Tailscale Essentials
What this article covers
- What Tailscale is and how it works.
- How to install and configure Tailscale.
- How to connect devices and enable remote access.
- How to use Access Control Lists and Exit Nodes.
- When Tailscale makes sense for local AI projects.
Introduction: Tailscale Essentials
Tailscale is a VPN service that connects devices through an encrypted mesh network. Unlike traditional VPNs with a central server, Tailscale devices establish direct connections with each other. This makes remote access to homelab servers, AI tools, and self-hosted services remarkably straightforward.
For local AI projects, Tailscale shines when you need to reach Open WebUI, Ollama, Proxmox, or other services from anywhere without exposing public ports.
Key terms
- Tailnet: Your private network at Tailscale.
- Node: A device in your Tailnet.
- Mesh VPN: Direct connections between devices, not routed through a central server.
- MagicDNS: Automatic DNS resolution within the Tailnet.
- ACL: Access Control List that defines who can reach whom.
- Exit Node: A device that routes internet traffic from other devices.
- Subnet Router: Enables access to entire networks instead of individual devices.
Why Tailscale?
- Simple: Setup and login in minutes.
- Secure: End-to-end encrypted, WireGuard-based.
- No port forwarding needed: Devices are reachable without public IPs or router port mapping.
- Cross-platform: Linux, Windows, macOS, Android, iOS, Proxmox, Docker.
- Free: The Personal plan covers most homelabs.
Installation
Linux
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
You’ll see an authentication link afterwards.
Proxmox VE
On the Proxmox host:
curl -fsSL https://tailscale.com/install.sh | sh
tailscale up
If Tailscale will run inside an LXC container or VM, the TUN device must be available.
Docker
docker run -d --name tailscale \
--cap-add NET_ADMIN \
--cap-add NET_RAW \
--device /dev/net/tun \
-v /var/lib/tailscale:/var/lib/tailscale \
tailscale/tailscale
Connecting devices
After installation, sign each device in with the same account. The Tailscale admin dashboard shows all nodes. Each node gets an IP address and optionally a MagicDNS name like pve.tailXXXX.ts.net.
Accessing services
Once a device is in your Tailnet, you can reach services via the Tailscale IP or MagicDNS name:
http://pve:8006
http://open-webui:8080
ssh admin@ollama-server
No public IP or port forwarding required.
Subnet Router
To make an entire network accessible without installing Tailscale on every device, set up a Subnet Router:
sudo tailscale up --advertise-routes=192.168.1.0/24 --accept-routes
You’ll need to approve the route in the admin console.
Exit Nodes
An Exit Node routes internet traffic from other devices through itself. Useful for secure browsing on public networks:
sudo tailscale up --advertise-exit-node
On the client:
sudo tailscale up --exit-node=<node-name>
ACLs and security
Tailscale lets you control access through Access Control Lists. By default, all nodes can communicate with each other. For basic restrictions, define rules explicitly:
{
"acls": [
{
"action": "accept",
"src": ["group:admins"],
"dst": ["tag:proxmox:22", "tag:open-webui:8080"]
}
]
}
Tags help organize devices by function, independent of user.
Tailscale for local AI projects
- Manage Proxmox remotely: Secure access to the web interface.
- Use Open WebUI on mobile: Chat interface from anywhere.
- Access Ollama API externally: Developer access to your local model.
- SSH to servers: Secure management without public ports.
- Agent monitoring: Check dashboards without exposing them.
Common pitfalls
- TUN device missing: LXC and Docker need
/dev/net/tunavailable. - Firewall blocks traffic: Tailscale requires UDP port 41641.
- Exit Node not approved: Must be enabled in the admin console.
- Subnet routes not activated: Enable them in the console.
- Too many open permissions: Default ACL allows everything, consider restricting it.
Further reading and resources
FAQ: Tailscale
Is Tailscale free? The Personal plan is free and sufficient for most homelabs.
Do I need public ports? No. Tailscale uses UDP hole punching and relay servers as fallback.
Can I use Tailscale in an LXC container? Yes, but the TUN device must be available.
Is Tailscale secure? Yes, it’s built on WireGuard and uses end-to-end encryption.
How does Tailscale differ from a traditional VPN? Tailscale is a mesh VPN without a central server. Traditional VPNs route everything through a server.
Sources and further reading
- Tailscale Docs: https://tailscale.com/kb/
- Tailscale GitHub: https://github.com/tailscale/tailscale
- WireGuard: https://www.wireguard.com/
Summary: Tailscale Essentials
Tailscale is a simple and secure way to connect devices in a private mesh VPN. For local AI projects, it enables remote access to Proxmox, Open WebUI, Ollama, and other services without exposing public ports. Proper installation, Subnet Routers, and ACLs are essential for clean separation. With Tailscale, you get convenient access combined with strong security.


