Tailcat Requirements: Installation Prerequisites and System Compatibility
To use Tailcat, you only need a recent Go toolchain and network connectivity to a DERP relay—no root privileges, kernel modules, or Tailscale control plane are required.
Tailcat is a userspace utility from the tailscale/tailcat repository that creates encrypted point-to-point connections over Tailscale’s data plane without requiring the Tailscale control plane. It operates as a standalone Go binary that generates ephemeral WireGuard keys and establishes tunnels through DERP relays, making it suitable for environments where you cannot install kernel modules or modify system networking configuration.
Core Installation Requirements
Go Toolchain
Tailcat is written in Go and distributed as both source and pre-built binaries. You can install the CLI directly from the repository:
go install github.com/tailscale/tailcat/cmd/tailcat@latest
The main entry point in cmd/tailcat/tailcat.go parses subcommands and embeds documentation via readme.go. Packagers should review build-tags.txt for the specific Go build tags used to optimize official release binaries.
Privilege Requirements
Unlike traditional VPN clients, Tailcat requires no root or administrator privileges. According to the source documentation (Lines 29‑31), the tool runs entirely in userspace and does not modify routing tables, DNS settings, or network interfaces. This makes it safe to run on any user account and simplifies deployment on laptops, servers, or restricted containers where elevated permissions are unavailable.
Network and Cryptographic Requirements
DERP Relay Access
Tailcat requires access to a DERP (Deterministic Enroute Relay Protocol) server to bootstrap connections when direct NAT hole-punching fails. By default, the binary contacts the public DERP map at https://tailcat.dev/derpmap.json. You can override this with a custom map using the --derpmap-url flag (Lines 35‑38, 58‑66).
DERP serves as the out-of-band signaling channel that coordinates the WireGuard handshake between peers. Without connectivity to at least one DERP region, Tailcat cannot establish the initial connection, though traffic flows directly between peers once the tunnel is established.
WireGuard Key Management
The tool generates an ephemeral WireGuard keypair on each run, implemented in tailcat.go. For persistent identity across restarts, generate a persistent key with:
tailcat genkey
These keys form the cryptographic basis of the end-to-end encrypted tunnel and are managed entirely within the application layer.
Pre-Shared Keys (PSK)
By default, Tailcat enables an additional layer of post-quantum protection using a pre-shared key (PSK). This prevents DERP operators from injecting traffic even if they observe both peers’ public keys (Lines 31‑34). You can disable this for compatibility with older clients:
tailcat --psk=false
Platform Support and Deployment Options
Supported Operating Systems
Tailcat supports any platform where Go can compile, with official pre-built binaries available for:
- Linux: Static binaries requiring no external dependencies
- macOS: Available via Homebrew
- Windows: Distributed as zip archives
- Package managers: Nix, Arch AUR, and Conda formulas are maintained by the community (Lines 46‑78)
Container and Restricted Environments
Because Tailcat requires no kernel modules or CAP_NET_ADMIN privileges, it runs unmodified in Docker containers, Kubernetes pods, and restricted shell environments. The tailcat_exec.go file implements the exec service for running commands per incoming connection, further simplifying containerized deployments.
Optional Service Components
While the core functionality requires only the elements above, specific subcommands have additional optional dependencies:
SSH Server Requirements
When running tailcat serve --ssh, the implementation in tailcat_ssh.go can operate in two modes:
- No authentication: Accepts any connection (development only)
- Key authentication: Requires a local
authorized_keysfile specified via--ssh-authorized-keys
File Transfer and Proxy Services
The SFTP implementation in tailcat_files.go enables the serve files, cp, and ls subcommands. These services require no additional system dependencies beyond the base binary, functioning as pure Go implementations of the respective protocols.
Summary
- Build requirement: Recent Go toolchain (or download pre-built binary from releases)
- Privilege requirement: None—runs entirely in userspace without root access
- Network requirement: Outbound HTTPS to a DERP relay (default: tailcat.dev)
- Cryptographic requirement: Ephemeral WireGuard keys generated automatically; optional persistent keys via
genkey - Platform support: Linux, macOS, Windows, and any Go-supported architecture
- Optional enhancements: Pre-shared keys enabled by default for post-quantum resistance; SSH keys for authenticated sessions
Frequently Asked Questions
Do I need a Tailscale account to use Tailcat?
No. Tailcat connects exclusively to the Tailscale data plane via DERP relays and WireGuard tunnels without authenticating to the Tailscale control plane. You do not need an account, API keys, or coordination server access to establish connections.
Why doesn't Tailcat require root privileges?
Because Tailcat operates as a userspace network implementation, it handles encryption and packet forwarding within the application rather than through kernel network stacks. The source code in tailcat.go manages sockets directly without modifying system routing tables or DNS resolvers, eliminating the need for CAP_NET_ADMIN or administrator tokens.
Can I run Tailcat without internet access?
Only if you deploy your own DERP infrastructure. Tailcat requires at least one DERP relay for initial peer coordination. You can host a private DERP map and specify it with --derpmap-url, but peers must reach this relay to exchange WireGuard handshakes before establishing direct connections.
How do I create persistent keys for server identity?
Run tailcat genkey to generate a persistent keypair saved to disk. Without this step, Tailcat generates ephemeral keys on each invocation, causing the connection address to change every restart. Persistent keys are essential for providing stable addresses to clients.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →