From Tailnet to platform (Interview)

11 Mar 2026 · 1 h 42 min · 34 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Summary: From Tailnet to Platform (Interview with David Carney)

Episode Overview This episode of "The Changelog" features an interview with David Carney, co-founder and Chief Strategy Officer of Tailscale. The conversation revolves around Tailscale's upcoming features and products, including TSIDP (Tailscale Identity Provider), TSNet, multiple tailnets, and Aperture, their private AI gateway. The discussion highlights key concepts in networking, authentication, and API management.

Key Topics Discussed

  1. Introduction to Tailscale
  2. Tailscale enables secure connections between devices globally, focusing on identity verification.
  3. Functions as a VPN alternative, offering a connectivity platform that supports building secure private networks.
  1. Upcoming Features
  2. TSIDP (Tailscale Identity Provider): Allows users to manage identity within their tailnet, enhancing security and access control.
  3. Functions like a locally hosted OIDC (OpenID Connect) endpoint.
  4. Facilitates integration with existing identity providers (e.g., Azure, Google) for seamless authentication.
  • Multiple Tailnets: Users can create isolated networks within their organization for different purposes (e.g., staging, production).
  • Enhances security and allows easier management of resources.
  • Aperture: A private AI gateway that assists with API key management, observability, and security.
  • Aims to solve the API key proliferation problem by consolidating API access within controlled environments.
  • Provides logging and auditing capabilities to track API usage and interactions.
  1. Enhancements to Security and Management
  2. The significance of clickless authentication through TSIDP, allowing users to access services without manual login processes.
  3. Focus on observability: The ability to track API calls, usage patterns, and user activities for enhanced security and compliance.
  4. Introduction of a potential AI firewall, allowing for dynamic adjustments to security policies based on real-time data.
  1. The Role of Partnerships
  2. David emphasizes the importance of collaboration, inviting individuals and companies to reach out for partnerships or feature requests.
  3. Mentioned the potential for office hours to discuss features and foster community engagement.
  1. Common Misconceptions about Tailscale
  2. Not just for hobbyists: Tailscale is used by enterprises with serious engineering resources.
  3. More than a VPN: Tailscale integrates identity into its networking model, going beyond traditional VPN functionalities.

Key Takeaways

  • Tailscale provides a modern solution for secure networking, emphasizing user identity and connectivity.
  • Upcoming features like TSIDP, Aperture, and multiple tailnets are set to enhance security, management, and user experience.
  • Community involvement and partnership opportunities are encouraged, fostering collaborative innovation.

Conclusion The episode provides valuable insights into the evolving landscape of network security and management through Tailscale's innovative solutions. David Carney's vision reflects a commitment to improving how teams connect and manage their resources securely, with a keen eye on the future of AI integration.

Contact Information For inquiries or partnership opportunities, reach out at aperture@tailscale.com.

---

This markdown file serves to summarize the key points discussed in the podcast, highlighting essential topics and encouraging further exploration into Tailscale's offerings and opportunities for community engagement.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Understanding Tailscale's Strategy

3:37 to 5:00

Discussion with David Carney on Tailscale's current strategy and direction.

“Click that, install it, and change your world.”

Exploring Tailscale's Core Functionality

5:00 to 7:54

David explains Tailscale's functionality and how it builds private networks.

“And so explaining it to a layperson is very helpful.”

Innovations in Tailscale: The Edge

7:54 to 11:28

David elaborates on innovative applications and services being developed on Tailscale's platform.

“What are the applications we can build on top of our own platform?”

TSIDP: Local Identity Provider

11:28 to 14:00

The functionality and benefits of TSIDP as a local identity provider within Tailscale.

“And so when I first started using Proxmox, I set it up on tail scale.”

Understanding TSIDP and Its Maturity

14:00 to 15:00

Learn about the maturity and usage of TSIDP in development.

“or an Incas on top of a Proxmox, just anything like that where I have a network of other machines what is the process to support TSIDP?”

Integration and Benefits of TSNet

15:00 to 16:10

Explore how TSNet enhances application integration and networking.

“Is it something that is just inherent of you using Tailscale that just comes along with using Tailscale and authenticating to it?”

Using Tailscale with Proxmox: A Practical Guide

16:10 to 17:40

Discover how to integrate Tailscale with Proxmox and manage services.

“It's like a user space networking stack.”

Exploring OIDC, OAuth 2.0, and TSIDP

17:40 to 19:00

Understand the role of OIDC and OAuth in the context of TSIDP.

“and I will not have to authenticate to my Proxmox.”

The Evolution and Challenges of MCP

19:00 to 21:20

Examine the evolution of the MCP spec and its impact on development.

“As long as you support OIDC or OAuth 2 or 2.1, then you can use this as an OIDC provider, which essentially is the effectiveness of signing with Google or signing with GitHub.”

Dynamic Client Registration Explained

21:20 to 23:20

Learn what dynamic client registration means for the MCP and deployment.

“I think Simon Wilson had this great quote, which is a lot of people were just adopting MCP for lack of their own AI roadmap.”
Show all 34 chapters

The Concept of Self-Hosted Identity Providers

23:20 to 28:00

Explore the potential of creating self-hosted identity providers with TSIDP.

“and even some experimental stuff and a few RFCs that people were referring to.”

Exploring TSIDP and Identity Management

28:00 to 31:14

Learn how TSIDP enables self-hosted identity management and its implications.

“And now agentic is thrown into this world and they're bolting on and kind of rebuilding their platforms on top of essentially AI.”

Aperture: AI Gateway on TSNet

33:04 to 37:41

Understand how Aperture serves as a private AI gateway and simplifies API key management.

“And so for those of you who aren't aware, Aperture is basically an AI gateway built on top of TSNet, which I mentioned earlier, that works inside of your tail net.”

Self-Hosting and Future of Aperture

37:41 to 42:01

Discuss the potential for self-hosting Aperture and its implications for users.

“We launched it just, well, we quietly launched it a couple of weeks ago.”

The Shift to Self-Hosting

42:01 to 44:52

Discussion on the decision to explore self-hosting and its implications.

“Why build out instances and hosting and I guess responsibility?”

Exploring Licensing and Self-Hosting

44:53 to 47:26

Exploration of potential licensing models for self-hosted solutions.

“You just add water, essentially, which is one kind of fascinating idea.”

The Importance of Speed and Feedback

47:27 to 48:58

The significance of maintaining velocity and customer feedback in development.

“I like to be able to just turn it off if I want to.”

Tailscale as a Platform

48:59 to 53:24

Discussion on Tailscale evolving into a platform and opportunities for developers.

“I mean, it's easy just to say those words, but then to actually support it is the challenge because then you have versions out there.”

Network Isolation and Container Management

53:25 to 56:00

Ideas on enhancing network isolation with new container technologies.

“or if it let me export this kind of thing or if I could transport this kind of policy or if I could connect to these different things then I could achieve X.”

Exploring Network Isolation with Multinets

56:00 to 59:20

Learn about the benefits of network isolation and how multinets enhance security.

“and I want them to be in an isolated state.”

Building on Tailscale: Use Cases and Challenges

1:01:30 to 1:07:10

Understand the practical applications of Tailscale in enterprise environments.

“We got there by talking about different applications you think can be built on top of TSNet.”

The Future of AI Gateways

1:07:10 to 1:10:08

Explore the concept of AI gateways and their implications for security and usability.

“That's why I keep investing more and more of my knowledge into what you are doing because you guys are just networking wizards.”

Exploring the AI Gateway and its Benefits

1:10:08 to 1:14:11

Learn about the AI gateway's features and its impact on team collaboration.

“It's largely even learning about things, building toy applications just to learn.”

Real-Time Security Policies and Monitoring

1:14:11 to 1:17:42

Discover how real-time monitoring can enhance security and policy enforcement.

“There's a lot of like, like post hoc analysis you can do and those kinds of things.”

The Role of Partners in Development

1:17:42 to 1:21:19

Understand how partnerships can expand the capabilities of the AI gateway.

“We're not going to build that entire ecosystem.”

Access Models and User Privacy

1:21:19 to 1:23:42

Examine how access models can enhance user privacy and trust within teams.

“It is crazy, though, how fast those tools can let you move and the stuff they can do if left unchecked.”

The Evolution of Educational Tools in Development

1:23:42 to 1:24:00

Learn how AI tools are transforming the education and coding landscape.

“and how the contacts evolve, it's super neat.”

Navigating Codebases in the Age of AI

1:24:00 to 1:25:50

Learn how advancements in AI are transforming the way developers interact with codebases.

“like we do today reveals, you know, a lot more because you may say, hey, I'm new to this scenario.”

Embracing Transparency in Learning

1:25:50 to 1:27:40

Discover the importance of openness and candidness in leveraging new technologies.

“Cause I'm not judging me, but somebody else might if I'm in an enterprise.”

The Evolution of Tailscale's Identity Management

1:27:40 to 1:29:10

Explore how Tailscale's unique approach to identity management transcends traditional VPN concepts.

“of how to work with these tools going forward to make them effective.”

Debunking Myths About Tailscale

1:29:10 to 1:33:00

Understand the common misconceptions surrounding Tailscale and its capabilities.

“in a world that is burgeoning and very tumultuous in terms of security.”

Understanding Connectivity and Identity

1:33:00 to 1:35:10

Learn how Tailscale integrates connectivity with identity in innovative ways.

“Even when I SSH run my network, I don't do it via tailscope, I don't think.”

Leveraging Tailscale for Secure Networking

1:35:10 to 1:38:01

Find out how to maximize the benefits of Tailscale for secure network setups.

“I feel like I learn more and more about what tailscale can do for me because you do so much.”

Closing Thoughts and Collaboration Opportunities

1:38:01 to 1:40:24

Learn about the importance of collaboration and reaching out for partnerships.

“so there you go for that front there Anything left in closing?”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:01Adam Stacoviak:What's up, friends? I'm off the grid this week on vacation with my family. Spring Break is here. I'm enjoying my life. And this week I have a show for you with the Chief Strategy Officer from TailScale. His name is David Carney. We're talking about where TailScale is heading. TSIDP, TSNET, acronyms all over the place, multiple tailnets, Aperture, their AI gateway, ClickList Auth, and so much more. Big thank you to our friends and partners over at Fly for getting our back. They support the show. They make it happen. I'm so thankful for that. Check them out, fly.io. That is the home of changelaw.com.

0:39Adam Stacoviak:If you didn't know, learn more at fly.io. Okay, let's do this.

0:55Adam Stacoviak:well friends i'm here with my good friend chris kelly over at augment code chris i'm a fan i use augie on the daily it's one of my daily drivers now i use cloud code i use augment augie and i also use amp code and others but augie i keep going back to it and here's where i'm at i feel like not enough of our audience knows about augment code not enough about augie the cli

1:19David Carney:it's amazing i love it what can you share yeah we often say augment is the best coding assistant you've never heard of and that's both frustrating as someone that works there and it's like very proud of the work we've done but also like inspiring like we want to go and and sort of punch above our weight because like we aren't anthropic and we aren't open ai and so the quality

1:39Adam Stacoviak:the product itself, you know, with our context engine, once you do touch it, people are like

1:43David Carney:just blown away by that. And so like that keeps me going every day.

1:46Adam Stacoviak:So not to bear the lead here, but this is a paid spot. You are sponsoring this show to get this awareness. Now, at the same time, we're selective and I love to use your tool, but there is in the world. So a lot of developers look at the space and they say, okay, well, how long can this work? How long is this sustainable in the case of Cursor or Windsurf, or you pick the name and you think discounted tokens, help me shape a lens for our audience.

