[{"data":1,"prerenderedAt":239},["ShallowReactive",2],{"seo-verification":3,"blog-migrating-from-tailscale-to-headscale-2026-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-migrating-from-tailscale-to-headscale-2026-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":28,"featuredImage":30,"bgImage":31,"posterImage":32,"relatedSolution":33,"intro":36,"sections":37,"ctaTitle":177,"ctaBody":178,"ctaButton":179,"ctaUrl":180,"relatedPosts":181},428,"migrating-from-tailscale-to-headscale-2026",{"fr":12,"en":10,"ar":13,"es":14},"tailscale-headscale-migration-2026","الهجرة-من-tailscale-إلى-headscale-2026","migracion-tailscale-headscale-2026","Migrating from Tailscale to Headscale: the break-even point","Tailscale Standard is now $8\u002Fseat\u002Fmonth. Find out when Headscale on a VPS costs less, and how to migrate in 3 steps without reinstalling your clients.",11,0,false,"2026-10-10T00:00:00+00:00","2026-10-10T21:55:40+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},7,"Self-hosting","self-hosting","bg-indigo-500\u002F10 text-indigo-400","cloud",[29],{"id":23,"name":24,"slug":25,"color":26,"icon":27},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Ftailscale-headscale-migration-2026-poster.svg",{"categorySlug":34,"appSlug":35},"networking-vpn","headscale","On April 8, 2026, Tailscale announced pricing v4: the Standard plan, formerly Starter, moves to $8 per seat per month. For a five-person team, that is $40 per month — $480 per year — for a service whose core value, the WireGuard mesh control plane, can be self-hosted on a VPS for a few euros per month.\n\nHeadscale is the open source implementation of the Tailscale coordination server. Licensed under BSD-3-Clause, it speaks the same protocol as the official controller. Your existing Tailscale clients — Linux, macOS, Windows, iOS, Android — continue working without reinstallation: you only change the login URL. The network traffic itself, end-to-end encrypted with WireGuard, never passed through Tailscale anyway; only the control plane changes hands.\n\nThis article gives you the exact break-even numbers, the technical prerequisites, and the three steps to migrate an existing team from Tailscale to your own control plane.",[38,42,52,55,95,98,106,109,133,136,150,153,160,164,167,174],{"type":39,"title":40,"body":41},"h2","Why reconsider your mesh network in 2026","Tailscale does not carry your traffic: WireGuard packets travel directly between your machines, end-to-end encrypted. What Tailscale manages in the cloud is the control plane — public key exchange, peer discovery, `100.x.x.x` address assignment, MagicDNS resolution, and DERP relay distribution. You can self-host this control plane with Headscale. In 2026, the pricing increase makes this option financially obvious for any team with at least two people on a paid plan.",{"type":43,"items":44},"ul",[45,46,47,48,49,50,51],"Full data control: no list of your machines, internal IP addresses, node names or connection logs passes through a third-party server.","No node or user limits imposed by the software: Headscale is bounded only by your VPS resources.","Full compatibility with official Tailscale clients: the `--login-server` flag is all you need to point to your own control plane.","MagicDNS on your own domain: each node is reachable by its short name under the suffix you choose.","Optional OIDC: delegate authentication to Keycloak, Authelia, or any compatible OIDC provider.","Operational durability: your mesh network no longer depends on a third-party pricing decision or outage.","Reasonable maintenance: a package update every few weeks, a SQLite backup schedulable in one cron line.",{"type":39,"title":53,"body":54},"Financial analysis: the break-even point","Tailscale Personal remains free for up to six users on non-commercial use. Once you move to the Standard plan — a professional team, multi-user