−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

VPS for Headscale: self-hosted Tailscale control

Run Headscale on a small VPS and keep your mesh VPN's coordination server under your own control. Install, first user, connecting devices, and the limits.

A mesh VPN is one of those tools that quietly makes everything easier: your laptop, home server, phone and VPSes all see each other on private addresses, wherever they are. The catch with hosted mesh VPNs is the coordination server — a company keeps the map of every device you own. Headscale is an open-source replacement for that control server. Run it on a small VPS, keep using the normal client apps, and the map is yours.

How it fits together

That last point is why a tiny plan works: the VPS only answers small coordination requests.

What you need

Install (Debian 12 / Ubuntu 24.04)

Grab the current .deb from the Headscale releases page on GitHub — replace the version with the latest one:

HS_VER=0.26.1
wget -O headscale.deb \
  "https://github.com/juanfont/headscale/releases/download/v${HS_VER}/headscale_${HS_VER}_linux_amd64.deb"
apt install -y ./headscale.deb caddy

Edit /etc/headscale/config.yaml — the two lines that matter:

server_url: https://hs.example.com
listen_addr: 127.0.0.1:8080

Put Caddy in front for HTTPS:

cat > /etc/caddy/Caddyfile <<'EOF'
hs.example.com {
    reverse_proxy 127.0.0.1:8080
}
EOF
systemctl enable --now headscale
systemctl reload caddy

Add a user and a device

headscale users create alice
headscale users list            # note the user's ID
headscale preauthkeys create --user 1 --expiration 24h

Older releases take the user name instead of the ID in --user; headscale preauthkeys create --help tells you which yours expects.

On a Linux device:

tailscale up --login-server https://hs.example.com --authkey YOUR_KEY

On phones and desktops, the Tailscale app lets you set a custom control server in its settings. Run headscale nodes list on the VPS and your device should be there.

Relays and NAT traversal

Most devices connect directly. When two of them can't (strict mobile networks, double NAT), traffic goes through a DERP relay. Out of the box Headscale uses Tailscale's public relays — they only see encrypted packets. If you want nothing external in the path, enable the embedded relay in config.yaml (derp.server.enabled: true) and open UDP 3478. The relayed traffic then counts against your VPS bandwidth.

Honest limits

There's no official web dashboard: users, keys and routes are CLI commands (fine once you've done it twice). Newer features of the hosted service show up in Headscale later, if at all. And the control server is now your responsibility — if it's down, existing connections keep working, but new devices can't join and keys can't refresh. Back it up: the whole state is /var/lib/headscale.

For a home lab, a family, or a small team that wants its device map off third-party servers, it's one of the best uses of an $8 VPS.

Ready to deploy? Pay with crypto, no KYC — live in about a minute.

Deploy now →

FAQ

What does the Headscale server actually see?

Metadata: which devices exist, their public keys, their addresses and when they were last online. Your traffic itself flows directly between devices over WireGuard (or through a relay if they can't reach each other) and is end-to-end encrypted. Self-hosting means that metadata sits on your server instead of someone else's.

Do I need special clients?

No. You use the regular Tailscale apps on Linux, macOS, Windows, iOS and Android and point them at your server's URL. On Linux that's one flag: --login-server.

Which plan is enough?

Headscale is tiny — Nano-IP ($8/mo) handles a family or a small team easily. You need a dedicated IP because devices must reach the control server over HTTPS; a NAT plan doesn't accept inbound 443.

What if two devices can't connect directly?

They fall back to a relay (DERP). By default Headscale uses Tailscale's public relays, which only ever see encrypted packets. You can enable Headscale's built-in relay instead; it needs UDP 3478 open and uses your VPS bandwidth for relayed traffic.

What's missing compared to the hosted Tailscale service?

There's no official web admin panel — you manage users and keys from the command line (community UIs exist). Some newer hosted features arrive in Headscale later or not at all. For a personal or small-team network the core — mesh, ACLs, MagicDNS, exit nodes — works well.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.