Tailscale

tl;dr

  1. We use Headscale – an alternative Login Server for Tailscale.

  2. You’ll need your BKSP ID account to connect.

  3. Our Login Server URL is https://tail.bksp.in

  4. Follow the official guide on how to use a custom Login Server.

Connect a Personal Device (PD)

  1. Download a Tailscale client for your platform.

  2. Make sure you have access to your BKSP ID account.

  3. Follow the official guide, using https://tail.bksp.in as Login Server URL.

ACL

Personal devices can connect to any other nodes unless explicitly defined in ACL policy.

Exit nodes

You’re welcome to use available exit nodes for your personal needs but please ensure you don’t abuse or violate local laws. If you’re unsure about your specific use-case, ask an Infra WG.

Subnet Routers

You can access B4CK network remotely while connected via Tailscale. This should work right out of the box, but if not – check this article on how to manually enable it on your device.

Caveats

  • Personal sessions are limited to 8 hours. You’ll need to re-authenticate after that.

Connect a B4CKSP4CE Device (M2M)

We discontinued using Konstantin’s Service Account as of May 2026.
Tag-only key is now a preferred method.

We connect B4CKSP4CE-owned nodes using tag-owned keys. Unlike personal devices, these weren’t linked to a specific BKSP ID account but rather a special service account within Headscale.

This prevents them from being affected by the default 8-hour session timeout and ensures they remain functional even after the Resident has left.

Tags

Tag

Description

ACL Excerpt

public

Public devices available to guests, thus are not trustworthy.

Incoming: allow from anywhere.

infra

Infrastructure nodes.

Incoming: allow from anywhere but public-tagged nodes

Creating a pre-auth key

  1. Open Headplane and log-in using your BKSP ID account.

    1. If it’s your first login into Headplane – reach to Infra WG and ask somebody to elevate your permissions.

  2. Navigate to SettingsManage Auth Keys.

  3. Click on Create pre-auth key.

  4. Fill the modal form as on the screenshot below:

    1. Select Tag-only key (1).

    2. Fill the ACL Tags for this machine (2).

    3. Avoid enabling Reusable or Ephemeral unless you’re fully aware of their functions and certain you actually need them.

  5. Click on Confirm.

  6. Pre-auth key will appear alongside with a proper tailscale up snippet to use.