Receipts
The sources ledger.
Every factual product claim on this site resolves to an entry here. The hierarchy: official documentation first, then the knowledge base, the changelog, the official blog, and the open source code itself. Third party writeups are leads for investigation, never citations. When official pages conflict, the narrowest current claim wins and the resolution is noted on this page.
| Source | Checked | Cited by |
|---|---|---|
| 4via6 subnet routers | 2026-08-10 | 07 Routing, drill: overlapping-subnet-routers |
| Access the Kubernetes control plane using an API server proxy | 2026-08-10 | 09 The platform matrix |
| ACL syntax reference | 2026-08-10 | 04 Identity and auth, 05 Policy: ACLs and grants, drill: grants-migration-surprise, drill: acl-one-way-ping, drill: tag-ssh-lockout |
| Aperture by Tailscale is now self-serve | 2026-08-10 | 10 Enterprise operations |
| App connectors | 2026-08-10 | 07 Routing |
| Auth keys | 2026-08-10 | 02 The control plane, 04 Identity and auth, 09 The platform matrix, drill: key-expiry-outage, drill: ephemeral-node-vanished, drill: docker-node-multiplies |
| Autogroups | 2026-08-10 | 05 Policy: ACLs and grants |
| Can I use Tailscale alongside other VPNs? | 2026-08-10 | drill: magicdns-vpn-conflict |
| Can't connect to other tailnet devices | 2026-08-10 | drill: acl-one-way-ping, craft: repro-construction |
| Can't resolve domain names | 2026-08-10 | drill: magicdns-vpn-conflict |
| cmd/tailscale/cli directory listing | 2026-08-10 | lab: reading-go-for-investigation |
| Configuration audit logs | 2026-08-10 | 10 Enterprise operations |
| Configuring Linux DNS | 2026-08-10 | 06 MagicDNS and split DNS |
| Connection types | 2026-08-10 | 03 NAT traversal, STUN, DERP, and Peer Relays |
| Connection types | 2026-08-10 | drill: exit-node-slow, drill: relay-stuck, drill: works-then-drops, craft: handoff-package |
| Control and data planes | 2026-08-10 | 02 The control plane |
| Customize the Kubernetes operator and resources it manages | 2026-08-10 | 09 The platform matrix |
| Debug menu and options | 2026-08-10 | drill: macos-flap |
| Default DERP map | 2026-08-10 | drill: works-then-drops |
| DERP servers | 2026-08-10 | 03 NAT traversal, STUN, DERP, and Peer Relays, drill: exit-node-slow, drill: relay-stuck, drill: udp-blocked, drill: works-then-drops, lab: magicsock-guided-read, craft: handoff-package, lab: pcap-field-kit |
| Device approval | 2026-08-10 | 04 Identity and auth, 10 Enterprise operations |
| Device posture | 2026-08-10 | 05 Policy: ACLs and grants |
| DNS in Tailscale (DNS settings) | 2026-08-10 | 06 MagicDNS and split DNS, drill: magicdns-vpn-conflict, drill: split-dns-leak |
| DNS in Tailscale (reference) | 2026-08-10 | 06 MagicDNS and split DNS |
| Docker | 2026-08-10 | drill: docker-node-multiplies |
| Docker | 2026-08-10 | craft: repro-construction |
| Docker configuration parameters | 2026-08-10 | 09 The platform matrix, drill: docker-node-multiplies, craft: repro-construction |
| Enabling HTTPS | 2026-08-10 | 08 Exposing services |
| Ephemeral nodes | 2026-08-10 | drill: ephemeral-node-vanished, drill: docker-node-multiplies, craft: repro-construction |
| Exit nodes | 2026-08-10 | 07 Routing, drill: exit-node-slow |
| Generate a bug report | 2026-08-10 | craft: evidence-collection, craft: handoff-package |
| GitOps for the tailnet policy file | 2026-08-10 | 10 Enterprise operations |
| GitOps with GitHub Actions | 2026-08-10 | 10 Enterprise operations |
| google/pprof tool documentation | 2026-08-10 | lab: pprof-field-kit |
| Grants | 2026-08-10 | 05 Policy: ACLs and grants, drill: grants-migration-surprise |
| Grants generally available as an easier option to ACL syntax | 2026-08-10 | 05 Policy: ACLs and grants |
| High availability | 2026-08-10 | 07 Routing, drill: overlapping-subnet-routers |
| How NAT traversal works | 2026-08-10 | 03 NAT traversal, STUN, DERP, and Peer Relays, 12 The codebase, drill: relay-stuck, drill: works-then-drops, lab: magicsock-guided-read, lab: pcap-field-kit, craft: repro-construction |
| How Tailscale works | 2026-08-10 | 00 The shape of Tailscale, 01 WireGuard foundations, 02 The control plane, 05 Policy: ACLs and grants, 12 The codebase, lab: magicsock-guided-read |
| Identity providers | 2026-08-10 | 04 Identity and auth |
| Improving Tailscale performance, enhancing userspace with kernel interfaces (Tailscale blog) | 2026-08-10 | 01 WireGuard foundations |
| Install Tailscale on iOS | 2026-08-10 | 09 The platform matrix |
| Install Tailscale on Linux | 2026-08-10 | 09 The platform matrix |
| Install Tailscale on Synology | 2026-08-10 | 09 The platform matrix |
| Install Tailscale on Windows | 2026-08-10 | 09 The platform matrix |
| Install the Tailscale Kubernetes Operator | 2026-08-10 | 09 The platform matrix |
| Introducing Tailscale Peer Relays (Tailscale blog, 2025-10-29) | 2026-08-10 | lab: magicsock-guided-read |
| IP addresses in the 100.x.y.z range | 2026-08-10 | 00 The shape of Tailscale, 01 WireGuard foundations, lab: pcap-field-kit |
| ipnlocal package source and doc comments (LocalBackend) | 2026-08-10 | lab: reading-go-for-investigation |
| Key expiry | 2026-08-10 | 00 The shape of Tailscale, 02 The control plane, 04 Identity and auth, 11 Troubleshooting and observability, drill: key-expiry-outage |
| Log streaming | 2026-08-10 | 10 Enterprise operations |
| Logging overview | 2026-08-10 | 11 Troubleshooting and observability |
| MagicDNS | 2026-08-10 | 00 The shape of Tailscale, 06 MagicDNS and split DNS, drill: magicdns-vpn-conflict, drill: split-dns-leak |
| Manage permissions using ACLs (tailnet policy file) | 2026-08-10 | 02 The control plane, 05 Policy: ACLs and grants, drill: acl-one-way-ping |
| net/http/pprof package documentation | 2026-08-10 | lab: pprof-field-kit |
| Network flow logs | 2026-08-10 | 10 Enterprise operations |
| OAuth clients | 2026-08-10 | 04 Identity and auth |
| Open source at Tailscale | 2026-08-10 | 00 The shape of Tailscale, 02 The control plane, 12 The codebase, lab: reading-go-for-investigation |
| Package controlclient documentation | 2026-08-10 | 12 The codebase |
| Package derp documentation | 2026-08-10 | 12 The codebase |
| Package ipnlocal documentation | 2026-08-10 | 12 The codebase |
| Package magicsock documentation | 2026-08-10 | 12 The codebase |
| Package netcheck documentation | 2026-08-10 | 12 The codebase |
| Package tailcfg documentation | 2026-08-10 | 12 The codebase |
| Package tsnet documentation | 2026-08-10 | 12 The codebase |
| Peer relays | 2026-08-10 | 00 The shape of Tailscale, 02 The control plane, 11 Troubleshooting and observability |
| Poor performance between tailnet devices | 2026-08-10 | craft: repro-construction |
| Quick guide to Tailscale on Docker | 2026-08-10 | 09 The platform matrix |
| Run Tailscale unattended on Windows | 2026-08-10 | 09 The platform matrix |
| runtime/pprof package documentation | 2026-08-10 | lab: pprof-field-kit |
| Site-to-site networking | 2026-08-10 | 07 Routing |
| Subnet routers | 2026-08-10 | 07 Routing, drill: overlapping-subnet-routers, drill: route-not-approved |
| Tags | 2026-08-10 | 02 The control plane, 04 Identity and auth, 05 Policy: ACLs and grants, drill: key-expiry-outage, drill: tag-ssh-lockout |
| Tailnet Lock | 2026-08-10 | 10 Enterprise operations |
| Tailnet name | 2026-08-10 | 06 MagicDNS and split DNS |
| Tailnet policy file syntax | 2026-08-10 | 07 Routing |
| Tailscale API | 2026-08-10 | 10 Enterprise operations |
| Tailscale changelog | 2026-08-10 | drill: exit-node-slow, drill: relay-stuck, craft: evidence-collection |
| Tailscale CLI | 2026-08-10 | 03 NAT traversal, STUN, DERP, and Peer Relays, 06 MagicDNS and split DNS, 09 The platform matrix, 11 Troubleshooting and observability, drill: key-expiry-outage, drill: relay-stuck, drill: split-dns-leak, drill: tag-ssh-lockout, drill: udp-blocked, craft: live-incident-craft, craft: evidence-collection, craft: handoff-package, lab: pcap-field-kit, lab: pprof-field-kit, craft: repro-construction |
| tailscale CLI debug command source (cmd/tailscale/cli/debug.go) | 2026-08-10 | lab: pprof-field-kit |
| Tailscale client metrics | 2026-08-10 | 11 Troubleshooting and observability, drill: route-not-approved, craft: evidence-collection, lab: pprof-field-kit |
| Tailscale Funnel | 2026-08-10 | 08 Exposing services |
| tailscale funnel command reference | 2026-08-10 | 08 Exposing services |
| Tailscale Geneve header implementation (net/packet/geneve.go) | 2026-08-10 | lab: pcap-field-kit |
| Tailscale GitHub Action | 2026-08-10 | drill: ephemeral-node-vanished |
| Tailscale LocalAPI Go client source (client/local/local.go) | 2026-08-10 | lab: pprof-field-kit |
| Tailscale logging | 2026-08-10 | craft: evidence-collection |
| Tailscale netfilter modes | 2026-08-10 | 07 Routing |
| Tailscale Peer Relays (Tailscale docs) | 2026-08-10 | 01 WireGuard foundations, 03 NAT traversal, STUN, DERP, and Peer Relays, drill: exit-node-slow, drill: relay-stuck |
| Tailscale Peer Relays: Use your own devices as high-throughput relays | 2026-08-10 | 03 NAT traversal, STUN, DERP, and Peer Relays |
| Tailscale ping message types | 2026-08-10 | drill: acl-one-way-ping |
| Tailscale Serve | 2026-08-10 | 08 Exposing services |
| tailscale serve command reference | 2026-08-10 | 08 Exposing services |
| Tailscale Services | 2026-08-10 | 08 Exposing services, drill: grants-migration-surprise |
| Tailscale Services GA announcement | 2026-08-10 | 08 Exposing services |
| Tailscale SSH | 2026-08-10 | 05 Policy: ACLs and grants, drill: tag-ssh-lockout |
| tailscale status output source (cmd/tailscale/cli/status.go) | 2026-08-10 | lab: pcap-field-kit |
| tailscale up command | 2026-08-10 | 09 The platform matrix |
| tailscale.com/disco package source | 2026-08-10 | lab: magicsock-guided-read |
| tailscale/tailscale cmd/containerboot (tailscaled arguments) | 2026-08-10 | drill: docker-node-multiplies |
| tailscale/tailscale control/controlclient/direct.go | 2026-08-10 | drill: ephemeral-node-vanished, lab: reading-go-for-investigation |
| tailscale/tailscale GitHub repository | 2026-08-10 | 00 The shape of Tailscale, 02 The control plane, 12 The codebase, lab: reading-go-for-investigation |
| tailscale/tailscale health/warnings.go | 2026-08-10 | drill: key-expiry-outage, drill: ephemeral-node-vanished |
| tailscale/tailscale LICENSE (BSD-3-Clause) | 2026-08-10 | lab: reading-go-for-investigation |
| tailscale/tailscale net/netcheck/netcheck.go | 2026-08-10 | drill: udp-blocked, lab: reading-go-for-investigation |
| tailscale/tailscale README | 2026-08-10 | lab: reading-go-for-investigation |
| tailscale/tailscale tailcfg/tailcfg.go | 2026-08-10 | drill: works-then-drops |
| tailscale/tailscale version/prop.go (macOS bundle identifiers) | 2026-08-10 | drill: macos-flap |
| tailscale/tailscale wgengine/magicsock package | 2026-08-10 | lab: magicsock-guided-read |
| tailscale/tailscale wgengine/magicsock/magicsock.go | 2026-08-10 | drill: works-then-drops, lab: magicsock-guided-read, lab: reading-go-for-investigation |
| tailscale/tailscale, wgengine/filter/filter.go | 2026-08-10 | drill: acl-one-way-ping |
| tailscale/tailscale, wgengine/router/osrouter/router_linux.go | 2026-08-10 | drill: route-not-approved |
| tailscaled | 2026-08-10 | 09 The platform matrix |
| tailscaled debug server source (cmd/tailscaled/debug.go) | 2026-08-10 | lab: pprof-field-kit |
| tailscaled flags and default TUN names (cmd/tailscaled/tailscaled.go) | 2026-08-10 | lab: pcap-field-kit, lab: pprof-field-kit |
| tailscaled LocalAPI handler source (ipn/localapi/localapi.go) | 2026-08-10 | lab: pprof-field-kit |
| tailscaled LocalAPI pprof handler source (ipn/localapi/pprof.go) | 2026-08-10 | lab: pprof-field-kit |
| Targets and selectors | 2026-08-10 | drill: tag-ssh-lockout |
| Three ways to run Tailscale on macOS | 2026-08-10 | 00 The shape of Tailscale, 09 The platform matrix, drill: macos-flap, craft: evidence-collection |
| Troubleshoot TCP connection issues between two devices (Tailscale docs) | 2026-08-10 | 01 WireGuard foundations |
| Troubleshooting guide | 2026-08-10 | drill: macos-flap, craft: live-incident-craft, craft: evidence-collection |
| tsnet | 2026-08-10 | 08 Exposing services |
| tsnet package, tailscale/tailscale repository | 2026-08-10 | 08 Exposing services |
| User and group provisioning | 2026-08-10 | 10 Enterprise operations |
| User approval | 2026-08-10 | 04 Identity and auth |
| User roles | 2026-08-10 | 10 Enterprise operations |
| Userspace networking mode (Tailscale docs) | 2026-08-10 | 01 WireGuard foundations |
| Using Tailscale with other VPNs | 2026-08-10 | 09 The platform matrix |
| wgengine/magicsock/derp.go | 2026-08-10 | lab: magicsock-guided-read |
| wgengine/magicsock/endpoint.go | 2026-08-10 | lab: magicsock-guided-read |
| wgengine/magicsock/peermap.go | 2026-08-10 | lab: magicsock-guided-read |
| wgengine/magicsock/relaymanager.go | 2026-08-10 | lab: magicsock-guided-read |
| What firewall ports should I open to use Tailscale? | 2026-08-10 | 00 The shape of Tailscale, 11 Troubleshooting and observability, drill: exit-node-slow, drill: udp-blocked, drill: works-then-drops, lab: pcap-field-kit, craft: repro-construction |
| What happens if the coordination server is down? | 2026-08-10 | 02 The control plane |
| What is 100.100.100.100? | 2026-08-10 | 06 MagicDNS and split DNS, 11 Troubleshooting and observability, drill: magicdns-vpn-conflict, drill: split-dns-leak |
| What is a tailnet | 2026-08-10 | 00 The shape of Tailscale |
| What is Aperture? | 2026-08-10 | 10 Enterprise operations |
| WireGuard project homepage | 2026-08-10 | 01 WireGuard foundations |
| WireGuard protocol and cryptography | 2026-08-10 | 01 WireGuard foundations, drill: works-then-drops, lab: pcap-field-kit |
| WireGuard whitepaper (Next Generation Kernel Network Tunnel) | 2026-08-10 | 01 WireGuard foundations, drill: works-then-drops |
| wireguard-go message sizes, Tailscale fork (device/noise-protocol.go) | 2026-08-10 | lab: pcap-field-kit |
| wireguard-go protocol constants, Tailscale fork (device/constants.go) | 2026-08-10 | lab: pcap-field-kit |
| Wireshark display filter reference, WireGuard (wg) | 2026-08-10 | lab: pcap-field-kit |
| Workload identity federation | 2026-08-10 | 04 Identity and auth |
| Workload identity federation GA blog post | 2026-08-10 | 04 Identity and auth |
145 sources on ledger.