โ€น All docs / Admin & infrastructure / VPN
๐Ÿ”’
Admin & infrastructure

VPN

A Tailscale tailnet for your workspace โ€” secure, private access to internal services from anywhere, with nothing exposed to the open internet.

Overview

The VPN page is the front door to your workspace's Tailscale tailnet. It shows whether the integration is active, lists the devices on the tailnet, points to the internal services you can reach over it, and gives you everything you need to join โ€” install links and step-by-step instructions.

VPN page on desktop
Tailnet status, devices, and how to join.

Features

How it works

VPN is backed by the Tailscale Kubernetes operator running in the cluster. The workspace reads tailnet status โ€” and, with a Tailscale API key, the device list โ€” and renders it here. Devices that sign in to the same tailnet gain access to the services the operator exposes; no ports are opened to the public internet.

Backend
Tailscale (WireGuard-based mesh VPN)
Operator
Tailscale Kubernetes operator in-cluster
Config
GROWN_TAILSCALE_TAILNET + optional GROWN_TAILSCALE_API_KEY