Tailscale SSH, now in beta, is a better way to establish SSH connections between devices in your Tailscale network, as authorized by your access controls, without managing ssh keys, and authenticates and encrypts your SSH connection using WireGuard.
👋 Hi everybody, I’m Maya, the Product Manager behind Tailscale SSH.
💡Why did we build Tailscale SSH? We realized that many organizations were using Tailscale to protect SSH connections, but that given we already manage authentication, authorization and encryption for other Tailscale connections, we could simplify SSH connections while keeping them secure.
🔒What is Tailscale SSH? Tailscale SSH lets you establish SSH connections between hosts easily, and also introduces check mode, to require recent re-authentication for high-risk connections. So you can check that there’s a real human sitting at that keyboard before they get access to prod :)
👩💻Why should you use Tailscale SSH? It’s easier than managing SSH keys (or certificates), as you can define permissions in code, so you know exactly who has access, and can add devices or revoke users’ access without having to update every device. It’s more reliable than using a bastion, since you don’t need to maintain a single public point of access to your network, through which all your traffic is funneled (and it’s faster too). And you get all the benefits of Tailscale: SSH access is integrated with your identity provider, you can manage permissions as code, and keys are automatically rotated.
We’d love to hear your feedback - we want to keep delivering a great experience for our users.
Thanks @chrismessina for hunting Tailscale SSH!
I’m co-founder and CEO of Tailscale. I’ve been working in networking and security for pretty much my whole career, and SSH key management has been a pain the whole time. It only got worse with mobile devices, security keys, and ever more restrictive firewalls and NATs.
Tailscale creates an instant link between all your devices anywhere in the world, authenticated with your Google/GitHub/etc identity. The new Tailscale ssh feature authenticates ssh the same way. I think you’ll like it!
I'm one of the engineers who worked on Tailscale SSH, and have since deployed it throughout my personal tailnet.
Even though I know how it works, it still feels magical every time I SSH into my machines!
I no longer have to manage SSH keys in the dozen or so devices that I have in my homelab!
I'll be hanging around the comments to answer any questions.
I'm one of the very early customers and use Tailscale for pretty a while now, it looks like ages. Once you have into it (that's one of the handiest matters to do) you'll love it. No doubt. I could not promote it my mother, however for you out here, who is aware of why a VPN is usually not anything clean to set up, you without a doubt will by no means pass someplace else.
I'm one of the very early users and use Tailscale for quite some time now, it feels like ages. Once you've got into it (which is one of the simplest things to do) you will love it. No doubt. I couldn't sell it my mother, but for you out here, who knows why a VPN is always nothing easy to set up, you definitely will never go somewhere else.