioritize safety over quality, how to build guardrails without slowing.
Talos Linux for Kubernetes
Talos Linux is a minimal, immutable OS designed exclusively for running Kubernetes. Learn why it exists, how it works, and when to use it instead of Ubuntu.
Taskfile Modern Build Automation
Taskfile is a modern alternative to Makefiles for task automation. Learn how to use Task for build scripts, development workflows, and CI/CD tasks with YAML.
Tekton Cloud Native CI/CD
Tekton runs CI/CD pipelines as Kubernetes custom resources. Learn how Tekton works, how to build pipelines with Tasks and Pipelines, and when to choose it.
Explore topics
Browse more articles on the topics covered here.