Headscale

Self-hosted control server for Tailscale

Security & Privacy BSD-3-Clause advanced ★ 44,252 stars

What is Headscale?

Headscale is an open-source, self-hosted implementation of the Tailscale control server. It lets you build your own WireGuard-based mesh network using official Tailscale clients, without depending on the commercial coordination service.

Best for

People who want Tailscale-style networking under their own control

Why choose Headscale

Headscale exists because Tailscale's software is excellent and open source, while its coordination server is neither. If you have ever wanted the mesh-networking experience — connect devices across the internet as if they were on the same LAN, with automatic key exchange and NAT traversal — but you want the coordination layer to live on your own hardware, Headscale is the replacement control server. You keep the polished official clients on every platform; only the part that coordinates them moves to your machine.

Replaces

  • Tailscale
  • ZeroTier
  • WireGuard manual setup

Key features

  • WireGuard-based mesh networking
  • Works with official Tailscale clients
  • ACL and route management
  • Single binary, low resource use

What to watch out for

The clients are Tailscale's, which means you are running a self-hosted server against an ecosystem controlled by someone else — feature mismatches and client updates that assume the official service are an ongoing reality. You also become the coordinator, with all that implies: if your server is down, new nodes cannot join and existing ones eventually lose connectivity, and it needs to be reachable from the public internet to work anywhere. The project has historically been maintained by a small team. Documentation assumes real networking knowledge.

How to deploy

  • Docker
  • Binary

Getting started

Run it on a small VPS with a real domain and TLS from the start, because clients will not trust a plain-HTTP coordination server. Bring up one client, register it with the node registration command, and confirm it can reach a second machine before enrolling anything else. Decide upfront whether you will use DNS-based naming, which requires a little more configuration but makes routes far easier to remember. Back up the database — it holds every registered node and key — and think about what happens to your devices if the VPS disappears.

Typical setup

Almost every installation runs on a small VPS with a public address and a real domain, because the coordination server must be reachable for nodes to join. The devices themselves — laptops, phones, home servers, remote machines — run the official client and are enrolled against that server. People commonly pair it with a DNS setup so devices get memorable names, and they treat the server's database as critical infrastructure, since it holds every registered node and key.

Who should look elsewhere

Avoid it if you need a supported product with guaranteed uptime for your device fleet. This is a self-hosted coordination server maintained by a small team, and when it is down, new devices cannot join and existing connectivity degrades. Also a mismatch for anyone unwilling to become the networking administrator — the documentation assumes real familiarity with routing and mesh concepts.

Project health

  • GitHub stars: 44,252
  • Last code push: 2026-09-30
  • Open issues: 136
  • Status: actively developed

Figures pulled from the GitHub API and refreshed periodically.

Headscale as an alternative

More in Security & Privacy