tailscale / tailscale/tailscale

Tailscale Funnel but behind Authentication Service (OpenID/SAML or other)

Open
#14,244 0 comments 1 reaction 0 assignees View on GitHub
fr funnel needs-triage
Dominant language
Go
Stars
36.5k
Forks
3.2k
Avg merge
2d 3h
Merged PRs (30d)
123

Description

### What are you trying to do?

We are trying to expose local web apps on several nodes but behind a centralized user management (a paid service which is resistant to brute force attacks etc.).
If I understand Tailscale Funnel correctly, it would allow us to expose local web apps. However, anyone could access these devices/webapps.

It seems other [services](https://ngrok.com/blog-post/authentication-with-ngrok) have that scenario covered or at least documentation for it.

Is this something you would consider for TS Funnel?

### How should we solve this?

Provide more documentation / out of the box authentication support.

### What is the impact of not solving this?

TS only works for devices we use internally. Customers without TS client can't access the software.

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.