AIAI EngineerJun 1, 2026· 24:29

What if the network was the sandbox? — Remy Guercio, Tailscale

Remy Guercio from Tailscale argues that standard sandboxing conflates execution isolation with access control, proposing Aperture—an LLM gateway built on Tailscale's WireGuard identity network—which gives every connection verified identity (user, tag, or group) so agents get placeholders instead of real API keys, making exfiltration impossible. Aperture provides visibility into every tool call, bash command, and MCP request without instrumentation inside the container; internally at Tailscale, bash dominates over structured tool calls. Access permissions are configured via Tailscale's grants and ACLs, supporting quotas, cost controls across providers, and webhooks for tool calls. The gateway works at the LLM layer, capturing even non-tool-call agent behaviors like direct code execution, and is available on Tailscale's free plan.

  1. 0:00Intro
  2. 1:15Sandbox Components
  3. 3:18Tailscale Identity
  4. 5:42Aperture Gateway
  5. 7:28Live Demo
  6. 11:46Agent Config
  7. 13:59Cost Controls
  8. 15:35tsnet
  9. 17:03Permissions Config
  10. 18:46Network Transparency
  11. 20:25User Permissions
  12. 21:28Code Execution

Powered by PodHood

Transcript

Intro0:00

Remy Guercio0:15

Yeah, hi everybody. Thanks for joining. I know we're a little late starting, so yeah, I appreciate it. Yeah, I'm happy to— excited to talk about kind of a— both a question that I kind of want to pose and kind of want to, you know, think about.

And then I'll just do a demo of something that— basically what you can do, a project that we were working on and building— that you can do if you start to think about the network as more of a sandbox environment rather than, you know, just necessarily the network.

So, yeah, I mean, just kind of starting by asking the question: what are the components of a sandbox? Right? You know, so I know I say that. You've probably all thought of different things. You've probably all thought of probably a VM or a container and the debate between whether that's the case or whether or not the agent should go in the box or outside of the box or, you know, around the box or both or things like that.

So, you know, I'm just going to break it down to something, you know, very simple and then kind of ask, you know, a little bit of an— found, you know, about what it might look like at the network layer.

So, you know, what are the components? Like, at the very, you know, very basic level, like, what are the components of the sandbox? So, first is a boundary,right? So it's just— there's a thing in and there's a thing out,right, of the sandbox.

Sandbox Components1:15

Remy Guercio1:28

And the second is a set of permissions,right? So if you don't have the set of permissions or identity that's a part of that, you— you don't have a very fun sandbox,right? It's a sandbox without any toys,right? It's a sandbox, but it's not— there's not really anything, anything there.

And so, you know, if we think about that and we think about agents,right, in particular, like what it means to put an agent in a box or something, something similar to that, you know, we can kind of think about how permissions are typically handled today and what that means.

And so it's one of two ways,right? It's typically one of two ways. It's— there's the first way, which I think is what the major model labs would really like you to do, which is use API keys,right? So you pay the full price.

And, you know, that's one. And, you know, it doesn't also get at the heart of the true, like, auth-in versus auth-z,right? It's just like, here's an API key. It lets you, you know, it lets you have access,right, to, like, to, you know, all of the models or some of the models or things like that.

And the other fun part is it's an API key. So even if it's a synthetic one, the models are very clever at doing things with keys that they maybe shouldn't necessarily do, especially if you run them in a loop for a very long time.

And then the other, you know, other way, you know, the— maybe the more cost-effective way is to use, you know, OAuth or, you know, OIDC in terms of, like, you know, actually handling the permissions for your agents. So, but again, both of these things are actually things that happen, like, you do them in the sandbox,right?

So, like, your key goes in the sandbox or, you know, you've, like, logged into your agent and it's running over there somewhere. You know, your OpenClaw is running over there with your, you know, your account just kind of hanging out over there in the, you know, in the corner.

And so, yeah, so that— what that means is, like, the, you know, is the agent has access,right, to its kind of own permissions,right? It's in a box, but it actually has access to the thing to give it permissions.

Tailscale Identity3:18

Remy Guercio3:18

And so my question is, you know, what if we, you know, again, what if we use the network? What if we thought about the network? And I don't know, who's familiar with WireGuard, like the WireGuard protocol? Okay, yeah, most people.

But yeah, so, you know, what WireGuard lets us do, and that's what Tailscale is built on top of, is WireGuard basically lets us, you know, give a set of keys to all of the, you know, any node on a given network.

And then at Tailscale, we're actually able to put kind of like the identity component on top of that. And so, you know, here, basically, we kind of have the question of this is— this is effectively what Tailscale is.

