Features
Which Tailscale features slopscale supports, what it adds on top such as the admin console and access rules, and what it does not do.
Slopscale is a self-hosted, open source implementation of the Tailscale control server, run as a single binary with its CLI and an admin console. This page lists what it supports of Tailscale’s feature set, what it adds of its own, and what it does not do. Each item links to the page that explains it.
Tailscale features
- Node registration: web authentication, pre-authenticated keys and OpenID Connect, with device and user approval
- OpenID Connect: profile sync, allowed domains, emails and groups, group sync into slopscale groups, and switching providers by matching on email
- User roles: owner, admin, network admin, IT admin, auditor and member, bounding the admin API and the console
- DNS: MagicDNS, global and split nameservers, search domains, extra records, split DNS per group, nameservers kept while an exit node is in use, all changeable at runtime
- File sharing: Taildrive and Taildrop
- Tags
- Routes: subnet routers, exit nodes, suggested and global exit nodes with ordered failover, high availability with regional routing, and route filtering with via
- Apps and app connectors
- Tailscale Services
- Dual stack (IPv4 and IPv6) and IP pools
- Ephemeral nodes, by key or by the client’s own request
- Embedded DERP relay, on by default, and relays managed at runtime
- Peer relays
- Policy: ACLs, grants, autogroups including the role autogroups,
autogroup:sharedandautogroup:self, auto approvers, node attributes includingappandipPool, Tailscale SSH,testsandsshTests - Device trust: device posture and postures in the policy and in access rules, hardware attestation, posture integrations with CrowdStrike Falcon, SentinelOne, Intune, Jamf Pro, Kandji and Kolide, and suspending a machine
- Node sharing
- Tailnet lock
- Identity tokens (
tailscale id-token) - Serve with HTTPS certificates from Let’s Encrypt
- Funnel, through an ingress node you run
- SSH session recording, with an embedded recorder
- Key expiry as a tailnet setting
- Webhooks in Tailscale’s delivery format, and log streaming to Splunk, Elastic, Datadog, Axiom, Loki or any HTTP sink
- Audit log
- Traffic monitor: what each machine sends through exit nodes, subnet routers and app connectors, where it goes and, with DNS logging, which names it looks up while it uses a gateway as its exit node
- Device management over the control connection: client updates, health, diagnostics and managed preferences
- Client update notices, so an old client shows Tailscale’s own update warning
- Tailscale-compatible API with OAuth clients and scopes, so the Terraform provider and the Kubernetes operator work unchanged, and workload identity federation for CI jobs
Slopscale features
- Admin console built into the binary, signing in through the identity provider
- Groups and access rules, for access without a policy file, with an access graph
- Networks: subnets and exit nodes handed to groups
- Temporary access: expiring rules and memberships, and access requests
- User invitations by email and console sessions an administrator can end
- SSH from the console with Tailscale’s in-browser client
- Notifications to Slack, Mattermost, Google Chat, Discord, Microsoft Teams, Telegram, ntfy and email
- DNS and DERP settings stored in the database and changed without a restart
- Database backup and restore while the server runs
- Relay latency reported by every client
- A control dial plan, so clients keep the server’s addresses through a DNS outage
- A REST API with an OpenAPI 3.1 document and interactive docs at
/api/v1/docs
Not available
- Tailscale’s client-side network flow logs: the client sends them to a host it does not let a control server change. The traffic monitor counts the traffic through your gateways instead, and serves it in the same shape on the v2 API.
- Tailscale’s hosted Funnel ingress: Funnel needs an ingress node of your own
- IP sets in the policy file
- Contacts and the AWS external ID of the Tailscale API: the Terraform resources for them are refused with an explanation