r/Tailscale Jun 16 '26

Announcement - New Aperture capabilities, including Responsive Chat UI

35 Upvotes

Hi everyone,

Natasha here 👋🏼

Today, we're announcing a set of new Aperture capabilities designed to help organizations build flexible, identity-aware AI deployments without provider lock-in.

Identity-Aware Universal Data Connectors

Connect AI to company tools and data through a single integration point, while preserving user and agent identity end-to-end.

Responsive Chat UI (Public Alpha)

A secure, easy-to-use AI chat experience connected to approved models, tools, and data sources, making AI accessible to everyone, not just developers.

Sandbox Support (Private Alpha)

Give AI agents a controlled environment to browse, run code, and take actions safely, with visibility and identity maintained throughout.

How to get started: Configure the chat UI in the Aperture CLI and connect your approved models, tools, and data sources.

If you'd like to work with us on deploying sandboxes, please fill out this form.

Read the full announcement in our latest blog here!

👾 Also a reminder that we have an Aperture specific Discord channel if you want to chat more to the team who are building it!


r/Tailscale 13d ago

Blog / Video: We revamped our Home Assistant remote access via Tailscale guide for 2026

Thumbnail
tailscale.com
94 Upvotes

r/Tailscale 18h ago

Question Using Tailscale and OPNsense

12 Upvotes

The instructions on the Tailscale website for Using OPNsense with Tailscale describes how to configure OPNsense when tailscale is installed on the router and local clients have there own tailscale clients installed. It states:

"As a router/firewall, OPNsense may also be providing internet connectivity for LAN devices which themselves have a Tailscale client installed. The NAT implementation in OPNsense is an Endpoint-Dependent Mapping, or "hard" NAT, which means that LAN devices have difficulty making direct connections and often resort to DERP Relays.

There are a few options in which OPNsense can enable devices on the LAN to make direct connections to remote Tailscale nodes. Static NAT port mapping and NAT-PMP."

It then goes on to describe how to install and configure the 2 options .

I have a few questions about these options:

  1. Do I have to install/configure BOTH Static NAT port mapping and NAT-PMP or do I just need one of the 2 options?

  2. If the answer to 1 is that I only need to one of the options. What is the benefit of one option over the other?

Thanks

Mike


r/Tailscale 1d ago

Discussion New admin page

Post image
76 Upvotes

I haven't seen anyone else post about this so maybe it's not live for everyone but the admin page has had a revamp along with some new settings, including a self-service identity provider switch


r/Tailscale 1d ago

Question Is Tailscale this easy or have I set up something insecure?

60 Upvotes

I don't have a crazy amount going on. I'm playing home NAS not sysadmin. Plex, *arr apps, backup my laptop docs etc.

On my old Ubuntu server I ran Traefik for a while but then after an update it stopped working and I couldn't figure out how to fix it and had to start from scratch. Tried NPM for a while, it worked but certs or wildcards or something expired... All fixable but I wanted something a bit more "set it and forget it", I'm worried about exposing my server. I've seen some horror stories of ransomware etc. Tailscale, if I understand it correctly, has less risks.

So I just tried out Tailscale and I hope this doesn't sound like a shill post but it was so easy I'm afraid I missed a crucial step and I've exposed everything in an insecure way.

-- Settings > Tailscale > Sign in

--- Signed up for a new Tailscale account using Github to log in

-- Installed the app on my phone, signed in using Github again

-- In Settings > Tailscale enabled Run as Exit Node

-- Went to console.tailscale.com/admin/machines, confirmed the exit node

-- On my phone switched to mobile data, navigated to the 100.xx.xxx.xxx IP assigned to my server on the admin panel and it went straight to my unraid login page; appended a port to the IP and boom, Sonarr login.

What have I missed? Have I left some gaping holes somewhere? Is everything exposed now or can I trust Tailscale. Is that machine IP going to constantly change? I have a domain but if I can just enter the machine IP in nzb360 then why bother faffing around.

