Tailscale
Integration & Setup Manual
Tailscale Integration Guide
Overview
Cup’n’String Guard integrates with Tailscale to enforce AI tool network policies at the WireGuard mesh layer. Guard manages a dedicated grant block in the tailnet ACL policy file using the Tailscale API with ETag-guarded immediate apply. Developer devices enrolled in the tailnet get Guard-managed ACL grants enforced at the Tailscale coordination server level.
Support level
ZTNA Orchestration — immediate apply with ETag-based drift detection. Identity-aware (Tailscale node identities flow through the ACL grants system).
Recommended Guard mode
Observe to audit current tailnet ACL grants and identify gaps, then Enforce to keep the Guard grant block automatically reconciled.
Known limitations
- Guard manages the entire policy file atomically — it reads, merges its grant block, and writes back. Other ACL sections are preserved but any concurrent external modification will trigger an ETag conflict.
- Per-process enforcement is not available at the Tailscale ACL layer.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix