Give the Tailscale ACL step a working policy file #53

Merged
sulthan merged 2 commits from docs/tailscale-acl into main 2026-08-09 16:12:03 +07:00

2 Commits

Author SHA1 Message Date
sulthan 240edfb677 Write the Tailscale policy in grants, not acls (#46)
The console ships a grants-based default policy, so an acls example forces the
operator to translate before they can use it - and the two differ in exactly
the place that matters: grants carry ports in `ip` (`tcp:9222`) rather than
suffixed onto `dst`.

Adds the three things dropping the blanket grant silently takes away: an ssh
block, since tagged devices leave `autogroup:self` and Tailscale SSH stops
resolving them; a commented `autogroup:internet` grant for exit-node users;
and `tcp:22` to the browser machine, without which tagging locks you out.
2026-08-09 16:05:13 +07:00
sulthan 35a254a86e Give the Tailscale ACL step a working policy file (#46)
The DEPLOY §7 snippet was a bare `acls` fragment: it named tags without
declaring tagOwners, without saying how tags get applied, and without the rule
that keeps the operator's own SSH access once the blanket accept is gone.
Following it literally locks you out of the browser machine.

Also records why tagging is load-bearing rather than stylistic - Tailscale has
no deny, so excluding CDP from a selector that still covers your own devices
requires the destination to fall outside autogroup:member/self, which is
exactly what a tag does - and separates the bind proof from the ACL proof,
which the old text conflated.
2026-08-09 16:01:01 +07:00