Tailscale
Scope
Tailscale is the private mesh networking layer used across TazLab for secure operator access and cluster connectivity.
Current Synthesis
Tailscale provides the zero-trust network backbone for TazLab. In this workspace it appears both as infrastructure-as-code in ephemeral-castle and as a Kubernetes operator model for exposing cluster services and routers.
Why It Matters
It is the private connectivity layer that replaces the need for broad public exposure or brittle ad-hoc VPN flows.
Key Characteristics
- WireGuard-based mesh networking
- OAuth clients preferred over expiring pre-auth keys
- tag-based access control model
- system extension support on Talos
- Kubernetes operator support for proxies, connectors, and DNSConfig
Relationships
- used by ephemeral-castle
- central to TazLab Infrastructure Tech Stack
- summarized in Tailscale Networking Research
Source Basis
raw/inbox/Talos e Tailscale_ Guida Operativa.mdraw/inbox/Tailscale Operator su Talos con Flux.mdraw/inbox/MetalLB su Talos OS_Proxmox.md