Tailscale Mesh · infrastructure
Ask your tailnet what is wrong.
Every device, route and key on your mesh, watched from QuoxCORE, and MESHNET, the plugin’s networking specialist, answering for all of it in plain English.
In plain words
What it is, where it lives, when to reach for it
- What is it
- A plugin for the QuoxCORE dashboard that shows and manages the Tailscale network your machines already use.
- Where do I use it
- On the TailMesh tab in your dashboard, connected to your tailnet through the Tailscale API.
- When would I use it
- When you need to see devices, keys or routes on your tailnet without opening Tailscale's admin console.
- How do I use it
- Buy it once in the store for $55, then an org admin installs it with
quox plugin install.
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
What it does
One tailnet, nothing hidden.
The sphere behind this page is your tailnet: every point a peer, every filament a tunnel. Pay once, paste your licence key in Settings, and the TailMesh tab appears with the MESHNET agent alongside it. No subscription, ever.
The mesh overview is a live device grid: online state, IPs, OS, advertised routes and key expiry, refreshing every 30 seconds. Route management covers subnet routers and exit nodes, key lifecycle covers creation through revocation, and MagicDNS, split DNS and ACL policy get summarised in language humans read.
When a device drops offline or a key nears expiry, the alert lands in your inbox, Telegram, Slack or email. Polling is 60 seconds by default and configurable, and the offline threshold and key expiry warnings are yours to tune.
Governed, like everything on Quox
What happens when you say revoke.
A tool that can revoke keys and change routes has to answer to something. This one answers to the same governance layer as your agents. Follow one sharp action through it.
You tell MESHNET to revoke a compromised key.
Plain English in, a concrete Tailscale API operation out. Nothing has touched your tailnet yet.
The action waits in your inbox.
Authorising devices, revoking keys and changing routes are HITL-gated: they hold until a human says yes. Reading the mesh never needs approval; changing it always does.
Approved, executed, enveloped.
Every operation is wrapped in an AEE envelope, so cause and effect stay traceable through the AOCL timeline in the activity feed.
Witnessed on WARD.
The operation lands in the platform's audit pipeline and is witnessed on the WARD chain, the same tamper-evident record your auditors verify.
The nervous system
Five alerts, one inbox.
| event | severity | where it lands |
|---|---|---|
| device_offline | warning | inbox · Telegram · Slack · email |
| key_expiring (7 d) | info | inbox · Telegram · Slack · email |
| key_expired | warning | inbox · Telegram · Slack · email |
| device_needs_approval | info | inbox |
| subnet_misconfigured | critical | inbox · Telegram · Slack · email |
Destructive, so HITL-gated: authorize_device · revoke_key · manage_routes · every operation wrapped in an AEE envelope, AOCL timeline in the activity feed
Pricing
Everything on one receipt.
Tailscale Mesh is a one-off purchase, not a subscription. Fifty-five dollars, once, and the mesh view, the agent and the approval gates are part of your QuoxCORE install for good.
It unlocks with a licence key: paste it in Settings, the TailMesh tab appears, MESHNET comes online, and the device grid fills on the first poll of your Tailscale API key.
Quox store · Tailscale Mesh