Tailscale co-founder and Chief Strategy Officer David Carney told the Changelog exactly where the company is heading: TSIDP for clickless OIDC authentication inside a tailnet, TSNet for embedding Tailscale directly into Go applications, multiple tailnet support for hard network isolation between environments, and Aperture, a private AI gateway that handles API key management, request observability, and agent-level access control for providers like Anthropic and Amazon Bedrock.
The Aperture piece is the sharpest signal here. Tailscale is positioning itself as infrastructure for AI agent security, not just networking. Aperture sits between your agents and external LLM APIs, giving operators audit trails and policy enforcement where there are currently none. Contact is aperture@tailscale.com. The conversation also gets specific on how multiple tailnets solve the isolation problem that a single shared tailnet cannot, and how TSIDP eliminates the external identity provider dependency for internal service auth, replacing Okta or Entra ID in scoped scenarios.
Read or listen to the full episode for the technical depth on TSNet architecture, how the tailnet policy file syntax ties access control together across these features, and Carney's framing of why MCP and agent proliferation make Aperture urgent now rather than eventual.
[READ ORIGINAL →]