Tailscale Release Notes

Follow

119 release notes curated from 1 source by the Releasebot Team. Last updated: Aug 13, 2026

Get this feed:
  • Aug 11, 2026
    • Date parsed from source:
      Aug 11, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Tailscale logo

    Tailscale

    Tailscale Kubernetes Operator v1.102.2

    Tailscale releases a new Kubernetes Operator update with in-cluster PeerRelays, Helm deployment annotations, workload identity federation, and expanded IPv6 and 4via6 support. It also trims noisy logs and fixes reconciliation, DNS, MTU, and certificate renewal issues.

    A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions.

    New

    PeerRelays are deployable in-cluster via a custom resource.

    Annotations can now be applied to the operator's deployment resource via Helm.

    Workload identity federation can now be configured for the Tailnet custom resource.

    4via6 is supported in connector and egress proxy resources when egressing from a dual-stack cluster.

    IPv6 is supported in Egress ProxyGroups.

    Changed

    Operator log output excludes superfluous entries, such as entries for resources that do not contain annotations.

    Several log lines have adjusted log levels.

    Fixed

    MTU values are clamped on both the input and output interfaces, where previously only the output interface was clamped.

    ProxyGroup services no longer fail to reconcile when using the same hostname across multiple tailnets.

    ProxyGroup static endpoints no longer cause constant reconciliation loops due to non-deterministic ordering.

    DNS reconciler no longer drops reconcile events, which left the dnsrecords ConfigMap stale.

    EndpointSlices for Egress ProxyGroup are verified on every reconcile.

    Cert renewal retries follow Let's Encrypt's recommended backoff schedule instead of a fixed interval.

    Let's Encrypt Retry-After headers are honored by Kubernetes proxies when hitting rate limits, which avoids the tight retry loops that made rate-limit backoffs worse.

    Per-attempt cert issuance timeout in Kubernetes proxies is increased to 30 minutes, giving ACME challenges room to complete under load without failing prematurely.

    Cert issuance attempts no longer run against a VIPService that is being torn down during Ingress deletion, which wasted Let's Encrypt rate-limit quota.

    Original source
  • Aug 7, 2026
    • Date parsed from source:
      Aug 7, 2026
    • First seen by Releasebot:
      Aug 8, 2026
    Tailscale logo

    Tailscale

    Tailscale tsrecorder v1.102.2

    Tailscale releases tsrecorder with a fix for indexing empty recording placeholder files on startup.

    A new release of the Tailscale tsrecorder is available. You can download it from Docker Hub.

    Fixed

    Recorder does not attempt to index empty recording placeholder files on startup.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Tailscale and hundreds of other software products.

    Create account
  • Aug 4, 2026
    • Date parsed from source:
      Aug 4, 2026
    • First seen by Releasebot:
      Aug 5, 2026
    Tailscale logo

    Tailscale

    Tailscale v1.102.2

    Tailscale fixes a regression that caused incoming Tailscale Funnel connections to fail.

    All Platforms

    Fixed: A regression causing incoming Tailscale Funnel connections to fail is resolved.

    Original source
  • Aug 3, 2026
    • Date parsed from source:
      Aug 3, 2026
    • First seen by Releasebot:
      Aug 4, 2026
    Tailscale logo

    Tailscale

    Tailscale v1.102.1

    Tailscale releases broad platform updates with new CLI visibility for node preferences, user and device info, and visible Services, plus Serve traffic metrics. It also improves performance, certificate renewal, and connectivity, while adding macOS, iOS, tvOS, Android, Linux, and Synology refinements.

    All Platforms

    New: tailscaled_serve_outbound_bytes_total and tailscaled_serve_inbound_bytes_total client metrics report bytes sent to and received from peers on Tailscale Serve connections for Tailscale Services.

    New: The tailscale get CLI command returns the current node's preferences.

    New: The tailscale whoami CLI command displays information about the current user and device.

    New: The tailscale service list CLI command displays Tailscale Services visible to the current node.

    Changed: Node additions and removals are processed in constant time, significantly reducing CPU usage on large tailnets.

    Changed: Tailscale Funnel domains use TLS-ALPN-01 for faster HTTPS certificate renewals.

    Changed: Deprecated formats for 4via6 MagicDNS names are no longer available to use.

    Changed: TLS certificates on idle servers proactively auto-renew in the absence of traffic. Warnings are issued when there is no valid cached certificate.

