---
title: "Features"
description: "Which Tailscale features slopscale supports, what it adds on top such as the admin console and access rules, and what it does not do."
---

Slopscale is a self-hosted, open source implementation of the Tailscale control server, run as a single binary with
its CLI and an [admin console](/slopscale/ref/console). This page lists what it supports of Tailscale's feature set, what it adds
of its own, and what it does not do. Each item links to the page that explains it.

## Tailscale features

- [x] [Node registration](/slopscale/ref/registration): [web authentication](/slopscale/ref/registration#web-authentication),
      [pre-authenticated keys](/slopscale/ref/registration#pre-authenticated-key) and
      [OpenID Connect](/slopscale/ref/oidc), with [device and user approval](/slopscale/ref/approval)
- [x] [OpenID Connect](/slopscale/ref/oidc): profile sync, allowed domains, emails and groups, group sync into
      [slopscale groups](/slopscale/ref/access-control#groups), and [switching providers](/slopscale/ref/oidc#switching-oidc-providers) by
      matching on email
- [x] [User roles](/slopscale/ref/roles): owner, admin, network admin, IT admin, auditor and member, bounding the admin API and
      the console
- [x] [DNS](/slopscale/ref/dns): MagicDNS, global and split nameservers, search domains,
      [extra records](/slopscale/ref/dns#setting-extra-dns-records), [split DNS per group](/slopscale/ref/dns#split-dns-per-group),
      nameservers kept while an exit node is in use, all changeable at runtime
- [x] File sharing: [Taildrive](https://tailscale.com/docs/features/taildrive) and
      [Taildrop](https://tailscale.com/docs/features/taildrop)
- [x] [Tags](/slopscale/ref/tags)
- [x] [Routes](/slopscale/ref/routes): [subnet routers](/slopscale/ref/routes#subnet-router), [exit nodes](/slopscale/ref/routes#exit-node),
      [suggested](/slopscale/ref/routes#suggested-exit-nodes) and [global](/slopscale/ref/routes#global-exit-node) exit nodes with
      [ordered failover](/slopscale/ref/routes#exit-node-failover-in-a-fixed-order),
      [high availability](/slopscale/ref/routes#high-availability) with [regional routing](/slopscale/ref/routes#regional-routing), and
      route filtering with [via](https://tailscale.com/docs/features/access-control/grants/grants-via)
- [x] [Apps and app connectors](/slopscale/ref/apps)
- [x] [Tailscale Services](/slopscale/ref/services)
- [x] Dual stack (IPv4 and IPv6) and [IP pools](/slopscale/ref/policy#ip-pools)
- [x] [Ephemeral nodes](/slopscale/ref/registration#ephemeral-nodes), by key or by the client's own request
- [x] Embedded [DERP relay](/slopscale/ref/derp), on by default, and relays managed at runtime
- [x] [Peer relays](/slopscale/ref/networks#peer-relays)
- [x] [Policy](/slopscale/ref/policy): ACLs, grants, [autogroups](/slopscale/ref/policy#autogroups) including the role autogroups,
      `autogroup:shared` and `autogroup:self`, [auto approvers](/slopscale/ref/routes#automatically-approve-routes-of-a-subnet-router),
      [node attributes](/slopscale/ref/policy#node-attributes) including `app` and `ipPool`, Tailscale SSH, `tests` and `sshTests`
- [x] [Device trust](/slopscale/ref/device-trust): [device posture](/slopscale/ref/device-trust#device-posture) and postures in the policy
      and in access rules, [hardware attestation](/slopscale/ref/device-trust#hardware-attestation),
      [posture integrations](/slopscale/ref/device-trust#posture-integrations) with CrowdStrike Falcon, SentinelOne, Intune,
      Jamf Pro, Kandji and Kolide, and [suspending a machine](/slopscale/ref/device-trust#suspending-a-machine)
- [x] [Node sharing](/slopscale/ref/sharing)
- [x] [Tailnet lock](/slopscale/ref/tailnet-lock)
- [x] [Identity tokens](/slopscale/ref/identity-tokens) (`tailscale id-token`)
- [x] [Serve](https://tailscale.com/docs/features/tailscale-serve) with [HTTPS certificates](/slopscale/ref/https-certificates)
      from Let's Encrypt
- [x] [Funnel](/slopscale/ref/funnel), through an ingress node you run
- [x] [SSH session recording](/slopscale/ref/ssh-recording), with an embedded recorder
- [x] [Key expiry](/slopscale/ref/approval#key-expiry) as a tailnet setting
- [x] [Webhooks](/slopscale/ref/webhooks) in Tailscale's delivery format, and [log streaming](/slopscale/ref/log-streaming) to Splunk,
      Elastic, Datadog, Axiom, Loki or any HTTP sink
- [x] [Audit log](/slopscale/ref/audit)
- [x] [Traffic monitor](/slopscale/ref/traffic): what each machine sends through exit nodes, subnet routers and app connectors,
      where it goes and, with DNS logging, which names it looks up while it uses a gateway as its exit node
- [x] [Device management over the control connection](/slopscale/ref/device-management): client updates, health, diagnostics
      and managed preferences
- [x] Client update notices, so an old client shows Tailscale's own update warning
- [x] [Tailscale-compatible API](/slopscale/ref/api#tailscale-compatible-api) with OAuth clients and scopes, so the Terraform
      provider and the Kubernetes operator work unchanged, and workload identity federation for CI jobs

## Slopscale features

- [x] [Admin console](/slopscale/ref/console) built into the binary, signing in through the identity provider
- [x] [Groups and access rules](/slopscale/ref/access-control), for access without a policy file, with an
      [access graph](/slopscale/ref/access-control#access-graph)
- [x] [Networks](/slopscale/ref/networks): subnets and exit nodes handed to groups
- [x] [Temporary access](/slopscale/ref/temporary-access): expiring rules and memberships, and access requests
- [x] [User invitations](/slopscale/ref/console#inviting-users) by email and [console sessions](/slopscale/ref/console#sessions) an
      administrator can end
- [x] [SSH from the console](/slopscale/ref/console#ssh-from-the-console) with Tailscale's in-browser client
- [x] Notifications to Slack, Mattermost, Google Chat, Discord, Microsoft Teams, Telegram, ntfy and
      [email](/slopscale/ref/webhooks#notifications)
- [x] [DNS](/slopscale/ref/dns#changing-dns-settings-at-runtime) and [DERP](/slopscale/ref/derp#configuration) settings stored in the
      database and changed without a restart
- [x] [Database backup and restore](/slopscale/setup/backup) while the server runs
- [x] Relay [latency](/slopscale/ref/derp#latency) reported by every client
- [x] A control dial plan, so clients keep the server's addresses through a DNS outage
- [x] A [REST API](/slopscale/ref/api#rest-api) with an OpenAPI 3.1 document and interactive docs at `/api/v1/docs`

## Not available

- [ ] Tailscale's client-side [network flow logs](https://tailscale.com/docs/features/logging/network-flow-logs): the
      client sends them to a host it does not let a control server change. The [traffic monitor](/slopscale/ref/traffic) counts
      the traffic through your gateways instead, and serves it in the same shape on the v2 API.
- [ ] Tailscale's hosted Funnel ingress: [Funnel](/slopscale/ref/funnel) needs an ingress node of your own
- [ ] [IP sets](https://tailscale.com/docs/features/tailnet-policy-file/ip-sets) in the policy file
- [ ] Contacts and the AWS external ID of the Tailscale API: the Terraform resources for them are refused with an
      explanation
