Integrate Your AssetsNetworking

Secure Tailscale with Mondoo

Continuously scan your Tailscale tailnet, devices, and users for misconfigurations and security issues.

Mondoo continuously scans your Tailscale tailnet for misconfigurations and security issues. Create a Tailscale integration to give Mondoo read-only access to the tailnet.

Mondoo adds the tailnet and its members to your space as assets:

  • The Tailscale Organization asset represents the tailnet itself, including its access control policy, auth keys, tailnet settings such as device and user approval, log streaming, and webhooks.
  • Each Tailscale Device asset covers a device's authorization, key expiry, client updates, and Tailnet Lock state.
  • Each Tailscale User asset represents a member of the tailnet.

Prerequisites

  • Editor or Owner access to the Mondoo space
  • A Tailscale tailnet
  • The Owner, Admin, Network admin, or IT admin role in the tailnet, to create an OAuth client

Create Tailscale credentials

Mondoo can authenticate with an OAuth client or an API access token. Tailscale recommends OAuth clients, because you can limit them to read-only scopes and they don't expire with a user's account.

  1. Log in to the Tailscale admin console and go to Settings > Trust credentials.

  2. Select Credential, then choose OAuth.

  3. Grant read access only. The simplest choice is the all:read scope, which covers every read endpoint, including any Tailscale adds later. To grant only what Mondoo uses today, give read access to:

    • Devices (devices:core:read)
    • Users (users:read)
    • Policy file (policy_file:read)
    • Auth keys (auth_keys:read)
    • Feature settings (feature_settings:read)
    • Log streaming (log_streaming:read)
    • Webhooks (webhooks:read)
  4. Select Generate credential.

  5. Copy the client ID and the client secret. Tailscale shows the secret only once.

To learn more, see OAuth clients and trust credential scopes in the Tailscale documentation.

Generate an API access token

  1. Log in to the Tailscale admin console and go to Settings > Keys.

  2. Generate an API access token and copy it.

An API access token acts with the permissions of the user who created it and expires after at most 90 days. When it expires, Mondoo can't scan until you add a new token.

Treat the OAuth client secret or API access token like a password. Don't commit it to source control.

Add a Tailscale integration

Only team members with Editor or Owner access can perform this task.

In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:

  1. Under Network Security, select Tailscale.

    Add a Tailscale integration in Mondoo

  2. In the Choose an integration name box, enter a name that identifies the tailnet.

  3. Under Authentication, choose how Mondoo authenticates:

    • On the OAuth (suggested) tab, enter the Client ID and Client Secret of the OAuth client.
    • On the Token Authentication tab, enter the API access token.
  4. (Optional) Under Enable security policies, review the policies that apply to Tailscale. The Mondoo Tailscale Security policy checks tailnet ACLs and device settings. If a policy isn't enabled in the space yet, select ENABLE. A policy you enable here applies to the whole space, not only this integration.

  5. Select CREATE INTEGRATION.

Mondoo scans the tailnet that the credentials belong to, and starts the first scan as soon as the integration is created. To learn how policies work, read Manage Policies.

View results

Mondoo adds the tailnet, device, and user assets to the space inventory. To review them, navigate to the space and select Inventory > Assets. To see how the assets score against the policy, select Findings > Policies and choose Mondoo Tailscale Security.

Manage your integration

To open the integration, navigate to the space, select Integrations > Tailscale, and choose the integration.

From the integration detail page, you can:

  • Scan now. Select RUN.
  • Pause or resume scanning. Select the more actions menu, then Pause or Resume.
  • Remove the integration. Select the trash can icon and confirm. Mondoo stops scanning the tailnet.

Mondoo doesn't support editing a Tailscale integration. To use different credentials, remove the integration and add a new one.

Scan Tailscale from the command line

The integration scans continuously from the Mondoo Platform. To scan a tailnet from your workstation or a CI pipeline instead, see Secure Tailscale with cnspec.

Next steps

On this page