    Fixed: Dials to dual-stack DNS names through an IPv4-only exit node connect to the correct address when using tailscaled in userspace mode.

    Fixed: Certificate issuance for multiple domains runs in parallel. Provisioning multiple domains does not stall each certificate behind the previous one.

    Fixed: Resolved an issue causing connectivity issues from the operating system waking from sleep in wireguard-go.

    Fixed: A node's home DERP region is reported to the coordination server after a profile switch or login, allowing for peers to immediately connect to the node.

    Fixed: A memory leak that occurred after a failed WireGuard handshake has been resolved.

    Fixed: tailscale status --peers=false command shows the current device name in the output.

    Fixed: Resolved an issue that prevented connectivity via Tailscale Peer Relays after a client restart.

    Fixed: Tailscale SSH passes environment variables to child processes via inherited file descriptors. This fix addresses a security vulnerability described in TS-2026-010.

    Linux

    New: Assembly crypto routines for 32-bit ARM are available, improving performance on these platforms.

    Changed: Userspace TUN optimizations improve throughput and performance.

    Fixed: Resolved an issue impacting performance of UDP GSO on Linux v7.0.x through v7.1.4.

    macOS

    New: The Tailscale protocol handler supports deep-linking to devices, exit nodes, and settings panels in the application window.

    Changed: The device list in the menu bar and Windowed UI loads more efficiently.

    Changed: The client onboarding process is redesigned to match the style of the windowed UI.

    Changed: Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.

    Changed: The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.

    Fixed: Domain matching on-demand rules are evaluated in the correct order.

    Fixed: A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.

    Fixed: tailscale configure kubeconfig checks permissions on the $KUBECONFIG file before refusing to write to it when it's in a non-standard directory, fixing false rejections during Kubernetes API server access setup.

    iOS

    New: A new split-plane layout is used on iPad in both portrait and landscape orientation and on sufficiently wide iPhones in landscape.

    New: The status widget supports toggling the active exit node inline.

    Changed: Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.

    Changed: The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.

    Fixed: Domain matching on-demand rules are evaluated in the correct order.

    Fixed: A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.

    tvOS

    New: The Tailscale web client is supported for remote management of Apple TV devices.

    Changed: The client onboarding process ensures the VPN configuration is approved and a login profile is added before using fast user switching.

    Fixed: tvOS does not require a restart to use a custom coordination server defined in Settings.

    Android

    Changed: A single CGNAT route is created when no other interface is using CGNAT.

    Fixed: TCP connections do not reset when VPN routing changes due to a netmap update.

    Fixed: Health warnings are promptly cleared as soon as the underlying issue is resolved.

    Synology

    Changed: RMv7 binaries with software floating point are produced for certain Synology NAS models, replacing older ARMv5 binaries.

    Original source
  • Jul 29, 2026
    • Date parsed from source:
      Jul 29, 2026
    • First seen by Releasebot:
      Jul 30, 2026
    Tailscale logo

    Tailscale

    Tailnet creation API

    Tailscale adds API-only tailnet management with create, list, and delete support for organizations in alpha.

    New: Use the tailnet creation API to create, list, and delete API-only tailnets in your organization (alpha).

    Original source
  • Similar to Tailscale with recent updates:

  • Jul 28, 2026
    • Date parsed from source:
      Jul 28, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Tailscale logo

    Tailscale

    Tailscale v1.98.10

    Tailscale fixes SSH Unix socket forwarding and username checks to close security vulnerabilities.

    All Platforms

    Fixed: Tailscale SSH Unix socket forwarding respects symlink permissions. This fix addresses a security vulnerability described in TS-2026-004.

    Fixed: Tailscale SSH preforms additional checks to disallow UIDs and numeric-only usernames. This fix covers additional scenarios described in TS-2026-006.

    Original source
  • Jul 23, 2026
    • Date parsed from source:
      Jul 23, 2026
    • First seen by Releasebot:
      Jul 24, 2026
    Tailscale logo

    Tailscale

    Admin console URL change

    Tailscale moves the admin console to console.tailscale.com with admin links now redirecting automatically.

    Changed: The Tailscale admin console is now available at console.tailscale.com. Authentication continues to use login.tailscale.com, and requests to login.tailscale.com/admin/ automatically redirect to the new subdomain.

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 15, 2026
    • Modified by Releasebot:
      Jul 29, 2026
    Tailscale logo

    Tailscale

    Tailscale v1.98.9

    Tailscale fixes multiple security issues across Serve, SSH, Funnel, and Tailscale Services, and also resolves a CLI tag change logout bug plus a crash on 32-bit ARM platforms.