access, or extended ACL features — the cost is $8 per seat per month. A 1 vCPU \u002F 1 GB RAM VPS is sufficient to run Headscale for dozens of nodes; it runs in under 64 MB of RAM at idle. The cost of that VPS at ServOrbit starts at a few euros per month.",{"type":56,"title":57,"headers":58,"rows":62},"comparison","Tailscale Standard vs Headscale on VPS",[59,60,61],"Criterion","Tailscale Standard","Headscale on VPS",[63,67,70,73,77,80,84,88,92],[64,65,66],"Monthly cost (1 seat)","$8","VPS cost (~99 DH\u002Fmonth)",[68,69,66],"Monthly cost (5 seats)","$40",[71,72,66],"Monthly cost (10 seats)","$80",[74,75,76],"Funnel \u002F Serve","Included","Not available",[78,79,76],"SSH Recording","Premium plan only",[81,82,83],"Maintenance","None (managed service)","~2h\u002Fmonth (updates, backups)",[85,86,87],"Data control","Tailscale cloud","Your server",[89,90,91],"Node limit","100 (Standard)","No software limit",[93,94,91],"User limit","No fixed limit on Standard",{"type":39,"title":96,"body":97},"Technical prerequisites","Headscale is lightweight: an entry-level VPS handles a dozen nodes. Here are the minimum resources and ports required.",{"type":43,"items":99},[100,101,102,103,104,105],"VPS running Debian 11\u002F12 or Ubuntu 22.04\u002F24.04 — 1 vCPU, 512 MB RAM minimum (Headscale runs under 64 MB idle; 1 GB recommended for headroom).","TCP port 443 open inbound: clients connect here for registration and configuration retrieval over HTTPS.","UDP port 3478 open: used for STUN negotiation (discovery of candidate addresses for direct connections).","UDP port 41641 open: WireGuard signaling port that Tailscale clients use to contact the coordinator.","A domain name or subdomain pointing to the VPS: required for a valid TLS certificate. Let's Encrypt works via certbot or the integrated nginx module.","Embedded SQLite: Headscale requires no external database — a single SQLite file in `\u002Fvar\u002Flib\u002Fheadscale\u002F` is sufficient for hundreds of nodes.",{"type":39,"title":107,"body":108},"Installing Headscale on a ServOrbit VPS","The steps below start from a fresh Debian 12 VPS. Installation takes under ten minutes.",{"type":110,"steps":111},"steps",[112,115,118,121,124,127,130],{"title":113,"body":114},"Update the system and install dependencies","Connect via SSH and update packages:\n\n`apt update && apt upgrade -y`\n\nInstall nginx and certbot for the HTTPS reverse proxy:\n\n`apt install -y nginx certbot python3-certbot-nginx`",{"title":116,"body":117},"Download and install the Headscale package","Headscale v0.29.4 (September 2026) provides `.deb` packages for amd64 and arm64. Download and install:\n\n`curl -Lo \u002Ftmp\u002Fheadscale.deb https:\u002F\u002Fgithub.com\u002Fjuanfont\u002Fheadscale\u002Freleases\u002Fdownload\u002Fv0.29.4\u002Fheadscale_0.29.4_linux_amd64.deb`\n\n`dpkg -i \u002Ftmp\u002Fheadscale.deb`\n\nVerify the installation: `headscale version` should return `0.29.4`. On ARM64, replace `linux_amd64` with `linux_arm64`.",{"title":119,"body":120},"Configure Headscale","The package creates the `headscale` system user and `\u002Fetc\u002Fheadscale\u002F`. Edit the minimal configuration:\n\n`nano \u002Fetc\u002Fheadscale\u002Fconfig.yaml`\n\nSet at minimum: `server_url: https:\u002F\u002Fheadscale.your-domain.com`, `listen_addr: 0.0.0.0:8080`, `db_type: sqlite3`, `db_path: \u002Fvar\u002Flib\u002Fheadscale\u002Fdb.sqlite`, and in `dns_config`: `magic_dns: true`, `base_domain: your-domain.com`. Create the data directory: `mkdir -p \u002Fvar\u002Flib\u002Fheadscale && chown headscale:headscale \u002Fvar\u002Flib\u002Fheadscale`.",{"title":122,"body":123},"Enable and start the service","The package installs the systemd unit automatically:\n\n`systemctl enable --now headscale`\n\nCheck status: `systemctl status headscale`. Output should show `Active: active (running)`. If there is an error, check logs: `journalctl -u headscale -f`. The most common error at first start is a malformed `server_url` — it must start with `https:\u002F\u002F`.",{"title":125,"body":126},"Set up the HTTPS reverse proxy","Obtain a Let's Encrypt certificate and configure nginx:\n\n`certbot --nginx -d headscale.your-domain.com`\n\nIn the generated nginx vhost, add to the `location \u002F` block:\n\n`proxy_pass http:\u002F\u002F127.0.0.1:8080;`\n`proxy_http_version 1.1;`\n`proxy_set_header Upgrade $http_upgrade;`\n`proxy_set_header Connection \"upgrade\";`\n`proxy_set_header Host $host;`\n\nReload nginx: `systemctl reload nginx`. Verify that `https:\u002F\u002Fheadscale.your-domain.com\u002Fhealth` returns `{\"status\":\"pass\"}`.",{"title":128,"body":129},"Create a first user and an authentication pre-key","Headscale organizes nodes by users. Create your first user:\n\n`headscale users create my-team`\n\nGenerate an authentication pre-key (preauthkey) to register machines without manual approval:\n\n`headscale preauthkeys create --user my-team --expiration 24h`\n\nCopy the returned key — you will need it when migrating clients. The `--reusable` option allows reusing the same key for multiple machines.",{"title":131,"body":132},"Open required ports in the firewall","If your VPS uses `ufw`, open the required ports:\n\n`ufw allow 443\u002Ftcp`\n`ufw allow 3478\u002Fudp`\n`ufw allow 41641\u002Fudp`\n\nIf you use `iptables` directly or a security panel (CSF, Imunify360), add these ports to the allowed inbound port list. Verify from an external machine that the UDP ports are reachable before migrating your clients.",{"type":39,"title":134,"body":135},"Migrating clients from Tailscale in 3 steps","Migration requires no reinstallation of Tailscale clients. The official client has supported the `--login-server` flag for several versions; you simply disconnect the client from the old network and reconnect it to your Headscale server. WireGuard traffic between nodes is not interrupted during migration — only the brief disconnect\u002Freconnect window (a few seconds per node) causes a short interruption.",{"type":110,"steps":137},[138,141,144,147],{"title":139,"body":140},"Disconnect the client from the existing Tailscale network","On each machine to migrate, disconnect the client from the Tailscale network:\n\n`tailscale logout`\n\nOn macOS and Windows, use the system tray menu: right-click the Tailscale icon → Log out. On iOS and Android, go to app settings → Log out. This step revokes authentication on the old network but does not uninstall the client.",{"title":142,"body":143},"Reconnect the client to your Headscale server","Reconnect the client pointing to your new Headscale server. On Linux:\n\n`tailscale up --login-server https:\u002F\u002Fheadscale.your-domain.com --authkey YOUR_PREAUTHKEY`\n\nOn macOS, from the terminal:\n\n`tailscale up --login-server https:\u002F\u002Fheadscale.your-domain.com --authkey YOUR_PREAUTHKEY`\n\nIf you do not pass a preauthkey, the client displays an authentication URL to validate on the server side with: `headscale nodes register --user my-team --key \u003CNODE_KEY>`. Verify registration: `headscale nodes list` should show the node with `online` status.",{"title":145,"body":146},"Verify connectivity between migrated nodes","From a migrated node, verify that other nodes are visible:\n\n`tailscale status`\n\nThe list should show all nodes registered on your Headscale server with their mesh IPs (`100.64.x.x`). Test direct connectivity with a ping: `ping 100.64.0.2`. A status of `active (direct)` confirms the WireGuard connection is established without a relay. If you enabled MagicDNS, test resolution: `ping node-name.your-domain.com`.",{"title":148,"body":149},"Migrate remaining nodes and close the Tailscale account","Repeat the previous two steps for each machine. Migrate development or test machines first to validate the process, then production machines. Once all nodes are migrated and verified, you can close your Tailscale account or downgrade to the Personal plan if you still have personal use cases (six users max, free). Keep the preauthkey used or generate a new one for future nodes.",{"type":39,"title":151,"body":152},"ACL and internal DNS configuration","Headscale manages access policies via a HuJSON policy file (JSON extended with comments), compatible with Tailscale ACL syntax. This file defines which users or groups can access which nodes on which ports. By default, all nodes on the same Headscale network can reach each other on all ports — this permissive behavior suits a small trusted team, but should be restricted when nodes of different trust levels (developers, clients, production servers) coexist on the same network.",{"type":43,"items":154},[155,156,157,158,159],"Edit the policy file: `headscale policy set --policy-file \u002Fetc\u002Fheadscale\u002Fpolicy.hujson`","Define user groups (`groups`) and per-port ACLs to segment access between dev, staging, and prod environments.","Enable split DNS to resolve internal names: in `dns_config`, define `nameservers` with your internal DNS servers and `search_domains` for search suffixes.","Export and version your policy file in a private Git repository — this simplifies audits and rollbacks.","Test policy changes on a test node before applying them to the entire network: `headscale policy check`.",{"type":161,"title":162,"body":163},"tip","Hardening, backups, and automatic updates","A few precautions for a robust installation. Back up the SQLite database regularly: `cp \u002Fvar\u002Flib\u002Fheadscale\u002Fdb.sqlite \u002Fbackup\u002Fheadscale-$(date +%Y%m%d).sqlite` — a daily cron job or a script to S3 object storage is sufficient. Also back up the private keys in `\u002Fvar\u002Flib\u002Fheadscale\u002Fprivate.key` and `\u002Fvar\u002Flib\u002Fheadscale\u002Fnoise_private.key`: they sign your server's identity and cannot be regenerated without forcing all nodes to reconnect. For automatic updates, configure `unattended-upgrades` on Debian\u002FUbuntu. Restrict access to the Headscale admin API (gRPC port 50443) to `127.0.0.1` only — never expose it directly to the internet.",{"type":39,"title":165,"body":166},"Troubleshooting common issues","The most common errors after migration and how to fix them.",{"type":43,"items":168},[169,170,171,172,173],"Node shows `offline` in `headscale nodes list`: verify that UDP ports 3478 and 41641 are open on the VPS side. Test from an external machine with `nc -vzu headscale.your-domain.com 41641`.","Connection shows `relay` instead of `direct`: indirect connections via DERP occur when two nodes cannot reach each other directly (strict NAT, firewall). Run `tailscale netcheck` on both nodes to identify network constraints.","MagicDNS does not resolve names: verify that `magic_dns: true` and `base_domain` are defined in the Headscale config, and that the client retrieved the new DNS configuration after reconnecting (`tailscale status --self`).","Invalid TLS certificate at startup: the `server_url` in `config.yaml` must exactly match the certificate domain. A URL starting with `http:\u002F\u002F` when nginx expects `https:\u002F\u002F` triggers an infinite redirect loop.","macOS or Windows clients do not see a `--login-server` option in the GUI: always use the terminal for migration. The Tailscale GUI does not allow changing the coordination server; only the command line supports this.",{"type":39,"title":175,"body":176},"What Headscale does not replace","Headscale implements the Tailscale control plane protocol, but not the full commercial platform feature set. Tailscale Funnel (exposing local services to the internet) and Serve (local reverse proxy) are not available in Headscale. SSH Recording (recording SSH