Skip to content
appsgit

Alternatives

Self-hosted Tailscale: Headscale, NetBird and the open-source mesh VPN options

Can you run Tailscale self-hosted? Headscale, NetBird, wg-easy, Pangolin and Firezone compared: licences, features, requirements, and when the free plan wins.

  • appsgit editors
  • Published
  • 6 min read

You cannot self-host Tailscale's own control server, but you can get a self-hosted Tailscale setup with Headscale, an open-source (BSD-3-Clause) reimplementation of the coordination server that works with the official Tailscale clients. If you want a fully open-source mesh VPN instead, NetBird is the strongest option: WireGuard-based, with its own clients, web dashboard and a self-hosted control plane that runs on a 2 GB VM. For simpler needs, wg-easy gives you a plain WireGuard server with a web UI, and Pangolin publishes internal services without opening ports.

How Tailscale works, and what you can self-host

Tailscale builds a peer-to-peer mesh of WireGuard tunnels between your devices. The data plane is the clients themselves: traffic flows directly between devices, or through DERP relays when a direct connection is impossible. The control server hands out keys, applies access rules and tells devices how to find each other.

Most of Tailscale is open source, but not the control server or the GUI clients for Windows, macOS and iOS. So "self-hosted Tailscale" really means replacing the coordination server, which is exactly what Headscale does.

The options at a glance

Licence What it is Clients Web UI Best for
Headscale BSD-3-Clause Open-source Tailscale control server Official Tailscale clients No official UI; community projects Personal and small-team tailnets
NetBird BSD-3 clients; AGPL-3.0 server Complete mesh VPN platform NetBird clients Yes, built in Teams, fully open-source stack
wg-easy AGPL-3.0 WireGuard server with web UI Standard WireGuard apps Yes Simple remote access to home
Pangolin AGPL-3.0 Tunnelled reverse proxy with access control Browser, plus tunnel agent Yes Publishing services without port forwarding
Firezone Apache-2.0 Zero-trust access gateway Firezone clients Yes Managed service; self-hosting unsupported

Headscale: keep the Tailscale clients, own the server

Headscale aims to be "a self-hosted, open source alternative to the Tailscale control server" for a single tailnet, suitable for personal use or a small organisation. It has about 44,400 GitHub stars and over 1,000 commits in the past year, and one of its active maintainers is employed by Tailscale, although the project is independent.

You point the standard Tailscale apps at your Headscale URL, and most everyday features work. According to its documentation, supported features include MagicDNS and split DNS, ACLs and grants, subnet routers and exit nodes, ephemeral nodes, an embedded DERP server, OIDC login, Taildrop, Taildrive and Tailscale SSH. Funnel, Serve and network flow logs are not supported, and OIDC groups cannot be used in ACLs.

Headscale is a single Go binary with SQLite or PostgreSQL, so it runs comfortably on a small VPS. Management is through the CLI; there is no official web interface, though community front ends exist. It needs a public HTTPS endpoint, so put it behind a reverse proxy with a valid certificate.

NetBird: a complete open-source mesh VPN

NetBird is a WireGuard-based mesh network with everything included: clients for desktop and mobile, a management service, signal and relay servers, and a web dashboard for peers, groups, access policies and DNS. Client code is BSD-3-Clause, while the management, signal and relay components are AGPL-3.0. It has about 29,800 GitHub stars and more than 1,000 commits in the past year.

Its self-hosting quickstart asks for a VM with at least 1 CPU and 2 GB of RAM, a public domain, and open TCP ports 80 and 443 plus UDP 3478. A single script deploys the management, signal and relay servers, a STUN service, the dashboard, an embedded Dex identity provider for local users and a reverse proxy with automatic Let's Encrypt certificates. You can also connect an external identity provider for SSO.

NetBird's cloud has a Free plan for up to 5 users and 100 machines, with Team at €6 and Business at €12 per user per month as of October 2026, so you can trial it before self-hosting.

Simpler options

wg-easy is not a mesh. It runs a single WireGuard server with a clean web UI for creating clients and QR codes. If all you need is to reach your home network from your phone, it is the lightest option, and the standard WireGuard apps work with it.

Pangolin solves a different problem: exposing self-hosted web apps to the internet through a tunnel, with authentication in front, without opening ports at home. It is an alternative to Cloudflare Tunnel and ngrok rather than to a device mesh.

Firezone is Apache-2.0 and well engineered, but its README states that production self-hosting is not officially supported, so treat it as a managed service.

When the free Tailscale plan is the better choice

Self-hosting the control plane gives you control and removes a third-party dependency, but it also makes you responsible for the piece that every device relies on to connect. As of October 2026, Tailscale's Personal plan is free for up to 6 users with unlimited user devices, and paid plans start at $8 per user per month for Standard and $18 for Premium. If you have a small homelab, are happy with a Tailscale account, and want features like Funnel, the free plan is hard to beat.

Self-host when you need the coordination server inside your own infrastructure for compliance or privacy, want no external accounts, have more users than the free tier allows, or simply want to understand and own every layer.

Which should you choose?

  • Choose Headscale if you love the Tailscale apps and want a self-hosted control server for yourself, family or a small team.
  • Choose NetBird if you want a fully open-source platform with a web dashboard, user management and policies for a team.
  • Choose wg-easy if you only need remote access to your home network.
  • Choose Pangolin if you want to publish web services securely without port forwarding.

Browse every open-source Tailscale alternative and ngrok alternative, or explore the VPN and proxy and remote access categories. A private mesh is also a safe way to reach services like Jellyfin from outside your home.

FAQ

Questions and answers

Still curious? Email info@appsgit.com.

Can you self-host Tailscale?

Not the official control server, which is proprietary. You can self-host Headscale, an open-source implementation of the Tailscale control server, and keep using the regular Tailscale clients on your devices. Alternatively, NetBird is a complete open-source mesh VPN with its own self-hostable control plane.

Is Headscale or NetBird better?

Headscale is better if you want to keep Tailscale's polished clients and run a single personal or small-team network. NetBird is better if you want a fully open-source stack with a web dashboard, built-in user management and multi-user access controls, without depending on another company's clients.

Is the free Tailscale plan enough?

For many homelabs, yes. As of October 2026 the Personal plan is free for up to 6 users with unlimited user devices. Self-hosting makes sense when you need full control of the coordination server, no third-party account, or more users than the free plan allows.

Does self-hosted Headscale support Tailscale Funnel?

No. Headscale's feature list marks Funnel, Serve and network flow logs as not supported as of October 2026. Core features such as MagicDNS, ACLs and grants, subnet routers, exit nodes, Taildrop and Tailscale SSH work.

The weekly digest

Liked this? Get the next one by email

Fresh releases, rising projects and one deploy guide a week. Join home labbers and engineers who self-host.

One email a week. No spam, unsubscribe anytime.