# Tailcat Requirements: Installation Prerequisites and System Compatibility

> Discover Tailcat installation prerequisites and system compatibility. Learn what you need to use Tailcat, including Go toolchain and network access. No root needed.

- Repository: [Tailscale/tailcat](https://github.com/tailscale/tailcat)
- Tags: getting-started
- Published: 2026-09-08

---

**To use Tailcat, you only need a recent Go toolchain and network connectivity to a DERP relay—no root privileges, kernel modules, or Tailscale control plane are required.**

Tailcat is a userspace utility from the `tailscale/tailcat` repository that creates encrypted point-to-point connections over Tailscale’s data plane without requiring the Tailscale control plane. It operates as a standalone Go binary that generates ephemeral WireGuard keys and establishes tunnels through DERP relays, making it suitable for environments where you cannot install kernel modules or modify system networking configuration.

## Core Installation Requirements

### Go Toolchain

Tailcat is written in Go and distributed as both source and pre-built binaries. You can install the CLI directly from the repository:

```bash
go install github.com/tailscale/tailcat/cmd/tailcat@latest

```

The main entry point in [`cmd/tailcat/tailcat.go`](https://github.com/tailscale/tailcat/blob/main/cmd/tailcat/tailcat.go) parses subcommands and embeds documentation via [`readme.go`](https://github.com/tailscale/tailcat/blob/main/readme.go). Packagers should review [`build-tags.txt`](https://github.com/tailscale/tailcat/blob/main/build-tags.txt) for the specific Go build tags used to optimize official release binaries.

### Privilege Requirements

Unlike traditional VPN clients, Tailcat requires **no root or administrator privileges**. According to the source documentation (Lines 29‑31), the tool runs entirely in userspace and does not modify routing tables, DNS settings, or network interfaces. This makes it safe to run on any user account and simplifies deployment on laptops, servers, or restricted containers where elevated permissions are unavailable.

## Network and Cryptographic Requirements

### DERP Relay Access

Tailcat requires access to a DERP (Deterministic Enroute Relay Protocol) server to bootstrap connections when direct NAT hole-punching fails. By default, the binary contacts the public DERP map at `https://tailcat.dev/derpmap.json`. You can override this with a custom map using the `--derpmap-url` flag (Lines 35‑38, 58‑66).

DERP serves as the out-of-band signaling channel that coordinates the WireGuard handshake between peers. Without connectivity to at least one DERP region, Tailcat cannot establish the initial connection, though traffic flows directly between peers once the tunnel is established.

### WireGuard Key Management

The tool generates an ephemeral WireGuard keypair on each run, implemented in [`tailcat.go`](https://github.com/tailscale/tailcat/blob/main/tailcat.go). For persistent identity across restarts, generate a persistent key with:

```bash
tailcat genkey

```

These keys form the cryptographic basis of the end-to-end encrypted tunnel and are managed entirely within the application layer.

### Pre-Shared Keys (PSK)

By default, Tailcat enables an additional layer of post-quantum protection using a pre-shared key (PSK). This prevents DERP operators from injecting traffic even if they observe both peers’ public keys (Lines 31‑34). You can disable this for compatibility with older clients:

```bash
tailcat --psk=false

```

## Platform Support and Deployment Options

### Supported Operating Systems

Tailcat supports any platform where Go can compile, with official pre-built binaries available for:

- **Linux**: Static binaries requiring no external dependencies
- **macOS**: Available via Homebrew
- **Windows**: Distributed as zip archives
- **Package managers**: Nix, Arch AUR, and Conda formulas are maintained by the community (Lines 46‑78)

### Container and Restricted Environments

Because Tailcat requires no kernel modules or `CAP_NET_ADMIN` privileges, it runs unmodified in Docker containers, Kubernetes pods, and restricted shell environments. The [`tailcat_exec.go`](https://github.com/tailscale/tailcat/blob/main/tailcat_exec.go) file implements the `exec` service for running commands per incoming connection, further simplifying containerized deployments.

## Optional Service Components

While the core functionality requires only the elements above, specific subcommands have additional optional dependencies:

### SSH Server Requirements

When running `tailcat serve --ssh`, the implementation in [`tailcat_ssh.go`](https://github.com/tailscale/tailcat/blob/main/tailcat_ssh.go) can operate in two modes:
- **No authentication**: Accepts any connection (development only)
- **Key authentication**: Requires a local `authorized_keys` file specified via `--ssh-authorized-keys`

### File Transfer and Proxy Services

The SFTP implementation in [`tailcat_files.go`](https://github.com/tailscale/tailcat/blob/main/tailcat_files.go) enables the `serve files`, `cp`, and `ls` subcommands. These services require no additional system dependencies beyond the base binary, functioning as pure Go implementations of the respective protocols.

## Summary

- **Build requirement**: Recent Go toolchain (or download pre-built binary from releases)
- **Privilege requirement**: None—runs entirely in userspace without root access
- **Network requirement**: Outbound HTTPS to a DERP relay (default: tailcat.dev)
- **Cryptographic requirement**: Ephemeral WireGuard keys generated automatically; optional persistent keys via `genkey`
- **Platform support**: Linux, macOS, Windows, and any Go-supported architecture
- **Optional enhancements**: Pre-shared keys enabled by default for post-quantum resistance; SSH keys for authenticated sessions

## Frequently Asked Questions

### Do I need a Tailscale account to use Tailcat?

No. Tailcat connects exclusively to the Tailscale data plane via DERP relays and WireGuard tunnels without authenticating to the Tailscale control plane. You do not need an account, API keys, or coordination server access to establish connections.

### Why doesn't Tailcat require root privileges?

Because Tailcat operates as a userspace network implementation, it handles encryption and packet forwarding within the application rather than through kernel network stacks. The source code in [`tailcat.go`](https://github.com/tailscale/tailcat/blob/main/tailcat.go) manages sockets directly without modifying system routing tables or DNS resolvers, eliminating the need for `CAP_NET_ADMIN` or administrator tokens.

### Can I run Tailcat without internet access?

Only if you deploy your own DERP infrastructure. Tailcat requires at least one DERP relay for initial peer coordination. You can host a private DERP map and specify it with `--derpmap-url`, but peers must reach this relay to exchange WireGuard handshakes before establishing direct connections.

### How do I create persistent keys for server identity?

Run `tailcat genkey` to generate a persistent keypair saved to disk. Without this step, Tailcat generates ephemeral keys on each invocation, causing the connection address to change every restart. Persistent keys are essential for providing stable addresses to clients.