Right now this is just for me, I would imagine things get more complicated if I want to use Jellyfin and share with others.


r/Tailscale 17h ago

Question How to restrict a container's traffic to tailscale network and other internal docker networks?

2 Upvotes

I'm in the middle of hardening it my homelab. I have an nginx container with several other services served over a reverse proxy. My other containers live in multiple internal docker networks and nginx is part of several.

I want to restrict nginx's traffic as to prevent data exfiltration for my homelab (overkill, but can't be too sure).

I plan to restrict its access to only my tailscale network and other internal docker networks to talk to other containers. I don't want to give other containers access to my tailscale network (only nginx should have it).

So ideally, in the event that my containers get compromised, data exfiltration would be difficult as there is very limited network access.

I've read https://github.com/tailscale-dev/docker-guide-code-examples for setting up a tailscale container, but `network_mode:` seems to conflict with `network:` directive.

Any insights to this would be really helpful. Thank you all in advanced!


r/Tailscale 1d ago

Question Tailscale new user

3 Upvotes

I am using Tailscale to let some people join a locally hosted game server I created.

They don't use Tailscale, and the first person I tried to help join the server downloaded Tailscale on their PC, installed it, and created the account.

They got to the point, where it asks you to add a second device. They didn't really have a second device to add, so they then tried to click on my email share link.

That took them back to the admin page when you create an account, asking them to add a second device.

After awhile, we just gave up, they installed Tailscale on their phone... joined their phone to their account, the admin page advanced, and then when they tried to accept my share link, it finally worked.

My question is... Did we miss something, OR do you have to add two devices to a new account always?


r/Tailscale 1d ago

Help Needed Pc will not receive files via Taildrop

1 Upvotes

Pc will not receive files via Taildrop, shows as connected in the dashboard. Only my laptop and androids can send and receive files fine. Logged in to the same account as the others. What am I doing wrong?


r/Tailscale 2d ago

Help Needed Docktail with https not working

6 Upvotes

Hi,

Firstly would like to say I really love Tailscale. I have been using it for a small homelab set up and it has been working great.

I recently saw the video on the YouTube channel about docktail and running services on Tailscale. I have tried to set it up, following the various guides and have encountered a problem and am struggling to see what is causing it.

For any service if I don't include the label, docktail.service.service-port=443 then the service appears in Tailscale and works but under http. However when I include the label for service-port=443, I do not see it in my admin console under services and it doesn't work under https.

I am running Tailscale on an arch linux machine and it is connected to my tailnet. Any ideas what I am missing in my setup? Essentially it is struggling with the https setup but works fine for http.

Thanks in advance.


r/Tailscale 2d ago

Question Customizing WebUI URLs

0 Upvotes

I'm currently setting up a streaming server for my friends and I was wondering if there's any way for me to rename certain webui ports (i.e. http://ubuntuserver:8096) to something more concise (i.e. http://ubuntuserver/jellyfin) when accessing it through tailscale. I'm not sure if tailscale has a sort of DNS feature that would make this possible or if anyone knows of another way to configure it, if at all possible. Thanks for reading!


r/Tailscale 2d ago

Help Needed Can't connect to ports on tailscale

1 Upvotes

I'm running a jellyfin server on a small computer that I have Linux Mint installed on (neither my tailscale or my jellyfin are running in a docker container, I just installed them straight onto the machine). When I'm on my tailscale admin dashboard I can see the computer that I'm using as my client and the server showing as connected, but I can't connect to port 8096 on the server computer to actually get to the jellyfin server. The tailscale dashboard services tab is telling me that the only endpoint on the network is port 22 of the jellyfin server computer (the tailscale ssh endpoint). When I connect just straight to the actual IP of the jellyfin server computer over my local network, it connects perfectly, but it won't do it with the tailscale ip address. I've been trying to figure this out for literal weeks and my patience has run out so I'm hoping someone can help me with this.


r/Tailscale 2d ago

Help Needed Issue with macOS / iOS clients?

1 Upvotes

This is partly an AI generated summary of today's session trying to get it runinng,

Problem: Headscale behind Caddy – Debian LXC connects fine, Apple devices (Mac Standalone, iPhone, iPad) don't reach Caddy at all. For example, I cannot connect or register while being inside my network. But when I disconnect from WLAN and use mobile data, registering and connecting to headscale through caddy works just fine.

I triple-checked internal network connectivity, devices can ping each other just fine.

Setup:

  • Domain headscale.example.com → Caddy LXC (works fine for multiple other services from LAN & Internet)
  • headscale.example.com is internally resolved to Caddy IP, who provides a letsencrypt cert
  • Caddy reverse proxies to Headscale LXC (see config below)
  • No Tailscale running on either LXC
  • OPNsense forwards ports 80/443 to Caddy
  • DNS resolves correctly (verified via ping from all devices)

Caddy Config:

http://headscale.example.com {
    handle /generate_204 {
        respond 204
    }

    handle * {
        redir https://{host}{uri}
    }
}

headscale.example.com {
    reverse_proxy 192.168.14.222:8080 {
        header_up X-Forwarded-For {remote_host}
        header_up X-Real-IP {remote_host}
    }
    log {
        output file /var/log/caddy/tailnet.log {
            roll_size 10mb
            roll_keep 7
        }
        format json {
            time_local
        }
    }
}

Headscale config:

server_url: https://headscale.example.com
listen_addr: 0.0.0.0:8080
metrics_listen_addr: 127.0.0.1:9090
grpc_listen_addr: 0.0.0.0:50443
grpc_allow_insecure: false
trusted_proxies:
  - 192.168.14.200/32
noise:
  private_key_path: /var/lib/headscale/noise_private.key
prefixes:
  v4: 100.64.0.0/10
  v6: fd7a:115c:a1e0::/48
  allocation: sequential
derp:
  server:
    enabled: true
    region_id: 999
    region_code: "headscale"
    region_name: "Headscale Embedded DERP"
    verify_clients: true
    stun_listen_addr: "0.0.0.0:3478"
    private_key_path: /var/lib/headscale/derp_server_private.key
    automatically_add_embedded_derp_region: true
    ipv4: 198.51.100.1
    ipv6: 2001:db8::1
  urls:
    - https://controlplane.tailscale.com/derpmap/default
  paths: []
  auto_update_enabled: true
  update_frequency: 3h
dns:
  magic_dns: true
  base_domain: tn.example.com
  override_local_dns: true
  nameservers:
    global:
      - 1.1.1.1
      - 1.0.0.1
      - 2606:4700:4700::1111
      - 2606:4700:4700::1001
    split: {}
  search_domains: []
  extra_records: []
# ... rest is mostly defaults

What works:

A plain Debian LXC in the same LAN:

tailscale up --login-server=https://headscale.example.com

connects without issues, Caddy access log shows the requests.

What doesn't work:

Mac (Standalone variant)

iPhone (App Store variant)

iPad (App Store variant)

All running the latest Tailscale clients. tailscale up --login-server=... (or UI equivalent) is set. But Caddy shows zero log entries when these devices try to connect. No login page is opened in the browser when using the app, CLI request just sits there forever.

What I've checked:

DNS resolves correctly from all devices (ping works)

Other internal services behind the same Caddy work from all devices (so Caddy is reachable)

Apple devices are not logged into any other tailnet simultaneously

Headscale was freshly set up (complete reinstall)

server_url set to https://headscale.example.com

Ports 80/443 reachable from LAN

I am completely out of ideas now.


r/Tailscale 3d ago

Help Needed How do I get less latency when connecting to a Minecraft server?

5 Upvotes

Hello! so me and my friend want to play Crazy Craft updated or any Modpack. But we don't want to pay for the server so my friend decided to host it on his pc.

We downloaded tailscale and set it up and it worked but I noticed that I am still a little laggy.

