The following fix didn't make it through the refactor: https://github.com/tailscale/tailscale/commit/e296a6be8dcf2ad8f6a16a9e84afa11fd0546bec In the current setup, files will be written to the home directory of the user running tsidp.