Harden Tailscale ACL policy with least-privilege grants #23
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "pulumi-tailscale-security-hardening"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
autogroup:adminandautogroup:memberautogroup:adminwithdst: ["*"]Important lesson learned: Don't tag user-owned devices (like gilbert) via Pulumi - tagging converts them to "tagged devices" which lose user
identity and break user-based SSH rules.
Deployment and Testing
mise run tailnet-upmise run indri-services-check🤖 Generated with Claude Code