sessions over the mesh) is a Tailscale Premium feature absent from Headscale. These gaps are documented and stable: the Headscale project actively tracks protocol compatibility, not interface feature parity. If your use case is limited to mesh connectivity, MagicDNS, and ACLs — the case for the vast majority of technical teams — Headscale covers the need entirely. If you actively use Funnel or SSH Recording, evaluate whether those features justify the cost differential before migrating.","Deploy Headscale on your VPS in a few clicks","The Headscale template in the ServOrbit marketplace pre-installs and pre-configures Headscale on a Debian VPS. Ports open, systemd service active, nginx configured: your WireGuard mesh control plane is operational in under five minutes.","Deploy Headscale on VPS","\u002Fmarketplace\u002Fnetworking-vpn\u002Fheadscale",[182,205,225],{"id":183,"slug":184,"slugs":185,"title":189,"excerpt":190,"readTime":191,"views":192,"isPinned":19,"publishedAt":193,"updatedAt":194,"category":195,"categories":201,"featuredImage":30,"bgImage":31,"posterImage":203,"relatedSolution":204},164,"self-host-headscale-on-a-vps-your-own-tailscale-control-server",{"fr":186,"en":184,"ar":187,"es":188},"self-host-headscale-tailscale-vps","استضافة-headscale-على-vps-خادم-تحكم-tailscale-خاص-بك","auto-alojar-headscale-en-un-vps-servidor-tailscale","Self-Host Headscale on a VPS: Your Own Tailscale Control Server","Replace Tailscale's cloud control server with Headscale on your own VPS — unlimited users, full WireGuard mesh networking, magic DNS and ACLs, with no SaaS dependency.",6,1,"2026-07-05T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":196,"name":197,"slug":198,"color":199,"icon":200},8,"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[202],{"id":196,"name":197,"slug":198,"color":199,"icon":200},"\u002Fblog\u002Fcovers\u002Fself-host-headscale-tailscale-vps-poster.svg",{"categorySlug":34,"appSlug":35},{"id":206,"slug":207,"slugs":208,"title":212,"excerpt":213,"readTime":214,"views":192,"isPinned":19,"publishedAt":215,"updatedAt":216,"category":217,"categories":222,"featuredImage":30,"bgImage":31,"posterImage":224,"relatedSolution":30},291,"netbird-self-hosted-wireguard-mesh-vpn-on-a-vps",{"fr":209,"en":207,"ar":210,"es":211},"deployer-netbird-controle-vpn-mesh-vps","netbird-شبكة-vpn-مشبكة-wireguard-باستضافة-ذاتية","desplegar-netbird-vpn-mesh-wireguard-en-vps","Netbird: Self-Hosted WireGuard Mesh VPN on a VPS","Connect multiple client VPS without opening any ports: Netbird builds a WireGuard mesh you control — Management, Signal and COTURN relay all self-hosted.",10,"2026-08-21T00:00:00+00:00","2026-09-21T15:22:03+00:00",{"id":218,"name":219,"slug":220,"color":221,"icon":220},3,"Deployment","deploiement","bg-success\u002F10 text-success",[223],{"id":218,"name":219,"slug":220,"color":221,"icon":220},"\u002Fblog\u002Fcovers\u002Fdeployer-netbird-controle-vpn-mesh-vps-poster.svg",{"id":226,"slug":227,"slugs":228,"title":232,"excerpt":233,"readTime":214,"views":192,"isPinned":19,"publishedAt":234,"updatedAt":194,"category":235,"categories":236,"featuredImage":30,"bgImage":31,"posterImage":238,"relatedSolution":30},248,"cloudflare-tunnel-expose-a-vps-app-without-opening-ports",{"fr":229,"en":227,"ar":230,"es":231},"cloudflare-tunnel-exposer-application-vps","نفق-كلاود-فلير-عرض-تطبيق-vps-بدون-فتح-منافذ","cloudflare-tunnel-exponer-app-vps-sin-abrir-puertos","Cloudflare Tunnel: expose a VPS app without opening ports","Expose an application on your VPS via a Cloudflare Tunnel without opening any inbound port. Full guide with cloudflared, Docker Compose and a systemd service.","2026-08-12T00:00:00+00:00",{"id":218,"name":219,"slug":220,"color":221,"icon":220},[237],{"id":218,"name":219,"slug":220,"color":221,"icon":220},"\u002Fblog\u002Fcovers\u002Fcloudflare-tunnel-exposer-application-vps-poster.svg",1791669699461]