Tailscale
runZero imports the devices in your Tailscale tailnet, including their addresses, operating system, hostnames, tags, and the Tailscale account that owns each node. Tailscale is the first integration runZero ships as a platform-packaged Starlark integration. It runs on the same engine as custom integration scripts, with the script embedded in the product, so you configure it like any other connector and never edit a script.
Getting started
To set up the Tailscale integration:
- Create a Tailscale API access token, or an OAuth client, in the Tailscale admin console.
- Add the Tailscale credential to runZero.
- Set up and activate the connector task that syncs your data into runZero.
Requirements
- Access to the Tailscale admin console with permission to create API access tokens or OAuth clients.
- The runZero custom integrations entitlement.
- An Explorer running version 5.0.260723.0 or newer, if the task runs on an Explorer. The Tailscale API is reachable from the cloud, so the task can also run without one.
Step 1: Create a Tailscale API token or OAuth client
The integration accepts either kind of credential:
- For an API access token, go to Settings > Keys in the Tailscale admin console and generate one (it starts with
tskey-api-). Tokens expire, so prefer an OAuth client for a scheduled sync. - For an OAuth client, go to Settings > OAuth clients in the Tailscale admin console and create a client with at least the
devices:core:readscope. Copy the client ID and client secret.
Step 2: Add the Tailscale credential to runZero
- Go to the Credentials page in runZero and click Add Credential.
- Choose Tailscale Settings & Secrets from the list of credential types.
- Fill in the fields:
- Leave Tailscale API URL at the default
https://api.tailscale.comunless you proxy the API. - Set Tailnet to the tailnet ID or name, for example
T1234CNTRLorexample.com. - Enter your client ID in OAuth client ID, or leave it blank to use a plain API key.
- Set API key / OAuth client secret to the API access token, or to the OAuth client secret when a client ID is set.
- Leave Tailscale API URL at the default
- Save the credential.
Step 3: Set up and activate the Tailscale integration
- Activate a connection to Tailscale. You can also reach it from the Tailscale card on the integrations page.
- Choose the credential you added earlier. If it isn’t listed, check that it has access to your current organization.
- Enter a name for the task, like
Tailscale sync. - Schedule the sync and choose the site for newly discovered assets.
- To stop the sync from creating assets runZero hasn’t seen any other way, enable Exclude assets that cannot be merged into an existing asset.
- Select an Explorer, or leave the selection empty to run the sync from the runZero cloud.
- Activate the connection. The sync runs on the schedule you set.
Step 4: View Tailscale assets
After a successful sync, your Tailscale devices appear in your inventory with the Tailscale icon in the Source column. Their attributes live under tailscale.device.*, and runZero resolves the Tailscale account that owns each node into asset ownership. Managing ownership explains the owner types and how to assign an owner to an asset.
To filter by Tailscale assets:
source:tailscale