Tailscale Local Diagnostics CLI Pack
V3 bounded Tailscale local-device diagnostics capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local tailscale CLI ingredient exposes 18 fixed, read-only operations for version, node/peer state, local Tailscale IPs, physical-network checks, bounded peer ping and identity lookup, DNS, exit-node inventory, Serve/Funnel exposure status, Tailnet Lock state/logs, system policy, local accounts, metrics, and App Connector routes. This pack is intentionally separate from tailscale-api: it uses the installed client and its existing local identity state, never an API connection or token argument. All private daemon/tailnet/network reads require approval; only the local CLI version is approval-free. It exposes no custom --socket, login server, auth key, arbitrary argv, environment override, stdin, shell wrapper, or output-file write. It also excludes login/logout, up/down/set routing changes, SSH/nc sessions, Taildrop/Taildrive file access, certificates/private keys, Serve/Funnel mutations, Tailnet Lock mutations, system configuration, software update, web servers, GUI processes, and indefinite waits. Requires tailscale on PATH; all operations except version and netcheck require a compatible running tailscaled-equivalent local daemon, and tailnet-scoped reads require the local client to be enrolled.
What this pack installs
- tailscale-cli Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.