---
title: Tailscale login prompts on the fleet (2026-10-08)
summary: Why every ssh to enuc demanded a browser login, what was changed, and the three admin-console actions that stop it for good. Verdict: stay on Tailscale.
---

Symptom

Since the fleet went live (2026-10-07), ssh enuc from yacht and starlight, by Eric, by cc/cx, and by
the Cyberdeck/deck pollers, kept printing # Tailscale SSH requires an additional check. To
authenticate, visit: https://login.tailscale.com/a/... and hanging until someone clicked the link.

Cause

Two separate tailnet settings, both Tailscale defaults, not a bug in the fleet code:


    Tailscale SSH on enuc ran under the default check rule. The policy enuc receives from the

control plane is holdAndDelegate for every node, with a 12-hour checkPeriod: after each
browser approval a per-source accept rule appears with ruleExpires 12 h later, then the next
connection prompts again. The laptops open a lot of sessions (yacht 295, starlight 103 in the
last two days), so a prompt appeared every 12 h per laptop, and each unattended session piled up
as "failed to fetch next SSH action: context deadline exceeded" in enuc's tailscaled journal.
iris and sentinel never prompted because they run plain OpenSSH over the tailnet (RunSSH false).


    Node key expiry is enabled. yacht, starlight and enuc keys expire 2026-10-26 (iris, sentinel,

jetpack on 2027-01-03). Without action each of those three will need a full re-login in 18 days.

Nothing on this Mac holds a Tailscale API key, so the tailnet policy and key expiry could not be
changed from here.

Done on 2026-10-08 (cc@yacht)


    sudo tailscale set --ssh=false on enuc. Port 22 on 100.106.112.69 now reaches enuc's OpenSSH

(publickey only, password auth off). Verified: ssh enuc from yacht reports
remote software version OpenSSH_10.2p1, no check banner. Yacht's RSA key was already authorized;
yacht's ed25519 key (eric@yacht) was appended to ~e/.ssh/authorized_keys. The ed25519 key
already there is presumably starlight's; if starlight cannot log in, add its key via the LAN path
e@192.168.1.142. Reversible with sudo tailscale set --ssh=true.

Eric: three actions in the admin console (about two minutes)


    Disable key expiry on yacht, starlight, enuc (and the others while there):

https://login.tailscale.com/admin/machines → machine menu → "Disable key expiry".


    Change the SSH rule from check to accept so Tailscale SSH never prompts again on any node

where it is re-enabled: https://login.tailscale.com/admin/acls → in the ssh section, the rule
with "action": "check" becomes "action": "accept" (keep src, dst, users as they are).


    Approve Botical's enrollment: ssh root@voice.botical.com tailscale status prints the login

URL; open it once. This has been pending since 2026-10-07 and is why afterglow-tailnet.service
retries every minute.

Should we leave Tailscale?

No. Both prompts were defaults chosen for interactive humans, not a reliability problem with the
mesh itself: every node has been online and direct-connected through this. The self-hosted
alternative is Headscale (same Tailscale clients, our own control server): it removes key expiry
and check-mode by default but adds a server to run, back up, and keep reachable from every host,
and MagicDNS/Serve/Funnel/SSH become our problem. Worth revisiting only if Tailscale's control
plane itself becomes the thing that fails, or if the per-user plan limits bite.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime