SIMSY + Tailscale | Add SIMs to your tailnet | SIMSY Developers
Back to tools
SIMSY + Tailscale

Add SIMs to your tailnet as first-class nodes

Enrol a SIMSY SIM in your Tailscale integration and it comes up as a full node on your tailnet. Each SIM carries the tags you nominate, participates in your existing policy file, and is reachable across the mesh by tailnet name. Because the SIM is the participant, the device on the other end is left untouched.

Six capabilities that come with the integration

The SIM is the tailnet node

The SIM itself participates in the mesh, which means any device can join the tailnet whether or not it can accept a client. Modules with locked-down firmware, industrial PLCs and simple sensors all become reachable by tailnet name.

Direct participation from every SIM

Each SIM joins the mesh in its own right, so the mesh stays a mesh all the way to the device. Every SIM is reachable directly, whether you have five in a lab or fifty thousand across a country.

Addressing under your control

SIMSY assigns the SIM-side addressing from ranges you define, so every deployment sits inside a subnet plan you designed. Multiple customer estates coexist cleanly and address the equipment predictably.

Governed by your policy file

Your existing tags, grants and policy tests apply to SIMs the moment they are enrolled. One huJSON file governs your servers, your agents and your fleet in the field, reviewed the way you review everything else.

First-class identity for machines

Every SIM carries its own tailnet identity, so a machine in the field gets the same identity, policy and audit treatment as an agent running in a container. The network becomes the identity layer for both halves.

Tailscale and Headscale, either way

Enrol against the hosted Tailscale coordination servers, or point the integration at your own Headscale control server. The enrolment shape is the same; only the endpoint changes.

Three steps between your tenant and a working node

  1. STEP 01

    Connect your tailnet to SIMSY

    Create a Tailscale integration on your SIMSY tenant. Point it at the Tailscale coordination server or at your own Headscale, and give it an OAuth client with permission to mint auth keys for the tags you plan to use.

  2. STEP 02

    Nominate the SIMs and their tags

    Enrol a SIM, or a whole endpoint group, into the integration. Attach the tags you want the nodes to carry, and SIMSY passes them straight through to Tailscale when it mints the auth key.

  3. STEP 03

    Your nodes appear and your policy applies

    Each SIM shows up in the Tailscale admin console as a node with its tags. Grants in your policy file take effect immediately, and the device on the other end has nothing installed on it.

enrol-sims.py (illustrative)
# Illustrative - see API reference for current endpoints
import simsy

client = simsy.Client("your-api-key")

# 1. Register a Tailscale integration on your tenant, pointing at the
#    coordination server (or your Headscale) and holding an OAuth
#    client for auth-key issuance.
integration = client.create_tailscale_integration(
    name="prod-tailnet",
    coordination_url="https://controlplane.tailscale.com",
    oauth_client_id="tskey-client-...",
    oauth_client_secret="...",
)

# 2. Enrol a group of SIMs as tailnet nodes. SIMSY generates a
#    per-SIM auth key with the tags you nominate; the SIM comes up
#    as a node with that identity, no client on the device.
client.enrol_sims_in_tailnet(
    integration_id=integration.id,
    endpoint_group="edge-sensors-eu",
    tags=["tag:edge-sensor", "tag:eu-west"],
    ephemeral=False,
)

# 3. Nodes appear in your admin console with the tags above. Apply
#    grants in your policy file the same way you would for any node.

The exact method names and payloads are placeholders while the SIMSY + Tailscale API surface stabilises. The shape (integration, group, tags, ephemeral flag) is stable and reflects how the finished endpoints will read.

The tags and grants you already write, applied to SIMs

Once a SIM is enrolled with tags on it, everything downstream reads the same as it always has. Tags own the identity, grants control who reaches what, policy tests block accidental widening, and your huJSON policy file remains a single source of truth for the whole estate.

policy.hujson (fragment)
// Fragment of your tailnet policy file (huJSON).
// Once SIMSY has enrolled your SIMs with the tags below,
// grants apply to them the same way they do to anything else.
{
  "tagOwners": {
    "tag:edge-sensor":     ["group:field-ops"],
    "tag:eu-west":         ["group:field-ops"],
    "tag:collector":       ["group:platform"]
  },

  "grants": [
    // Field-ops can SSH into any edge sensor (over the tailnet, of course).
    {
      "src": ["group:field-ops"],
      "dst": ["tag:edge-sensor"],
      "ip":  ["tcp:22"]
    },

    // Edge sensors post to the collector, and nothing else.
    {
      "src": ["tag:edge-sensor"],
      "dst": ["tag:collector"],
      "ip":  ["tcp:443"]
    }
  ]
}

The same syntax, applied everywhere. Managing policy works the way it always did in your tailnet. The nodes labelled tag:edge-sensor above happen to be SIMs in the field rather than servers in a rack, and everything reviewed at merge time treats them identically.

Design decisions to fit into your set up.

Auth key rotation

SIMSY holds an OAuth client for your tailnet so it can mint per-SIM auth keys on demand. Rotate the OAuth secret the same way you would for any Tailscale integration and SIMSY picks up the new value on next enrolment.

Ephemeral or reusable enrolment

Ephemeral nodes are a good default for high-churn fleets because they self-clean from the admin console when they go offline. Reusable auth keys work well when you want the node identity to persist across power cycles and re-enrolments.

MagicDNS and node names

MagicDNS is on by default in most tailnets. Give SIMs meaningful node names when you enrol them so their MagicDNS short names read like device inventory across your organisation.

Exit nodes and route acceptance

A SIMSY-enrolled SIM is a node in its own right. Any advertised routes already on your tailnet keep working, and the SIMs accept them the same way any other node would.

Policy tests before large rollouts

Add a policy test that asserts your SIM tag only reaches what you expect it to, then flip a large fleet into the integration confident that the grants read as intended.

Regional coordination

For latency-sensitive deployments in one region, keep the coordination path short by pointing the integration at a Tailscale DERP region close to your SIMs. For Headscale, run the control server near the traffic.

Try it on a Launch SIM.

Grab a Launch SIM, enrol it into your tailnet under a test tag, and SSH into it from your laptop by tailnet name. The whole exercise takes an afternoon.

Works with Tailscale and Headscale