Tailscale
When you connect a Tailscale tailnet to Oblique, Oblique will automatically sync the tailnet and its users.
As you add people to your tailnet, change their role, suspend them, or remove them, these changes are automatically synced to Oblique.
You can add multiple tailnets to Oblique. These function as separate integrations and are distinguished by their tailnet name.
Supported options
Section titled “Supported options”Oblique syncs the following from your tailnet.
| Tailscale object | Oblique object | Capability |
|---|---|---|
| Users | Accounts | Read-only |
| Tailnet | Resources | Read-only |
| Roles | Roles | Read-only |
| Tailnet membership | Entitlements | Read-only |
Accounts
Section titled “Accounts”Oblique syncs each Tailscale user as an Oblique account. Oblique doesn’t sync:
- Suspended users
- Users who are waiting for an admin to approve them
- Users who have a device on your tailnet shared with them, but who aren’t members of your tailnet
Tailscale accounts are matched to Oblique users by email.
Resources
Section titled “Resources”Oblique syncs the following from Tailscale as resources:
- The tailnet you connected
Every account has an entitlement for the tailnet.
The resource is named after your tailnet, for example Acme tailnet. If the OAuth client doesn’t have Read access to Tailnets, the resource is named Tailnet.
Oblique syncs Tailscale roles as Oblique roles. Certain roles may only be available on certain Tailscale pricing plans.
Every entitlement from Tailscale is for exactly one role.
Required permissions
Section titled “Required permissions”The Tailscale integration connects using an OAuth client you create in Tailscale, and requests the following scopes for your tailnet:
| Tailscale scope | What Oblique uses it for |
|---|---|
users:read | Read the tailnet’s users and their roles |
tailnets:read | Read the tailnet’s name (optional) |
Oblique doesn’t read or change your devices, policy file, DNS, or keys.
Add Tailscale integration
Section titled “Add Tailscale integration”You connect a tailnet to Oblique by creating an OAuth client in Tailscale, then adding its credentials to Oblique. You need an admin role in Tailscale, such as Owner or Admin, to create an OAuth client.
To add a Tailscale integration, navigate to the Integrations page:
- Select Add integration.
- Select Tailscale.
- Select Open Tailscale admin console, which opens Settings > Trust credentials in Tailscale.
- In Tailscale, create a new OAuth credential, for example with the description
Oblique. - Grant it Read access to Users. Optionally, grant it Read access to Tailnets so Oblique can show your tailnet’s name.
- Generate the credential, then copy the client ID and the client secret, which starts with
tskey-client-. Tailscale only shows the client secret once. Back in Oblique, under Connect, paste them into Client ID and Client secret. - Select Add integration.
Oblique will immediately start syncing the tailnet’s users.
Change Tailscale integration’s authorizations
Section titled “Change Tailscale integration’s authorizations”If the OAuth client is revoked or needs rotating, you can replace it without removing the integration. From the integration’s detail page:
- Navigate to the Settings tab.
- Under Connection, select Replace OAuth client credentials….
- Paste the new Client ID and Client secret, then select Replace OAuth client credentials.
You can only replace the credentials with an OAuth client for the same tailnet. To change the tailnet, instead delete the integration and add another one.
Manage entitlements
Section titled “Manage entitlements”Oblique’s Tailscale integration is read-only, so it can’t be used to manage your tailnet, its users, or their roles. Make these changes in Tailscale directly, and Oblique will sync them automatically.
Remove Tailscale integration
Section titled “Remove Tailscale integration”To remove a Tailscale integration, from the integration’s detail page:
- Navigate to the Settings tab.
- At the bottom of the page, under Delete integration, select Delete integration….
- In the confirmation dialog, type the text to confirm, then select Delete integration.
This will immediately stop all syncing and remove all resources from the integration.