From the newsletter:
We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.
Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.
Potential usage info from the website link - https://tailscale.com/tailcat:
Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.
A technical explanation from the github:
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.
License: BSD 3-Clause License
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.

DERP
This GIF reminds me that I kept saying “who loves orange soda? Kel loves orange soda!” Do my significant other.
Okay so i think this section is one of the most useful ones for a normal user:
Send and receive files
To receive files, run a drop box and share the printed tailcat address:
$ tailcat recv ~/inbox # 🐈 Server listening with new address: tcXXXXXXXXXThe sender then runs:
$ tailcat cp report.pdf tcXXXXXXXXX:tailcat cpruns the systemscpwith the connection routed through tailcat, so you get its usual progress display, and-rfor directory trees. The drop box is write-only: senders can’t list the directory, read anything back, or touch existing files.To offer files instead, serve a directory read-only (the default) or read-write:
$ tailcat serve files # current directory, read-only $ tailcat serve --files=/pub:rw files # a given directory, read-write$ tailcat ls -l tcXXXXXXXXX $ tailcat cp tcXXXXXXXXX:report.pdf .And this can presumably hopefully finally fucking condemn hamachi to the grave, maybe?
Forward local ports to a tailcat server
To make ports served by a tailcat server available as ordinary local TCP ports (for browsers, database clients, or other tools that do not support SOCKS or stdio), run
forwardwith the server’s tailcat address:$ tailcat serve 8080,3306 # 🐈 Server listening with new address: tcXXXXXXXXX $ tailcat forward tcXXXXXXXXX 18080:8080 3306A local port of 0 asks the operating system for a free port; each listener prints its address once it’s listening.
To forward local ports to assets on the network reachable by an exit-node server, run the server in exit-node mode and specify each remote IP address and port in the mapping:
$ tailcat serve exit-node # 🐈 Server listening with new address: tcXXXXXXXXX $ tailcat forward tcXXXXXXXXX \ 3001:172.23.52.30:3001 \ 17170:172.23.52.31:17170This forwards
127.0.0.1:3001to172.23.52.30:3001and127.0.0.1:17170to172.23.52.31:17170through the exit-node server.By default, listeners bind to
127.0.0.1and diagnostic logs are suppressed. Pass--verbosebefore the subcommand to enable verbose networking logs. Use--bind=0.0.0.0only when clients on other machines should be able to connect:$ tailcat forward --bind=0.0.0.0 tcXXXXXXXXX 18080:8080Press Ctrl-C to stop forwarding.
ELI5? I barely understood original Tailscale.
Tailscale is a private treehouse. Everyone gets an official member badge, has their name on the roster, and can walk in anytime to hang out, share toys, and see everone else in the club.
Tailcat is two tin cans tied together with a string. There is no club, no badges, and no rules. You give one can to someone, whisper a secret through the string, and as soon as you hang up, it’s gone.
So they made wireguard?
But isnt tailscale built on wireguard?
Are girls allowed?
Only if you invite them. But be warned, they have cooties.

Excellent I am five years old and I completely understand this analogy
Soooo, netbird?
Not quite:
Netbird is a treehouse you build and maintain yourself. You’re the club leader: you set the rules, issue the badges, keep the roster, and decide who gets in. No one runs it for you. You have to build it, keep it up, and handle the maintenance. It’s still a real club with a real roster and persistent membership, just like Tailscale’s treehouse, except you’re the one who has to insure the roof doesn’t leak.
Easy VPN is how I see it. Like zero config, very smooth and pretty slick
With normal Tailscale they host the management end of things, you host the servers, their system negotiates directly connecting them together.
I think this lets you host that management connection yourself. But I’m kinda confused just wtf is going on.
I think this lets you host that management connection yourself.
No, but if you wanted to do that, headscale is the answer
Headscale any easier to config nowadays?
I’d tried running it ages ago, but I was very new to Linux, and nixos as a whole. Eventually gave up and just ran tailscale for ease of use.
I followed the compose file in the docs with podman and it was fine, configured headplane as the management gui inside the same compose. I then later converted the compose to a quadlet and it continues to be fine. I leave it alone, it leaves me alone
Nice, thanks for the info.
I’ll give it another go hopefully on my one day off over this long weekend 😅
Having less reliance on major tech providers is something I’m slowly moving towards, probably like lots of us here.
There is no management connection. It’s just managed locally but has their UDP hole punching feature
Scales are rough… Cats are fluffy and smooth :D !
Never mind me, wait for a better ELI :D
“like netcat” huh, i wonder what netcat is…
“netcat (often abbreviated to nc) is a computer networking utility for reading from and writing to network connections using TCP or UDP. The command is designed to be a dependable back-end that can be used directly or easily driven by other programs and scripts. At the same time, it is a feature-rich network debugging and investigation tool, since it can produce almost any kind of connection its user could need and has a number of built-in capabilities.”
So… Wireguard?
It sounds more like netcat maybe? Less server client architecture more peer to peer?
Yeah seems more like nectat. From the name I would guess that’s the intent.
My first reaction was that it’s similar to dumbpipe (which is also inspired by netcat). Variety is good I guess.








