Workload identity federation is now GA in Tailscale.

CI, cloud, and Kubernetes workloads can authenticate using native OIDC identities instead of long-lived secrets, with API, Terraform, and tsnet support.

https://tailscale.com/blog/workload-identity-ga/?utm_source=Mastodon&utm_medium=owned-social&utm_campaign=tailscale-winter-update-2026

#TailscaleWinterUpdate