2:14David Carney:I think it's a lot of awareness, right? Like Cursor got a lot of publicity early on for like fast revenue growth, which well deserved. I think, you know, frankly, some of the media gets the story wrong in that like, if I gave you$1.50 for every dollar you sent me, I'd be the fastest growing startup in the valley. And so when you're selling discounted tokens, yes, of course you're gonna grow very fast, but all that money plus more goes to the model providers. So I think the real story is the story of Anthropic and being an API provider. I think the market has just moved so fast and there's so many pieces of competition out there that it's just hard to get noticed.

2:54Adam Stacoviak:So friends, I love Augment Code and I love using Augie and I highly recommend you use it. I love using Augie. I can hand Augie a well-defined specification, a well-defined PEP, as I call them in my world, an agent flow, and it executes flawlessly. So the cool thing about Augie that I love most really is that context engine. And I can hand it a task and it can just churn away on my well-defined plan and just never bother me and accomplish the mission. It is so cool leveraging the latest models, the context engine, and all the fun things behind the scenes in that awesome CLI. So yes, go try it out, augmentcode.com.

3:36Adam Stacoviak:Right in the top there is a CLI icon, a terminal icon. Click that, install it, and change your world. It's going to be awesome. Augmentcode.com.

3:49Adam Stacoviak:Well, friends, we're here with David Carney, co-founder, chief strategy officer of TailSkill. Friends, you know I'm a big fan of TailSkill. So David, welcome to the show. Yeah, thank you. I'm glad to be here. That's a big role. I mean, that would shake me in my boots if I was chief strategy officer of Tailscale. What a big platform you're building and a lot of moving parts and a lot of direction you can go.

4:13David Carney:It is a big title. And I just want to be clear, I'm certainly not the only one thinking about strategy at Tailscale. There's a lot of moving parts.

4:20Adam Stacoviak:But being the top of it all, what does it take to lead strategy inside of an organization like Tailscale?

4:28David Carney:Well, I wouldn't even say I'm leading the holistic strategy. The stuff I'm working on in close partnership with my co-founder, Avery, and a new VP product and other parts of the team, I'm focusing largely on the strategy at the edge of Tailscale, which is something that's come about in the past year or so.

4:48Adam Stacoviak:So for the uninitiated then, describe Tailscale from the non-edge and then take me to the edge and what that means.

4:56David Carney:The simplest way to think about Tailscale, and sometimes people ask me, what are you building, what do you do? And so explaining it to a layperson is very helpful. And so first and foremost, Tailscale makes it possible to connect any two devices anywhere in the world with strong guarantees of the identity of the user and the device at either end. And if you can do that for any two devices, you can do it for an arbitrary number. So you can start adding one device, one user, one server, or whatever at a time until you have basically what looks like a mesh network and it's completely private. Then you can layer on things like access controls.

5:33David Carney:So you can be like, oh, only these people should be able to access these servers or devices. For instance, the engineers can only access production, the accountants can only access the finance servers, so on and so forth. But fundamentally what you can do with Tailscale is create private networks. And so when we launched the product, I guess we launched it maybe six and a half years ago now, It was pitched as a VPN alternative or zero trust kind of replacement. It does a lot more than what a VPN is, but at the heart of it, it's a connectivity platform that lets you build private networks that are fully secured and sort of using a mesh overlay pattern.

6:07David Carney:So that's the core of what Tailscale is, and it has been for a very long time. And we've been continuing to build and build and build on top of that. There's this motion that's started in the past year or so where the use cases for Tailscale have gone from just internal within a company. So it's like, I'm using it to replace my VPN or I'm using it to access production or I'm using it to deploy infrastructure within my company. So that people are starting to use Tailscale to deploy infrastructure to their customers. So for instance, there's a couple of cloud provider startups that are using us in a way that they bring up a tail net, is what we call it, per customer.

6:45David Carney:And so they connect a bunch of, say, bare metal GPUs with customer infrastructure, and they spin up one of these per customer, and then they manage it. There's this ability to create multiple tailnets inside of your organization now. So people are starting to do that to build, say, a staging tailnet, or a testing tailnet, or a production tailnet, that kind of stuff. What I've been working more on over the past, I guess, year now, is building applications and services on top of this platform. So showing people like, oh, you can create a tail net. It has these very interesting primitives where identity and connectivity and security are baked in.

7:19David Carney:Well, look how easy it is to build applications on top of these tail nets and deploy them within a bit of private infrastructure. And that has gotten me, I guess, more involved in things like agentic workloads and that kind of stuff where you want really tight boundaries on who can do what with identity associated with all those actions and some kind of compliance trail and all that kind of fun stuff.

7:41Adam Stacoviak:This fringe, this edge, you call it the edge, I call it the fringe. What are some of the things that you've thought of? Like how did you go with either yourself or other folks on the team to sort of go into a room and think, okay, what is the true edge? What are the applications we can build on top of our own platform? I'm assuming that's how you position this. What are some of those things? I know we mentioned authentication is one of them, obviously. so you have your Aperture product you recently launched. But what are some of the edges of that? What products are you thinking about?

8:16David Carney:Well, the thing we started with earlier last year is that we revived a project, an internal project, called TSIDP, which, like a lot of things that we've built at Tailscale, we don't do a great job of telling the world about. TSIDP was in our community projects repo. We'd done a bunch of work on it a year or two prior. And for those of you who don't know what it is, and it's probably most of your listeners. That's me too. Yeah, yeah. So TSI-VP, you can think of it as a reflection of your identity provider inside of your tail net, right? So it's almost like a locally hosted version of your identity provider that's private to your network.

8:58David Carney:The way it works is that it leverages the fact that every connection in TailScale has your identity baked into it already. When you provision a tail net, you basically have to say like, oh, I'm going to authenticate with Azure or G Suite or Okta or whatever. We don't have our own IDP. We just hook into all the ones that are commonly used out there. Well, once we can start generating keys based on a handshake or an interaction with your external IDP, every connection has got your identity baked into it. And so if you're sitting inside of a tail net, you know everything that is connecting to you.

9:30David Carney:And so you can actually build a small little application that just knows everything, or it knows the identity of everybody. And so with that, you can actually create effectively an OIDC provider. So that's what TSIDP is. You can think of it as like a locally hosted private OIDC or OAuth endpoint. And that allows you to do all sorts of neat little things. Like you can start plugging MCP clients and servers into it. You can build little gateway patterns where if you need to do like token exchange or if you need to do dynamic client registration, You can basically do it with TSIDP. So you can keep all this interesting identity management stuff private to your telnet, not expose it to an external IDP.

10:11Adam Stacoviak:That's interesting. I mean, we've talked about OIDC recently with Nicholas Zakis around NPM's security. And that's one of the things that NPM required modern maintainers of this age to essentially have one blessed way to publish to NPM. And they had this issue with like rotating keys and that secure layer was largely brought on by OIDC. That was the first time I'd started to dip my toe into, I'm not an authentication nerd too deeply besides I like to authenticate with things. I like to have an identity when I go around. I like my SSH keys. I like to be me where I need to be me. But I think I've been like hitting rocks together compared to maybe what, But even though I've been a tail scale user for so long, I feel like every day I learn something new about tail scale.

11:04Adam Stacoviak:So what does this help me understand what that enables them? What kind of applications does it mean? So if when I authenticate and I have a tail net that gives me a mesh network across whatever device I want to connect to, whether it's a home lab or enterprise or prod or staging, like you mentioned, what are some ways that enables developer to not have to like shell out to somebody else's OIDC, but to be their own within their own tail net? What does that do?

11:27David Carney:Yeah, so for instance, I have a home lab. I have a Proxmox server on it. Fantastic. And so when I first started using Proxmox, I set it up on tail scale. I'd hit the internal IP on it so I could access it over my tail net wherever I was in the world. But I'd still have to log in with my credentials. There is a way to set up authentication with Proxmox that uses TSIDP so that it basically just automatically authenticates you just by virtue of the fact that you're on the tail net. It knows who you are. So I don't have to type my username and password into a modal and hit submit. I basically just visit my Proxmox instance locally.

12:10David Carney:I'm listening very closely now. Yeah, so Alex published a lot of videos on all of Tailscale tech. He actually has a video on this, and I think an update for it too after we brought TSIDP up to the MCP spec last year. He refreshed his video on how to set up TSIDP to work with Proxmox. But yeah, it's super convenient like that. At Tailscale, we use it internally. For instance, we have it set up so that our revenue team, if they need to access Salesforce, they don't have to type a username and password. They can just visit Salesforce. Salesforce is configured basically to jump through our local TSIDP instance instead of having to do an OAuth flow.

12:51Adam Stacoviak:So this is like click list login, essentially. This is just, I'm me, and I can just go around my, do my business inside my business or in my home lab, which is kind of like a mini playground for most people, and not have to even rely upon something like 1Password to put a password in. You're just you, and you just go there, and you're just logged in? How does that work?

13:15David Carney:Yeah, I mean, you're already logged in. I guess that's the thing with Tailscale. When you're on the tail net, you've already done an OAuth flow. And so why do it again is basically the question we asked. Every connection can assert your identity, so we just leverage that. Obviously, there's a bit of work you have to do, say, with Proxmox or whatever to set it up and point it at TSIDP. You've got to set up TSIDP inside of your network. It's pretty straightforward. We're working on making that easier, too. but once it's set up it's just like this magical experience where people just forget about the fact that they need to log in anymore.

13:51David Carney:But under the covers or under the hood it's all safe and secure. It's just like you're doing it all off flow, it's just silent.

13:58Adam Stacoviak:So if I had a Proxmox server or maybe a database server or an Incas on top of a Proxmox, just anything like that where I have a network of other machines what is the process to support TSIDP? Is that well-published? Is that burgeoning? How mature is that for a developer to pick that up today and just start implementing that in their infrastructure?

14:27David Carney:Well, the code is open source. It's on our community projects page. I think it's github.com slash tailscast slash TSIDP now.

14:41David Carney:it does support I believe OAuth 2.1 nowadays we brought it up to speed basically to keep pace with the evolving MCP spec last year so we added a bunch of other stuff to it but people are using it, a lot of home labbers are already using it we've got a bunch of what we call tailscal insiders that are using it too again, we just haven't talked about it enough so I don't think enough people are using it or are even aware of it But it's there, and it's open for contributions, too, if people want to add or extend or make more requests.

15:11Adam Stacoviak:Is it something that is just inherent of you using Tailscale that just comes along with using Tailscale and authenticating to it? Or is this the OIDC part of it? Does it have to be a hosted server locally and run that you authenticate against?

15:28David Carney:Yeah, you need to run it as an instance. I have it running in LXC on my Proxmox server, for instance. It just starts on boot.

15:36Adam Stacoviak:What's involved in that? Is that running on Ubuntu? Pretty common, pretty easy via system D? Can you walk me into some of the details potentially there?

15:45David Carney:I think I'm using Alpine for it. I'd have to double check. But it's just a Go binary.

15:59David Carney:TSIDP is built on top of this other little piece of tech we have called TSNet. you can think of TSNET as a complete user space stack, like Tailscale stack. It's like a user space networking stack. Again, it's a Go library. So you can compile TSNET into existing Go applications, for instance. And we've done a bit of work on bindings for other languages, but the Go chain is the most mature by far for this. But what using TSNET lets you do is any Go application where you've compiled it in, have it show up so it looks just like a node on your network, just like any laptop or iPhone or whatever. And so it shows up as a node, gets its own IP address in the CGNet range, which we use internally.

16:42David Carney:You can apply ACLs to it, policies, all that kind of stuff. You can build applications with that. That's what Aperture is as well. It's fundamentally a TSNet application. So it just shows up as a service. The nice thing about TSNet is that, yeah, you can turn any kind of service into effectively what appears to be a device. And then you can apply rules in terms of who can access that with what level of permissions and all that kind of stuff.

Read the full transcript

17:08Adam Stacoviak:I feel like you're the most coolest, under-known, crazy tech. Every time I peek behind the scenes even further, I've talked to Alex many times. He and I are friends. Alex Kretschmar, our audience knows Alex. And obviously you do too. But every time I go a little further and a little deeper into my networking nerd world. I just learn more about what I can do with Tailscale. And it's so wild how, like, I'm really, like, when we're done with this, the first thing I'm going to do, it's a Wednesday. I'm hoping maybe by next week, I will get this spun up and I will not have to authenticate to my Proxmox.

17:46Adam Stacoviak:What does a tool like Proxmox or other services that one might run either in their enterprise infrastructure or in their home lab, which is kind of a snapshot version or a playground for most folks that might be, not so much enterprise, but team-based or just running ops and infrastructure. Like who isn't doing that these days? A lot of people are. What does it take for a Proxmox to support that? Is that something that Proxmox has to do? And what are some of the protocols required to support this?

18:15David Carney:In terms of just running like TSIDP as a service inside of your network? Well, how does Proxmox be able to support TSIDP? Oh, it's just another OIDC endpoint. So as long as it supports OIDC,

18:33Adam Stacoviak:then that's the ticket in.

18:35David Carney:Yeah, and we've added, I mean, there's OAuth 2.1 support or 2.0. I mean, we brought it up to the almost OAuth 2.1 as the MCP spec was evolving last year. And then we paused it a little bit. But yeah, OIDC, OAuth 2, it should just work.

18:52Adam Stacoviak:That's it, huh? That seems pretty simple then. I've never messed with this at all. I'm going to mess with this. It's a new world for me on that front there. Yeah, please do. I love the feedback. Yeah, I'll give you feedback. Good. So this is an example of the edge. So you got TSIDP. As long as you support OIDC or OAuth 2 or 2.1, then you can use this as an OIDC provider, which essentially is the effectiveness of signing with Google or signing with GitHub. Is that right? Is that what you're putting down? Yeah.

19:28David Carney:One of the reasons we spent some time working on TSIDP last year is because a lot of the existing IDPs, like the big ones out there, didn't support some of the things that MCP was calling for, like dynamic client registration, for instance. So we built that into TSIDP so it effectively let us bolt on these missing capabilities. So you can not only continue to use your existing external identity provider, but you can augment its capabilities with TSIDP inside of your private network.

19:59Adam Stacoviak:Take me into that world, because there's a lot of folks who are down with MCP and not down with MCP. They say it's a fad. They say it's here to stay. I think it's all about how the context when it gets impacted to the user. I think everything in this world is burgeoning and what was yesterday is not tomorrow. What is, I mean, you've been steeped in this for probably 12 months or more, building Aputure and this edge you're talking about. What's your stance on MCP from an implementation standpoint and leveraging it?

20:29David Carney:I was getting deeper and deeper into MCP last summer and definitely into the fall, going to a lot more conferences, talking with many more people, and it seemed like things were just getting bigger and bigger and crazier and crazier all the time. it seemed like iterations of the spec were coming out people were reinventing things it got to the point where I think a lot of companies or organizations were like we're just not going to implement this right now because we're worried the spec is going to change again it's too fraught and it got very fraught and we actually pulled back a little bit from it because I think in September I could definitely feel this fatigue just creeping in I was talking with more people and they sort of started pulling back from going to conferences related to it.

21:16David Carney:I think everybody was just getting tired of trying to keep up with the spec and the evolving landscape. I think Simon Wilson had this great quote, which is a lot of people were just adopting MCP for lack of their own AI roadmap. And so I think there's something along those lines. I forget the exact word, but I was paraphrasing it. But I got that sense too. A lot of people were sort of chasing this thing because they thought it was the right thing to chase for them to actually come up with an AI strategy. and it just got more and more complex for them. And I think a lot of people started pulling the chutes, pulling the cords and slowing down to regroup a little bit into the fall.

21:54David Carney:And that's sort of how we felt too. The more we sort of dug into it, the crazier things seemed to get. So we're like, we just need to take a step back and simplify our own thinking and focus on a couple of problems that we want to solve as opposed to trying to chase all of them, which is what MCPU felt like it was doing. Now, in my experience with these kinds of standards, there's usually this explosion and then things coalesce to something a lot more sane. I think that is going to happen with MCP. It's just going to take us more time than we thought.

22:22Adam Stacoviak:Dig me further into the dynamic term that you mentioned. I get the write down with MCP. You said it was calling for this feature set that wasn't there and that's why you had to go that route.

22:33David Carney:Oh, dynamic client registration, DCR. And I will admit, I don't know all the technical details of this. So you'll have to forgive me on it.

22:44Adam Stacoviak:Well, don't go into the details necessarily about that, but what does it do? What does it enable for the MCP? Why is it in the protocol?

22:50David Carney:It basically lets things like MCP clients and servers wake up and register themselves against an endpoint without requiring a lot of manual steps or human interaction. So it removes a lot of friction in terms of getting things like MCP deployed across an organization. And you need to support that. and that's why you went that route. Yeah, well MCB was calling for it. Right. And so it was like, well, this is where the spec is going. And there's other parts of OAuth 2.1 and even some experimental stuff and a few RFCs that people were referring to. Dynamic client registration was definitely one that a lot of people were talking about and were like, look, we can build this.

23:31David Carney:It's not exactly rocket science. It would be hard for an existing identity provider to retrofit this in because being an identity provider is a horrendous amount of work. Tailscale doesn't want to be an IDP. We've known that from day one. But we can extend the functionality of existing ones. And DCR was pretty straightforward for us, largely because with Tailscale, you know the identity of things on the network. So if you have this trust and these assertions you can make in terms of who is connecting to what, then client registration becomes a lot more straightforward that way.

24:09Adam Stacoviak:Is it the point of dynamic client registration to enable the MCP server to spin up whenever you launch it or initiate it or instantiate it to attach itself to the tail net? Is that the point of this dynamic client registration? Or is it the individuals coming into the MCP, maybe through a CLI or other agentic workflows?

24:31David Carney:I mean, in my limited experience with this, again, is been more about us just allowing, you know what? I don't have a great answer for you on that one.

24:41Adam Stacoviak:That's okay. That's okay. I'm trying to pick it up with you because this is, you know, when you're in the land of burgeoning, right, you kind of have to navigate some seaweed and some tall grass and you got to get your hatchet on. You're like, you know what? I don't really know where I'm at right now. This is moving so fast. What is the point of this need? That's what I'm curious about because it seems like that might be the case. I see a lot of folks delivering a CLI and a MCP in one. You know, a lot of Go applications are doing this or Go CLIs are doing this where they'll deliver a CLI and MCP server in one single thing and you can launch it via the CLI, which is pretty easy.

25:17Adam Stacoviak:And I'd imagine you want that thing to authenticate with a tail net. Like if I'm spinning up a network, I want it to have an identity. Be the MCP server for XYZ server or service and that's who you are and you've got ACLs and identity attached to you.

25:32David Carney:Yeah, and I mean, That's how we've been showing it off to people. It's like, oh, I'm going to create a server, I'm going to create a client, I'm just going to have it automatically join the network. A big part of, again, tailscales, you want to give these things identity, you want to pass them around, you don't want people to have to, say, make a manual or static configuration with this kind of thing. I should be able to spin up, if I'm on a tail net, for instance, I should be able to set up an MCP server, I should be able to launch it, I should be able to grant access to that to certain people, I should be able to tell my colleagues and maybe some agents that are in a tailwind somewhere, like, hey, you've got this new resource available.

26:09David Carney:You can go access it safely and securely. That's why dynamic client registration is super important for us in general. And I think it's why it's so important just to the MCP spec as well.

26:19Adam Stacoviak:Take me back into TSIDP. You mentioned not wanting to be an IDP. These are acronyms, everybody, okay? I think it's, what does IDP stand for? Identity provider. What does that mean? Identity provider. Identity provider.

26:37David Carney:Yeah, like G Suite, Azure, Okta. There's a lot of them. Key Cloak.

26:47David Carney:A third-party service that you trust to assert the identity of other things. Or yourself to other services, broadly speaking. So everybody logs into, well, not everybody has a Gmail account, but everybody logs into services like they enter username and password or configure, like logging with SSO or logging with Facebook or whatever. These are all authentication flows. Something has to know who you are and be able to assert that to other things that people trust. That's basically the job of an IDP.

27:21Adam Stacoviak:Here's where I'm going with this. And maybe this is just hypothesizing this edge that you're maybe navigating with you and your team that are thinking through these things. I'm thinking like if you don't want to be an IDP, that makes sense. But you want to enable folks to create their own IDP, which is TSIDP. It's this thing I can use to build my own essentially. And I can sort of carry my own identity around with me. It seems like I could run my own instance in my home lab on my Proxmlk server, but it could be me everywhere if I wanted it to be. That's what it seems like I could be, or I can build my own thing on top of that.

27:54Adam Stacoviak:I feel like we're going into this world where maybe the next layer of a lot of folks stacks, whether it's internally in a home lab, whether it's a small team, but in the next big thing to maybe a medium sized team that's already got motion in place. And now agentic is thrown into this world and they're bolting on and kind of rebuilding their platforms on top of essentially AI. I feel like this world is moving towards self-hosted. And the reason why I'm asking this question is like, is the idea for TSIDP to enable me to self-host my own identity provider. So I don't have to log in with Google or log in with GitHub or log in with whomever.

28:34Adam Stacoviak:Because the thing I forget most is like, which one did I log in with? And now I've given you my stuff and I got to trust you with my SSO, my single sign-on provider. all these acronyms in this world is just ludicrous, basically. But is that the direction you're trying to take things? Kind of.

28:53David Carney:So just to be clear, you still need an external identity provider when you're using Tailscale, and specifically if you use TSIDP. It leverages the fact that you've got an external thing that you trust. Because that's what generates the identity, and that's what we use for the encryption keys, so you can figure out, oh, this thing is connecting to me, I know who it is. And so however you're using tail scale right now, you've got to, you know, when you create that tail net, you're plugging it into whatever identity provider is out there that you currently use. What I think is really magic about TSIDP is that it lets you not only manage identity sort of privately and internally, so you can bring OIDC to all of your internal apps.

29:38David Carney:You don't need to configure them to go external. It lets you start thinking about your network is more of an extension of your identity, not just individual devices. And so you can actually start treating a tail net as a collection of identities or perhaps just one identity. And so it lets you, I guess, have a pocket of identity that's privately your own that you can start to do and manipulate and share things in the world with. Now, I think there's a lot of interesting ideas and maybe a philosophy we can get into on this kind of stuff. And I'd love to explore it. I know my co-founder, Avery, has thought a lot about this kind of stuff too.

30:14David Carney:It's very early days for us. It's a very interesting and academic piece of tech. I guess I can talk more about some of the journey last year if you want, but we started going to conferences and talking about TSIDP to people, especially in the AI space, because we're like, oh, this is very fascinating from an MCP point of view. Facilitates ease of use within a side of a tail net. It helps you keep things private. Identity is a first-class thing. TSIDP is a way of showing that off and people were very interested in it but then they kept on coming back to just more concrete problems of like, oh, I need to get access to a customer network or I'm dealing with API keys or like much more tangible like, you know, first order problems whereas TSIDP was like three or four steps down the line for them which is why we pivoted last year sort of a little bit away from it but I guess in terms of projects it's still very actively there's a lot of active interest and we use it internally but the stuff I've worked on has shifted a little bit.

31:13Adam Stacoviak:Big thanks to our friends at NordLair for sponsoring this episode. So you 2FA your GitHub org. You rotate your API keys. Maybe you run Dependabot on every repo or something like it. And then you onboard a contractor by sharing a VPN config over Slack and forget to revoke it four months after the contract ends. And that person still has a tunnel into your internal systems. Maybe even right now. Go check it. All this from a laptop you don't control on a network you can't see. Well, NordLayer is a network security platform built for businesses that actually operate the way modern teams do. Distributed, remote first, and moving fast.

31:51Adam Stacoviak:It combines VPN, access control, and threat protection into a single platform based on zero trust. Only the right people get access to the right resources, under the right conditions, no implicit trust, no access lists. First, it deploys in minutes, not months. NordLayer runs on NordLynx, their VPN protocol is built on top of WireGuard and works across every platform. Mac OS, Windows, Linux, iOS, Android, no hardware to rack, no complex configs. You get granular control over who accesses what, from where, on which device. And when that contractor's engagement ends, well, you know what? Revoke access from day one on one dashboard.

32:33Adam Stacoviak:And it's done right then and there. So plan to start at eight bucks a month. Get up to 22 % off NordLayer right now yearly plans plus an extra 10 % off with the coupon code changelog-10-NordLayer. Try it risk-free with a 14-day money-back guarantee. Check it out at nordlayer.com slash the changelog. Again, nordlayer.com slash the changelog.

33:04Adam Stacoviak:what are the things that are most active for you now then like i think this might be one of them given aperture's announcement and that's this is sort of the underpinnings of all that but like what are some of the other things that are more active like even with api keys and those are being thrown around everywhere and tail scales kind of to some degree solved most of that and like you'd it's hard to tell everyone about the cool stuff you have and now you have a chance yeah and and

33:27David Carney:thank you for that yeah so aperture is uh definitely the evolution of a lot of that exploration last year. And so for those of you who aren't aware, Aperture is basically an AI gateway built on top of TSNet, which I mentioned earlier, that works inside of your tail net. And you can expose it. Well, there are ways to expose it externally. But essentially, it's a private AI gateway that lets you consolidate all of your API keys inside of it. And it just looks like a node on your tail net like any other would. After spending months and months going to various AI conferences and showing off TSIDP and just talking with all sorts of people, like engineers, CISOs, people in IT, what have you.

34:09David Carney:Time and time again, people were saying things like, oh, TSIDP, it's super fascinating, interesting that you guys are working on all this kind of stuff. I see the merits of TailScale. Multi-TailNet, which is this other thing we've been working on internally, is super neat. But what I'm really struggling with is just trying to figure out how to manage API keys because they're all over the place. I can't claw them back because it'll potentially disrupt production or some engineering workflow. So we're trying to go really fast as a business. And it's just dangerous. You've got API keys all over the place.

34:37David Carney:People trade them, they get exfiltrated, they get checked in, and they have very large, I guess, well, accounts or credit cards associated with them. And so it's very hard in some cases to track usage because a lot of API calls are inherently anonymous. We were sitting around at a company offsite back in November, just talking about all the things we've been learning over the past few months. And we're like, well, wait a minute. if we built a gateway and we used TSNet for that, the gateway already knows exactly who you are because everything that connects to it over tail scale has identity baked in.

35:10David Carney:So if we put the API keys all inside of the gateway, then you wouldn't need to share an API key with anybody inside of your company. You could just say, oh, if you have a coding agent, just point the coding agent to use the gateway instead. Gateway knows who you are. So then all the API accesses have identity associated with them. All the API keys can be withdrawn. And so that you end up with a single point of, I guess, observability, control, and access for your entire team. So plus engineers get onboarded faster because they can just tell their peers, like, oh, just put your coding agent at the proxy.

35:42David Carney:Everything just works if you're on tail scale. Plus the security team say, like, great, we can get rid of all the security, like all the API keys that are all over the place. We can just tell people, just go to HTTP. For us, it's HTTP colon slash AI. and then every API call has your identity associated with it so you can just log everything. We use Aperture internally right now and I think we've got, I don't know how many tens of thousands of API calls across a big part of the company at this point. We've just got every interaction with all of our coding agents going through Aperture right now internally so we have full visibility into how people are using AI.

36:19David Carney:All the requests, all the responses, the full logs. We're mining it for tool calls. And our security team gets to review it if they need to. And we're working with third-party providers to start doing analysis of the logs in real time and after the fact. There's all this stuff that is unlocked for us. But initially it just started with the simple idea of we just want to solve the API key problem. And I'm meandering a little bit, but one of the reasons I love it so much is it builds so much on top of the fact that Tailscale makes things so much easier because it takes identity and encryption and it brings them way down into the stack, like right at layer three.

36:57David Carney:And if you do that, it can simplify so much stuff on top of it. And Aperture is just an example of that. Anybody can take TSNet and build an application that looks like a node in your network and you get identity and connectivity and security baked in for free. And it's such a joy to work with it because as a developer for years, I spent so much time and heart, I had so many headaches about building authentication systems and managing infrastructure, opening up firewall ports, and dealing with whitelisting IPs. And now with Tailscale, you just don't need to do that. Not at all. Yeah, and with applications you build, with TSNet, you don't need to do that.

37:36David Carney:So it's just been a joy to work on this project over the past while.

37:40Adam Stacoviak:As a home labber, I'm thinking about having, is Aperture available to anyone? Is it a product? Do you have to pay for it? How do you deliver it to someone?

37:52David Carney:I mean, it's an early alpha right now. There is a self-serve flow. We launched it just, well, we quietly launched it a couple of weeks ago. It's not quiet now. Yeah, yeah, yeah. We did more of a push just the other day on it. Right. But if you go to aperture.talescale.com, you can sign up. There's a bit of, like, we manage it as a waitlist just because we don't want the service to get overloaded. But the idea is that we're going to open it up very quickly for everybody as soon as we're sure that things are just going to scale just fine. But basically, we will provision an instance. You authenticate it as a node into your network.

38:29David Carney:It just shows up. You can start using it right away. It's in line with what we already do for Tailscale. It's free for home lab use. We're going to be announcing how we're bundling it as part of the free plan. Just free for home use, that kind of thing, just like we do. Obviously, we're planning on it being a paid product for enterprise, but we're still exploring pricing and all that there. Yeah. But I want every home lab, anybody who's playing with LMs and API keys and stuff at home, they should just be using it. It just makes things easier. It's sort of like the tail scale way.

39:06Adam Stacoviak:Is this self-hosted then, or is it not self-hosted? Because you said provision and instance.

39:10David Carney:Yeah, so we are hosting these instances for customers right now. There is plans and talk about self-hosted versions, and certainly enterprises. Some of them would insist on that. There's varying degrees of what that might mean. Customers might be like, oh, I want to bring my own cloud, you just write the logs there, but you can host the stuff that's taking up the CPU. Or some customers might want just, no, we have to have everything on-prem. But right now, we wanted to get Aperture into as many hands as possible, as quickly as possible. And the easiest way to do that, And I think one of the safest ways, frankly, is just to let us host the instances at this point.

39:47Adam Stacoviak:The reason I ask that question is, one, I said earlier that I feel like the world is moving to self-hosted. As a home labber, I already felt that way years and years ago, but I feel that way more and more now because when the cost to produce an application that's bespoke to me goes to near zero, except for my ability to specify it and my ability to describe intent, And then everyone theoretically can be a builder in this new future we're going towards. And why not self-host a lot of things that I'm going to do? Because I'm already a home lab where that makes a lot of sense. But I imagine a lot of teams, a lot of tech companies, a lot of non-tech companies that are now tech companies, they think the same thing.

40:29Adam Stacoviak:They want sovereignty over their things. They want to control their CPU costs. They want to trust the cloud less and still leverage cloud native type things, but in their own controlled way, especially when it comes to identity and especially when it comes to all tool calls and all responses, etc. I mean, because as an individual AI user, a team of one, basically, when it comes to the things I'm building, one of the things that I have anxiety about is, or just I suppose not anxiety, but I just wish there was a record. It sounds like with Aperture, I can gateway my way into all my AI and have my prompts and the responses stored there versus the compacting that happens and goes away.

41:13Adam Stacoviak:And you even have, you know, in Cloud Code, for example, you have an export where you can export the conversation, basically. It's like, let me snapshot what we've talked about. So worst case, I can walk away with context of the conversation, maybe not context of what we actually, the underneath we've described and, you know, some of the world we explored. I feel like that, to me, like I would want personally, maybe this is direct feedback, but like as a home labber, I would want to self-host that. especially because of how secure or exposed I might be, you know, with those. It's like not self-hosting your email.

41:54Adam Stacoviak:I think today you definitely don't do that. But I think in this case, it's such sensitive or could be such sensitive information. I personally would prefer to self-host it. And I'm curious why, given that you largely haven't done a lot of infrastructure in the history of tail scale, You've pretty much been a pointer in a lot of cases and not a lot of infrastructure required to build what you've built. Why now? Why build out instances and hosting and I guess responsibility? Yeah, or liability.

42:24David Carney:Liability too.

42:25Adam Stacoviak:All the abilities. Accountability, responsibility, liability, all those things.

42:32David Carney:It's a very, very good question. And I agree with you. I think a lot of people will want and will expect to self-host it. And we do want to provide a path for that. So early, I get that. It's early. This little team of mine right now that built Aperture over the past few months, it's cliche, but we're operating very much like a startup. And it's like, well, we just need to choose one path and go really fast on that path. And it's like, what's the quickest way we can get feedback from customers, get people experimenting with it, getting to the point where we actually have traction. Do we have product-market fit is the fundamental question.

43:14David Carney:Once you have more product-market fit, then we can start branching out into figuring out where that takes us. And frankly, internally, I also wanted to experiment. I think there is a world, to your point, I think data sovereignty and data governance is extremely important to people. But so is speed. And I think there is a lot to be said for motions where it's like, oh no, we can, like Tailscale can help you provision instances. Like maybe we hook into other cloud providers or maybe we get to the point where, I don't know, like people could start sharing their infrastructure and to compute with other people and we can make it possible for people to, like, I don't know, create their own cloud providers or some kind of like democratic cloud system using tailscale infrastructure.

44:01David Carney:But I wanted to experiment with the idea of, what would it take or how much would customers resist a, I just want to launch an instance into my network. Just make it easy for me. Just give me one click, drop a node in. Because we can't just simply start injecting nodes into customers' networks. People have to authenticate them in. So there's a lot of guarantees that we already have in terms of our ability to just, or the lack thereof to take over customers' networks. And I think a lot of customers just want the speed and convenience just to try something out. So we made a decision. It's working out really well so far.

44:39David Carney:I've been actually surprised with how many people have just been willing to say, yes, spin it up, add it to my network. At some point, we might want to have a conversation about self-hosting, but for the purposes of experimenting with it now, this is totally fine because we trust you guys.

44:51Adam Stacoviak:But yeah, it's really days for us too. you know there's something else i'm this thread i'm pulling on too with this self-hosted world is like you know especially in your history and just just go with me here and think think out loud if you don't mind put all your cards on the table david um i've been thinking about this world of self-hosted like we just had a a really good conversation with the founder of tldraw and one of the things that tldraw basically does is sell an sdk so it's not even you know fully big software. It's the SDK to build on top of. It's the concentrate. You just add water, essentially, which is one kind of fascinating idea.

45:29Adam Stacoviak:Great business, a lot of upside, no infrastructure, high margins because there's no servers to spin up. There's no attached to AWS or GCP, or you pick your cloud and you're now competing with them at some point Because you've got software that you're putting out there in the world as licensed software, whether it's truly MIT licensed open source or a source available open source code. Not to blend the terms there, just to be clear about that. But you've got this world where you have, I think we'll have a lot more people wanting to self-host. And those people can still be customers. You know, have you all explored or have you even thought about yet, if you went that route, how you can license it and still sell licenses of it, where you can provide essentially a source available version to the open source world that, hey, if you're in a home lab environment like you do now, totally free, this license applies to you.

46:30Adam Stacoviak:But if you're in production or you're in an enterprise or you're in this kind of business class, the source is available. Contributions are not necessarily what you're trying to achieve, but you do want to have your code out there so people can see it. But then you're also saying, here's a license to you or here's a license per node. You want to have an Aputure instance in your stack. You want to have multiple. I don't see why you'd need multiple. Maybe just one is fine. but you got maybe a per-user license or a per-node license. You're telling me, I don't know how it actually permutates into the network, but have you explored that world yet?

47:07Adam Stacoviak:Are you planning to?

47:08David Carney:Yeah, we're planning to. We've definitely started talking about it. We've had a lot of enterprises show up that are very interested in Aperture and they've been bringing these things up with us as well. I think there's a world of possibilities for us there. I'm a big fan of open source in general and I'm a big fan of self-hosting things. I like to play around with it. I like to tinker it. I like to feel like I'm in control. I like to be able to just turn it off if I want to.

47:34Adam Stacoviak:You've got a home lab, David, of course. I mean, that's where we bake all of our ideas first. We do them in the home lab. We figure out how it works. We nerd out. We learn. We explore. And then we take it to wherever we're going. That's kind of cool stuff.

47:46David Carney:Yeah, exactly. And I think with me, the bigger thing that just keeps me going as a founder I want everybody in the world to be using Tailscale because it's just a better way to do networking. Anything that's going to encourage that, I want to pursue it. I think, obviously, having a self-hosted version of Aperture is one way that will enable that. Getting more people just to build TSNet applications is another way to do it. Everything's on the table right now. For the purposes of speed and getting feedback and figuring out where we need to go next, this model that we have right now I think is the best one because frankly we're making updates and rolling out features so quickly that trying to manage those with self-hosted installations and worrying about database upgrades and all the security and everything behind them we sort of did a bit of the math where we need to choose one path and keep it super simple and just manage things aggressively

48:40Adam Stacoviak:so it makes sense in this case then to cloud first not because you're not for self-hosting but because you need to maintain velocity and the only way you can really maintain reliable velocity in this case is to have your own instances but in the future if someone says hey you know what I love this I'm down for it except I want to self host then when the product has proven itself that makes more sense later on that makes a lot of sense

49:08David Carney:that's where I'd like to go with it

49:11Adam Stacoviak:for sure it's easy to say that it's easy for me to say hey David but just make this a self-hosted instance, right? I mean, it's easy just to say those words, but then to actually support it is the challenge because then you have versions out there. And I suppose you do have database migrations. But I mean, if you know which version you're on, you can pin to a version and you do a good job with engineering and database migrations, then that can largely be collapsed to almost no pain. I get that that can be painful. And then you also have containers. Docker is certainly one of the things you can easily do that with.

49:44Adam Stacoviak:they've rolled out hardened images I'm sure they would easily roll you into an aperture hardened image that you can just boom it's there you're using the latest version of it kind of thing so there's a lot of things you can do to simplify it from a hosted standpoint or a self hosted standpoint that doesn't have to be here's my code it is a binary too right you say it's a go binary you're largely a go shop so I mean go binary is plus system d or go binary plus container is pretty easy worlds to navigate for the most part so Yeah.

50:13David Carney:Yeah. It is designed to be portable like that.

50:15Adam Stacoviak:Yeah.

50:16David Carney:I mean, I'm excited about all the stuff you're mentioning. It's definitely stuff we've talked about internally as well.

50:21Adam Stacoviak:The moment you offer, I mean, I'm going to try to no matter what, but I would, the moment, I mean, I'm a self-hoster and in fact, a little side note here, I want Alex to bring back self-host it so bad because I feel like now is the time to bring back the podcast self-hosted. I don't know if he's thinking about it. I know he's got a big job to do for you all there and maybe he's just too busy can't think about it but i like the idea of it because there's just so much happening there yeah um yeah so aperture is built on tsnet you mentioned tsnet applications what are some other things like can i go build on tsnet like if i'm a builder what ideas can you give this world to say you know what we can't do it all here's some ideas do you want me to build do you want people like me to build on tsnet or do you want to be the only application builder oh no no no no no like Like, I mean, yeah, the bigger arc here is like, I think Tailscale can and should become a platform.

51:18David Carney:I think every platform needs a few killer apps.

51:20Adam Stacoviak:Yeah.

51:21David Carney:And it needs to sort of lead the way, it needs to demonstrate to people like, look, this is viable. Like, this is why you should spend your time on this kind of thing, because there's an ecosystem that you can plug into. And Aperture is definitely one of those projects for us. Now, if somebody else goes and takes an existing AI gateway and retrofits it on top of Tailscale, that's a win-win as far as I'm concerned. More people are using Tailscale. Customers have better security. More people are just familiar with TSNet, which is fantastic. When you start thinking about Tailscale in terms of, oh, I can create a private network and I can add things to it and then I can start controlling access to it.

52:00It's a very abstract, I guess, model.

52:05David Carney:There's a lot of different kinds of opportunities and problems that can help to solve. And I will say there is something that we've started talking about more in the past 12 months. It's something called multi-tailnet. We have a blog post or two about that, which is the ability for you to create multiple independent tailnets instead of your org or your team or your home. And there's API-only ones right now, which is basically for machine-to-machine use cases. There's not a strong notion of user identity in that. And then there's ones that are more directly tied to the user identities. So we've got some customers that have a staging tailnet and a testing tailnet.

52:42David Carney:User identity is a first class thing. I believe those tracks of development will converge at some point. But there's already some really incredible stuff you can do with multi-tailnets, for instance. And that's one of the reasons I think things like Aperture and TSNet are so fascinating. I could create a separate tailnet and I could make sure that nothing can escape from that. And I can go off and do its thing and I can run coding agents in YOLO mode. I can have them connect to MCP servers and I have permissions that can fly around inside of the network and it's all nice and contained. And you can use Tailscale for that kind of thing.

53:18David Carney:Those are the kinds of areas where I'm really excited for people to start experimenting with and bringing up ideas of just like, oh, if Tailscale did this for me or if it let me export this kind of thing or if I could transport this kind of policy or if I could connect to these different things then I could achieve X. And I want to hear more of those ideas so that we can start building more stuff and more features at the edge so that people can start using tailscale more as a platform yeah i'd love to explore the idea

53:41Adam Stacoviak:not so much in this podcast but something that's on my plate is network isolation like spinning up an instance let's just say like an incus are you familiar with incus money chance did i say that earlier yeah i'm sorry canonical used to have lxd so you know that you got lxc in uh and i don't even use those i'm not super versed this is where i'm exploring and learning more about so i'm sure my audience will be like adam get yourself up to speed here okay i'll attempt to to follow this here incus is like system level containers so versus docker where it's a protocol it runs on systemd it spins up instances and it is a go binary it's built on go the person who invented it for canonical ubuntu's uh parent company it was called lxd i think they had a license snafu i don't want to i don't know what happened there but something happened licensing wise that made canonical change the direction of it and remove it away from, I believe it's Linux containers.org.

54:41Adam Stacoviak:If I can recall, let me just double check my notes here. So I don't jack up that. Yeah. Linux containers.org, which if you go there, you will see Incas, you'll see Incas OS, you'll see LXC, which is something you use in Proxmox, Distro Builder, which can do some cool stuff with like building distributions. But Incas, let me actually go to their homepage so I don't actually jack up what they say. Incas is a next generation system container, application container, and virtual machine manager. So much like you can do a VM and you want to actually have control of the kernel or the container itself can be you're borrowing the OS level, the hosts level kernel, where a VM you want to have your own kernel.

55:22Adam Stacoviak:So it can do both of those in easy exchange. So unlike Proxmox, they're very much differentiated. and actually largely abandoned from a CLI standpoint. They don't really have a good CLI in the Proxmox world. So if you want to spin up a new VM or a new LXC, you've got to do a bunch of clicking inside the web UI. Painful. Whereas Incas has got a really great CLI. You can script a lot of this stuff. And the difference between a container and a VM from a scripting API CLI world is the same, like the same kind of commands, but arbitrarily different whenever you spin them up. Why am I telling you this?

55:58Adam Stacoviak:Okay, the reason I'm telling you this is like, is I want to spin up different layers of Vincas or a different container of VM, and I want them to be in an isolated state. I want that particular container to know nothing about anything else around it. As far as it's concerned, it's in black space. Like it's literally, there's no star around it. There's no asteroid. There's no planet. There's no moon. Like it's just in a sea of abyss. And all it could do is do internet traffic out, pull down updates, send traffic back, but to its peers, there is no peer. You could do that with typical networking, but it sounds like with a multinet or some telnet food that I just don't have yet that I'm still learning about, I might be able to jail one of those containers or VMs in ways I just wasn't able to do before.

56:48Adam Stacoviak:So that's why I'm camping out as like this world of like network isolation. Put that new instance, that new VM or new container into network jail, essentially. Basically, yeah.

56:59David Carney:I mean, a lot of the stuff you can do with multi-tailnets, you can do with just modifying the policy file in a single tailnet. If your rules are aggressive enough, for instance. But there's a lot of people that were like, no, I don't want to mess around with a complex policy file. It's too risky. Or I'm dealing with multiple customers, and my customers demand complete guarantees and isolation between them. I don't want to be managing something where I accidentally add a star somewhere that all the customers can see each other, for instance. Multi-tailnet facilitates that significantly. A lot of it's just peace of mind.

57:40David Carney:Like, oh no, I have this particular tailnet. It's used exclusively for this. It's not like it can make a lateral. It can't move laterally to a different tailnet. They're completely isolated from each other. So it gives a lot of people just peace of mind. And frankly, it's like a divide and conquer kind of problem. It's like, well, why have one big complex tail net when I can have two simple ones?

58:02Adam Stacoviak:Or I have my own that I've authenticated with because you said you have to have an OIDC provider, right? I've got to authenticate with tail scale with one of those providers. Could be Google, could be GitHub, could be whomever I choose. And so that establishes my tail net. And then beneath me building on tail scale, I want to be able to have a whole separate tail net that is not, I guess, even tied to mine, but something I can talk to. but it's isolated, that's where I think you provide some networking that is just like dark arts, essentially.

58:31David Carney:Yeah, well with the API-only tailnets, you basically, when you create, when you get, I mean you get an OAuth client back. And then with that OAuth client, you can do things like add nodes, create OAuth keys, provision stuff within that particular tailnet. So it is still tied with what you might call the primary tailnet, like it is associated with that. but you know for all intents and purposes it's a separate network right well for me to spin up

58:57Adam Stacoviak:another subtail net i have to have a tail net which means i have to authenticate the tail scale right so i have to have a tail net to begin with to spawn subtail nets that are basically blue you know they're just blue oceans they're they're by themselves they don't have a clue whoever else is around them just but i have to i have to have a tail scale and a tail net to create subtail nets Yes, exactly. Yeah. Yeah.

59:28Adam Stacoviak:Well, friends, this episode is brought to you by our friends at Squarespace, the all-in-one website platform for building your online presence and running your business. Here's something I've learned over the years. The best developers out there know when to build and when to buy. And you could hand roll a booking system, wire up Stripe, build an invoicing workflow, stitched together email marketing. And honestly, you'd probably do a great job doing that. But that's weeks of your life spent on infrastructure that isn't your actual thing. Sometimes the smartest move is choosing the right tool so you can focus on the work that actually matters to you.

1:00:02Adam Stacoviak:That's Squarespace. It's the all-in-one platform that handles the business side of whatever you're building for yourself, for someone, for a friend, whomever. And two things I think are worth noting. First, offering services. If you're freelance dev, mentoring, content. Squarespace brings scheduling, invoicing, online payments, and EMO marketing together in one single place, one dashboard. You list your offerings, clients book and pay, and you skip the part where you are playing accounts receivable in your DMs, and it's a real business. It's a business workflow, not a pile of SaaS subscriptions that are kind of duct taped together.

1:00:41Adam Stacoviak:Second, selling content. If you've got your course ideas, your video tutorial ideas, or deep technical content you've been meaning to package up. Squarespace lets you gate it behind a paywall. One-time fee or subscription, it's your call. Recurring revenue from expertise you've already built, that's a good trade. And the point isn't that you can't build this stuff, it's that should you, maybe not. Okay, head to squarespace.com slash changelog for a free trial. And when you're ready to launch, use our offer code changelog to save 10 % off your first purchase of a website or a domain. That's squarespace.com slash changelog.

1:01:22Adam Stacoviak:And we use our link. Of course, you're supporting the show. And we love that. Once again, squarespace.com slash changelog.

1:01:34Adam Stacoviak:We got there by talking about different applications you think can be built on top of TSNet. And I think where we may have dropped off at or not given a good trail for, and I know the listeners may be potentially upset if we didn't do this yet, is like, can you give me a couple ideas? Like, if you can go and if you were at a, if you're in the hallway of a conference right now and you were just talking to some folks, you know what, here's what you can go and build on your TSNet or TSNet application. Here's a place you can go play. If an enterprise came to you and they're like, you know, we're just leveraging our tail scale, our tail net in these ways.

1:02:09Adam Stacoviak:How, what are some problems they're coming to you with that you're like, we're not going to get to that for a while. These are things you should build. What problems are some of your largest customers just, you know, on your, not so much on your case about, but what's the loudest cry in the woods of this is what I want to build on top of my TS net.

1:02:28David Carney:One of the bigger issues that a lot of, especially larger companies, that I've seen coming up more recently is they have a traditional network, traditional VPN. It's like one monolithic thing. And they're trying to bring up MCP servers and they're trying to bring up MCP clients. And they've got these notions of, like, they basically are thinking like, oh, I've got now agents that are trying to operate inside of the network the same way humans used to. except I don't need to go on about the dangers of letting an agent run amok on an internal corporate network. But it's becoming

1:03:07David Carney:obviously more and more an issue for especially bigger organizations that have traditionally dealt with security from a very centralized monolithic perspective. So I think there's definitely been this push of how do we start segmenting or isolating or subdividing our network? How do we start decentralizing it more so that we can enable these different teams and pockets of the company to work more independently with each other or to work independently to solve particular domain problems while still enabling the velocity and freedom of access to required information. I think Tailscale is actually a way that companies can do that.

1:03:50David Carney:I think there's lots of different approaches, but Tailscale definitely makes it easy. It's just like, okay, well, instead of one gigantic monolithic network, maybe you start building one Tailnet per workload, for instance. And we've seen this kind of thing with people who are playing around with Kubernetes. And they have custom internal tooling that they need, some kind of internal and monitoring system. It's like, oh no, when we bring up a cluster, we've got these applications that need to sit inside of it. It has to sort of moderate or govern certain kinds of networking access. We do a bunch of log analysis.

1:04:19David Carney:Maybe we do a bunch of real-time stuff. How do we insert these applications that we've built into these networks in an isolated way? And so I think there's a lot of internal applications inside of companies that need to stay internal and private. Tailscale is good for that kind of thing. You can retrofit them inside of TSNet, and then you can encapsulate entire workloads inside of Tailnets themselves. And it helps people reason much more about safety and security that way.

1:04:44Adam Stacoviak:Where does someone get more details about Multinets then?

1:04:47David Carney:because this is multi-tailed yeah we i mean if there's a couple of multi-tailed net yes let me

1:04:52Adam Stacoviak:let me be on brand with that i like that yeah yeah multi-tailed net yeah i just shortened it to multi-net because everything else is something net ts net is like multi-net i'm just trying to

1:05:02David Carney:follow your lead there david no no it's good and in fact i'm sure our product team will watch this video maybe and maybe think more about the name we've been debating it internally of how to call these like what to call these things um there have been a couple of blog posts even over the past year. So even if you were to Google for like tail scale multi-tail net, you would find one. It is, I believe, in beta right now. I'd have to double check that. But it is accessible.

1:05:30Adam Stacoviak:Yeah. To home lab users? Yep. Sweet. Okay. While you're doing that look up here, I'll fill some air with this. I think for the branding team or marketing team, whoever's listening, our listeners as well, I think the better name actually is multi-tail net. because you already say tail net. It would not make sense to shorten that to multi-net. I messed up. And so I put my branding hat on thinking about how I would actually frame it in my own mind if it were my product. And I would call it a multi-tail net because that's truly what it is. That's what makes the most sense to me as well. So if that's what you all are thinking, good job.

1:06:07David Carney:Yeah, I just double-checked. Yeah, so our marketing team did a great job with this fall update we had back in late October. and there's a blog post called One Organization, Multiple Tailnets. It talks about this over a page or two and then just how things are, at least at the time of this blog post in Alpha program. But we've been steadily working on the features related to multi-tailnets over that time.

1:06:31Adam Stacoviak:I'm super interested in this. I'd love to see where this goes because I think there's a lot of opportunity with subnets, multi-tailnets, this problem that your customers are bringing to you. I concur with that because there's things that I'm doing inside my network that essentially is on my flat VLAN. I got my traditional network that's across my 192 space. And then I got my tail net, of course. And there's things I want to isolate that I'm just not. And I guess I'm just crossing my fingers because I'm moving at a velocity that doesn't let me slow down enough to be secure. And that's the job of tail scale, I feel.

1:07:09Adam Stacoviak:That's why I use tail scale. That's why I keep investing more and more of my knowledge into what you are doing because you guys are just networking wizards. And you love Go. I love Go. Yeah. If you're not going to be at GopherCon this year, David, you all should reconsider that. GopherCon is the best place to be. Yeah, I just think this is super cool, this idea of multi-tail nets. So I want to dig into this. Between this and TSOI. What was it? My gosh. So many acronyms. I'm in my notes here. Don't tell me.

1:07:43David Carney:We need better names. We need better names for these things.

1:07:45Adam Stacoviak:It's okay, though. I mean, it is a TSIDP. That does make sense. It's a tail scale identity provider. That totally makes sense. There's just so many acronyms in this world. It's hard to keep them all on the tip of my tongue. So you got a lot to cover there. So those are two things I'm taking away from this for me personally on homework. Because I don't want to log into my Proximus anymore. I don't want to log into certain things I'm self-hosting. If everything I self-host that has a login prompt, even my TrueNAS box, if my TrueNAS box can be OIDC compliant and let me use this TSIDP, gosh, I'm on it.

1:08:23Adam Stacoviak:Yeah. Then that'd be great, you know, because I don't have to log in anymore. That'd be awesome if my identity could truly just follow me. And I think the challenge that I think for you all is it's a constant, I would say marketing battle, but I think it's like you have so many home labbers out there. So many people probably playing with your stuff. You need more people just naturally sharing this stuff. And I know Alex does a great job on your YouTube channel. I mean, just tremendous job on that front there. I think you're going to constantly have this problem, David. I don't envy your position at all with constantly having to update people, but there's just a sea of great stuff underneath tail scale from multi-tail net to the things we just talked about.

1:09:07Adam Stacoviak:Those are things I'm walking away with. I do want to circle back to, if you don't mind, this idea of Aperture and really just this less about the product, but more about this idea of having an AI gateway. Help me understand why you feel so strongly about it. I imagine you do, because I'm kind of having this feeling too, is that I'm not sure if I'd apply it in my home. I think maybe I would, but certainly in a burgeoning team, a small team, definitely in a smaller business or an enterprise where you're sort of like mid, small to medium size. But this idea of an AI gateway, one for security, two for API keys and just like the concerns there.

1:09:52Adam Stacoviak:But even just me not having to have this anxiety of loss when it comes to transactions I'm doing with a generative AI, where I'm knee deep in a world where exploring it, you know, it's largely just pros. It's largely defining specifications, largely defining intent. It's largely even learning about things, building toy applications just to learn. Not so much to build something to ship it to the world, but to learn about even authentication. Like when I go play with multi-tailing nets later on, I'm going to go build a toy application and I'm going to work with an AI to do that. But it sounds like the gateway can help me have a transactional history.

1:10:32Adam Stacoviak:Help me understand that world of an AI gateway and what people can do with it.

1:10:35David Carney:Yeah, so we're definitely not the first person to build an AI gateway. I mentioned this in a blog post just the other day, but I was talking with another founder months and months ago and they're just talking about the proliferation of gateways and they're like, oh, it's the obvious idea. And I agreed at the time, but then later on I realized, oh no, there's a tail scale spin that can make things much simpler and so we should just show the world that. but Aperture in particular let me think maybe I should talk about it but the reasons I love working with it

1:11:10Adam Stacoviak:because I think it'll resonate you've been knee deep in 12 months of research you must have if you don't love it, we've got problems

1:11:18David Carney:I love it because it's kind of like tail scale the first time you used it was just like oh my gosh, everything just got easier and tail scale seeing that wow, or that realization of just like, wait a sec, here's all the work I didn't have to do. And Aperture is kind of the same thing. It's like, oh, if you have a coding agent that you can point at a proxy, you can use Aperture. If you're using API keys. And so I've run Aperture on my home lab. And the reason being is just like, oh no, I've got a server. I like to run everything through it. I like to have all my logs. I just want one spot that if I'm working on my laptop or elsewhere and I need to connect to my tail net, I just have a single path.

1:12:09David Carney:Something where I just know I'm just going to route everything. So I can take my tail net anywhere. That's one of the nice benefits of it all. From a team perspective, it lets us have full visibility into the logs of other members of our team. So I can, it's like, oh, how is my teammate Ben? How does he write prompts? Why are things with him? He does things much more efficiently than me. I'm curious, oh, I want to learn from Ben. How is he constructing the prompts? How is he interacting with these LLMs? It lets us have access to all sorts of, I guess, different backends. So we use Cloud Code extensively.

1:12:49David Carney:You can get to Opus through a variety of means. You can go directly to Anthropic. you can use Bedrock so we've got both of those configured inside of Tailscale there's been times where Anthropic or Bedrock have had issues of being able to just quickly switch over to the other one it gives us obviously I guess metrics into token usage across the team so like input, output, cache, tokens, reasoning, tokens who's using what, that kind of workload it gives our security team visibility because most people don't realize this every API call is stateless which basically means that entire context window is getting shipped back and forth across the wire every single time.

1:13:27David Carney:We log every single one of those. And then we've got some tech in there so that you can consolidate those into sessions so that you can actually go through all the API calls in a given coding session and get context and understand what's going on with that, which is really helpful for visibility. It's like, oh, what was Carney working on at 2 a.m., for instance? And then from, I guess, maybe more of a legal and a compliance standpoint, you could actually start, you know, you could start pointing your Git histories back to individual coding sessions. Like, oh, like this code was developed in conjunction with this developer, like, and here's the proof of why and who contributed to it and how, because I know that's an issue that some legal teams have brought up.

1:14:07David Carney:Our security team, you know, we can export the logs. There's a lot of like, like post hoc analysis you can do and those kinds of things. We're working with integration partners to do like sort of real time investigations of like tool calls, for instance, or like after the fact log analysis. So there's a bunch of fascinating stuff there. Could you block things? Yes. I mean, the short answer is yes. Something like an AI firewall even, too. That's why I think it's really interesting.

1:14:36Adam Stacoviak:You can do so much with this gateway.

1:14:38David Carney:Yes, you can. So we mentioned them in a blog post just the other day, but there's some integration partners. Oso is one, Servos is another. Yeah, I love Oso. Yeah, and so they've been great to work with just over the past few weeks. But yeah, we have an integration with them where we have an API, for instance, tool call hooks, they can intercept them and analyze those. And you can start to do things where you can dynamically adjust your network or your security policy based on effectively real-time signals.

1:15:15Adam Stacoviak:Yeah, like activity. what's being called what's being prompted what's is that what you mean about that like if I'm trying to do not so much nefarious things but let's just say dangerous things yes I could be a new developer new builder or just maybe have ulterior motives who knows what but like could you pay attention essentially and like do different

1:15:39David Carney:things and react or you have or you have like an agent that is starting to get a little bit more fast and loose with the rules and starting to access things that maybe it shouldn't be. There's ways we can send signals out to those tools and those tools have their own application-level network policy that they can start to adapt in real time based on signals they're getting from Aperture because it's all centralized. So you can say, oh, this agent or this person or whatever, they're deviating a little bit off of the regular behavior. Maybe we should start locking down or auditing more and slowing down their interactions with these kinds of resources.

1:16:17Adam Stacoviak:Is there latency involved in this if you're doing tool level? Is it literally like, does the call go to the gateway back to the agent to allow it? Or is it just paying attention and sniffing it?

1:16:31David Carney:Well, right now, it's just the sniffing part. We actually are working on, I guess, adding an approval loop. Well, like RMs.

1:16:39Adam Stacoviak:Don't do RMs that are dangerous RMs, for example. Yes, do some of those because you have to remove files and add files and take things away. So yes, do that. But if I can intercept a really dangerous RM or a SQL injection or a database drop or a table drop or who knows what, that's where I would want the gateway to even as a developer give me the ability to go in the dangerous zone of using the agent because I want it to have free reign. I really hate sitting there babysitting the yeses and the nos and like, oh my, yes, please commit and push the code. I don't want to tell you to commit and push.

1:17:16Adam Stacoviak:That's inherent. That's what we do here, okay? It's part of like getting in and out of the door. Let's do, I don't want to babysit you doing that. So I almost live in a dangerous world. I do live in a dangerous world. I would say like I do dash dash dangerous a lot on pick your, you know, codex, opus, whatever. but I feel like this gateway could be my security policy and maybe even my own personal big brother in a way.

1:17:46David Carney:We're not going to build that entire ecosystem. It's one of the reasons we want partners so early to demonstrate the fact, oh no, we want to work with a lot of people. We're not going to build everything ourselves by any stretch of the imagination. There's a lot of really incredible tech out there that we want to be able to plug into. A lot of great teams doing deep research on this kind of stuff. We think of our tail scale as generally a very broad, horizontal connectivity platform. It's pretty deep in the stack. There's a lot of great tech that can be built on top of that. It's also just part of a security solution.

1:18:24David Carney:There's no way I'm going to run a coding agent on my machine with dangerously skipped permissions, for instance. I'm going to do that in a sandbox. no no i'm doing it i'm doing oh gosh i'm doing i'm not doing it locally i i have a sandbox i have a sandbox in a cloud provider that can't get out and you know i don't put i don't put my ssh keys on that thing i just i push things to it you know and i think there's i know my colleague avery our ceo he's been experimenting a lot with this kind of stuff too just like yeah because like velocity is super important you know these agents nowadays and like just like the code like lms are just improving dramatically week over week.

1:19:01David Carney:I want to give them, I want to really leverage that safely. And I think Aperture is part of that safety solution, but it's not the whole answer.

1:19:10Adam Stacoviak:So you built an AI gateway with identity baked in. Yep. API keys not have to be passed around. There's a lot of benefits here. You mentioned the desire for partners. Give me an idea of what you mean by that. You said, we're not going to build all that. And you alluded to all that. We talked through a bunch of stuff. I mentioned agent policy and stuff like that. What do you mean by all of that? And how can partners step in? How can an individual, a team of one, step in and become a partner of Tailscale and build out what you're not going to build out?

1:19:44David Carney:Well, let me think. I mean, they can contact me. Okay. Happy to have a conversation with companies and individuals working in this space.

1:19:51Adam Stacoviak:What's the best way to reach you? You want to say your email address here or is there another way to get a hold of you?

1:19:57David Carney:Oh, just aperture at tailscale.com. okay i'll see it yeah that's you uh yeah well it's it's it's me and the team it's it's you plus

1:20:05Adam Stacoviak:yeah it's the proverbial you yep and uh aperture is a p e r is that right or a p u r e r yeah i always misspell i mean listen ever since aperture apple had this software called aperture for photographers if you know this you know 15 years ago it was amazing they don't make it anymore I've never been able to spell aperture properly it's like I gotta remind myself you know I before E after like every single time my brain doesn't get it okay so please spell aperture if you don't mind info aperture at tailscale.com A-P-E-R-T-U-R-E put that in the show notes for everyone to get a hold of you because I'm really curious about this I think this is cool I mean when I first heard about it I was thinking oh my gosh big brother but then we kind of need a big brother in a way because agents can't be trusted.

1:20:55Adam Stacoviak:Until we can trust them, we sort of have to big brother them because they're already big brothering us in a way. And logging all the things to me gives me some peace of mind because I want history. I want my own history. And from an enterprise standpoint and maybe a peer standpoint, it might be a little weird to see what David's coding or how you're prompting, but I don't know. I think we're going to have to be just okay with that to some degree. But I'm going to want to learn or peek over your shoulder and say, well david's clearly like 10x in my own 10x here what is he prompting here you know how is he what is this magic he is he is doing here maybe it's just like do it yeah is that your prompt david just do it oh there's been i've been tempted sometimes that's my prompt it's like yeah there's an idea do it yeah i like that sounds great that's an amazing idea i gave you the

1:21:44David Carney:original idea you morphed it now it's amazing yeah do it do plane one i love that yeah i i spent a lot of time in planning mode with Claude. It is crazy, though, how fast those tools can let you move and the stuff they can do if left unchecked. You've got to be careful. I think, I guess, comments on a couple of things you just said.

1:22:09David Carney:We've got some basic permissions with Aperture right now. Users can only see their own stuff, for instance. Admins can see the world. We've got of stuff to implement there about, oh, maybe we only want a team to be able to see logs within their team. Maybe we only want a manager to see the team members. There's all these different kinds of, I guess, access models that we need to explore with customers on this. And we are doing that. So there's a lot of room for new features there. But again, we're just trying to keep things simple at this point. One of the neat hacks that we've done internally, and I really like this one, is that you can actually point a coding agent because we have an API.

1:22:48David Carney:There's a whole bunch of endpoints inside of Aperture. And one of the endpoints inside of your tailwind is that you could actually get your own logs out of it. So you could point a coding agent and say, oh, I want you to explore basically how you've worked in the past. And so you can start to get these recursive learning or feedback loops with a coding agent reviewing how it's worked in the past or reviewing its previous logs. And I think there's a lot to unlock with that. We've just only started to scratch the surface. But as Yield has some really interesting insights for us as we've been digging into, how do these protocols work, for instance?

1:23:24David Carney:How do these coding agents tend to function? When they start delegating stuff or using sub-agents, how do those mechanics work? And so I think for a home lab, if you want to explore more about just the protocols and the request headers and the bodies and how these coding agents are sort of, how the API calls evolve and how the contacts evolve, it's super neat.

1:23:45Adam Stacoviak:I like the fact that you have access models. That gives me more peace of mind because, you know, gateways are great. You already have it at the network, so you can't hide from that. And IP addresses, DNS, those reveal a lot about an individual. But, you know, an LLM and your interaction with a model like we do today reveals, you know, a lot more because you may say, hey, I'm new to this scenario. and like maybe your team thinks you're really steeped in it or whatever i think you're more advanced and that's not so much judgment happens but you you may show or have to be more truthful with your awareness and level of understanding of something and that may be either one be embarrassing or a fireball fence or i don't know but then you start to think about like okay who has access to that information i realize this is all work stuff but i have to be and we're almost getting more and more i don't want to say the word intimate but it kind of is the word a little bit more relational a little more intimate with the other side let's just say the the machine behind the machine uh because it feels a lot like we're talking to something a peer and it in a lot of ways it acts as a peer as an educational peer education is dramatically changing let alone uh code level understanding like navigating code base is so much different today than it was like, like not even 180, like, like 720 difference in terms of like spins that it's just dramatically different to navigate a code base and have an understanding in a world where you have agentic properties available to you.

1:25:19Adam Stacoviak:And in a lot of cases, you might be more forthcoming with the agent because you have to be, you know, to get it, to give you what you need. You kind of have to be like, you know what? I don't know a lot about this subject matter. You know, can you, can you, can you steep me in it? Can you school me? what do I need to learn here? Can we build a toy application? And then you get launched into it, but it can be a little revealing. Sometimes maybe too exposed. And that's where I, that's where I was like, you know what? I like the fact that you have guardrails because I was a little, a little apprehensive myself in my own self-hosted version of it.

1:25:51Adam Stacoviak:Hey, that's cool. Cause I'm not judging me, but somebody else might if I'm in an enterprise. Yeah.

1:25:55David Carney:Oh, totally. No, I, I, I have like, when I started using coding agents, like the prompts are like, I, I almost, I'm scared to go back cause it might be. It's like, ooh, I was burning a lot of tokens on useless things. I didn't know how to use this tool properly. But the thing is, we're all trying to learn how to use these tools properly. And the thing is, they change every few months. I think back to earlier Sonnet versions back in September versus what I'm using now. It's night and day, the capabilities. Teams really have to stay on top of this stuff if you want to keep up with it.

1:26:31David Carney:privacy, obviously security is key. I think people have to be pretty open and candid and transparent if they actually want to learn with this space and really leveraging and getting advice from other people too. Which is another one of the reasons I'm so excited about Aperture just in terms of the transformation I think it can help our company make. Because we're seven years old. We've got a lot of incredible engineers and other people working on all sorts of technical stuff. When we started the company, LOMs basically didn't exist. And look where the industry is now. I dare think where it's going to be a year from now, we have to adapt and learn more about these things.

1:27:08David Carney:But a world where people are just clicking yes all the time is not a world I want. I want us to be leveling up. And I think to do that, you have to look at what you did. It's kind of like code reviews, just much more aggressively. It's like prompt reviews and just understanding how do these tools work. How do our workloads need to change? Where did this agent go wrong? Where did they make the wrong kind of assumptions? How do we have to shape our code base so it doesn't do this in the future? That kind of stuff. There's so much knowledge that we have to uncover of how to work with these tools going forward to make them effective.

1:27:44Adam Stacoviak:I love the fact that prompt review and PR, pull requests, just naturally translate. I don't know if that was like serendipitous 17 years ago when GitHub inspected itself and said, okay, pull requests are the thing. Fork yourself kind of stuff. That was like the founding detail of GitHub was being able to fork a code base and submit a pull request. It was brand new territory. And now look at us. We're just talking to our code bases. I still can't believe it. I still can't believe it. I have to pinch myself every day like, that's crazy. I don't know about you, but GPT 5.3 codex is really, I've just never worked with an agent that was that advanced.

1:28:34Adam Stacoviak:It's like working with the most advanced engineer ever. And in some cases, I'm a little pissed because it's like it knows way more than I think I would ever know. And I'm almost like, yeah, I know a lot about this. but like, wow, you clearly, you're speaking a whole different language and you're moving way faster than I can ever do it. And it's a little scary. It's a little scary. But I think this gateway idea has got some merit, especially in the field you're trying to go to, which you need a killer app, right? You need a killer app on tail scale that is beyond the VPN, right? So this is taking you beyond the VPN.

1:29:07Adam Stacoviak:It's taking identity in a whole new place. It's securing our API keys in ways we've never been able to before in a world that is burgeoning and very tumultuous in terms of security. so I'm all for this my only my only desire would be uh self-hosted at some point and whenever you get to that obviously you know I'll I'll check it out no matter what between now and then but I'm going to be in a world where and this is just my own personal opinion I've just been in this world where these are the kind of things that I want to have sovereignty over and I already have compute so why not dedicate my own compute to it I'm happy to pay a licensing fee or you know the business model however it needs to go but i'm in this world where i want to self-host a lot more than i ever wanted to before and it's not it's not that i don't trust the world it's when i want to have more control over the world i'm building and they're already interconnected i've already used uh tailscan already have my tail net i haven't tapped into multi-tail nets yet but i'm going to that's where i'm at is is uh give me the self-hosted version of it because that's gonna be that's gonna be fun i hear you yeah i hear you what's uh what's left what have i not asked you about your journey with tail scale what you think people do and don't know what like what is the biggest myth if you could debunk a myth about tail scale what what might that be do you often have to debunk myths about what you do and what you don't do and how deep of a well you all have

1:30:35David Carney:one of the myths is that we're just for home labs or small teams that's not true we've got a significant number of enterprise customers but I've often heard and called bump into people at conferences who were like oh so and so was saying that you're just for home labs or you're just for small teams you're just like a hobbyist kind of thing it's like no we're serious you have some of the most advanced engineers

1:31:01Adam Stacoviak:I've ever known of Like you got some really talented people in your team. I'm, I'm very fortunate. I know you agree with that. You really do.

1:31:09David Carney:You have some serious engineering talent. Yeah, we do. Yeah. I'm very grateful for that.

1:31:14Adam Stacoviak:It's, yeah, it's an incredible team. Brad Fitzpatrick is one of the ones I'm thinking of. Like he's been on our podcast, Go Time. We used to host this podcast called Go Time. That's why I'm so emphatic about GopherCon even too, and, and go the language. And Brad's been on that podcast. And I think, I'm not sure who all is still there over these, all these years, but a lot of folks that I've just paid attention to and have leaned on for wisdom on how to morally navigate the software we're building, even from a technical level, just bar none, some really awesome people there.

1:31:45David Carney:Yeah, yeah, I count my blessings with the team we have. But yeah, to talk about the myths, we're never going to give up having a free plan. Free forever. Yeah, free forever. We're always going to have something, and we're going to be pushing more and more into that over time. That's really important to Avery and me and so many other members of Tailscale in general. But we are building more and more stuff all the time, and a lot of that has enabled us to just take on bigger and bigger and bigger customers to help, frankly, pay the bills and help us grow and help us expand. It just makes Tailscale a better product for everyone.

1:32:25David Carney:We are definitely enterprise-ready. and that has been one of the myths that over the past couple years we've done a lot I think to establish that but there's always more I think we could do because we've come bottom up and so there's always that people who learn about you in the early days that's how they think about you, it's like the curse of SaaS once somebody adopts you, you have to spend so much time re-educating them because the products change and evolve a lot and so we had a lot of early adoption and we have to go back and just talk more about what we did and the technologies we've built and where we're acting and the kinds of customers and stuff that's one of the myths the other one is that we're just a VPN tailscales more than a VPN a lot of conventional VPNs it's all about IPs and connections like tailscales bakes identity and it's a fundamental guarantee of every connection you know who and what is connecting if it can connect to you it's already authorized and you can tell who it is immediately you know who it is and that is that's more of a paradigm shift where people think about like connectivity and identity being the sort of the same thing or paired very closely together which is not how most people think about like networking they think about oh i've got this connect i've got this connection and then i've got identity that's like way on top somewhere like layer seven it's like oh no no it's but tail scale it's like it's baked in and if it is you can just do so much more with that you don't have to think of worry about identity and i think that once people get their head around it like you can see these lights go off that's that's the real sort of yeah like i said paradigm shift i want to bring to people i do not know what you can do differently

1:34:04Adam Stacoviak:because i'm a i would say i'm a pretty steep user of tailscale and and even some of the things you're saying now about these myths they're myths even to me as a as a daily active user of tailscale i don't know what you do or what you can do to solve for that problem um but i agree not just a vpn it's unclear to me how in all the ways that my identity is attached to my, it obviously makes sense not to explain it like that, but it's just not obvious in my daily use of it. Even when I SSH run my network, I don't do it via tailscope, I don't think. I will SSH via tailscope with like maybe, let's say if I have a machine that has a host name of Cineplex.

1:34:49Adam Stacoviak:So my Plex machine is called Cineplex. It's not like that. I'm just SSH Cineplex. I don't know if I'm using any special niceties of tailscope besides maybe host name mapping. That's about it, probably. I'm not using my tailscale identity, I don't think. And that's maybe my own fault. Maybe it's your fault. I don't know. But I agree. I feel like I learn more and more about what tailscale can do for me because you do so much. and I don't know how you explain to folks more differently than you already do. Besides just keep, I guess, keep trying. I don't know.

1:35:24David Carney:Yeah, good infrastructure gets out of your way really quickly. And that's been a guiding principle for us ever since day one.

1:35:33Adam Stacoviak:Yeah.

1:35:33David Carney:So you don't want infrastructure to make noise. At the same time, it would be awfully nice if more people sort of, I don't know, just understood all the cool stuff that we were building. So it's a very tricky balance. We try to be very quiet, just works, like always works, in the background. Do we want to make a lot of noise about our new feature? It creates tension, I'd say. We try to be very cautious with that.

1:36:03Adam Stacoviak:Even with Aputure, just thinking out loud here, I think one of the ways you can show off a lot about it is not so much build-tweet applications, but show off the cool things you can do with it. Like this podcast is one example diving into it. There's just so much you could do with an AI gateway, which I think is worth exploring. That the way you can explain things to folks is really just to show it off, demo it. And maybe that's conferences. Maybe that's in the hallway track. Maybe it's via YouTube and Alex's team and what they're doing there. But I think there's so much you can do with identity on your network that I'm just now thinking about that I personally care deeply about on a daily basis because I'm building things that require it.

1:36:47Adam Stacoviak:And I'm not leveraging any of this tooling. I'm doing it the hard way despite being a user. And I'm almost angry at you and the proverbial you for not, and maybe you do. And maybe Alex is like, Adam, just watch my YouTube. And maybe that's the easy button there. Alex, there's a lot of content. Yeah, there's a lot of things.

1:37:07David Carney:But, you know, don't put an LLM on a public port. You know, don't put an LLM on the public internet. Don't do that. But you can share that with, you can create a private network and you can share that with your friends with Tailscale. There's so many little things like, it's like, oh, I just didn't realize there's sort of an easier, better, more secure way.

1:37:28Adam Stacoviak:I'm telling you, I need to know the easier, better, more secure way, the Tailscale way, the Telnet way, the multi-Tailnet way. I can't wait to play. oh my gosh I punned and I rhymed at the same time David it's been so awesome talking to you going into the details of this I'm a big fan as you already know I'm looking forward to the self hosted version of it as you already know because I've said that a couple times already I think that's where the future is at in a lot of cases here I can see why you're spinning up instances to achieve velocity but I think ultimately sovereignty is the key to my book at least so there you go for that front there Anything left in closing?

1:38:06Adam Stacoviak:What else you want to say? Aperture at tailscale.com. We'll put that in the show notes, of course, to reach out to you to become a partner or a builder who's got some ideas on top of TSNet and the things you're building there, or maybe even Aperture itself.

1:38:18David Carney:What else? I invite people to reach out, whether it's for partnerships or ideas or feature requests or whatever. I'm here. I'm accessible. I don't want people to think that just because tailscale's a few years in and we're sort of the size we're at right now, that I'm unreachable and that we're, you know, we definitely don't have all the best ideas. We've got some good ones, but we want to work with a lot of other people and help them get their ideas to market quickly and in a more safe, secure, and expedient way. Yeah, please, reach out. I'd love to hear from people. Maybe some office hours for you.

1:38:57Adam Stacoviak:Maybe you could do some office hours. Would you entertain that?

1:39:00David Carney:Yep, yep. No, that's come up. that's definitely, I think once we get through a bit more of this push on Aperture. I'd record it too.

1:39:06Adam Stacoviak:I'd turn it into some content because I mean, I would pay attention to the behind the scenes of that. I think that's like peer-to-peer is where I think a lot of developer, that's one of the ways we really educate folks that listen to our pod and we have a lot of sponsors who sponsor our stuff. But one of the directions we take is not just throw an ad out there, but something that's like, it goes behind the scenes. It's informative and it's peer-led. And you can kind of see, okay, well, this one team over here has got this idea for how they can leverage Aperture or an AI gateway. And now I can see what they're using it for.

1:39:45Adam Stacoviak:Now I've got some ideas as well, kind of thing. I think Office Honors could be kind of fun. And to speak to the top like you are and your team members, that'd be kind of cool to bring some questions, dig into how that works out, throw some ideas out there. let it be a little loose but also a little structured and yeah that'd be cool I could see that happening

1:40:05David Carney:yeah it'd be a lot of fun I'm yeah I just I love helping people get their ideas to market and removing some of the pain like it's just it's such a fantastic experience and I just want to see and help with more of that yeah very very very happy to talk to people about their ideas and work on collaborations and partnerships and stuff like that

1:40:24Adam Stacoviak:alright well David thank you so much appreciate you awesome meeting you awesome conversation yeah thank you we'll see you again soon

1:40:34Adam Stacoviak:well that's it the show's done thank you for tuning in big thank you for being a listener of this podcast if you haven't yet become a member it is free yeah you can go to changelaw.com slash community free to join hang with us in zulip chat everyone's there everyone's welcome and you are welcome and i want to see you there and if you love this show just a little bit more than you love every other show out there and you want to go deeper get bonus content get closer to the metal drop the ads support the show but we have a membership that is not free it's called changelog plus plus learn more at changelog.com slash plus plus it's better it is better you know why it's better because you get bonus content you get the little extras you get close to that metal and like i said you support the show big thank you to our sponsor for this show today big thank you to bmc for being our beats freak in residence the brake master cylinder my gosh those are awesome beats and thank you to you for tuning in to this show that's it we'll see you again soon

1:42:04To be continued...

From the publisher

Adam talks with Tailscale co-founder and Chief Strategy Officer David Carney about where Tailscale is headed next: TSIDP, TSNet, multiple tailnets, and Aperture. They get into clickless auth (via TSIDP), TSNet apps, multiple tailnets for isolation and control, and Aperture, Tailscale’s private AI gateway for API key management, observability, and agent security.

More from The Changelog: Software Development, Open Source

All 232 episodes
From Tailnet to platform (Interview)The Changelog: Software Development, Open Source · 1 h 42 min
Listen in VO