From the newsletter:
We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.
Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.
Potential usage info from the website link - https://tailscale.com/tailcat:
Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.
A technical explanation from the github:
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.
License: BSD 3-Clause License


Okay so i think this section is one of the most useful ones for a normal user:
Send and receive files
To receive files, run a drop box and share the printed tailcat address:
The sender then runs:
tailcat cpruns the systemscpwith the connection routed through tailcat, so you get its usual progress display, and-rfor directory trees. The drop box is write-only: senders can’t list the directory, read anything back, or touch existing files.To offer files instead, serve a directory read-only (the default) or read-write:
And this can presumably hopefully finally fucking condemn hamachi to the grave, maybe?
Forward local ports to a tailcat server
To make ports served by a tailcat server available as ordinary local TCP ports (for browsers, database clients, or other tools that do not support SOCKS or stdio), run
forwardwith the server’s tailcat address:A local port of 0 asks the operating system for a free port; each listener prints its address once it’s listening.
To forward local ports to assets on the network reachable by an exit-node server, run the server in exit-node mode and specify each remote IP address and port in the mapping:
This forwards
127.0.0.1:3001to172.23.52.30:3001and127.0.0.1:17170to172.23.52.31:17170through the exit-node server.By default, listeners bind to
127.0.0.1and diagnostic logs are suppressed. Pass--verbosebefore the subcommand to enable verbose networking logs. Use--bind=0.0.0.0only when clients on other machines should be able to connect:Press Ctrl-C to stop forwarding.