Everything we ship, newest first. Subscribe to get it by email, or follow the RSS feed.
Clients release weekly; the control plane deploys continuously behind feature flags. Nothing user-visible goes live without a note here — the changelog is generated from the same PRs that close the tickets, so nothing ships silently.
What changed, who's affected, where to read more. Fixes say what broke and since when; features say where the toggle lives. If an entry can't answer those, it isn't done — the PR doesn't merge without the note.
Unified AI governance: service inventory, agent identity policy, and usage analytics on your tailnet.
Learn more →Client 1.8x cuts median connection setup time by 30% across all platforms.
Rules can now require disk encryption, minimum OS versions, or MDM enrollment — evaluated continuously.
Resolved a long-standing issue with search-domain ordering on Linux clients.
The drag-and-drop ACL editor is generally available, with policy-as-code export still in Git.
Route and log outbound traffic through approved exit nodes by group.
Exit nodes →Filter network flow logs with a purpose-built query syntax — no more export-to-SIEM for quick answers.
Sessions survive failover between redundant subnet routers without drops.
Full coverage of ACLs, DNS, devices, and tailnet settings — with import for existing resources.
Ingress, egress, and service exposure CRDs updated for the latest Kubernetes.
K8s use case →Transfer queues show per-file progress and resumable state.
Taildrop →Reliability fix for on-demand VPN rules when switching between Wi-Fi and cellular.