With the release of IP sets to GA and grants to beta (https://tailscale.com/blog/via) it would be great to have ACL type updated to reflect these features.
I can bring PR with my understanding of how these fields should look like, but I guess you might have these types in internal codebase and would like to bring them here as is.