An open source, self-hosted implementation of the Tailscale control server.
Documentation · Getting started · Install · Changelog
Point the stock Tailscale clients at slopscale instead of the hosted control plane: your machines exchange WireGuard keys, get their IP addresses, DNS and DERP relay from a server you run, under an access policy you write.
slopscale is a fork of headscale with these improvements:
- Faster map responses, lower memory use, a smaller database footprint
- Built-in admin console at
/console/, signed in through your identity provider, with a terminal to any machine running Tailscale SSH - User roles, device and user approval, invitations, machine sharing, groups and access rules, networks, temporary access, device posture and postures, hardware attestation, suspension
- Tailscale features the hosted control plane has: Services, app connectors, Funnel, HTTPS certificates for Serve, tailnet lock, identity tokens, SSH session recording, key expiry, client update notices
- OAuth clients with scopes and workload identity federation, so the Tailscale Terraform provider and Kubernetes operator work unchanged
- DNS, DERP relays, key expiry and certificates configurable at runtime, with an embedded relay on by default
- Webhooks and chat or email notifications, log streaming to a SIEM, audit log, client updates and diagnostics over the control connection
- Bug fixes to the control protocol: exit node suggestions, ephemeral registration, DNS records, deleted machines, and more
The documentation covers setup and every feature. CHANGELOG.md lists what changed against headscale, including the rename.
This project is not associated with Tailscale Inc. or the headscale project.