Skip to content

Tailscale

When you connect a Tailscale tailnet to Oblique, Oblique will automatically sync the tailnet and its users.

As you add people to your tailnet, change their role, suspend them, or remove them, these changes are automatically synced to Oblique.

You can add multiple tailnets to Oblique. These function as separate integrations and are distinguished by their tailnet name.

Oblique syncs the following from your tailnet.

Tailscale objectOblique objectCapability
UsersAccountsRead-only
TailnetResourcesRead-only
RolesRolesRead-only
Tailnet membershipEntitlementsRead-only

Oblique syncs each Tailscale user as an Oblique account. Oblique doesn’t sync:

  • Suspended users
  • Users who are waiting for an admin to approve them
  • Users who have a device on your tailnet shared with them, but who aren’t members of your tailnet

Tailscale accounts are matched to Oblique users by email.

Oblique’s Tailscale integration is read-only. Oblique can’t make changes to your tailnet, its users, or their roles.

Oblique syncs the following from Tailscale as resources:

  • The tailnet you connected

Every account has an entitlement for the tailnet.

The resource is named after your tailnet, for example Acme tailnet. If the OAuth client doesn’t have Read access to Tailnets, the resource is named Tailnet.

Oblique syncs Tailscale roles as Oblique roles. Certain roles may only be available on certain Tailscale pricing plans.

Every entitlement from Tailscale is for exactly one role.

The Tailscale integration connects using an OAuth client you create in Tailscale, and requests the following scopes for your tailnet:

Tailscale scopeWhat Oblique uses it for
users:readRead the tailnet’s users and their roles
tailnets:readRead the tailnet’s name (optional)

Oblique doesn’t read or change your devices, policy file, DNS, or keys.

You must be an admin to add an integration.

You connect a tailnet to Oblique by creating an OAuth client in Tailscale, then adding its credentials to Oblique. You need an admin role in Tailscale, such as Owner or Admin, to create an OAuth client.

To add a Tailscale integration, navigate to the Integrations page:

  1. Select Add integration.
  2. Select Tailscale.
  3. Select Open Tailscale admin console, which opens Settings > Trust credentials in Tailscale.
  4. In Tailscale, create a new OAuth credential, for example with the description Oblique.
  5. Grant it Read access to Users. Optionally, grant it Read access to Tailnets so Oblique can show your tailnet’s name.
  6. Generate the credential, then copy the client ID and the client secret, which starts with tskey-client-. Tailscale only shows the client secret once. Back in Oblique, under Connect, paste them into Client ID and Client secret.
  7. Select Add integration.

Oblique will immediately start syncing the tailnet’s users.

Change Tailscale integration’s authorizations

Section titled “Change Tailscale integration’s authorizations”
You must be an admin to replace an integration's credentials.

If the OAuth client is revoked or needs rotating, you can replace it without removing the integration. From the integration’s detail page:

  1. Navigate to the Settings tab.
  2. Under Connection, select Replace OAuth client credentials….
  3. Paste the new Client ID and Client secret, then select Replace OAuth client credentials.

You can only replace the credentials with an OAuth client for the same tailnet. To change the tailnet, instead delete the integration and add another one.

Oblique’s Tailscale integration is read-only, so it can’t be used to manage your tailnet, its users, or their roles. Make these changes in Tailscale directly, and Oblique will sync them automatically.

You must be an admin to remove an integration.

To remove a Tailscale integration, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. At the bottom of the page, under Delete integration, select Delete integration….
  3. In the confirmation dialog, type the text to confirm, then select Delete integration.

This will immediately stop all syncing and remove all resources from the integration.