Connect a Tailscale tailnet
Configure one account-level OAuth connection for private agent launches, DNS, routes, and custom tools.
Tailscale exposure keeps an agent workspace private to your tailnet and can give it access to approved private services. Connect the tailnet once at the account level, then choose Tailscale for individual launches.
Create the tag
Open Tailscale Access controls and create or authorize the tag shown in Cloud Console settings,
normally tag:pneum-agent. Your tailnet policy should define who owns the tag and which destinations
tagged devices can reach.
A tag does not grant unrestricted access by itself; ACL or grants policy still determines traffic.
Create an OAuth client
Open Tailscale Trust credentials and create an OAuth client with auth_keys write access and the
same tag. Copy the client ID and secret immediately.
Pneum.ai uses the OAuth credential to create short-lived per-launch auth keys. The OAuth secret is stored encrypted and is not inserted into VM metadata as a reusable tailnet key.
Connect in Cloud Console
Go to Cloud Console → Settings → Tailscale and enter:
- Tailnet: the tailnet name, or
-for the credential’s default tailnet; - Tag: the exact authorized tag;
- OAuth Client ID;
- OAuth Client Secret.
Choose whether launched nodes should Accept DNS, Accept routes, and enable Private custom tools. Select Connect Tailscale.
Option meanings
Accept DNS allows tailnet DNS configuration and is normally required for MagicDNS names and tailnet certificates. Accept routes lets the node use advertised subnet routes. Private custom tools allows the runtime’s approved custom-tool path to use private destinations.
Enable only routes and destinations required by the agent.
Launch and verify
Select Tailscale under agent Exposure. After boot, the card shows a tailnet hostname or DNS name. Wait for HTTPS readiness before opening the private UI.
Verify that the UI is reachable from an authorized tailnet device, unreachable from the public internet, and able to reach only intended private services.
Disconnect
Disconnecting the account credential prevents future Tailscale launches. Existing nodes and their tailnet state may require separate lifecycle cleanup. Review running agents before disconnecting or rotating the OAuth client.
Your response helps us keep product instructions useful.
