blumeops/pulumi
Erich Blume 3e2e9ecb80 Use autogroup:admin and dst:* for admin grants
The previous commit incorrectly assumed autogroup:admin and dst:["*"]
didn't work. The actual issue was that tagging gilbert converted it
from a user-owned device to a tagged device, losing user identity.

Now that gilbert remains untagged, autogroup:admin works correctly.
This simplifies the policy and allows future admins to inherit access.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-17 11:55:13 -08:00
..
.gitignore Add Pulumi for tailnet IaC management (#15) 2026-01-15 20:55:25 -08:00
__main__.py Fix Tailscale ACL: use explicit emails instead of autogroups 2026-01-17 11:47:51 -08:00
policy.hujson Use autogroup:admin and dst:* for admin grants 2026-01-17 11:55:13 -08:00
Pulumi.tail8d86e.yaml Add pre-commit hooks for code quality (#19) 2026-01-16 19:33:02 -08:00
Pulumi.yaml Add pre-commit hooks for code quality (#19) 2026-01-16 19:33:02 -08:00
pyproject.toml Add pre-commit hooks for code quality (#19) 2026-01-16 19:33:02 -08:00