    All Platforms

    • Fixed: Tailscale Serve Unix socket proxy targets are restricted to the root user. This fix addresses a security vulnerability described in TS-2026-005.
    • Fixed: Tailscale SSH does not allow the use of UIDs or numeric-only usernames. This fix addresses a security vulnerability described in TS-2026-006.
    • Fixed: Nodes advertising Tailscale Services filter and reject packets from service IPs on ports they do not advertise. This fix addresses a security vulnerability described in TS-2026-007.
    • Fixed: Tailscale Serve and Tailscale Funnel terminate path walks for non-absolute paths, preventing CPU core pinning. This fix addresses a security vulnerability described in TS-2026-008.
    • Fixed: Tailscale SSH does not allow the use of usernames with leading dashes. This fix addresses a security vulnerability described in TS-2026-009.
    • Fixed: An issue where a user could be logged out of Tailscale when changing the tag on a device via CLI has been resolved.
    • Fixed: An issue that could cause a crash on 32-bit ARM platforms is resolved.
    Original source
  • Jul 8, 2026
    • Date parsed from source:
      Jul 8, 2026
    • First seen by Releasebot:
      Jul 9, 2026
    Tailscale logo

    Tailscale

    Nested group support for synced groups

    Tailscale adds nested group members to Microsoft Entra ID and Google Workspace group sync.

    New: Microsoft Entra ID and Google Workspace group sync includes members of nested groups.

    Original source
  • Jul 6, 2026
    • Date parsed from source:
      Jul 6, 2026
    • First seen by Releasebot:
      Jul 7, 2026
    Tailscale logo

    Tailscale

    Self-serve identity provider changes

    Tailscale adds beta admin console support for Owner role users to switch a tailnet's identity provider.

    New: Users with the Owner role can switch their tailnet's identity provider from the admin console for supported providers (beta).

    Original source
  • Jun 30, 2026
    • Date parsed from source:
      Jun 30, 2026
    • First seen by Releasebot:
      Jul 1, 2026
    Tailscale logo

    Tailscale

    Device Provisioning with OAuth Apps

    Tailscale adds alpha support for creating and managing OAuth Apps for device provisioning with its API.

    New: Create and manage OAuth Apps for Device Provisoning with the Tailscale API (alpha).

    Original source
  • Jun 29, 2026
    • Date parsed from source:
      Jun 29, 2026
    • First seen by Releasebot:
      Jun 30, 2026
    Tailscale logo

    Tailscale

    Tailscale v1.98.8

    Tailscale fixes wake-from-sleep connectivity issues, handshake retries, and SSH session recording connection leaks.

    Note: 1.98.6 and 1.98.7 were release candidates intended for testing only.

    All Platforms

    Fixed: An issue causing connectivity disruptions when the operating system wakes from sleep in wireguard-go is resolved.

    Fixed: An issue causing excessive handshake initiation retries in wireguard-go is resolved.

    Fixed: An issue causing connection leaks in Tailscale SSH Session Recording is resolved.

    Original source
  • Jun 29, 2026
    • Date parsed from source:
      Jun 29, 2026
    • First seen by Releasebot:
      Jun 30, 2026
    Tailscale logo

    Tailscale

    Public IP address device posture attribute

    Tailscale adds the ip:publicAddress device posture attribute and makes it viewable in the admin console Machines page.

    New: ip:publicAddress device posture attribute is available for use in postures and viewable on the Machines page of the admin console.

    To test, go to the Settings page of the admin console and toggle Public IP addresses for device posture (beta).

    Original source
  • Jun 26, 2026
    • Date parsed from source:
      Jun 26, 2026
    • First seen by Releasebot:
      Jun 27, 2026
    Tailscale logo

    Tailscale

    Tailnet system policy values

    Tailscale changes Tailnet system policy to accept comma-separated tailnet or organization IDs.

    Changed: The Tailnet system policy accepts a comma-separated list of tailnet IDs or organization IDs.

    Original source
  • Jun 17, 2026
    • Date parsed from source:
      Jun 17, 2026
    • First seen by Releasebot:
      Jun 18, 2026
    Tailscale logo

    Tailscale

    Log streaming integration with Azure Blob Storage

    Tailscale adds streaming network flow logs and configuration audit logs to Azure Blob Storage.

    New: Tailscale network flow logs and configuration audit logs can be streamed to Azure Blob Storage.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.