📁 Other

Tailscale ACL Checklist from Policy Inventory (No Invented Node IDs)

Turn a Tailscale policy inventory into an ACL checklist only. No invented node IDs, tag owners, or IP ranges beyond the inventory.

0.0
0Reviews
P
September 11, 2026

Prompt

Act as a Tailscale network policy engineer who only uses a pasted policy inventory. You write an ACL checklist the inventory already supports. You do not invent node IDs, tag owners, IP ranges, or auth keys. This is not a live Tailscale ACL push and not a security penetration test.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Policy inventory I lock (ACL stubs, grant cues, group notes): [Inventory]
- Tailscale / policy version notes I lock: [Version]
- Tailnet or workspace label I may quote (or UNKNOWN): [Workspace]
- Required ACL or grant names I may quote (or UNKNOWN): [SpecNames]
- ACL stanzas already present in the policy (or UNKNOWN): [ACLStanzas]
- Tag owners already declared (or UNKNOWN): [TagOwners]
- Group names already present (or UNKNOWN): [GroupNames]
- Words I must not use: [Banned]
- What I must never invent (node IDs, tag owners, IP ranges, auth keys): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, ACLStanzas, TagOwners, GroupNames, Lang. Forbidden: invented node IDs, tag owners, IP ranges, auth keys. Banner: not a live Tailscale ACL push; not a security penetration test.
2. ACL checklist table: one row per Inventory ACL stub or grant cue. Missing group notes write NOT IN INPUTS. Use Tailscale ACLs, Grants, Tags, and Groups language when Inventory supports it. Quote ACLStanzas and TagOwners only when present.
3. Spec name set: only names in SpecNames. Unnamed grants stay NOT IN INPUTS. Never print node-ID or IP-range VALUES not in Inventory.
4. Version lock: print Version. Refuse Tailscale features newer than Version if Version is named.
5. Refuse list: inventing node IDs, inventing tag owners, inventing IP ranges, inventing auth keys.
6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format.

Constraints:
- Checklist from Inventory only. No invented node-ID VALUES. Teach Tailscale ACL mapping, not a generic VPN-rule swap.
- Honor Version. No emojis.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Tailscale ACL Checklist from Policy Inventory (No Invented Node IDs) - Result

Examples

Example Input

Inventory: acl Harbor Quay Berth SSH as pasted grant cue tag:berth as pasted group note eng as pasted; acl River Ops Gate HTTPS as pasted grant cue tag:gate as pasted. Node ID NOT IN INPUTS. IP range NONE.
Version: Tailscale ACL v2 as pasted (do not invent unreleased grants syntax)
Workspace: Harbor Quay Tailnet as pasted
SpecNames: Berth SSH as pasted; Gate HTTPS as pasted. Admin UNKNOWN.
ACLStanzas: ssh-berth as pasted; https-gate as pasted. dns UNKNOWN.
TagOwners: tag:berth -> group:eng as pasted; tag:gate -> group:ops as pasted. tag:ci UNKNOWN.
GroupNames: eng as pasted; ops as pasted. contractors UNKNOWN.
Banned: guaranteed node id, owner invent, ip invent, auth invent
Never: invent node IDs, invent tag owners, invent IP ranges, invent auth keys
Format: ledger + table + specs + version + refuse + compliance
Lang: English

Example Output

1. Ledger. Inventory: acl Harbor Quay Berth SSH grant cue tag:berth group note eng; acl River Ops Gate HTTPS grant cue tag:gate. Node ID NOT IN INPUTS. IP range NONE. Version Tailscale ACL v2. Workspace Harbor Quay Tailnet. SpecNames Berth SSH; Gate HTTPS; Admin UNKNOWN. ACLStanzas ssh-berth; https-gate; dns UNKNOWN. TagOwners tag:berth->group:eng; tag:gate->group:ops; tag:ci UNKNOWN. GroupNames eng; ops; contractors UNKNOWN. Lang English. Banner: not a live Tailscale ACL push; not a security penetration test. Forbidden: invented node IDs, tag owners, IP ranges, auth keys, guaranteed node id, owner invent, ip invent, auth invent.

2. ACL checklist.
1. Harbor Quay Berth SSH | grant tag:berth as pasted | stanza ssh-berth as pasted (ACLStanzas) | tag owner group:eng as pasted (TagOwners) | group eng as pasted (GroupNames) | node ID NOT IN INPUTS | IP range NONE | Tailscale ACL checklist only.
2. River Ops Gate HTTPS | grant tag:gate as pasted | stanza https-gate as pasted (ACLStanzas) | tag owner group:ops as pasted (TagOwners) | group NOT IN INPUTS beyond TagOwners | node ID NOT IN INPUTS | IP range NONE.
Auth keys not printed. IP ranges not invented.

3. Spec name set. Berth SSH; Gate HTTPS as SpecNames. Admin UNKNOWN so write Admin NOT IN INPUTS. No node-ID VALUES printed. No third ACL invented.

4. Version lock. Tailscale ACL v2 as pasted. Unreleased grants syntax not used. Auto-approvers NOT IN INPUTS.

5. Refuse. Node invent: refused. Owner invent: refused. IP invent: refused. Auth invent: refused. Guaranteed node id: refused.

6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: group note depth for River Ops Gate HTTPS, Admin decision, dns ACLStanzas, tag:ci TagOwners, contractors GroupNames if any.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...