Why?
* The Tailscale clients are dead simple and good quality (but not perfect). OpenVPN clients for mac and iOS are pretty bad. Onboarding OpenVPN users was a large document that generated a lot of questions and support issues. Tailscale onboarding is about two minutes for most users and we had nearly no support requests rolling it out widely to our company.
* Tying OpenVPN to Okta is a truly terrible experience. Users would login with their Okta creds and a push would silently go to their devices. If they didn't know to check their phone it would just fail to login. Alternatively you can paste your TOTP code after your password. Yes, really.
* We don't have to manage or debug anything related to LDAP.
* Maintenance on our side is extremely minimal. Just install subnet routers (<10 lines of bash) and put our ACLs in source control.
* We no longer have to tell users to logout and login to another VPN to get to certain resources. We just grant them access and suddenly they can reach what they need. ACLs are amazing and super easy to script, audit, and test.
* Split DNS that actually works on all operating systems. For private domain A, query this resolver (over the wireguard link), for private domain B, query this other resolver.
* I rolled it out as a PoC to all of our major VPCs in a day.
The bad? It's still a young product and is missing features and has some warts.
* Notifications on macOS that you need to relogin are just plain broken (they know and are working on it).
* We're currently battling issues with network resets due to what looks like a client bug when you have lots of users.
* No access to audit logs yet
* You can't restrict people from using exit nodes
* No good way to canary changes to your user population. Any mistake in the UI instantly breaks everyone.