And we're sort of kind of asking the question, it's like, what if we took the components of, like, auth-in and auth-z and we just stuck them at the network level? So, at least on a, you know, on a tailnet,right?

So we're using WireGuard to establish these connections. And these are direct connections between anything that you might think. So a container, a GPU server, you know, your laptop, a phone, a whatever. We are able to say, so in each connection, we're able to give, like, the actual identity of what and who might be connecting.

So with each connection that happens over Tailscale, you get a user. If that user is logged into the device, you get all of the groups, like, in that sense of, like, if you're a SCIM syncing group, so, like, if you're in the engineering org or things along those lines, you get all of— you can get all of those.

You can get, you know, if this is a, like, an agent, so, like, a PR review bot maybe that you have running somewhere,right, in a GitHub Action, it can be a tag or a set of tags. So this is the PR review bot for this project, or this is the PR review bot for this sort of thing.

And, you know, we can take that and apply it to every single network connection. So not only can we— we can basically govern network access based on that. So you can't even talk to something if you don't have a certain set of permissions.

But the thing on the other side actually also gets all of the information. So there's a very— I mean, if you're used to doing things with networking, you're probably used to doing things with, like, IP address or, like, you know, here's a thing over here and, like, we're kind of, like, you know, connecting things or, you know, it's IP address plus some key, again, like an API key that your service is providing.

This is all kind of in one. So the connections happen, you know, like, the connections happen with identity. And so what that lets you do is that lets you build some very interesting applications on top of that. So, and I realize this is very dark here on the screen, so I apologize.

The— it lets you build some very interesting applications, one of which we happen to build is an AI gateway. So what's happening here is, you know, everybody's probably, you know, familiar with kind of your typical LLMs, you know, LLM gateway,right?

Aperture Gateway5:42

Remy Guercio5:56

Aperture works the same from that perspective. So you take, like, a single key from a provider, you know, be it, you know, Anthropic or OpenAI or, you know, Gemini or Vertex or Bedrock or whatever. You can take a single key from any given provider.

You can put it on Aperture. And then on the other side, so Aperture is just a node, again, on this network. So it's like a node that you deploy into this network. So it is actually able to see all of the identity from everything that's talking to it.

So in the case of an agent in a sandbox, that sandbox has a tag. That sandbox is, like, we can think of in this case, let's think of, like, a GitHub Action runner as sort of a sandbox that your agent is running in.

You can use something like the federated OIDC from GitHub. That will basically, when that runner spins up, that runner will suddenly, basically, it gets the access into the tailnet. It gets a tag on that tailnet. And that tag on the tailnet is what determines what it is able to do via or through Aperture, because, again, it can see that.

And I'll show you an example in just a second. So, yeah, so that's kind of like where we are. So we have, you know, a single key on Aperture. You can then write all your rules in Aperture. And then on the other side, there's actually no key.

It's just, so, like, that runner connecting from the sandbox has no key to accidentally exfil or share or do something with or, you know, kind of go beyond its boundaries. There's just no key whatsoever in that sandbox. So, yeah, so that's that.

And just to kind of show you, like, live, I kind of like to— I actually prefer to just show things. Sorry, just show things live. So this is Aperture, just kind of like I had a screenshot before. Let me change it to be— we're going to go light mode just to make things easier to read.

Live Demo7:28

Remy Guercio7:37

So this is Aperture. Again, this is what I was showing you. This is my view into, like, my Aperture instance. So I am connected here. I'm actually on our corporate tailnet. So I'm logged in on our corporate tailnet.

I have visited Aperture as a user. It knows who I am. I'm on my laptop,right? So I'm just on my laptop. It knows I'm logged in as me. And so it's showing me all of my, like, usage metrics on our kind of, like, demo instance here.

And so, you know, I can see, you know, all the tokens that I've used. I can see the models that I've used. I can see how much money I've spent on the given models, on any given model. And then I can even see all of the requests that have come through the gateway from my particular identity.

So that works for me. That also works for everything else. I can even drill down and see, like, so this was me testing it before, and I can show you live. But I just asked it to say hello.

And with all of the context in Claude Code, even if you just ask it to say hello, that costs you 20 cents. That's a, you know,

it costs you 20 cents. But the next one is not as expensive. But I can actually even go in here and, you know, see all of the request headers, request response body, you know, everything here. And if I scroll all the way down, there should be— oh, yeah, see, this is everything.

In case you were wondering, this is everything that Claude Code sends at the very beginning. And so let's say— let's say hello. Oh, no, maybe I didn't— this is literally everything that Claude sendsright off the— like,right off the bat as a particular request.

And then you can see the response and the response body. Oh, sorry, I asked it to tell me a 10-word story. So there we go. You know, a cat sat on a mat and then simply vanished. But this is the— like, this is what's actually going through the gateway when you make that first, like, very first request from Claude Code.

So, yeah, so that's that. If I wanted to look at me,right, see, that's me here. I can see my session. This is my Claude Code session with two, you know, with two requests here. So there was the haiku thing to tell me, you know, to give you the summary of what was going on and the 20 cents I spent to get that 10-word story.

And then I can even also— so, you know, I mentioned, like, GitHub Actions runners. So this is actually a PR review bot that we have, you know, it's just a small, like, simple check that we have run on every PR, like, update.

And so you can even see here,right, so this is it. It has a tag. It's our dog food tag. And, you know, you can see everything that the dog food bot has done here over the last 30 days.

And I can open it up. I can take a look. I can see every single request that it's run. And I can even take a look at something like this. And we can see, you know, here, it spent 4 cents and it ran three commands at the same time.

So I'm actually able to see all of the, like, bash commands and everything along those lines here.

Yeah, so, you know, that's the case there. You know, I mentioned seeing those bash commands. You can actually extract. And it's a fun part about working at the LLM layer and having everything at the network layer. There's no— I have sort of a guarantee that I've seen every tool call that this thing has ever, like, this thing has ever made through the instance.

This is not happening, like, from inside the container. This is not happening from the harness or anything along those lines. If it had to make a tool call, it had to go through Aperture and we would, you know, we would extract it here and you would see it.

So if I, like, go here and, you know, you can see all of the, you know, all of the tool calls that it made, you know, requested an MCP tool call to update the code review, did some bash, did some grep, you know, and then re-updated the comment on the code review.

And there's no, like, again, we see everything. So,right, and if you wanted to cut it off or you wanted to stop it, it's happening at the network layer. So the moment you say no, it's not like it has a key and then it can be like, oh, I see the key no longer works.

Let me go to this other endpoint,right? Or let me try this other thing or let me do this, you know, you know, I mean, it would be very helpful here,right? It literally is like, oh, key no longer works.

It's just a dash. So, and just to show you that, we have our, like, sort of agent setup script. This is all you actually have to do. So in, like, Claude Code, it's just, hey, you're going to run an API key mode.

Agent Config11:46

Remy Guercio11:55

Here's a dash, like, just so you have something so you don't complain that there is no API key for API key mode. And then here is the endpoint that you need to, you know, the base URL that you need to use.

And again, it works across, you know, like Codex or Claude Code or Gemini CLI. And here's what you need to use. And, you know, when you do that, you can just, again, I can say, you know, I can say Claude.

This is my actual settings.json. You can see the same little, same things appear at the top. But, you know, I can do that. And I can say, you know, again, tell me a 10-word story. By the way, if I, when I asked it to tell me a 10-word story, like, three weeks ago, it was all about robots.

And then it became about dogs. And then now it's about cats. So if there's a sort of, I don't know, model eval suite or something like that, I don't know. You can tell something's happening on the back end.

So, you know, in terms of what they do, yeah, cat, you know, cat sat on a mat and then found a home. But,

yeah, actually, wow. So still can't count. That's fun. Opus 4.6, 1 million context, you know.

Host13:05

So let's explore that.

Remy Guercio13:11

There we go. Allright. And then finally found home. So there we go,right? You know, it just forgot the extra bit. But again, you know, if we wanted to see that,right, you know, hey, you've got a pipeline that, you know, actually depends on that being 10 words or something, you know, or having a certain structure.

Things can easily break, like, in a PR review bot. And, you know, that can happen. And when it happens in, like, something like a PR review bot, it's hard to actually know what's going on or, you know, what happened or when.

You know, I can go back to my logs,right? Here's my session,right, with three requests instead. And, you know, here they all are,right? Here's the summary thing. And then here's the first request with, you know, all of the input tokens.

You know, that was the 20 cents. And then here's the, you know, are you sure about that? And, you know, here's the, you'reright, that was nine. So, you know, again, if you're trying to go back and look at certain things, you can do that here as well.

Cost Controls13:59

Remy Guercio14:01

And again, there's no hiding it from you because it's not like, you know, I'm going to be super helpful and go do this thing and all that stuff and go around. It's, you know, it just has to be here.

