Back to articles
Technology Insight

Advanced Zero-Trust Security: Hardening Your Tailscale Tailnet with Tailscale Lock and Authentik OIDC on a VPS

May 29, 2026

Introduction: The Imperative of Advanced Zero-Trust

In the contemporary digital landscape, traditional perimeter-based security models are no longer sufficient. The rise of distributed teams, cloud infrastructure, and sophisticated cyber threats has necessitated the adoption of a Zero-Trust architecture: a security framework predicated on the principle of "never trust, always verify."

Tailscale has revolutionized modern networking by allowing organizations to create secure, mesh Virtual Private Networks (VPNs)—known as Tailnets—with minimal configuration. However, relying solely on default settings leaves a critical vector exposed: the control plane. If an attacker gains unauthorized access to your Tailscale coordination server or administrative console, they could potentially inject malicious nodes into your network. To mitigate this risk, enterprise-grade architectures require two advanced hardening mechanisms: Tailscale Lock (tailnet locking) and an independent, self-hosted Identity Provider (IdP) like Authentik utilizing OpenID Connect (OIDC). This guide provides an exhaustive, step-by-step blueprint for configuring these advanced security controls on a Virtual Private Server (VPS).

---

Understanding the Core Components

Before proceeding to the technical implementation, it is vital to understand how these technologies interact to establish a bulletproof security posture.

  • Tailscale Tailnet: A private network mesh where every device connects directly to every other device via encrypted WireGuard® tunnels, coordinated by a central control plane.
  • Authentik: An open-source, all-in-one Identity Provider focused on flexibility and security. By hosting Authentik on a VPS, you maintain total ownership of your user directory and authentication flows, eliminating reliance on third-party public identity providers.
  • Tailscale Lock: An advanced cryptographic feature that shifts trust from the Tailscale coordination server to your own public/private key pairs. When enabled, no new device can join the Tailnet without being signed and approved by an existing, trusted administrative node. Even if Tailscale’s infrastructure is fully compromised, an attacker cannot add an unauthorized node to your network.
---

Prerequisites and Environment Setup

To successfully execute this deployment, ensure you have the following prerequisites in place:

  1. A Ubuntu 22.04 or 24.04 LTS VPS with a static public IP address and a fully qualified domain name (FQDN) pointed to it (e.g., sso.yourdomain.com).
  2. Docker and Docker Compose installed on the VPS for orchestrating the Authentik stack.
  3. A Tailscale account (Premium or Enterprise tier, or utilizing the open-source Headscale control plane with custom modifications, though this guide focuses on official Tailscale capabilities).
  4. At least two separate physical or virtual machines already connected to your Tailnet to act as the initial signing nodes for Tailscale Lock.
---

Step 1: Deploying and Configuring Authentik via OIDC

The first line of defense in a Zero-Trust network is robust identity verification. We will deploy Authentik on the VPS to handle all user authentication via OIDC.

1.1 Deploying Authentik

Connect to your VPS via SSH and execute the following commands to download the official Authentik Docker Compose configuration:

mkdir -p /opt/authentik && cd /opt/authentik
wget [https://goauthentik.io/docker-compose.yml](https://goauthentik.io/docker-compose.yml)
wget [https://goauthentik.io/environment.env](https://goauthentik.io/environment.env) -O .env

Generate a secure secret key and database password using the commands provided by the Authentik documentation, populate the .env file, and spin up the containers:

docker compose pull
docker compose up -d

Configure a reverse proxy (such as Nginx or Caddy) with Let's Encrypt SSL certificates to securely expose Authentik over HTTPS at your FQDN.

1.2 Creating the OIDC Provider in Authentik

Navigate to your Authentik admin interface ([https://sso.yourdomain.com/if/admin/](https://sso.yourdomain.com/if/admin/)). Follow these steps to establish the integration:

  • Navigate to Applications > Providers and click Create.
  • Select OAuth2/OpenID Provider.
  • Name the provider Tailscale-OIDC. Set the Authorization Flow to your default explicit consent flow.
  • In the Redirect URIs/Origins section, enter Tailscale's official OIDC callback URL: [https://login.tailscale.com/a/oauth_callback](https://login.tailscale.com/a/oauth_callback).
  • Save the configuration and note down the generated Client ID and Client Secret.

1.3 Connecting Tailscale to Authentik

Log in to your Tailscale Admin Console. Navigate to Settings > Identity Provider. Choose the option to use a custom OIDC provider and input the Issuer URL (your Authentik domain), Client ID, and Client Secret. Test the connection to ensure that user identity token exchange completes successfully.

---

Step 2: Activating and Initializing Tailscale Lock

With identity strictly verified via Authentik, we must now secure the data and control plane using Tailscale Lock. This prevents unauthorized machine registration.

2.1 Generating the Cryptographic Keys

Tailscale Lock utilizes public-key cryptography. You must initialize the lock from a trusted machine that is already a member of your Tailnet. Open a terminal on your primary administrative machine and execute:

tailscale lock init

This command generates a unique local key pair. The output will display a specific initialization command containing your node's public key. Crucial Note: Do not lose access to this specific node during the setup process, as it holds the primary signing authority.

2.2 Confirming the Lock Configuration

To finalize the initialization, you must sign the configuration from the local node. Run the command presented in the previous step's output:

tailscale lock local-signing-key

Verify the status of your Tailnet lock by running:

tailscale lock status

The output will indicate that your Tailnet is now locked, and it will list your current machine as the sole trusted signing authority. Any new device attempting to join the Tailnet will be placed in a pending state, unable to transmit or receive traffic until it is explicitly signed.

---

Step 3: Advanced Hardening and Node Authorization Workflows

Operating a locked Tailnet requires a structured process for onboarding new resources, such as adding a new production VPS or a team member's workstation.

3.1 Onboarding a New Node

When a new device installs Tailscale and authenticates via your Authentik OIDC portal, it will appear in the Tailscale Admin Console with a status of "Locked Out" or "Pending Lock Approval." To authorize this node, execute the following command from your trusted administrative machine:

tailscale lock sign

Once signed, the control plane distributes the cryptographic signature across the network mesh, allowing other nodes to establish peer-to-peer WireGuard tunnels with the new machine.

3.2 Establishing a Secondary Signing Authority

To prevent a Single Point of Failure (SPOF) if your primary administrative machine is lost or destroyed, you must designate a secondary signing node. From your primary machine, run:

tailscale lock add-signer

This ensures business continuity while maintaining strict cryptographic validation over network modifications.

---

Conclusion: The Ultimate Zero-Trust Perimeter

By implementing Tailscale Lock in tandem with a self-hosted Authentik OIDC provider on your VPS, you have effectively eliminated single points of failure in both identity and network control. User access is bounded by your strict Authentik authentication policies, while machine access is cryptographically secured against control-plane manipulation. This architectural synergy represents the pinnacle of modern, advanced Zero-Trust engineering, providing peace of mind that your infrastructure remains fully sovereign and impregnable.

Advanced Zero-Trust Security: Hardening Your Tailscale Tailnet with Tailscale Lock and Authentik OIDC on a VPS | DPTCloud