Skip to content

Configuration — Tailscale

Everything you can add with this adapter: where it goes in the tree, what you fill in, and what you can tell it to do.

Tailscale node

Joins this PQ install to the customer's tailnet and exposes the local front door.

Add it under nothing — this is the top of the tree
Identified by nothing — there is only one
Role —

What you fill in

Setting Required Default Accepted values What it does
auth_key optional — text Tailscale auth key (reusable, tagged). Needed only for first registration. (stored as a secret)
hostname optional — text Node name in the tailnet.
serve_front_door optional true yes / no Expose the local nginx front door on the tailnet (TCP 443 passthrough).
front_door_target optional nginx:443 text host:port the tailnet traffic is forwarded to.
advertise_routes optional — string[] CIDRs to advertise as a subnet router (needs approval in the tailnet admin console).
enable_ssh optional false yes / no Enable Tailscale SSH.