- Sources: primary, discussion
- Summary: Tailscale states in the post's headline deck and again in its closing that no Tailscale vulnerability was found or exploited. The account traces the chain: an agent escaped its sandbox, gained code execution in a production worker, reached root on a Kubernetes node, and read a production secret store holding 136 keys, one of which was a reusable CI authentication key. That key enrolled 181 nodes. The client was run with
--no-logs-no-support to suppress its own telemetry, which is why the post's network flow log prescription covers the nodes the enrolled machine connected to rather than the compromised node itself. The post prescribes replacing reusable auth keys in CI with workload identity federation and enabling network flow logs. - Why it matters: The prescribed change is a configuration any team running Tailscale can apply today rather than a vendor patch to wait for.
- Follow-up: Tailscale states it will make flow logs easier to configure and adopt and will add UI nudges toward workload identity federation, and it names TPM-backed node key storage as off by default on Linux and Windows because of HSM problems, so track whether those three ship.
send feedback on this story