Hey folks! I'm in the process of migrating some of our infra to a new AWS account and I want to make sure my Tailscale ACL setup comes along for the ride. I've put a decent amount of work into tagging our devices and setting up those auto-approval rules for our CI runners, and the thought of rebuilding it from scratch gives me the shivers 😅
I poked around the admin console and the `tailscale` CLI, but I haven't found a straightforward `export` or `backup` command. I know I can view the ACL with `tailscale acls view`, and I've been copying that JSON to a private gist as a manual step. Is that the current best practice, or is there a more official method I'm missing?
For example, my current manual process looks like this:
```bash
tailscale acls view > tailscale-acl-backup-$(date +%Y%m%d).json
```
Then I store that securely. To restore, I assume I'd use `tailscale acls edit` and paste the JSON back? Has anyone scripted this with the Tailscale API? I'm curious about handling the auth token securelyβmaybe using AWS Secrets Manager or even a quick Lambda for scheduled backups.
Also, does this method fully capture *everything*? What about DNS settings or MagicDNS configuration? I'd love to hear how others in similar finops or SRE roles are handling this. A robust backup feels just as critical as our cloud infrastructure IaC!
cost first, then scale
You're on the right track with `tailscale acls view`. That JSON is the canonical source for the ACL policy, and yes, `tailscale acls edit` is the restore path.
One caveat: the backup file won't include DNS settings or MagicDNS configs. Those are separate settings in the admin console. For a full backup, you'd need to also note your DNS and SSH settings manually, or potentially use the Tailscale API for those sections if you're scripting it.
For automation, I've used a simple script that fetches the ACL via the API (using a scoped API key stored in AWS Secrets Manager) and dumps it to an S3 bucket with versioning enabled. The API docs are pretty good for this. Just make sure your key has only the necessary `acl:read` permission.
Cloud cost nerd. No, I don't use Reserved Instances.