One other fun thing that you can do here in the middle is, well, you know, first we can also do, like, cost and cost controls and, you know, all those sorts of things that actually work across providers. So if you want to set a budget or, like, some sort of budget in Aperture, you can actually have it work across every provider.

It's not like, here's $1,000 for everybody. It's here's just $1,000 and you can decide to use it how you wish. And then the other thing is you can actually do integrations. So we offer webhooks on top of this where for each of those tool calls or for each of those things, you can actually send a request out to a third party to, you know, with all of the information about the tool call.

And again, there's no hiding it. It just, it has to go through here. So you can, you know, these hooks are basically guaranteed to sort of exist,right, and run no matter what. So, yeah, so, yeah, that's mostly it.

If you want to, you know, like, again, if you want to set up things like quotas, you can actually, you know, go in and say, hey, here's, you know, you get $5 a day, you know, all those sorts of things and kind of, you know, have as sort of much safe fun, I guess you could say, as you want to in the, you know, through the gateway.

And again, it works with pretty much any provider that you can imagine across the board that supports the major context. And so, you know, I kind of talked about this at the beginning, but this is Aperture,right? This is the thing that, you know, that we have built and that you can use and is available on our free plan.

tsnet15:35

Remy Guercio15:37

However, it is built using the Tailscale identity primitives. And those are, and that is all available via, like, an open source library we have called tsnet where you can write your own Go program,right, that actually puts itself on the tailnet and can read all of the same identity information, can read everything else.

And so you can do things like if you want to build an MCP server, but it's internal to your org or something along those lines or an API endpoint or something that's internal to your org, you don't have to think about OAuth or just think about opening it up to everybody.

You can actually do the exact same thing and be like, hey, who made this request? You know, I'm going to, you know, force that into, you know, whatever, you know, whatever thing I'm proxying on the, you know, on the MCP side or things along those lines.

So you can actually take all of that same, you know, all that same information and do it yourself. Hilariously, you could actually build Aperture yourself if you really wanted to using the same things. We had a whole charge here which was it had to be built on top of Tailscale.

It couldn't be built, like, inside using private API endpoints or anything along those lines. So this is actually built entirely in a way that in theory you could go build to yourself. So, yeah, I, you know, if any ideas have come from this, if you think about, you know, things that you would like to build internally, I would love to, you know, would love to hear and would love to chat afterwards.

So, yeah, I think I'm like a minute under here. And, yeah, so, you know, if there is a question, I'm happy to answer it. Yeah, hey.

Permissions Config17:03

Host17:05

How do you configure the permissions?

Remy Guercio17:06

How do you configure the permissions for, like, who can? So the question is, how can you configure the permissions? And are you saying is it, like, for who can access what or who gets to?

Host17:14

Yeah, like, you can make these tool calls or not these or.

Remy Guercio17:17

Yeah, so all of the, so we actually let you configure them in two places. So there's another fun little feature of, like, how Tailscale identity and how, like, that sort of stuff gets pushed through the network. First is you actually can set them up here in Grants.

So, you know, you can ask, say, who this applies to. We're going to be adding, like, the groups and everything soon here as well. But then you can say, like, we actually also have an MCP server in, like, MCP proxy in here as well.

So you can say model access and quotas, MCP access, hooks, roles, like, you know, kind of everything along those lines. You can do the Grants. You can even also define those. So Tailscale as a whole has a policy file that you can use.

It's how you define who can access what on the network. You can actually put this sort of, these are called application. Thisright here is called like an application capability. You can actually stick that in your main ACL file or your main access control file to send along with the identity.

So you not only can you send, like, the user or the tags or everything else, you can actually send any arbitrary metadata that you want guaranteed by the Tailscale control plane as well. So, yeah, so we try to, you know, we have the visual editor, but we also everything is, like, possible to do in JSON.

Just, you know, most folks, a lot of folks using this at scale are, they want to put it in some sort of GitOps workflow. So, you know, we have that. We have the API as well to if you actually want to, like, just, you know, put this as part of some sort of GitOps workflow that you have to do that.

Any other questions? I think that was, yeah.

Host18:46

I think I saw you for when you were setting up in Claude Code, you set the base URL to your Aperture node rather than, like, the default.

Network Transparency18:46

Remy Guercio18:54

Yes.

Host18:55

Is it possible to catch that just, like, at the network layer and just sub it out where everything going to Claude Code instead goes to your node?

Remy Guercio19:01

Yeah, so the question is, do you have to put the base URL in or is it possible to kind of, like, capture that at the network layer and just kind of transparent there? That is something we could do.

