Headscale logo

Headscale

Website

Self-hosted control server for Tailscale-based WireGuard networks

42.2k stars 2.4k forks last commit first released BSD-3-Clause

Actively maintained

Last commit 24 Jul 2026.

Headscale screenshot

Headscale is an open source, self-hosted implementation of the Tailscale control server. It coordinates a WireGuard-based overlay network by exchanging node keys, assigning addresses, and managing routes and sharing within a tailnet.

Key Features

  • Implements core control-plane functions for a Tailscale-compatible network (tailnet)
  • Node registration and coordination via Tailscale clients
  • WireGuard key exchange and IP address management
  • User/namespace boundaries and machine sharing between users
  • Route advertisement and management for subnet routing
  • Designed for a single tailnet suited to personal use or small organizations

Use Cases

  • Run a private Tailscale-compatible VPN without relying on the hosted control server
  • Connect homelab, servers, and remote devices via a WireGuard-based overlay network
  • Provide secure remote access and subnet routing for a small team or community project

Limitations and Considerations

  • Focused on a narrow scope: a single tailnet rather than large multi-tenant deployments
  • Some Tailscale features may be unavailable or behave differently depending on client support and Headscale version

Headscale is a practical choice for self-hosters who want the Tailscale experience with an open control plane. It emphasizes a lean, hobbyist-friendly approach while supporting common coordination features needed for a private overlay network.

Categories:

Tags:

Tech Stack:

Share:

Similar to Headscale

Pangolin logo

Pangolin

Identity-aware VPN and reverse proxy for secure remote access

21.9k
745
Last commit

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+16
OpenVPN logo

OpenVPN

Open-source VPN daemon for TLS-based secure tunneling

14.3k
3.4k
Last commit

OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

Actively maintained
Alternative to:
OpenVPN CloudConnexa logo
OpenVPN CloudConnexa
+18
ShellHub logo

ShellHub

Centralized SSH gateway for remote access and device management

2k
186
Last commit

Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

Apache-2.0Actively maintained
Alternative to:
Teleport logo
Teleport
+14
wg-easy logo

wg-easy

WireGuard VPN server with a web-based admin interface

26.5k
2.5k
Last commit

Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

AGPL-3.0Actively maintained
Alternative to:
Tailscale logo
Tailscale
+14
Amnezia logo

Amnezia

Cross-platform client to deploy and use your own VPN server

14k
1k
Last commit

Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

GPL-3.0Actively maintained
Alternative to:
NordVPN logo
NordVPN
+15
Firezone logo

Firezone

Zero-trust remote access platform built on WireGuard

8.9k
436
Last commit

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Apache-2.0Actively maintained
Alternative to:
Tailscale logo
Tailscale
+11