
Headscale
Self-hosted control server for Tailscale-based WireGuard networks
42.2k stars 2.4k forks last commit first released BSD-3-Clause
Actively maintained
Last commit 24 Jul 2026.

Headscale is an open source, self-hosted implementation of the Tailscale control server. It coordinates a WireGuard-based overlay network by exchanging node keys, assigning addresses, and managing routes and sharing within a tailnet.
Key Features
- Implements core control-plane functions for a Tailscale-compatible network (tailnet)
- Node registration and coordination via Tailscale clients
- WireGuard key exchange and IP address management
- User/namespace boundaries and machine sharing between users
- Route advertisement and management for subnet routing
- Designed for a single tailnet suited to personal use or small organizations
Use Cases
- Run a private Tailscale-compatible VPN without relying on the hosted control server
- Connect homelab, servers, and remote devices via a WireGuard-based overlay network
- Provide secure remote access and subnet routing for a small team or community project
Limitations and Considerations
- Focused on a narrow scope: a single tailnet rather than large multi-tenant deployments
- Some Tailscale features may be unavailable or behave differently depending on client support and Headscale version
Headscale is a practical choice for self-hosters who want the Tailscale experience with an open control plane. It emphasizes a lean, hobbyist-friendly approach while supporting common coordination features needed for a private overlay network.
Categories:
Tags:
Tech Stack:
Similar to Headscale

Pangolin
Identity-aware VPN and reverse proxy for secure remote access
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.
OpenVPN
Open-source VPN daemon for TLS-based secure tunneling
OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

ShellHub
Centralized SSH gateway for remote access and device management
Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.


wg-easy
WireGuard VPN server with a web-based admin interface
Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

Amnezia
Cross-platform client to deploy and use your own VPN server
Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

Firezone
Zero-trust remote access platform built on WireGuard
Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

