One private network for my clusters, my colleagues and my living room
Why I love Tailscale, and how I use it to reach Kubernetes APIs, Postgres, colleagues' machines and my Home Assistant setup without opening a single port.
There’s a category of tool I love most: the kind you set up once and then stop thinking about. For me, Tailscale is the best example.
If you haven’t used it: Tailscale builds a private WireGuard mesh network between your devices, called a tailnet. Every machine gets a stable address and a name. Connections go directly between devices wherever possible, and access is tied to your identity provider instead of shared keys or IP allowlists.
That sounds like “a VPN”. In practice it replaced a whole drawer of things: bastion hosts, jump boxes, kubectl port-forward sessions, IP allowlists that never get cleaned up, and the occasional “can you just open port 5432 for a minute”.
Here’s what I use it for.
The Kubernetes API
A public Kubernetes API endpoint is one of those things that’s probably fine and still makes me uneasy. With the Tailscale Kubernetes operator, the API server doesn’t need to be reachable from the internet at all. The operator runs a proxy inside the cluster, and I get a kubeconfig with:
tailscale configure kubeconfig my-cluster
The proxy can also pass my tailnet identity through to Kubernetes, so RBAC is based on who I actually am, not on whoever holds a long-lived token.
Postgres
Databases should never be on the internet. The trouble is that engineers still need to reach them sometimes: to debug a slow query, run a migration or check a support case.
There are two easy options. Expose a cluster Service to the tailnet through the operator, or run a subnet router inside the VPC so the private network behind it becomes reachable. Then it’s just:
psql -h postgres-staging -U peter
Access rules live in the tailnet policy file, which lives in git. That means access changes get reviewed in a pull request, and the history doubles as an audit trail.
My colleagues’ machines
Pairing on something running on someone else’s laptop used to mean screen sharing or ngrok. Now a colleague can share a machine with me, and I open their localhost service by name. Tailscale SSH lets us hop onto each other’s dev boxes with our normal company login, with no SSH keys to hand out and then forget to revoke.
Home, and Home Assistant
Then there’s the fun part. At home I run Home Assistant, plus the usual collection of small devices. None of it is exposed to the internet:
- Home Assistant runs the Tailscale add-on, so the app on my phone reaches it from anywhere as if I were on the sofa.
- A subnet router makes the rest of the home network reachable when I need it.
- On hotel or conference Wi-Fi, I route traffic through an exit node at home.
Same tool, same policy file, same identity. Turning off the lights from a train and debugging a staging database use exactly the same mechanism, which I find quietly satisfying.
The honest caveat
Tailscale’s data plane is peer-to-peer WireGuard, but the coordination server that hands out keys and policies is a SaaS service run by a US company. For my home network that’s fine. For a regulated production environment, it’s a dependency you should name in your risk assessment.
If that matters to you, Headscale is an open-source, self-hosted implementation of the coordination server that works with the standard clients. That fits the way I like to choose tools: use the managed service, as long as there’s a credible way out. I wrote more about that in Use the cloud, just don’t let your code know which one.