Tailcat: Secure Tunnels in Seconds Without Tailscale's Control Plane

Tailcat: Secure Tunnels in Seconds (Tailscale)

Tailcat: Secure Tunnels in Seconds Without Tailscale's Control Plane

Tailscale has released Tailcat, an open-source tool that reuses its encrypted data plane (WireGuard, magicsock, DERP) to create point-to-point tunnels without needing a Tailscale account or control plane. It works like netcat: one side runs a server and gets a short token, the other side uses it to connect, with end-to-end encryption and automatic NAT traversal. It can pipe stdin/stdout, expose local ports, run an auth-free SSH server, and more, all in userspace without root.

All traffic between the two is encrypted end-to-end with WireGuard.
  1. bradfitz

    One fun use case: a coworker just whipped up this Minecraft mod using tailcat as its transport: https://github.com/tailscale/tailcat-for-minecraft

    (just a cute demo, not intended for release or ongoing maintenance)

  2. megamorf

    So this is somewhat similar to Iroh?

    https://github.com/n0-computer/iroh

  3. Schlagbohrer

    The Tor network and Onion protocols used to be used for this type of thing 10 or 15 years ago, exposing a home service with a .onion address and then gaining secure private access over the global internet infrastructure that way. But I haven't even seen any Tor related headlines for ages.

  4. mikepurvis

    I enjoy that they supply a nix install/environment, similar to the main tailscale/tailscale repo. Is nix widespread or the standard dev environment at tailscale, or is it like a 10% option and most people just use Docker or whatever?

  5. pbohun

    This is so cool! I mean, we really wouldn't need it if we had 100% ipv6 (no cgnat), but this is the next best thing. I think people underestimate the innovation that could happen if we had trivial p2p.

  6. stillpointlab

    I've spent time finally learning what tailscale is and how it works and I'm impressed. It's a rare thing in the technology world but I'm glad I finally took the time.

    I literally just figured out how tsnet fits into the picture (an in-process Go based entire network stack that gets the process to act as a node in the tailnet) and so that helps me understand this (everything in tsnet excepting the control plane). It's very impressive that they can do this in a reliable way.

  7. archietect

    It looks like a direct competitor for the recently launched bitbang-cli

    https://github.com/richlegrand/bitbang-cli

  8. aseipp

    Just yesterday I was complaining that I wanted to SSH back to my homenet while at the office, on my office (not home) tailnet. I wrote something based on Iroh to do this, but it's one shot (ie not particularly generalized). Might be able to throw it away or redesign it with some inspiration from this! Thanks.

More from this day

2026-08-26