{"id":13424793,"url":"https://github.com/juanfont/headscale","last_synced_at":"2026-06-17T11:00:59.029Z","repository":{"id":37031749,"uuid":"273871859","full_name":"juanfont/headscale","owner":"juanfont","description":"An open source, self-hosted implementation of the Tailscale control server","archived":false,"fork":false,"pushed_at":"2026-06-14T01:00:25.000Z","size":52885,"stargazers_count":40000,"open_issues_count":113,"forks_count":2187,"subscribers_count":192,"default_branch":"main","last_synced_at":"2026-06-14T11:39:04.032Z","etag":null,"topics":["tailscale","tailscale-control-server","tailscale-server","wireguard"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/juanfont.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null},"funding":{"ko_fi":"headscale"}},"created_at":"2020-06-21T09:21:05.000Z","updated_at":"2026-06-14T09:50:21.000Z","dependencies_parsed_at":"2026-02-05T09:09:17.767Z","dependency_job_id":null,"html_url":"https://github.com/juanfont/headscale","commit_stats":{"total_commits":2389,"total_committers":177,"mean_commits":"13.497175141242938","dds":0.7170364169108414,"last_synced_commit":"5f9c26930ce796284a8fc7ad167f76e187813d64"},"previous_names":[],"tags_count":165,"template":false,"template_full_name":null,"purl":"pkg:github/juanfont/headscale","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/juanfont%2Fheadscale","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/juanfont%2Fheadscale/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/juanfont%2Fheadscale/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/juanfont%2Fheadscale/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/juanfont","download_url":"https://codeload.github.com/juanfont/headscale/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/juanfont%2Fheadscale/sbom","scorecard":{"id":385101,"data":{"date":"2025-08-11","repo":{"name":"github.com/juanfont/headscale","commit":"30cec3aa2b422a9d8184e47a747598fbe2f9f569"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.6,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1","Warn: no topLevel permission defined: .github/workflows/check-generated.yml:1","Warn: no topLevel permission defined: .github/workflows/check-tests.yaml:1","Warn: no topLevel permission defined: .github/workflows/docs-deploy.yml:1","Warn: no topLevel permission defined: .github/workflows/docs-test.yml:1","Warn: no topLevel permission defined: .github/workflows/gh-actions-updater.yaml:1","Warn: no topLevel permission defined: .github/workflows/integration-test-template.yml:1","Warn: no topLevel permission defined: .github/workflows/lint.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Warn: no topLevel permission defined: .github/workflows/stale.yml:1","Warn: no topLevel permission defined: .github/workflows/test-integration.yaml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Warn: no topLevel permission defined: .github/workflows/update-flake.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.26.1 not signed: https://api.github.com/repos/juanfont/headscale/releases/223618853","Warn: release artifact v0.26.0 not signed: https://api.github.com/repos/juanfont/headscale/releases/218597229","Warn: release artifact v0.26.0-beta.2 not signed: https://api.github.com/repos/juanfont/headscale/releases/217774067","Warn: release artifact v0.26.0-beta.1 not signed: https://api.github.com/repos/juanfont/headscale/releases/216371830","Warn: release artifact v0.25.1 not signed: https://api.github.com/repos/juanfont/headscale/releases/202369467","Warn: release artifact v0.26.1 does not have provenance: https://api.github.com/repos/juanfont/headscale/releases/223618853","Warn: release artifact v0.26.0 does not have provenance: https://api.github.com/repos/juanfont/headscale/releases/218597229","Warn: release artifact v0.26.0-beta.2 does not have provenance: https://api.github.com/repos/juanfont/headscale/releases/217774067","Warn: release artifact v0.26.0-beta.1 does not have provenance: https://api.github.com/repos/juanfont/headscale/releases/216371830","Warn: release artifact v0.25.1 does not have provenance: https://api.github.com/repos/juanfont/headscale/releases/202369467"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Pinned-Dependencies","score":7,"reason":"dependency not pinned by hash detected -- score normalized to 7","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration-test-template.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/juanfont/headscale/integration-test-template.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration-test-template.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/juanfont/headscale/integration-test-template.yml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile.derper:3","Warn: containerImage not pinned by hash: Dockerfile.derper:15: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f","Warn: containerImage not pinned by hash: Dockerfile.integration:5: pin your Docker image by updating docker.io/golang:1.24-bookworm to docker.io/golang:1.24-bookworm@sha256:e617461712dbebf8768e10c1a5deab2833d67d2b692894cb8f4f0a3c19a8efb5","Warn: containerImage not pinned by hash: Dockerfile.tailscale-HEAD:7","Warn: containerImage not pinned by hash: Dockerfile.tailscale-HEAD:39: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f","Warn: goCommand not pinned by hash: Dockerfile.integration:17","Warn: pipCommand not pinned by hash: .github/workflows/docs-deploy.yml:38","Warn: pipCommand not pinned by hash: .github/workflows/docs-test.yml:26","Info:  24 out of  24 GitHub-owned GitHubAction dependencies pinned","Info:  34 out of  36 third-party GitHubAction dependencies pinned","Info:   0 out of   2 pipCommand dependencies pinned","Info:   0 out of   5 containerImage dependencies pinned","Info:   2 out of   3 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 1 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":8,"reason":"2 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3830 / GHSA-x4rx-4gw3-53p4","Warn: Project is vulnerable to: GO-2025-3787 / GHSA-fv92-fjc5-jj9h"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T16:24:22.861Z","repository_id":37031749,"created_at":"2025-08-18T16:24:22.862Z","updated_at":"2025-08-18T16:24:22.862Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34402662,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-16T02:00:06.860Z","response_time":126,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["tailscale","tailscale-control-server","tailscale-server","wireguard"],"created_at":"2024-07-31T00:00:59.560Z","updated_at":"2026-06-17T11:00:58.988Z","avatar_url":"https://github.com/juanfont.png","language":"Go","funding_links":["https://ko-fi.com/headscale"],"categories":["Go","Proxy and VPN","Networking","Install from Source","others","🤖 AI \u0026 Machine Learning","HarmonyOS","网络服务","VPN","Repos","Self-hosted apps ![](https://img.shields.io/badge/_-SELF--HOSTED-10b981?style=flat-square)","Software","Table of Contents","Transport-layer defenses","Projects"],"sub_categories":["Python","VPN/Mesh","Remote Access","Windows Manager","网络服务_其他","Network tunnels and zero-trust","VPN","Overlay and Virtual Private Networks (VPNs)","Mesh Network"],"readme":"![headscale logo](./docs/assets/logo/headscale3_header_stacked_left.png)\n\n![ci](https://github.com/juanfont/headscale/actions/workflows/test.yml/badge.svg)\n\nAn open source, self-hosted implementation of the Tailscale control server.\n\nJoin our [Discord server](https://discord.gg/c84AZQhmpx) for a chat.\n\n**Note:** Always select the same GitHub tag as the released version you use\nto ensure you have the correct example configuration. The `main` branch might\ncontain unreleased changes. The documentation is available for stable and\ndevelopment versions:\n\n- [Documentation for the stable version](https://headscale.net/stable/)\n- [Documentation for the development version](https://headscale.net/development/)\n\n## What is Tailscale\n\nTailscale is [a modern VPN](https://tailscale.com/) built on top of\n[Wireguard](https://www.wireguard.com/).\nIt [works like an overlay network](https://tailscale.com/blog/how-tailscale-works/)\nbetween the computers of your networks - using\n[NAT traversal](https://tailscale.com/blog/how-nat-traversal-works/).\n\nEverything in Tailscale is Open Source, except the GUI clients for proprietary OS\n(Windows and macOS/iOS), and the control server.\n\nThe control server works as an exchange point of Wireguard public keys for the\nnodes in the Tailscale network. It assigns the IP addresses of the clients,\ncreates the boundaries between each user, enables sharing machines between users,\nand exposes the advertised routes of your nodes.\n\nA [Tailscale network (tailnet)](https://tailscale.com/docs/concepts/tailnet) is\nprivate network which Tailscale assigns to a user in terms of private users or an\norganisation.\n\n## Design goal\n\nHeadscale aims to implement a self-hosted, open source alternative to the\n[Tailscale](https://tailscale.com/) control server. Headscale's goal is to\nprovide self-hosters and hobbyists with an open-source server they can use for\ntheir projects and labs. It implements a narrow scope, a _single_ Tailscale\nnetwork (tailnet), suitable for a personal use, or a small open-source\norganisation.\n\n## Supporting Headscale\n\nIf you like `headscale` and find it useful, there is a sponsorship and donation\nbuttons available in the repo.\n\n## Features\n\nPlease see [\"Features\" in the documentation](https://headscale.net/stable/about/features/).\n\n## Client OS support\n\nPlease see [\"Client and operating system support\" in the documentation](https://headscale.net/stable/about/clients/).\n\n## Running headscale\n\n**Please note that we do not support nor encourage the use of reverse proxies\nand container to run Headscale.**\n\nPlease have a look at the [`documentation`](https://headscale.net/stable/).\n\nFor NixOS users, a module is available in [`nix/`](./nix/).\n\n## Builds from `main`\n\nDevelopment builds from the `main` branch are available as container images and\nbinaries. See the [development builds](https://headscale.net/stable/setup/install/main/)\ndocumentation for details.\n\n## Talks\n\n- Fosdem 2026 (video): [Headscale \u0026 Tailscale: The complementary open source clone](https://fosdem.org/2026/schedule/event/KYQ3LL-headscale-the-complementary-open-source-clone/)\n  - presented by Kristoffer Dalby\n- Fosdem 2023 (video): [Headscale: How we are using integration testing to reimplement Tailscale](https://fosdem.org/2023/schedule/event/goheadscale/)\n  - presented by Juan Font Alonso and Kristoffer Dalby\n\n## Disclaimer\n\nThis project is not associated with Tailscale Inc.\n\nHowever, one of the active maintainers for Headscale [is employed by Tailscale](https://tailscale.com/blog/opensource) and he is allowed to spend work hours contributing to the project. Contributions from this maintainer are reviewed by other maintainers.\n\nThe maintainers work together on setting the direction for the project. The underlying principle is to serve the community of self-hosters, enthusiasts and hobbyists - while having a sustainable project.\n\n## Contributing\n\nPlease read the [CONTRIBUTING.md](./CONTRIBUTING.md) file.\n\n### Requirements\n\nTo contribute to headscale you would need the latest version of [Go](https://golang.org)\nand [Buf](https://buf.build) (Protobuf generator).\n\nWe recommend using [Nix](https://nixos.org/) to setup a development environment. This can\nbe done with `nix develop`, which will install the tools and give you a shell.\nThis guarantees that you will have the same dev env as `headscale` maintainers.\n\n### Code style\n\nTo ensure we have some consistency with a growing number of contributions,\nthis project has adopted linting and style/formatting rules:\n\nThe **Go** code is linted with [`golangci-lint`](https://golangci-lint.run) and\nformatted with [`golines`](https://github.com/segmentio/golines) (width 88) and\n[`gofumpt`](https://github.com/mvdan/gofumpt).\nPlease configure your editor to run the tools while developing and make sure to\nrun `make lint` and `make fmt` before committing any code.\n\nThe **Proto** code is linted with [`buf`](https://docs.buf.build/lint/overview) and\nformatted with [`clang-format`](https://clang.llvm.org/docs/ClangFormat.html).\n\nThe **docs** are formatted with [`mdformat`](https://mdformat.readthedocs.io).\n\nThe **rest** (Markdown, YAML, etc) is formatted with [`prettier`](https://prettier.io).\n\nCheck out the `.golangci.yaml` and `Makefile` to see the specific configuration.\n\n### Install development tools\n\n- Go\n- Buf\n- Protobuf tools\n\nInstall and activate:\n\n```shell\nnix develop\n```\n\n### Testing and building\n\nSome parts of the project require the generation of Go code from Protobuf\n(if changes are made in `proto/`) and it must be (re-)generated with:\n\n```shell\nmake generate\n```\n\n**Note**: Please check in changes from `gen/` in a separate commit to make it easier to review.\n\nTo run the tests:\n\n```shell\nmake test\n```\n\nTo build the program:\n\n```shell\nmake build\n```\n\n### Development workflow\n\nWe recommend using Nix for dependency management to ensure you have all required tools. If you prefer to manage dependencies yourself, you can use Make directly:\n\n**With Nix (recommended):**\n\n```shell\nnix develop\nmake test\nmake build\n```\n\n**With your own dependencies:**\n\n```shell\nmake test\nmake build\n```\n\nThe Makefile will warn you if any required tools are missing and suggest running `nix develop`. Run `make help` to see all available targets.\n\n## Contributors\n\n\u003ca href=\"https://github.com/juanfont/headscale/graphs/contributors\"\u003e\n  \u003cimg src=\"https://contrib.rocks/image?repo=juanfont/headscale\" /\u003e\n\u003c/a\u003e\n\nMade with [contrib.rocks](https://contrib.rocks).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjuanfont%2Fheadscale","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjuanfont%2Fheadscale","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjuanfont%2Fheadscale/lists"}