Tailscale publishing
Set up your tailnet so projects can be published privately or publicly.
Set up your tailnet so projects can be published privately or publicly.
Publishing runs a small Tailscale container next to each published project’s sandbox. It shares the sandbox’s network, joins your tailnet as its own device named after the project, and serves the app with tailscale serve (private) or tailscale funnel (public).
Leave TAILSCALE_AUTHKEY empty. When someone publishes a project for the first time, the Publish panel shows Approve in Tailscale. They approve the device in their browser and it joins as their device.
zap-publish-<id>-statePrivate publishing uses Tailscale Serve and works on any tailnet with HTTPS enabled. Public publishing uses Funnel, which your access policy must allow. New tailnets allow it for members by default. If it’s not allowed, the Publish panel says so.