Recued
Menu
← Back to packs

Tailscale Local Diagnostics CLI Pack

by recued-core v1 app_pack 14 views

V3 bounded Tailscale local-device diagnostics capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local tailscale CLI ingredient exposes 18 fixed, read-only operations for version, node/peer state, local Tailscale IPs, physical-network checks, bounded peer ping and identity lookup, DNS, exit-node inventory, Serve/Funnel exposure status, Tailnet Lock state/logs, system policy, local accounts, metrics, and App Connector routes. This pack is intentionally separate from tailscale-api: it uses the installed client and its existing local identity state, never an API connection or token argument. All private daemon/tailnet/network reads require approval; only the local CLI version is approval-free. It exposes no custom --socket, login server, auth key, arbitrary argv, environment override, stdin, shell wrapper, or output-file write. It also excludes login/logout, up/down/set routing changes, SSH/nc sessions, Taildrop/Taildrive file access, certificates/private keys, Serve/Funnel mutations, Tailnet Lock mutations, system configuration, software update, web servers, GUI processes, and indefinite waits. Requires tailscale on PATH; all operations except version and netcheck require a compatible running tailscaled-equivalent local daemon, and tailnet-scoped reads require the local client to be enrolled.

What this pack installs

  • tailscale-cli Ingredient

Trust & control

What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.

What it's allowed to do

Read Local CLI tailscale-cli read-only
Read: tailscale.version · No approvalRead: node.status · Asks approvalRead: node.ipv4 · Asks approvalRead: node.ipv6 · Asks approvalRead: network.netcheck · Asks approvalRead: network.ping · Asks approvalRead: network.whois · Asks approvalRead: dns.status · Asks approvalRead: dns.query · Asks approvalRead: exit_node.list · Asks approvalRead: serve.status · Asks approvalRead: funnel.status · Asks approvalRead: tailnet_lock.status · Asks approvalRead: tailnet_lock.log · Asks approvalRead: system.policy · Asks approvalRead: account.list · Asks approvalRead: metrics.snapshot · Asks approvalRead: app_connector.routes · Asks approval

Data it touches

SurfacesLocal CLI

About

Tags

pack:tailscale-clitailscaleclinetworkingdiagnosticsmesh-vpndnstailnet-lockservefunnellocal-servicesecurityv3composition