Skip to content
BotServBotServ
TailscaleVPNMesh VPNRemote AccessLocal AI

Tailscale Basics

Secure access to local AI and self-hosting services with Tailscale. VPN mesh, setup, ACLs, and best practices.

S

schutzgeist

3 min read
Tailscale Basics

Tailscale Essentials

What this article covers

  • What Tailscale is and how it works.
  • How to install and configure Tailscale.
  • How to connect devices and enable remote access.
  • How to use Access Control Lists and Exit Nodes.
  • When Tailscale makes sense for local AI projects.

Introduction: Tailscale Essentials

Tailscale is a VPN service that connects devices through an encrypted mesh network. Unlike traditional VPNs with a central server, Tailscale devices establish direct connections with each other. This makes remote access to homelab servers, AI tools, and self-hosted services remarkably straightforward.

For local AI projects, Tailscale shines when you need to reach Open WebUI, Ollama, Proxmox, or other services from anywhere without exposing public ports.

Key terms

  • Tailnet: Your private network at Tailscale.
  • Node: A device in your Tailnet.
  • Mesh VPN: Direct connections between devices, not routed through a central server.
  • MagicDNS: Automatic DNS resolution within the Tailnet.
  • ACL: Access Control List that defines who can reach whom.
  • Exit Node: A device that routes internet traffic from other devices.
  • Subnet Router: Enables access to entire networks instead of individual devices.

Why Tailscale?

  • Simple: Setup and login in minutes.
  • Secure: End-to-end encrypted, WireGuard-based.
  • No port forwarding needed: Devices are reachable without public IPs or router port mapping.
  • Cross-platform: Linux, Windows, macOS, Android, iOS, Proxmox, Docker.
  • Free: The Personal plan covers most homelabs.

Installation

Linux

curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up

You’ll see an authentication link afterwards.

Proxmox VE

On the Proxmox host:

curl -fsSL https://tailscale.com/install.sh | sh
tailscale up

If Tailscale will run inside an LXC container or VM, the TUN device must be available.

Docker

docker run -d --name tailscale \
  --cap-add NET_ADMIN \
  --cap-add NET_RAW \
  --device /dev/net/tun \
  -v /var/lib/tailscale:/var/lib/tailscale \
  tailscale/tailscale

Connecting devices

After installation, sign each device in with the same account. The Tailscale admin dashboard shows all nodes. Each node gets an IP address and optionally a MagicDNS name like pve.tailXXXX.ts.net.

Accessing services

Once a device is in your Tailnet, you can reach services via the Tailscale IP or MagicDNS name:

http://pve:8006
http://open-webui:8080
ssh admin@ollama-server

No public IP or port forwarding required.

Subnet Router

To make an entire network accessible without installing Tailscale on every device, set up a Subnet Router:

sudo tailscale up --advertise-routes=192.168.1.0/24 --accept-routes

You’ll need to approve the route in the admin console.

Exit Nodes

An Exit Node routes internet traffic from other devices through itself. Useful for secure browsing on public networks:

sudo tailscale up --advertise-exit-node

On the client:

sudo tailscale up --exit-node=<node-name>

ACLs and security

Tailscale lets you control access through Access Control Lists. By default, all nodes can communicate with each other. For basic restrictions, define rules explicitly:

{
  "acls": [
    {
      "action": "accept",
      "src": ["group:admins"],
      "dst": ["tag:proxmox:22", "tag:open-webui:8080"]
    }
  ]
}

Tags help organize devices by function, independent of user.

Tailscale for local AI projects

  • Manage Proxmox remotely: Secure access to the web interface.
  • Use Open WebUI on mobile: Chat interface from anywhere.
  • Access Ollama API externally: Developer access to your local model.
  • SSH to servers: Secure management without public ports.
  • Agent monitoring: Check dashboards without exposing them.

Common pitfalls

  • TUN device missing: LXC and Docker need /dev/net/tun available.
  • Firewall blocks traffic: Tailscale requires UDP port 41641.
  • Exit Node not approved: Must be enabled in the admin console.
  • Subnet routes not activated: Enable them in the console.
  • Too many open permissions: Default ACL allows everything, consider restricting it.

Further reading and resources

FAQ: Tailscale

Is Tailscale free? The Personal plan is free and sufficient for most homelabs.

Do I need public ports? No. Tailscale uses UDP hole punching and relay servers as fallback.

Can I use Tailscale in an LXC container? Yes, but the TUN device must be available.

Is Tailscale secure? Yes, it’s built on WireGuard and uses end-to-end encryption.

How does Tailscale differ from a traditional VPN? Tailscale is a mesh VPN without a central server. Traditional VPNs route everything through a server.

Sources and further reading

Summary: Tailscale Essentials

Tailscale is a simple and secure way to connect devices in a private mesh VPN. For local AI projects, it enables remote access to Proxmox, Open WebUI, Ollama, and other services without exposing public ports. Proper installation, Subnet Routers, and ACLs are essential for clean separation. With Tailscale, you get convenient access combined with strong security.

Back to Blog
Share:

Related Posts