← Back to all sparks
T

Tailscale

INFRA · APIS
Velocity5.0

Tailscale launches PAM beta, staking out privileged access alongside its AI gateway

zero-trustkubernetesdevopsprivileged-accessai-infrastructurenetworking
◆Current state
Tailscale ships at a steady maintenance cadence while two new product lines take shape alongside the core VPN: Tailscale PAM (beta), a privileged access management product covering SSH, database, RDP, Kubernetes, and S3 with session recording and credential injection; and Aperture (GA), an AI/MCP gateway with cost controls and request hooks. The core network product continues incremental hardening—connectivity fixes, Kubernetes Operator improvements, and platform-specific stability patches.
◆Where it's heading
Tailscale is repositioning from a networking utility into a broader security platform. PAM puts them in the enterprise privileged access market; Aperture puts them in AI infrastructure. Both products use Tailscale's existing network connectivity layer as the distribution vehicle—if your services are already on a tailnet, adding PAM or Aperture becomes a much shorter sales motion than standalone competitors. The question is whether they can build enough depth in each to compete with Teleport and purpose-built AI gateways, or whether these remain thin surface extensions of the core product.
◆Prediction
PAM graduating from beta is the most likely near-term move; session recording, browser client, and credential injection suggest it's already fairly complete. Aperture will likely gain more model integrations and expanded MCP tooling as the AI agent ecosystem matures.

◆Recent moves

  1. 2d ago

    Tailscale container image v1.102.5

    A stability fix for large tailnets: the container no longer stops tailscaled on status update lag; it reconnects instead, exiting only if reconnection fails within one minute. Routine container maintenance with no user-visible capability change.

  2. 3d ago

    View device posture status

    The admin console now shows which posture assertions each machine passes or fails, alongside a count of policy rules that depend on each posture. A meaningful visibility addition for teams enforcing posture-based ACLs—previously you had to infer compliance state indirectly.

  3. 4d ago

    Tailscale GitHub Action v4.2.0

    Minor CI tooling improvements: binary re-download is skipped when a matching SHA exists, and log output is grouped by default with an opt-out via log-mode. Operational convenience for teams already using the GitHub Action; nothing directional.

  4. 9d ago

    Tailscale Kubernetes Operator v1.102.4

    A single reconciler bug fix for the Kubernetes Operator—incorrect event triggers no longer cause unnecessary reconciliation. Pure maintenance, no new capabilities.

  5. 16d ago

    Tailscale v1.102.4

    Multi-platform stability release fixing connectivity loss near reauthentication and exit node visibility failures on iOS, macOS, and tvOS when using custom coordination servers, plus a tvOS cold-boot VPN startup regression. These are practical reliability fixes that remove real rough edges for enterprise and mobile deployments.

  6. 1mo ago

    Tailscale PAM

    ⚡ SPARK

    Tailscale enters the privileged access management market with PAM (beta), adding SSH, database, RDP, Kubernetes, and S3 session types with recording, credential injection, and a browser client requiring no Tailscale install. This is the most significant capability expansion alongside Aperture and moves Tailscale from network connectivity into enterprise security infrastructure.