Give the Tailscale ACL step a working policy file #53
Reference in New Issue
Block a user
Delete Branch "docs/tailscale-acl"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-up to #52, which merged before this landed. Docs only — no code, no compose changes.
DEPLOY.md§7 told the operator to "tag the two machines" and showed a bareaclsfragment. Following it literally does not work and is actively harmful:tag:bookmark-api/tag:bookmark-browserwithout atagOwnerssection, so the policy is rejected on save;tailscale up --advertise-tags=..., which re-authenticates);Replaced with a complete, saveable policy file:
tagOwners, the CDP rule, a second rule preserving own-device access including:22, and atestsblock so a later edit that widens 9222 is rejected rather than silently applied.Also records two things that were assumed rather than stated:
deny, so restricting 9222 means removing the blanket accept and enumerating what remains. That is only expressible if the browser machine falls outside a selector that still covers your own devices — which is exactly what a tag does, since a tagged device has no user and stops matchingautogroup:member/autogroup:self. Without that, the whole step reads as arbitrary ceremony.Finally, separates two checks the old text conflated: the existing
curlruns on the home machine and proves only the bind, because node-local traffic is not filtered. Proving the ACL needs a third device, so that check is now its own step.Verified:
tailscale.com/docs/reference/syntax/policy-fileand/docs/features/tags(validated Apr 2026 / Dec 2025) fortagOwners,autogroup:selfsemantics vs tagged devices,--advertise-tagsre-auth and key-expiry behaviour. Markdown fences balanced.