Skip to main content
Use Tailscale webhooks to send the tailnet events an administrator has to act on to Flashduty On-call: a node key about to expire or already expired, a device or user waiting for approval, a device waiting for a signature under Tailnet Lock, and a subnet router or exit node without IP forwarding enabled. When a device is approved, signed, or deleted, Flashduty recovers the matching alert. According to the Tailscale documentation, webhooks are available on all plans, including the free Personal plan.

In Flashduty On-call


You can get the integration push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, go to Channels and open a channel
  2. Select Configuration → Integrations → Private integration, then click Add an integration
  3. Select Tailscale and click Save
  4. Open the new integration card and copy the push URL

Use a shared integration

  1. In the Flashduty console, go to Integration Center → Alert Events
  2. Select Tailscale and enter an integration name
  3. Configure the default route and select a channel. You can add more rules under Routes after creation
  4. Click Save and copy the generated push URL

Configure Tailscale


1

Add a webhook endpoint

You need the Owner, Admin, Network admin, or IT admin role in the tailnet.
  1. Sign in to the Tailscale admin console, open Settings → Webhooks, and click Add endpoint
  2. For Webhook URL, enter the full Flashduty push URL
  3. Leave Destination set to None (the Tailscale format). With Slack, Discord, or another destination format, Flashduty cannot parse the request
2

Select events

Select the following events. The two IP forwarding events make up the Device Misconfigurations category, so you can select that category instead; the others are in the Tailnet Management category:Rejecting a pending device in Tailscale deletes it, so no nodeApproved follows. Subscribe to nodeDeleted to recover such approval alerts when the device is deleted. Tailscale also sends nodeDeleted every time an ephemeral node is removed automatically; when no matching alert is open, Flashduty ignores the recovery.You can also select the whole Tailnet Management category. Its other events (such as nodeCreated, policyUpdate, and userRoleUpdated) are informational: Flashduty returns success and creates no alert.
3

Save and test

  1. Click Add endpoint. Tailscale shows the webhook secret; Flashduty does not use it, so you can close the dialog
  2. In the webhook list, open the menu to the right of the endpoint and select Test endpoint → Send test event
  3. Tailscale sends an event whose type is test. Flashduty returns success and creates no alert
4

Turn on the auto-resolve timeout

Node key expiry and IP forwarding misconfiguration have no recovery event: after you renew the key or enable IP forwarding, Tailscale sends nothing more. In the channel that receives these alerts, turn on the auto-resolve timeout. We suggest a timeout of 24 hours, counted from Incident trigger. Closing the incident also closes its alerts.

Payload


Each Tailscale delivery is a JSON array that can carry several events. Flashduty handles every event that creates an alert separately: Every alert also has the label source=tailscale and a check label (key_expiry, approval, signature, user_approval, exit_node_ip_forwarding, or subnet_ip_forwarding). When message is empty, the title is Tailscale <event type>: <device or user>.

Alert Key


Flashduty builds the Alert Key from the object (the device’s nodeID or the user’s user) and the check (check):
  • nodeNeedsApproval and nodeApproved for one device land on the same alert, which recovers when the device is approved
  • nodeKeyExpiringInOneDay and nodeKeyExpired for one device share an Alert Key. When the key expires, Flashduty opens a new Critical alert and keeps the earlier Warning alert open; nodeDeleted closes both
  • Different checks on one device (for example key expiry and pending approval) create separate alerts
  • Tailscale retries a failed delivery hourly for up to 24 hours; retried events merge into the original alert instead of creating duplicates
Renaming a device or the tailnet does not change the Alert Key.

Status and severity


If a device event that creates an alert has no data.nodeID, or a user event has no data.user, the whole request is rejected.

FAQ


Tailscale has no “key renewed” event. Turn on the channel’s auto-resolve timeout, or close the alert in Flashduty by hand. For servers that should not expire, you can also disable key expiry in Tailscale.
No. Flashduty identifies the integration by the integration_key in the push URL and does not verify the Tailscale-Webhook-Signature header. Keep the push URL as secret as a key.

Troubleshooting


  • Flashduty returns a parameter error: make sure Destination is None and the push URL is complete (it includes integration_key)
  • The test event succeeds but no alert appears: the test event creates no alert; make sure the endpoint subscribes to the events in the table above
  • The alert does not recover after the device is approved: make sure the endpoint subscribes to nodeApproved