Tailscale

View as Markdown

Community Platform

runZero imports the devices in your Tailscale tailnet, including their addresses, operating system, hostnames, tags, and the Tailscale account that owns each node. Tailscale is the first integration runZero ships as a platform-packaged Starlark integration. It runs on the same engine as custom integration scripts, with the script embedded in the product, so you configure it like any other connector and never edit a script.

Getting started

To set up the Tailscale integration:

  1. Create a Tailscale API access token, or an OAuth client, in the Tailscale admin console.
  2. Add the Tailscale credential to runZero.
  3. Set up and activate the connector task that syncs your data into runZero.

Requirements

  • Access to the Tailscale admin console with permission to create API access tokens or OAuth clients.
  • The runZero custom integrations entitlement.
  • An Explorer running version 5.0.260723.0 or newer, if the task runs on an Explorer. The Tailscale API is reachable from the cloud, so the task can also run without one.

Step 1: Create a Tailscale API token or OAuth client

The integration accepts either kind of credential:

  • For an API access token, go to Settings > Keys in the Tailscale admin console and generate one (it starts with tskey-api-). Tokens expire, so prefer an OAuth client for a scheduled sync.
  • For an OAuth client, go to Settings > OAuth clients in the Tailscale admin console and create a client with at least the devices:core:read scope. Copy the client ID and client secret.

Step 2: Add the Tailscale credential to runZero

  1. Go to the Credentials page in runZero and click Add Credential.
  2. Choose Tailscale Settings & Secrets from the list of credential types.
  3. Fill in the fields:
    • Leave Tailscale API URL at the default https://api.tailscale.com unless you proxy the API.
    • Set Tailnet to the tailnet ID or name, for example T1234CNTRL or example.com.
    • Enter your client ID in OAuth client ID, or leave it blank to use a plain API key.
    • Set API key / OAuth client secret to the API access token, or to the OAuth client secret when a client ID is set.
  4. Save the credential.

Step 3: Set up and activate the Tailscale integration

  1. Activate a connection to Tailscale. You can also reach it from the Tailscale card on the integrations page.
  2. Choose the credential you added earlier. If it isn’t listed, check that it has access to your current organization.
  3. Enter a name for the task, like Tailscale sync.
  4. Schedule the sync and choose the site for newly discovered assets.
  5. To stop the sync from creating assets runZero hasn’t seen any other way, enable Exclude assets that cannot be merged into an existing asset.
  6. Select an Explorer, or leave the selection empty to run the sync from the runZero cloud.
  7. Activate the connection. The sync runs on the schedule you set.

Step 4: View Tailscale assets

After a successful sync, your Tailscale devices appear in your inventory with the Tailscale icon in the Source column. Their attributes live under tailscale.device.*, and runZero resolves the Tailscale account that owns each node into asset ownership. Managing ownership explains the owner types and how to assign an owner to an asset.

To filter by Tailscale assets:

source:tailscale
Updated