Tailboot
Create a headless Debian live USB that joins your tailnet and accepts Tailscale SSH connections.
Create a Tailscale auth key
Open Tailscale’s Keys settingsand select Generate auth key. Use these settings:
- Description:
tailboot(optional) - Reusable: on
- Expiration: 90 days
- Ephemeral: on
- Pre-approved: on, if shown
- Tags: choose an isolated tag (recommended)
We recommend creating a tag such as tag:isolated inAccess Controls. Configure your policy so machines with this tag cannot initiate connections to other devices on your tailnet, while allowing you to connect to them with Tailscale SSH. The tag’s name alone does not restrict access: any broad allow rules must also exclude these machines. See Tailscale’s server setup guide.
Generate the key, then paste it below. Every boot joins as a new ephemeral device. When the key expires, generate a new key and create a new ISO.
The key is inserted locally in your browser. The customized ISO contains it in plain text, so keep the image private.