Headscale

Headscale

Self-hosted control server for Tailscale-based WireGuard networks

34.3kstars
1.8kforks
Last commit: 8d ago
Repo age: 6y old
Headscale screenshot

Headscale is an open source, self-hosted implementation of the Tailscale control server. It coordinates a WireGuard-based overlay network by exchanging node keys, assigning addresses, and managing routes and sharing within a tailnet.

Key Features

  • Implements core control-plane functions for a Tailscale-compatible network (tailnet)
  • Node registration and coordination via Tailscale clients
  • WireGuard key exchange and IP address management
  • User/namespace boundaries and machine sharing between users
  • Route advertisement and management for subnet routing
  • Designed for a single tailnet suited to personal use or small organizations

Use Cases

  • Run a private Tailscale-compatible VPN without relying on the hosted control server
  • Connect homelab, servers, and remote devices via a WireGuard-based overlay network
  • Provide secure remote access and subnet routing for a small team or community project

Limitations and Considerations

  • Focused on a narrow scope: a single tailnet rather than large multi-tenant deployments
  • Some Tailscale features may be unavailable or behave differently depending on client support and Headscale version

Headscale is a practical choice for self-hosters who want the Tailscale experience with an open control plane. It emphasizes a lean, hobbyist-friendly approach while supporting common coordination features needed for a private overlay network.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Pi-hole

Pi-hole

Network-wide DNS sinkhole for ad and tracker blocking

55.3k
3k
Last commit: 1mo ago

Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.

Alternative to:
AdGuard
AdGuard
+7
AdGuard Home

AdGuard Home

Network-wide DNS server that blocks ads, trackers, phishing and malware

32.1k
2.2k
Last commit: 1d ago

Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Alternative to:
AdGuard
AdGuard
+5
Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

30k
2.4k
Last commit: 4d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
wg-easy

wg-easy

WireGuard VPN server with a web-based admin interface

24.1k
2.3k
Last commit: 2d ago

Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

Alternative to:
Tailscale
Tailscale
+14
NetBird

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

21.1k
1k
Last commit: 1d ago

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Alternative to:
Tailscale
Tailscale
+17
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.1k
1.3k
Last commit: 2mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7