PageSourceSearch

https://tailscale.com/_next/static/chunks/4693.16024e78633c60a7.js

js tailscale.com collected 2026-09-24 08:09:21 UTC 6,587 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[4693],{4693:function(e,s,n){n.d(s,{default:function(){return i}});var o=n(85893),r=n(10741);function t(e){let s={a:"a",code:"code",h2:"h2",li:"li",ol:"ol",p:"p",pre:"pre",ul:"ul",...(0,r.a)(),...e.components},{ConsoleLink:n,Note:t,Warning:i}=s;return n||c("ConsoleLink",!0),t||c("Note",!0),i||c("Warning",!0),(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(i,{children:(0,o.jsx)(s.p,{children:"Sym announced that they will be shutting down in April 2024."})}),"\n",(0,o.jsxs)(s.p,{children:[(0,o.jsx)(s.a,{href:"https://symops.com",children:"Sym"})," is a security and access workflow platform that lets you manage just-in-time access to your Tailscale resources."]}),"\n",(0,o.jsxs)(s.p,{children:["On-demand access to Tailscale resources can be provisioned using Sym. This works by adding and removing members from ",(0,o.jsx)(s.a,{href:"/docs/reference/syntax/policy-file#groups",children:"groups"})," defined in Tailscale ",(0,o.jsx)(s.a,{href:"/docs/features/access-control",children:"access control policies"}),"."]}),"\n",(0,o.jsx)(t,{children:(0,o.jsxs)(s.p,{children:["Sym will use a user's Slack email address in Tailscale access control policies. If the user's Tailscale email is different from the email used by Slack, you will need to use the ",(0,o.jsxs)(s.a,{href:"https://docs.symops.com/docs/manage-users",children:[(0,o.jsx)(s.code,{children:"symflow"})," CLI"]})," to manage the user identity."]})}),"\n",(0,o.jsx)(s.h2,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,o.jsx)(s.p,{children:"Before you begin this guide, you'll need a tailnet with at least one device and a Sym account."}),"\n",(0,o.jsxs)(s.ul,{children:["\n",(0,o.jsxs)(s.li,{children:["\n",(0,o.jsxs)(s.p,{children:["For information about creating a tailnet, refer to the ",(0,o.jsx)(s.a,{href:"/docs/how-to/quickstart",children:"Tailscale quickstart"}),"."]}),"\n"]}),"\n",(0,o.jsxs)(s.li,{children:["\n",(0,o.jsxs)(s.p,{children:["For information about creating a Sym account, refer to ",(0,o.jsx)(s.a,{href:"https://docs.symops.com/docs/getting-started",children:"Getting Started with Sym"}),"."]}),"\n"]}),"\n"]}),"\n",(0,o.jsx)(s.h2,{id:"integration",children:"Integration"}),"\n",(0,o.jsxs)(s.p,{children:["For the full set of instructions, refer to Sym documentation for ",(0,o.jsx)(s.a,{href:"https://docs.symops.com/docs/tailscale",children:"setting up a Tailscale access target"}),". To use Sym with Tailscale, you'll need to:"]}),"\n",(0,o.jsxs)(s.ol,{children:["\n",(0,o.jsxs)(s.li,{children:["Generate a Tailscale ",(0,o.jsx)(s.a,{href:"/docs/reference/tailscale-api",children:"API access token"})," from the ",(0,o.jsx)(n,{id:"settings-keys-page"})," page of the admin console. Then, ",(0,o.jsx)(s.a,{href:"https://docs.symops.com/docs/share-secrets-with-the-sym-runtime",children:"share this API access token with the Sym Runtime"}),"."]}),"\n",(0,o.jsxs)(s.li,{children:["In Sym, define a ",(0,o.jsx)(s.code,{children:"sym_integration"})," resource with ",(0,o.jsx)(s.code,{children:"type = tailscale"}),".","\n",(0,o.jsxs)(s.ol,{children:["\n",(0,o.jsxs)(s.li,{children:["Set the ",(0,o.jsx)(s.code,{children:"external_id"})," to your tailnet ID. You can find your tailnet ID in the ",(0,o.jsx)(n,{id:"settings-general-page"})," page of the admin console."]}),"\n",(0,o.jsxs)(s.li,{children:["Set the ",(0,o.jsx)(s.code,{children:"api_token_secret"})," to the ",(0,o.jsx)(s.code,{children:"sym_secret"})," referencing your Tailscale API access token."]}),"\n"]}),"\n"]}),"\n",(0,o.jsxs)(s.li,{children:["Define which groups you'd like to manage access to in Tailscale. In Sym, define a ",(0,o.jsx)(s.code,{children:"sym_target"}),"\nresource with ",(0,o.jsx)(s.code,{children:"type = tailscale_group"}),", and specify the ",(0,o.jsx)(s.code,{children:"group_name"})," that appears in ",(0,o.jsx)(s.a,{href:"/docs/features/access-control",children:"access control policies"}),", for example, for\n",(0,o.jsx)(s.code,{children:"group:prod"})," in Tailscale access control policies, specify ",(0,o.jsx)(s.code,{children:"group_name=prod"})," in Sym."]}),"\n"]}),"\n",(0,o.jsx)(s.h2,{id:"example-configuration",children:"Example configuration"}),"\n",(0,o.jsx)(s.p,{children:"When configuring Tailscale to work with Sym, you will need to set up groups that Sym can add users to and\nremove users from as their access is granted or revoked."}),"\n",(0,o.jsxs)(s.p,{children:["Use ",(0,o.jsx)(s.a,{href:"/docs/features/tags",children:"tags"})," when adding servers to your Tailscale network, so that their access is based on their\
1npurpose. Then, you can allow ",(0,o.jsx)(s.a,{href:"/docs/reference/syntax/policy-file#groups",children:"groups"})," to have access to certain tags in Tailscale access control policies. You can also make a\ngroup a ",(0,o.jsx)(s.a,{href:"/docs/reference/syntax/policy-file#tag-owners",children:"tag owner"})," if they should be able to manage tagged devices."]}),"\n",(0,o.jsxs)(s.p,{children:["For example, if you want the SRE team ",(0,o.jsx)(s.code,{children:"group:sre-prod"})," to be able to SSH into production servers with ",(0,o.jsx)(s.code,{children:"tag:prod"}),",\nyou can set up a configuration like:"]}),"\n",(0,o.jsx)(s.pre,{children:(0,o.jsx)(s.code,{className:"language-json",children:'{\n  // This is the group that we will add/remove user to/from\n  "groups": {\n    "group:prod": []\n  },\n  // This allows users from the prod group to list tailnet resources with the "tag:prod".\n  "grants": [\n    {\n      "src": ["group:prod"],\n      "dst": ["tag:prod"],\n      "ip": ["*"]\n    }\n  ],\n  // This allow users from the prod group to connect to instances with the `tag:prod`\n  "ssh": [\n    {\n      "action": "accept",\n      "src": ["group:prod"],\n      "dst": ["tag:prod"],\n      "users": ["ec2-user"]\n    }\n  ],\n  "tagOwners": {\n    "tag:prod": ["group:prod"]\n  }\n}\n'})}),"\n",(0,o.jsxs)(s.p,{children:["Now when an SRE needs to access production, they can use the ",(0,o.jsx)(s.a,{href:"https://docs.symops.com/docs/sym-overview",children:"Sym Slack integration"})," to request temporary access to SSH into production, and Sym will update the ",(0,o.jsx)(s.a,{href:"/docs/reference/syntax/policy-file",children:"tailnet policy file"})," to allow the temporary access."]})]})}function i(e={}){let{wrapper:s}={...(0,r.a)(),...e.components};return s?(0,o.jsx)(s,{...e,children:(0,o.jsx)(t,{...e})}):t(e)}function c(e,s){throw Error("Expected "+(s?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.