Automated Tailscale Stale Device Chasing
Every Monday, WebRun opens the Tailscale admin console, reviews devices that haven't connected in over 30 days or have a key expiring soon, posts a chase list to Slack naming the device and owner, and mirrors a short version to Telegram.
How do I find Tailscale devices that haven't checked in or have an expiring key?
WebRun reviews your Tailscale network every Monday for devices that haven't connected in over 30 days or have a key expiring within 14 days, posts an owner-tagged chase list to Slack, and mirrors it to Telegram. It never removes a device or rotates a key itself, only flags what needs attention.
- Stale devices and expiring keys get an owner and a chase list every week
- Nothing sits unnoticed between quarterly access reviews
- The list lands in two channels so it's hard to miss
Built for IT admins · DevOps teams · security teams · remote-first companies
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
login.tailscale.comin a real browser with your saved login - no setup, no API keys. -
1
Tailscale - review stale devices and expiring keys
WebRun opens Tailscale to review stale devices and expiring keys. - Open the Tailscale admin console and review the device list
- Flag devices that haven't connected in over 30 days
- Flag devices with a key expiring within 14 days
Done when Stale devices and expiring keys are listed with owner and last-seen date.
-
2
Slack - post the chase list
WebRun opens Slack to post the chase list. - Post the chase list to the network channel in Slack
- Tag each device's owner
- Separate stale devices from expiring keys so they're easy to action differently
Done when The Slack channel has this week's chase list with owners tagged.
-
3
Telegram - mirror the alert
WebRun opens Telegram to mirror the alert. - Send a short mirror of the same list to the Telegram channel
- Keep it to device names and the issue type
- Skip sending anything the week nothing new is flagged
Done when The Telegram channel has a short mirror of this week's list.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Does WebRun remove the stale device or rotate the key itself?
No. WebRun only flags stale devices and expiring keys. Removing a device or rotating a key is always a manual step taken in the Tailscale admin console.
How stale does a device have to be to get flagged?
Anything that hasn't connected in over 30 days, or has an authentication key expiring within 14 days.
Why post to both Slack and Telegram?
So the chase list reaches wherever your team actually looks first, without anyone having to check two places on their own.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.