That was kind of a big point of discussion when we were first, you know, thinking about this. And in reality, it kind of, it's not, well, we could, it's not really something that we,

it's not really in the, I wouldn't call it the Tailscale way necessarily. The whole point here is we want to make things, like, really, really easy. Like, for you to, you know, you want to be able to get, you know, LLM access or, you know, into a sandbox.

You want to be able to do, you know, on somebody's computer. We want to make that, like, super, super easy from the outset. I realize, you know, there's some transparency stuff, but, you know, when you do that, things can kind of start to break and shift and kind of move.

Yeah, and it gets very confusing and moves out from under you. You know, we just want to make it the easiest way for you to actually, you know, offer this sort of LLM access and not necessarily, you know, kind of do it hidden under the surface where you're kind of doing everything else.

So it's definitely meant for folks who want to build, you know, with AI. And then on the other side,right, is like a security or an IT admin. It's like, great, you get easy to use controls. You get easy to, you know, like, easy to kind of, you get to see all of the tool calls.

You get to see, you know, all of those sorts of things. So we're really trying to do the best of both worlds for, you know, both devs and the kind of, you know, IT/security, like, manager. Yeah.

User Permissions20:25

Host20:25

Is that role-based? Like, can you say, like, these users are allowed to use these tools or is it just the model and the provider?

Remy Guercio20:32

So today it's, yes, we want to working on that. Today it's model provider. You can think of basically anything that we would put through Aperture. You should be able to say, hey, this group or this, you know, as defined by my SCIM provider, as defined by, you know, whatever gets access to model.

It's not just model and provider. It's also all of the quota stuff, you know, that I kind of, that all also has the same sort of permissioning system. So you can say this team gets this big budget. You know, each individual gets this, you know, smaller budget.

And then, you know, we kind of do the, you know, the union of the two there or, you know, or even do it where it's like, you know, you can use as much as you want of the internal GPU, you know, like, you know, kind of like the internal GPU endpoints that we're hosting.

But, you know, if it's Opus 4.6, you only get, you know, this amount or something along those lines. Yeah.

Code Execution21:28

Host21:28

How does permissioning work in a world where there's no tool calls? It's just writing code.

Remy Guercio21:33

How does permissioning work in a world where it doesn't do tool calls? It's just writing code?

Host21:38

Yeah, so I think, well, a lot of agents are somewhat moving away from MCP and tool calls and executing code, which actually makes some network requests harder to pass.

Remy Guercio21:50

Yes.

Host21:51

From the transcript.

Remy Guercio21:52

Yeah, so, you know, the question, you know, in a world where people are moving away from MCP and maybe the structured tool calling, what do we, you know, what do we, you know, how does it work? How does permissioning and things like that work?

You'reright. That is a little bit more complicated. However, it's the whole reason we chose to do this. We had originally thought about maybe doing this at the MCP, like, just the MCP layer. And we realized it was like, hey, it's actually way more valuable to, you know, do the LLM, the LLM layer here.

And this is where, you know, like, if I go to, let me just go to the logs and I, you know, I go again to, not to the chat, but to the, you know, a given here. Let's see that given metric.

You know, this is,right, so even with skills and everything else,right, or code, you're still running, like, you're typically still running something. Now, of course, you could write the thing, maybe obfuscate the thing, and then run the thing. You know, one step at a time, you know, kind of thing.

You know, and a lot of folks, to be honest, a lot of folks that we talked to were like, I don't even know what tools people are using. Like, please just tell me. Like, forget about blocking it for a second.

I don't even, like, what are people even doing,right? You know, it's like, because MCP was all the rage and it's like, are they using MCPs? Are they just using bash commands? I can tell you internally, like, this is, sorry, this is just our demo instance, but internally, if you were to look at our actual instance, bash dominates everything else.

But again, we get to see the command and we typically, you know, we get to see all the commands and, you know, and everything that's actually being run. And we'll be adding in more guardrails along the lines of like, hey, you can, you know, this is the bash command.

Let's, you know, if it's rm -rf /,right? Maybe not, you know, or, you know, you know, or something along those lines. You know, we'll be adding that in. But that's the whole reason why we decided to do it at the LLM layer.

So, yeah, we had that whole discussion of like, well, and if you can't see everything, then

how valuable is it,right? You know, if you can't see everything. And so we wanted to be able to see, you know, at least from particular agents that you want to put there, you know. Yeah. Any other, I was going to say, I don't, you know, I don't know exactly what the time is here, but I know we're kind of at the end.

I'm happy to answer any other questions downstairs if you want to come to the booth or in the hall. But, yeah, thank you.