Tailscale ACLs for a Household: When Sharing the Whole Tailnet Is the Mistake

Mira Kessler

Mira Kessler

September 21, 2026

Tailscale ACLs for a Household: When Sharing the Whole Tailnet Is the Mistake

The default Tailscale household setup is generosity: everyone you love joins the tailnet, every device can see every other device, and the NAS shares that were “temporary” become reachable from a teen’s school Chromebook at 2 a.m. Sharing the whole tailnet feels like the product working. It is often the mistake.

ACLs are how you keep the mesh useful without turning every phone into a lateral-movement gift. This is for apartments and houses where the threat model is not APT29—it is lost phones, curious kids, contractor laptops, and the guest who still has an invite from last Thanksgiving.

What “share the whole tailnet” actually grants

Without restrictive ACLs, a tagged laptop can often reach admin UIs, cameras, home-assistant, SSH ports you forgot, and file shares that never had a strong password because “they’re only on LAN.” Tailscale extends LAN. That is the feature. Extended LAN without segmentation is how a stolen backpack becomes a remote tour of your rack.

People confuse “encrypted path” with “authorized access.” Encryption gets packets there privately. ACLs decide whether those packets are allowed.

Laptop and phone on a kitchen table with ethernet cable

Household roles that deserve different grants

  • Admin devices — your laptop, maybe a partner’s: reach management ports, subnet routers, full services.
  • Family user devices — phones and tablets: reach media, photos, maybe a printer portal—not Proxmox.
  • Kids / school devices — narrow allowlists; assume malware and curiosity.
  • IoT and cameras — rarely need to initiate much; often should be destinations only for admins.
  • Guests — time-bounded tags or a separate tailnet/user; never permanent “auto-approve everything.”

If your ACL file cannot name these roles, you do not have a household policy—you have a flat trust blob.

Router glow behind a frosted glass door

Tags beat individual emails for homes

Granting access device-by-device via personal identities works until someone gets a new phone. Tags like tag:admin, tag:family, tag:kid, tag:server let you rewrite policy once. Pair tags with auto-approvers carefully; auto-approving tag:server onto any device that asks is how you recreate the flat network.

Owners still matter for human accountability. Tags matter for durable policy. Use both.

Common household ACL patterns

Servers accept; users initiate. Phones can reach Jellyfin and Nextcloud. Servers cannot lateral into kid devices. Cameras accept connections from admin only.

Split admin plane. Port 8006, 9090, SSH, and router UIs allow only tag:admin. Media ports allow tag:family.

Subnet router caution. Advertising 192.168.1.0/24 without ACL limits gives tailnet members a path into whatever that LAN trusts. Advertise carefully; restrict which tags can use the routes; do not treat subnet routers as a shortcut around ACL thinking.

Exit nodes are not VIP passes. Needing an exit node for travel does not require reaching the NAS. Separate the grants.

When sharing widely is still fine

Solo operator, two devices, both yours—full access is fine. Couple with high shared trust and no kids devices—still consider splitting admin ports. The moment a third identity appears (roommate, kid, helper), write ACLs the same week. Retrofitting after a scare is worse.

Failure modes

ACL too tight, shadow IT. Family cannot reach media, so someone opens a port on the router. Test the happy path after every policy change.

Tag sprawl. Twenty tags with identical grants is theater. Start with four.

Forgotten invites. Review users quarterly. Remove the contractor. Remove last year’s tablet.

Shared accounts. Two humans on one Tailscale user destroys audit trails. Separate users; shared grants via tags.

A minimal policy workshop for a Saturday

  1. Inventory devices and owners.
  2. List services by sensitivity (admin / family / public-on-tailnet).
  3. Assign tags.
  4. Write deny-by-default style allows for those paths only.
  5. Test from a family phone and from an admin laptop.
  6. Document how to onboard a new phone without granting admin.

Keep the policy file in git if you can. Diffs beat folklore.

Decision guide

Sharing the whole tailnet is the mistake when any device you do not fully control can reach ports you would not expose to a coffee-shop Wi-Fi. ACLs are how households keep Tailscale as a convenience mesh instead of a flattened castle.

Start with roles, tag them, allow only the paths people actually use, and review invites when seasons change. The mesh should feel magical for media and boringly strict for hypervisors—that combination is the household win.

Kids, schools, and MDM-shaped reality

School-managed Chromebooks and iPads may already phone home to districts. Putting them on a wide-open home tailnet can expose services to a device you do not control patching for. Prefer local Wi-Fi for homework and a narrow tag if they truly need one home service. Do not grant subnet routes to school devices “so printing works”—fix printing with a less powerful path.

If a child needs Nextcloud for homework photos, allow that destination only. If they need SSH to a Raspberry Pi for a coding club, stand up a dedicated Pi with nothing else on it rather than opening the production NAS.

Guests without permanent citizenship

Holiday guests who need the media server should not become permanent tailnet members with your ACL history. Use short-lived access patterns your plan supports, a separate SSID for streaming devices, or a temporary tag you delete on January 2. The social awkwardness of removing access is smaller than the technical awkwardness of an old phone still reaching cameras in July.

Write the offboarding step into your calendar when you onboard. Future-you will not remember who “Alex’s iPhone 12” was.

Testing without breaking movie night

Change ACLs before peak usage. Keep a break-glass admin device that you verify still reaches everything. Have a partner try the family path immediately. Roll back if media fails—do not debug policy during the opening credits. Save verbose experiments for weekday mornings.

Subnet routers, MagicDNS names, and accidental discovery

Even with ACLs, MagicDNS and service names teach people what exists. A family user who can resolve proxmox but cannot connect will still learn the hostname. That is usually fine. What is not fine is combining discoverable admin hostnames with an allow rule that is wider than you remember from last year’s policy paste.

Review who can use advertised subnet routes separately from who can use peer-to-peer node access. A phone that should only hit Jellyfin on a Tailscale IP should not also inherit a route into the IoT VLAN “because the subnet router is up.” Routes are a privilege. Treat them like SSH keys.

If you run Home Assistant, cameras, and a NAS on one flat LAN behind a subnet router, ACL mistakes are amplified: one allow to the prefix is an allow to everything on that prefix. Prefer routing only the prefixes that need it, or put sensitive admin hosts on addresses that family tags cannot reach.

Partner dynamics and break-glass

Household networks fail socially when only one adult can fix Netflix-on-the-NAS. Give a second human an admin-tagged device or a documented break-glass procedure. ACLs that lock out everyone except your travel laptop will strand the house when you are on a plane.

Break-glass is not the same as daily admin. Store it offline. Test it yearly. Do not leave an untagsed “emergency” device with full access sitting in a kitchen drawer forever without review—that device is a spare key under the mat.

Logging and soft accountability

You will not run a SOC. You can still notice oddity: a kid device opening SSH attempts, a guest tag active in August, a new node named vaguely. Periodically glance at the machines list. Remove stale nodes the way you remove old house keys after a roommate moves out.

When something looks wrong, shrink grants first, investigate second. Wide-open while curious is how short incidents become long ones.

Migration from flat trust without a fight

Do not flip to deny-by-default on Friday night. Inventory, tag, allow the popular family paths, then remove the implicit wide opens. Expect two or three “why can’t I reach X” messages—that is feedback for missing allows, not a reason to abandon ACLs.

Keep a written map of “who should reach what” on a single page. If you cannot explain a grant in plain language, delete it.

That single page becomes the onboarding checklist for the next phone, the next roommate, and the next “can you just add my iPad?” request. Without it, every addition trends back toward the whole-tailnet mistake—because saying yes is easier than reading last year’s JSON.

Say yes to the role, not to the network. Grant the tag that matches the human’s job in the house. Everything else stays dark until someone makes a case. That is how Tailscale stays a household convenience instead of a flat trust domain with better logos.

If you do only one thing after reading this, open your machines list tonight, remove anything you do not recognize, and write four tags on paper before you touch the policy file. Paper first, JSON second—household ACLs fail when the file is smarter than the story.

Then grant the smallest path that still lets movie night work—and stop there.

More articles for you