tailcat
like netcat, but over Tailscale's data plane, without Tailscale's control plane
Discover the Tailscale exit node service type in Tailcat. Learn how to configure Tailcat to act as a full-mesh exit node and forward inbound connections to your local network.
How Tailcat's SFTP File Server Works: Subsystem Architecture and Security ModesDiscover how Tailcat's SFTP server uses SSH subsystems for secure file transfers. Explore its subsystem architecture and security modes for flexible access control.
What Is the Exec Service Type in Tailcat? A Complete Technical GuideLearn about Tailcat's exec service type. This guide details how it runs a command for each TCP connection, using the connection as stdin/stdout in an inetd style.
How to Use Tailcat for Secure Shell (SSH) Access: Two Methods ExplainedLearn how to use Tailcat for secure SSH access with two methods. Tailcat offers WireGuard-encrypted tunnels, public-key authentication, and bearer tokens without root access.
Tailcat Server Mode Service Types: The Complete Guide to Built-in Network ServicesDiscover the six Tailcat server mode service types: all, exit-node, ssh, no-auth-ssh, files, and exec. Learn how to leverage built-in network services on your tailnet.
Ephemeral vs. Persistent Keys in Tailcat: What's the Difference?Understand ephemeral vs persistent keys in Tailcat. Learn how each key type manages identities for temporary sessions or across multiple restarts. Get the details now.
What Happens When NAT Traversal Fails in Tailcat: DERP Relay Fallback ExplainedDiscover what happens when NAT traversal fails in Tailcat. Learn how DERP relay fallback ensures your encrypted WireGuard tunnel stays connected and get insights into path-detection commands.
How Tailcat Establishes WireGuard Tunnels: A Deep Dive into the Tailscale Client IntegrationLearn how Tailcat establishes WireGuard tunnels by initiating a Tailscale client, managing virtual interfaces, and handling peer configurations for reliable network connections.
Tailcat Connection Establishment Flow: From Compact Address to WireGuard TunnelExplore the Tailcat connection establishment flow. Discover how Tailcat creates secure WireGuard tunnels from compact addresses using DERP for path discovery and a peer-to-peer handshake.
How gVisor Netstack Powers Tailcat’s Userspace Networking ArchitectureDiscover how gVisor Netstack empowers Tailcat with kernel-independent, userspace networking over WireGuard tunnels using a pure-Go TCP/IP implementation.
How Tailcat Achieves UDP Hole-Punching for NAT Traversal: Inside the Disco ProtocolDiscover how Tailcat achieves UDP hole-punching for NAT traversal using its disco protocol. Enable direct UDP connectivity between peers with seamless DERP fallback.
What Is Magicsock and How It Enables Direct P2P Connections in TailcatDiscover Magicsock, Tailscale's UDP networking layer. Learn how it enables direct P2P connections in Tailcat for low-latency, encrypted communication without manual port setup.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →