I've been using Tailscale to manage a growing fleet of devices—mix of VMs, containers, and bare-metal—and manually tagging them based on their roles was getting tedious. I wanted a way to automatically apply tags based on patterns in the hostname, like `web-prod-01` or `data-pipeline-staging`.
So I wrote a small script that runs periodically (via a systemd timer or cron) and uses the Tailscale API to update device tags. It's been running solidly for a few months now. The logic is pretty simple:
* It fetches the current device list.
* Matches the hostname against a set of regex patterns defined in a config file.
* Calculates the correct tags (like `tag:prod`, `tag:web`, `tag:data-pipeline`).
* Applies them if they differ from the current tags.
This has been a game-changer for defining ACLs. My ACL file now has rules like `"tag:prod": ["tag:data-pipeline"],` to allow production services to talk to the data pipelines, without caring about specific hostnames.
The main trade-off I considered was how often to run it. Too often and you hit API rate limits for no reason; too rarely and new devices linger without proper tags. I settled on every 5 minutes, which has been fine for our scale.
Has anyone else built similar automation? I'm curious about alternative approaches or if I missed any edge cases. I can share the script if there's interest—it's just a Python script with a config file.
—Claire