Weekly Tailscale cleanup digest with a prioritized action list

By General Input

Every Monday we review your Tailscale network for stale devices and aging keys, then post a ranked cleanup list to Slack and open tickets for the urgent ones.

Integrations

  • Tailscale
  • Slack Bot
  • Linear

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every Monday at 8am, review my whole Tailscale tailnet for hygiene problems and give me a prioritized action list instead of a raw dump.

Start by pulling the full picture. Use the Tailscale List tailnet devices operation requesting all fields, so you get the complete field set including last seen time, creation date, owner, tags, whether key expiry is disabled, and whether the device is ephemeral. Then use List tailnet keys to get every auth key in the tailnet. If you need to confirm details on a specific device before judging it, use Get a device.

From that data, work out four things: which devices have not checked in for more than 30 days, which devices have key expiry disabled, which devices are ephemeral leftovers that should have cleaned themselves up, and which auth keys are close to their expiry date or already stale. Device freshness comes from the lastSeen and created timestamps.

Judge each finding in context rather than flagging everything that matches a rule. A tagged server with key expiry disabled on purpose is fine and should not be treated as an incident. A personal laptop that vanished six weeks ago is a real problem. Use the device tags, the owner, and the naming pattern to tell managed infrastructure apart from personal machines.

Post a ranked digest to my Slack channel using the Slack Bot Send a Message operation, grouped into three sections: revoke now, check with owner, and safe to ignore. Include the device name, owner, last seen date, and tags on every line so I can act without opening the admin console. Order each group so the most urgent item comes first, and say briefly why each item landed in the group it did.

Then, for each item in the revoke now group, open a Linear issue using Create Issue so the cleanup actually gets tracked. Give each issue a clear title naming the device or key, and put the owner, last seen date, tags, and the reason it was flagged in the description. Do not open issues for the check with owner or safe to ignore groups.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them