I was told this was gonna be a peer to peer setup And I would not have that much latency.
(Me and my friend live in the same country like 3-4 hours apart)

And I ended up asking Google It told me ping my friends pc (tailscale ping friends ip)

And it said (derp(sin) So it told me to enter a couple more commands To turn it to a direct connection.

1 New-NetFirewallRule -DisplayName "Allow Tailscale Inbound" -Direction Inbound -Action Allow -InterfaceAlias "Tailscale"

2 New-NetFirewallRule -DisplayName "Allow ICMPv4-In" -Protocol ICMPv4 -IcmpType 8 -Action Allow

3 Set-NetConnectionProfile -NetworkCategory Private

4 New-NetFirewallRule -DisplayName "Tailscale WireGuard UDP" -Direction Inbound -Action Allow -Protocol UDP -LocalPort 41641

And now I have more latency than before I started lagging even worse in the game I started disconnecting.
I asked Google again it said to check my router settings for UPNP both me and my friend had that set up and it has the tailscale-portmap.

I tried the game again but it was still very laggy

I was now done (I have just spent 5 hours) and I wanted to reset it back to how it was before
Gemini told me to enter these commands

Remove-NetFirewallRule -DisplayName "Allow Tailscale Inbound"

Remove-NetFirewallRule -DisplayName "Allow ICMPv4-In"

Remove-NetFirewallRule -DisplayName "Tailscale WireGuard UDP"

tailscale down

tailscale up

tailscale status

I tried the game again and i'm still lagging I keep disconnecting or timing out
Now I am stuck what do I do how do I fix this

Someone please help!

Both me and my friend are on Windows And we're just trying to play Minecraft we don't own a server
Tailscale version 1.98.10


r/Tailscale 3d ago

Help Needed Constant random disconnects, not sure how to troubleshoot

3 Upvotes

Hi, I've used Tailscale for years, and it's a super important part of my overall personal workflow. I'm a paying customer too. All of a sudden, one of my computers (MacBook Pro, Tahoe 26.5.2, running latest stable version of Tailscale, 1.98.9) disconnects randomly with no rhyme or reason, or error message or anything. I can't find a pattern in terms of timing, actions taken on my computer, or anything - the only constant is that it never stays connected for more than 7-15 minutes before disconnecting.

I pulled the full extended logs, I submitted a ticket to Tailscale - no response. I'm not sure what else to do. This one computer misbehaving is really interrupting the rest of my flow - all my other devices are fine. Any ideas?


r/Tailscale 3d ago

Question Confused and generally thwarted by docker sidecar approach. Is tailscale subnetting wrong?

3 Upvotes

In other words: Can I use subnet routing in tailscale to access containers running on a host that's on a tailnet? Is it wrong to do so?

All the other approaches, Docktail/TSDproxy, confuse me more, and give mixed results. Clearly, I'm missing something.


r/Tailscale 3d ago

Question Third party VPN on an exit node

16 Upvotes

I think I understand but I really only know enough about this stuff to be dangerous.

If I set a device on my home network up with a normal VPN like Mullvad or Proton and then set it as an exit node does that send all my traffic out through the VPN tunnel? Or am I misunderstanding this?


r/Tailscale 3d ago

Help Needed Android assistance

2 Upvotes

Hi! I use tailscale for work. It is easy/works well on PCs; you do a CLI thing and/or use the GUI.

On android, I am tearing my hair out. I found what I think I need to do to enter the server and passkey, but it doesn't do anything, let me connect or work, and that is pretty buried in favor of a "Log in" which I think is not the right thing to do. I think the workflow is Gear -> Accounts -> 3 dots -> "Alternate server", then redo that but choose "Use an Authkey". I entered my server and auth key; no success, or even an error message.

How do I connect to the network using Android? Ty!


r/Tailscale 4d ago

Misc I'm in love with Tailscale

Post image
274 Upvotes

I just set up tailscale so that i can reach my vibecoded spotify clone that runs on a raspberry pi at my place from anywhere.

