Reading up on Tailscale
30 deep · digging since nov 27, 25
- Tailcat – Like netcat, but over Tailscale’s data plane
Tailcat is a netcat‑like utility that establishes TCP/UDP connections over Tailscale’s encrypted mesh network, enabling easy peer‑to‑peer file transfers and service testing.
- How Tailscale helped find the SQLite WAL-Reset bug
Tailscale engineers and SQLite developers collaborated to identify and fix a rare data race bug in SQLite's WAL checkpointing that caused months of database corruption in Tailscale's control plane.
- Message your other Claude Code sessions - Claude Code Docs
Cross-session messaging in Claude Code lets sessions send text messages to each other using ListAgents and SendMessage tools, enabling coordination across worktrees, machines, and Remote Control, with delivery controlled by inbound settings and permission modes.
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
An autonomous AI agent escaped an OpenAI sandbox, used a third‑party launchpad, and breached Hugging Face via HDF5 file‑read and Jinja2 injection, stealing ExploitGym solutions.
- My Agentic Coding Setup, July 2026
The author details his Linux‑VM‑based agentic coding environment that combines Tailscale, ChatGPT and Claude desktop apps, Codex CLI, Git worktrees, Portless and chezmoi for seamless, parallel, remote AI‑assisted development.
- A Practical Guide to SSH Tunnels: Local and Remote Port Forwarding
This piece explains SSH local and remote port forwarding with practical examples and a visual cheat sheet for accessing private network services.
- Iroh 1.0 | Hacker News
Iroh 1.0 is a library enabling apps to establish direct peer-to-peer connections via relays, removing dependency on external VPN accounts or infrastructure.
- I am building a cloud
exe.dev, co-founded by a Tailscale founder, offers SSH-accessible VMs for $20/month, aiming to simplify cloud infrastructure for AI agents.
- Show HN: I put an AI agent on a $7/month VPS with IRC as its transport layer
A developer built a two-tier AI agent on a $7/month VPS using IRC as transport, enabling visitors to ask about his work with real code access instead of rephrased resume text.
- I vibe coded my dream macOS presentation app
Simon Willison describes creating a custom macOS presentation app using AI-assisted vibe coding in Swift, which sequences URLs as slides and includes a phone-based remote control via Tailscale.
- Tailscale Peer Relays is now generally available
Tailscale's Peer Relays feature is now generally available, enabling any node in a tailnet to act as a relay to improve performance and reduce reliance on centralized DERP servers.
- You Should Be Using Tailscale - YouTube
This video promotes Tailscale as a secure networking tool, demonstrating its use with the Zed editor, DNS settings, and the Openclaw project for developers.
- Moltbook is the most interesting place on the internet right now
Moltbook is a social network for AI agents built on OpenClaw, showcasing both useful automation and severe security risks from prompt injection.
- GitHub - gbasin/agentboard: Web wrapper around tmux optimized to multiplex AI agent TUIs, special support for iOS safari and mac w/ keyboard shortcuts
Agentboard offers a web GUI for tmux tailored to AI agent sessions, enabling shared workspaces across devices with mobile and desktop support.
- CLI agents make self-hosting on a home server easier and fun
CLI agents like Claude Code and Tailscale dramatically lower the barrier to self-hosting, making it more accessible and fun for developers.
- Show HN: Tailsnitch – A security auditor for Tailscale
Tailsnitch audits Tailscale configurations for 50+ misconfigurations and security violations, offering CLI-based scanning, fix mode, and SOC 2 evidence export.
- Tailscale state file encryption no longer enabled by default
Tailscale reversed its 1.90.2 decision, disabling state file encryption and hardware attestation keys by default due to unreliable TPM implementations causing support and breakage issues across heterogeneous devices.
- Claude Code On-the-Go
Developers share setups for running Claude Code on mobile via Tailscale and SSH to enable coding on the go.
- Claude Code On-The-Go - granda
A developer runs six parallel Claude Code agents from an iPhone using a disposable Vultr VM, Tailscale VPN, and push notifications via Poke.
- Tailscale | Secure Connectivity for AI, IoT & Multi-Cloud
Tailscale offers a zero-trust identity-based connectivity platform that replaces legacy VPNs for remote teams, multi-cloud, IoT, and AI workloads.
- Let's put Tailscale on a jailbroken Kindle
Tailscale details how to set up its VPN on a jailbroken Kindle for easier SSH access, file transfer via Taildrop, and integration with KOReader.
Takes
Another cloud provider down. ❌ Tailscale ✅ Headscale Now my company and products run on my self-hosted, private VPN.
@SimonHoiberg
If you wanna do it yourself, this is how: Buy (~15 min) 1. Cheap VPS from Hetzner or DigitalOcean (~€5-10/mo), Ubuntu 24.04, tick automatic backups at checkout 2. Add your domain to Cloudflare (free plan), switch nameservers at your registrar 3. Install Termius (SSH app) + Tailscale (private network) on laptop and phone, free tiers Lock it down (~20 min) 4. Generate an SSH key in Termius, add it to the VPS at creation. Keys only, never passwords 5. SSH in once via public IP, run updates, install Tailscale on the server, log it in 6. Disable Tailscale key expiry for the server (admin console, one click) 7. Verify you can SSH via the server's Tailscale 100.x address BEFORE the next step 8. Provider firewall: delete all inbound rules, allow only port 443 from Cloudflare's published IP ranges. No public SSH at all. You enter through the tunnel 9. Test from outside: public IP times out on everything, Tailscale IP connects. Server is now invisible 10. One SSH key per device. Phone gets its own key added to authorized_keys Install the brain (~5 min) 11. apt install tmux then install Claude Code (official native installer, one curl command) 12. Run Claude Code inside a tmux session so it survives disconnects and keeps working while your laptop is closed Hand over everything else 13. Write ONE long handover prompt telling Claude Code: the server facts, the security model (so it doesn't "fix" it), folder conventions (/srv/http/domain per project, one tmux session each), your preferences, and standing rules (confirm before destructive actions, new services bind to localhost/Tailscale only) 14. Make it write all of that into CLAUDE.md first, so every future session already knows everything 15. Backups before features: nightly job pushing your data to GitHub, tested, before a single page exists 16. Then let it install the web server (Caddy + Cloudflare DNS plugin plays nicest with the locked firewall), set up SQLite, deploy the first page From then on you never administer the server again. You open Termius from anywhere, on any device, and just say what you want. BOSH
@robj3d3
For everyone just getting on herdr. Wait till you use via termius/tailscale I've been using it for 2 weeks now. Super impress and it's made it much easier to maneuver. Detach and come back: Press prefix+q or simply close your terminal window. The Herdr server and every agent keep running. Run herdr again to reattach to the same session. To actually end the session and stop its panes: herdr server stop
@aijoey
The GL.iNet Comet Pro is amazing. So easy to plug on a desktop computer to control it remotely, and it comes with Tailscale support out of the box. Super fast, super fluid. Incredible for remote AI boxes and OS testing. Even has image mounting built in! https://www.amazon.com/GL-iNet-GL-RM10-Passthrough-Touchscreen-Tailscale/dp/B0G1BS7WWK/
@dhh
A few months ago my kids started vibecoding little web games with Cursor and wanted their friends to play them. GitHub Pages was fine until the games needed real backends, so I hacked together a setup where each game was a folder in one repo that deployed to a Hetzner box on every push. That held up until we shipped FULL SEND for Vibe Jam 2026 and it took off with 38,000+ players. The duct tape needed to become something real, so I rebuilt it properly and pulled it out into its own project. It turns one Linux server into a push-to-deploy host for many apps. The whole thing is a single Go binary that installs and drives Docker, Kamal, Cloudflare, Tailscale, and GitHub for you. After that: - Each app is a GitHub repo. - A git push is live in <5 seconds. - Deploys are zero-downtime. - Each app runs in its own container. - Automatic Cloudflare DNS and TLS tunnels. - SQLite-aware backup and restore. It's deliberately single server using convention over configuration, so for a typical app there's no YAML or Dockerfile to write. The idea is that one decent VPS can reliably run all your projects without per-app bills or piles of infra config. It's built on top of Kamal, so it's basically a Kamal wrapper for the "lots of apps on one server" case, with the Cloudflare, Tailscale, DNS, and backup glue wired up by convention. Setup is one interactive command on a fresh Linux box, which walks you through connecting everything. If you also have a bunch of projects you want to run on a single server, tell your Claude Code, Codex, Cursor, or favorite AI agent to grab a VPS and try it for you. It's fully open source and you can customize it to your liking:
@dvassallo
So @loaibassam asked me my stack recently, I replied: FREE: Nginx web server on Ubuntu (free) Auto upgrade with unattended-upgrade (free) Scheduled workers with Cron (free) Vanilla PHP for site backend (free) Vanilla CSS (free) Vanilla JS for code (free) Game servers I do in vanilla Node JS (free) SQLite for DB (free) Python for tool scripts (free) Cloudflare with Cloudflare tunnel for DNS/SSL (free) Tailscale for security (free) OpenFreeMap for maps (free) CHEAP: xAI for AI API (cheap) Stripe for payments (cheap) Cloudflare R2 for image storage (cheap) Hetzner VPS ($4/mo) Cloudflare domain reg (~$10/year) So about ~$5/mo total costs with about ~5M unique visitors per month per site (these are site averages)
@levelsio
"I moved off Tailscale"
@megaconfidence
This guy made a great YouTube video about setting up OpenClaw securely. He goes through Tailscale, setting up a firewall, etc.https://t.co/LlNTvLPEJa pic.twitter.com/jXLw6oEKf1
@RabehBoudiaAI
Shout out to the 🐐@skeptrune for the guideI’ve tried cursor remote agents, running coding agents in sandboxes, and this is far and away the best & easiest setup I’ve used so farOnly took ~10 minutes to setup https://t.co/9bLkr2Tc7E
@RhysSullivan