How to Install Tailcat on Linux, macOS, and Windows
Tailcat is a lightweight, Go-based CLI utility that provides Netcat-style networking over Tailscale's magicsock data plane; you can install it via pre-built binaries, Docker, Homebrew, the Go toolchain, Nix, or Conda without requiring a Tailscale account or privileged system changes.
Tailcat is a pure userspace command-line tool that delivers Netcat-style networking capabilities through Tailscale's secure mesh network. According to the tailscale/tailcat source code, the binary is approximately 16% smaller than the full Tailscale client because it uses curated build tags defined in build-tags.txt to strip unused features. This guide covers every supported installation method across platforms, referencing the actual implementation in cmd/tailcat/tailcat.go and the official packaging configuration.
Installation Methods
Because Tailcat is a single static binary with minimal dependencies, it can be distributed through multiple package ecosystems. The repository's README.md documents all official pathways in the Install section.
Pre-built Binaries
The simplest method is downloading a release directly from the GitHub Releases page. Navigate to the tailscale/tailcat releases and download the appropriate asset for your platform (Linux, macOS, or Windows on amd64/arm64). Extract the binary and place it in a directory on your system PATH.
# Example for Linux amd64
tar -xzf tailcat_*.tar.gz
sudo mv tailcat /usr/local/bin/
Homebrew (macOS and Linux)
For macOS users and Linux systems with Homebrew installed, the official formula provides a pre-compiled binary:
brew install tailcat
This method places the tailcat executable in your Homebrew bin directory and handles updates automatically when you run brew upgrade.
Go Toolchain
If you have a recent Go compiler installed, you can build and install directly from the source code. The Go toolchain fetches the module, applies the recommended build tags from build-tags.txt, and places the resulting binary in $GOPATH/bin or $GOBIN:
go install github.com/tailscale/tailcat/cmd/tailcat@latest
This approach always compiles the latest commit on the main branch, ensuring you have the most recent features and bug fixes.
Docker Container
Run Tailcat without installing it locally by using the official container image from the GitHub Container Registry:
docker pull ghcr.io/tailscale/tailcat:latest
docker run --rm -it ghcr.io/tailscale/tailcat:latest tailcat --help
For interactive sessions that require network access, you may need to pass additional flags such as --network host on Linux or map specific ports with -p.
Nix and NixOS
For Nix users, Tailcat is available in the nixpkgs repository or directly from the project's flake:
# Using nixpkgs
nix profile install nixpkgs#tailcat
# Or using the upstream flake directly
nix run github:tailscale/tailcat
nix profile install github:tailscale/tailcat
This method is ideal for reproducible development environments and NixOS configurations.
Arch Linux AUR
Arch-based distributions can install Tailcat from the Arch User Repository using an AUR helper like yay:
# Install from source
yay -S tailcat
# Or install pre-built binary
yay -S tailcat-bin
Conda-forge
For Conda or Pixi environments, install via the conda-forge channel:
# Global installation with Pixi
pixi global install tailcat
# Or run without installing
pixi exec tailcat
Verifying Your Installation
After installation, verify that the binary is correctly built and accessible:
tailcat --version
This should display the version number and confirm that the CLI layer in cmd/tailcat/tailcat.go is properly parsing sub-commands.
Basic Usage Examples
Once installed, you can immediately use Tailcat for tunneling TCP traffic. The following examples demonstrate the core functionality implemented across cmd/tailcat/serve.go and cmd/tailcat/forward.go.
Pipe Mode Between Hosts
Transfer data via stdin/stdout without configuring servers:
# Server side (generates a temporary address)
$ tailcat
# Output: 🐈 Server listening with new address: tcomFwWCCcjS5nKNqAod034nWoJZW0LZqDhhC8U_dKdnDRYQ8uNGFpGQEu
# Client side
$ echo "hello" | tailcat tcomFwWCCcjS5nKNqAod034nWoJZW0LZqDhhC8U_dKdnDRYQ8uNGFpGQEu
hello
Expose a Local TCP Port
Forward a local service through the Tailcat tunnel:
# Expose local port 8080
$ tailcat serve 8080
# Output: tc1a2b3...
# Client connects to the address
$ tailcat tc1a2b3... 8080
Forward Multiple Ports
Use the forward sub-command to map multiple remote services to local ports, including through an exit node:
# Server running exit-node mode
$ tailcat serve exit-node
# Output: tcX...
# Client forwards multiple services
$ tailcat forward tcX... \
3001:172.23.52.30:3001 \
17170:172.23.52.31:17170
Build Architecture and Size Optimization
Tailcat remains lightweight because the build process in cmd/tailcat/tailcat.go wires together only essential components of the Tailscale library with a minimal CLI parser. The build-tags.txt file specifies which features to exclude, resulting in a binary that starts faster and consumes less memory than the full Tailscale daemon. When you install via package managers like Homebrew or Nix, these build tags are applied during the packaging phase, ensuring you receive the optimized binary regardless of installation method.
Summary
- Multiple installation paths support every major platform: pre-built binaries, Docker, Homebrew, Go toolchain, Nix, AUR, and Conda.
- No privileges required because Tailcat operates in pure userspace without needing a Tailscale account or system-level changes.
- Optimized binary size results from curated build tags in
build-tags.txt, making Tailcat approximately 16% smaller than the standard Tailscale client. - Core implementation resides in
cmd/tailcat/tailcat.go, with sub-commands forserve,forward, andsshdefined in adjacent files. - Immediate usage is possible after installation for pipe-mode data transfer, TCP port exposure, and multi-port forwarding.
Frequently Asked Questions
Do I need a Tailscale account to use Tailcat?
No. Tailcat operates independently of the Tailscale coordination server and does not require an account, API keys, or authentication tokens. The binary creates ephemeral connections using the magicsock data plane directly, though it can interoperate with existing Tailscale networks if needed.
Which installation method is best for CI/CD pipelines?
The Docker method is ideal for CI/CD environments because it requires no binary installation on the runner. Use docker run --rm ghcr.io/tailscale/tailcat:latest followed by your sub-command. Alternatively, the Go toolchain method (go install ...@latest) works well in Go-based workflows but requires caching $GOPATH/bin between runs for optimal performance.
How does the Go install method differ from package manager installations?
When you run go install github.com/tailscale/tailcat/cmd/tailcat@latest, the Go compiler fetches the source from the main branch, applies the build tags specified in build-tags.txt, and compiles a native binary for your architecture. Package managers like Homebrew or Nix perform this same compilation步骤 during their packaging process, then distribute the resulting binary, meaning both methods produce functionally identical executables but package managers handle updates automatically.
Can I run Tailcat on Windows?
Yes. Pre-built binaries are available for Windows on both amd64 and arm64 architectures from the GitHub Releases page. Download the Windows archive, extract tailcat.exe, and place it in a directory included in your system PATH. The command-line interface and functionality are identical to the Linux and macOS versions.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →