3 ms·
> When would I want this over a more generic solution like linking to an idp using something like keycloak I assume everyone using Tailscale are opting for "si
by ElectricalUnion 1y ago
> When would I want this over a more generic solution like linking to an idp using something like keycloak
I assume everyone using Tailscale are opting for "simple code and adminstration" instead of "let me pierce NAT and handle Wireguard tunelling myself". On that point of view, "Identity management" is part of "stuff" that Tailscale helps you in the first place. So why not use it as the "Identity management" solution as well?
When you use `tailscale serve`, you get the headers
Tailscale-User-Login, Tailscale-User-Name and Tailscale-User-Profile-Pic that identifies who connected thru the tailscale endpoint. https://tailscale.com/kb/1312/serve#identity-headers https://tailscale.com/kb/1312/serve#identity-headers
On a separete side note, if you had an exposed OpenID Connect service in the first place, you can use it as the Tailscale tailnet auth SSO: https://tailscale.com/kb/1240/sso-custom-oidc https://tailscale.com/kb/1240/sso-custom-oidc
- red0point 1y agoDoesn‘t tailscale force you to bring your own SSO / IdP already? So it‘s not part of what Tailscale brings, it just adds another layer of indirection between the SSO / IdP you have already and the app, plus requires some custom library integration work, further enhancing lock-in.