How to Configure Tailcat Server to Listen on Specific TCP Ports
Use the --serve flag or positional arguments with tailcat serve to specify TCP ports, port ranges, or all to control which local ports the server exposes.
Tailcat's server mode forwards local TCP ports through its secure tunnel, making services accessible across your Tailscale network. This article explains how to configure which ports the server listens on, based on the tailscale/tailcat source code.
Server Mode vs. Forward Mode
Tailcat operates in two distinct modes that affect port configuration:
- Server mode — started by
tailcat(no arguments) ortailcat serve, exposes local ports for remote access - Forward mode — started by
tailcat forward, connects to a server and maps remote ports locally
This article focuses on server mode configuration. Client-side binding is covered briefly for complete network setup.
Configuring Server Listen Ports with --serve
The --serve flag controls which TCP ports the tailcat server makes available. In cmd/tailcat/tailcat.go, the flag is defined at lines 53-56 and parsed by the serve subcommand at lines 140-155.
Supported Port Specifications
| Format | Example | Description |
|---|---|---|
| Single port | 8080 |
Expose one specific port |
| Multiple ports | 8080,8443 |
Comma-separated list |
| Port range | 3000-3010 |
Inclusive range |
| All ports | all |
Expose every listening TCP port |
Examples
Expose specific ports:
tailcat serve 8080,8443
Expose a port range for development servers:
tailcat serve 3000-3010
Expose all local TCP ports (use with caution):
tailcat serve all
The server output displays the generated tailcat address:
🐈 Server listening with new address: tcABCDEF...
Binding Forwarded Ports to Specific Interfaces
When using tailcat forward to access a remote server, the --bind flag controls which local address the forwarded port attaches to. By default, tailcat binds to 127.0.0.1 (localhost only).
In cmd/tailcat/forward.go at lines 26-28, the --bind flag is defined with a default value of 127.0.0.1.
Bind to all interfaces for external access:
tailcat forward --bind=0.0.0.0 tcXYZ123 8080:8080
Or bind to a specific interface:
tailcat forward --bind=192.168.1.10 tcXYZ123 8080:8080
Complete Workflow Example
Start a server exposing ports 8080 and 8443:
# On server machine
tailcat serve 8080,8443
# 🐈 Server listening with new address: tcABC123...
Connect from another machine:
# On client machine, bind to all interfaces
tailcat forward --bind=0.0.0.0 tcABC123 8080:8080 8443:8443
Now services on the server's ports 8080/8443 are reachable at the client's IP on the same ports.
Source Code Reference
Key files in tailscale/tailcat that implement port configuration:
cmd/tailcat/tailcat.go— Defines--serveflag andservesubcommand parsingcmd/tailcat/forward.go— Implements--bindflag for listener address controlREADME.md— User-facing documentation with usage examples
Summary
- Use
tailcat serve <ports>to configure which TCP ports the server exposes - Specify ports as comma-separated values, ranges with
-, orallfor every port - Server mode binds to loopback by default; remote accessibility requires
tailcat forward - Control the forward listener address with
--bind(default127.0.0.1, use0.0.0.0for all interfaces) - All configuration flags are defined in the main command handlers in
cmd/tailcat/
Frequently Asked Questions
What is the default port behavior if I run tailcat with no arguments?
Running tailcat without arguments starts server mode but exposes no ports by default. You must specify ports via --serve or use tailcat serve <ports> to make services accessible.
Can I expose both UDP and TCP ports with tailcat?
The current tailscale/tailcat implementation focuses on TCP port forwarding. UDP support is not indicated in the command-line flags or server implementation as analyzed.
Is there a security risk using tailcat serve all?
Yes. The all keyword exposes every TCP port listening on the server machine, including system services and databases. Use explicit port lists in production environments to minimize attack surface.
How do I forward ports from a server that doesn't expose them by default?
Tailcat creates the tunnel; you cannot forward a port that the server hasn't exposed via --serve. Coordinate with the server administrator to ensure the required ports are listed in their serve configuration.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →