In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select Tailscale and click Save
- Open the new integration card and copy the push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert Events
- Select Tailscale and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated push URL
Configure Tailscale
1
Add a webhook endpoint
You need the Owner, Admin, Network admin, or IT admin role in the tailnet.
- Sign in to the Tailscale admin console, open Settings → Webhooks, and click Add endpoint
- For Webhook URL, enter the full Flashduty push URL
- Leave Destination set to None (the Tailscale format). With Slack, Discord, or another destination format, Flashduty cannot parse the request
2
Select events
Select the following events. The two IP forwarding events make up the Device Misconfigurations category, so you can select that category instead; the others are in the Tailnet Management category:
Rejecting a pending device in Tailscale deletes it, so no
nodeApproved follows. Subscribe to nodeDeleted to recover such approval alerts when the device is deleted. Tailscale also sends nodeDeleted every time an ephemeral node is removed automatically; when no matching alert is open, Flashduty ignores the recovery.You can also select the whole Tailnet Management category. Its other events (such as nodeCreated, policyUpdate, and userRoleUpdated) are informational: Flashduty returns success and creates no alert.3
Save and test
- Click Add endpoint. Tailscale shows the webhook secret; Flashduty does not use it, so you can close the dialog
- In the webhook list, open the menu to the right of the endpoint and select Test endpoint → Send test event
- Tailscale sends an event whose
typeistest. Flashduty returns success and creates no alert
4
Turn on the auto-resolve timeout
Node key expiry and IP forwarding misconfiguration have no recovery event: after you renew the key or enable IP forwarding, Tailscale sends nothing more. In the channel that receives these alerts, turn on the auto-resolve timeout. We suggest a timeout of 24 hours, counted from Incident trigger. Closing the incident also closes its alerts.
Payload
Each Tailscale delivery is a JSON array that can carry several events. Flashduty handles every event that creates an alert separately:
Every alert also has the label
source=tailscale and a check label (key_expiry, approval, signature, user_approval, exit_node_ip_forwarding, or subnet_ip_forwarding). When message is empty, the title is Tailscale <event type>: <device or user>.
Alert Key
Flashduty builds the Alert Key from the object (the device’s
nodeID or the user’s user) and the check (check):
nodeNeedsApprovalandnodeApprovedfor one device land on the same alert, which recovers when the device is approvednodeKeyExpiringInOneDayandnodeKeyExpiredfor one device share an Alert Key. When the key expires, Flashduty opens a new Critical alert and keeps the earlier Warning alert open;nodeDeletedcloses both- Different checks on one device (for example key expiry and pending approval) create separate alerts
- Tailscale retries a failed delivery hourly for up to 24 hours; retried events merge into the original alert instead of creating duplicates
Status and severity
If a device event that creates an alert has no
data.nodeID, or a user event has no data.user, the whole request is rejected.
FAQ
Why did the alert not recover after I renewed the node key?
Why did the alert not recover after I renewed the node key?
Tailscale has no “key renewed” event. Turn on the channel’s auto-resolve timeout, or close the alert in Flashduty by hand. For servers that should not expire, you can also disable key expiry in Tailscale.
Do I need to configure the webhook secret?
Do I need to configure the webhook secret?
No. Flashduty identifies the integration by the
integration_key in the push URL and does not verify the Tailscale-Webhook-Signature header. Keep the push URL as secret as a key.Troubleshooting
- Flashduty returns a parameter error: make sure Destination is None and the push URL is complete (it includes
integration_key) - The test event succeeds but no alert appears: the
testevent creates no alert; make sure the endpoint subscribes to the events in the table above - The alert does not recover after the device is approved: make sure the endpoint subscribes to
nodeApproved