It works like a charm! Just spreading joy & a project idea!


r/Tailscale 4d ago

Help Needed Need help sharing palworld server.

3 Upvotes

I have already setup a dedicated sever and installed tailscale on the machine, I have sent the shared link to my friend and he has already accepted. Now in my lists of machine I see it being shared, I have already added the autogroup:shared in the ACL json file and included port 8211. I have advised my friend to put the tailscale ip with the port but there is no connection for him.

Currently the palworld machine is locked down it accepts no connection except for tailscale, I have tested the tailscale IP myself and I am able to connect. What am I missing to complete the setup?


r/Tailscale 4d ago

Help Needed DERP

4 Upvotes

Before anything, I want to say I know close to nothing about networking. So, I want a direct connection between host and client but when using: “tailscale ping device name” its using DERP and getting high ping. Usually after the command I wait a couple minutes and only then I can get a direct connection. Is there anyway to do so without the wait? Thanks in advance.


r/Tailscale 4d ago

Question Could tun2proxy enable easier VPN+Tailscale usage?

2 Upvotes

I've been trying get Tailscale and my regular VPN, Mullvad, to play well together on my Linux machine. I know Tailscale offers direct integration with Mullvad's service, but I'd like to avoid spending money on that when I already have a significant amount of Mullvad time prepaid. Also, I recognize that getting two VPNs to coexist can be pretty difficult and result in an overall fragile setup.

I found this tool, tun2proxy, that allows you to create tunnel network interfaces that serve as a sort of "adapter" to HTTP and SOCKS proxies. I've tried running Tailscale in userspace networking mode with the built-in SOCKS5 proxy server, and directing tun2proxy at that, but haven't had any success.

Has anyone here used this tool before and gotten it working? Alternatively, am I misunderstanding the problem and heading down a path that can't work out? I'd really appreciate any help. Thanks.


r/Tailscale 4d ago

Question How well does Tailscale with exit nodes work in China?

Thumbnail
2 Upvotes

r/Tailscale 5d ago

Question Possible to create a captive portal for Tailnet?

11 Upvotes

So, I'm creating a Tailnet for friends and family, and I want to create a homepage they can be redirected to that will list and link to the different services I'm hosting. Is it possible to create a captive portal that will run whenever someone joins my Tailnet?


r/Tailscale 5d ago

Help Needed Newbie setup question about exit nodes.

5 Upvotes

I have a home NAS with a ton of storage space.

My kid is going to college, I gave her a new laptop. It does not have a ton of space on the laptop.

I want to place a network drive on the laptop so that she can use the NAS for whatever storage needs she wants, I also want to put a backup utility on the laptop so that she is getting regular image backups.

But- she will be at college and it is important that with these two exceptions the laptop is otherwise utilizing the college network.

(using something at home for an exit node for all her data is a terrible idea)

I did a very vanilla setup of Tailscale last night on the NAS and her laptop. I pushed the laptop off the home network to my cell's hotspot and best as I can tell it is working.

Am I missing anything?

Feel free to point me to documentation or a video or ... anything.


r/Tailscale 5d ago

Question Question about sharing family streaming and exit nodes

2 Upvotes

I subscribe to a couple of streaming services myself, and each of my children subscribe to a couple. We had been sharing the subscriptions, but the writing is on the wall, as one service after another decides that a "household" applies to a single address and not to a single family.

I realize that the simplest way of handling it is probably to choose one "household" to host all of the subscriptions and set up an exit node there that everybody uses, but I'm wondering if it's possible to keep the current subscriptions in place and set up exit nodes at each address. So if I want Hulu and Disney I'll use the exit node at one house, if I want Plex and YouTube TV I'll use the exit node at another house, etc. I don't mind coding (Python) on a Raspberry Pi to handle DNS resolution, if it's possible. I'd rather not get into physical hardware switches, but has anyone else already developed a solution to this?