juanfont/headscale

An open source, self-hosted implementation of the Tailscale control server

View on GitHub ↗Jump to charts ↓Open shareable report →

Data as of . Signed-in members get hourly updates — create a free account.

Summary Information

Updated 31 minutes ago
Added to GitGenius on November 3rd, 2025
Created on June 21st, 2020
Open Issues & Pull Requests: 137 (+0)
GitHub issues: Enabled
Number of forks: 2,614
Total Stargazers: 44,453 (+2)
Total Subscribers: 234 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 42.5 hours
Mean response time: 68.7 days
90th percentile: 180.8 days
Tracked items: 765

Maintainer activity

3 people did triage or write work on this repository in the last 12 months.

Counts unlabeled, assigned, unassigned, milestoned, demilestoned, locked, unlocked over the last 12 months. These are issue and pull request events that require triage or write permission. Commits and code review are not counted. labeled and renamed are excluded because GitHub issue forms record the issue author as the actor. Figures from October 7, 2026. This count is not comparable across projects: each project's automation decides which of these events a person emits.

How this project is maintained

About 7% of issues opened in the past year have never received a reply. 89% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "bug" is answered fastest, typically in about 29 hours, while "tailscale-feature-gap" waits about 3 weeks. 26% of tracked open issues have had no activity in three months. 84% of issues opened in the past year have been closed, leaving a working backlog.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 71
New in 7 days: 4
Closed in 7 days: 8
Avg open age: 370 days
Stale 30+ days: 48
Stale 90+ days: 32

Recent activity

Opened in 7 days: 4
Closed in 7 days: 8
Comments in 7 days: 11
Events in 7 days: 61

Top labels

  • bug (606)
  • enhancement (301)
  • stale (170)
  • no-stale-bot (151)
  • policy 📝 (45)
  • OIDC (36)
  • tailscale-feature-gap (25)
  • good first issue (23)

Most active issues this week

Sign in to see which issues are moving.
Sign in

Detailed Description

Headscale is an open-source, self-hosted implementation of the Tailscale coordination server, designed to provide a private, secure mesh VPN network using the WireGuard protocol. It empowers users to build their own zero-configuration VPN, offering complete control over their network infrastructure without relying on Tailscale's proprietary cloud service. By running Headscale, individuals and organizations can manage their own Tailscale-compatible network, connecting devices securely across different locations, subnets, and cloud providers as if they were all on the same local network.

At its core, Headscale acts as the central brain for a Tailscale-like network. It handles critical functions such as user authentication, node registration, IP address assignment, and the distribution of WireGuard public keys among connected devices. When a new device joins the network, it authenticates with Headscale, which then orchestrates the secure WireGuard tunnels between all authorized nodes. This eliminates the need for complex firewall configurations or port forwarding, as each device establishes direct, encrypted peer-to-peer connections wherever possible, falling back to a DERP (Designated Encrypted Relay for P2P) server when direct connections are blocked.

One of Headscale's primary advantages is its emphasis on self-hosting and control. Users gain full ownership of their network's metadata, user data, and authentication processes, addressing concerns around privacy, data sovereignty, and vendor lock-in. It supports a wide range of authentication backends, including OpenID Connect (OIDC), SAML, GitHub, Google, and even local user management, offering flexibility to integrate with existing identity providers. This flexibility makes it suitable for diverse environments, from small homelabs to large enterprise deployments with strict security and compliance requirements.

Beyond basic connectivity, Headscale provides a rich set of features that enhance network management and security. It supports Access Control Lists (ACLs), allowing administrators to define granular policies for which devices can communicate with each other, based on users, tags, or specific IP ranges. MagicDNS automatically resolves hostnames within the private network, simplifying access to resources. Subnet routers enable the integration of entire existing subnets into the mesh VPN, allowing devices on the Tailscale network to access resources on a traditional LAN, and vice-versa. Exit nodes provide a way to route all internet traffic from specific devices through a designated node, useful for geo-unblocking or securing traffic.

Headscale is written in Go, known for its performance and concurrency, making it efficient and scalable. It supports both SQLite and PostgreSQL as database backends, catering to different deployment needs and scales. Deployment is straightforward, with official Docker images and pre-compiled binaries available, facilitating quick setup on various operating systems and cloud platforms. The project benefits from an active community and ongoing development, ensuring compatibility with the latest Tailscale client features and continuous improvements.

In summary, Headscale offers a powerful, flexible, and private solution for building modern mesh VPNs. It democratizes the sophisticated networking capabilities of Tailscale by making its coordination server open-source and self-hostable. For anyone seeking to establish a secure, zero-configuration network with complete control over their infrastructure, Headscale presents an compelling alternative, combining the ease of use of Tailscale with the freedom and privacy of self-managed open-source software.