⚡
SelfHostStackOpen-Source Directory

Why Migrate Away from Tailscale & Cloudflare Zero Trust?

Proprietary VPN services channel routing coordination through their proprietary servers and enforce node quotas. Self-hosting Headscale (an open-source implementation of the Tailscale control server) gives you an unlimited, private WireGuard mesh network that connects servers, laptops, and phones securely without opening any router ports.

Top 2 Recommended Open-Source Replacements

Tested, self-contained, and production-ready. Click any tool to inspect verified docker-compose configurations, hardware sizing, and deployment guides.

Headscale

BSD-3-Clause⭐ 26.0k+

An open source, self-hosted implementation of the Tailscale control server for unlimited private WireGuard mesh networks.

Min RAM512 MB
Min CPU1 vCPU
GitHub Repo ↗

✅ Advantages

  • Zero device limits or user seat fees
  • Uses official cross-platform Tailscale client apps
  • Negligible RAM footprint (<100MB)

⚠️ Trade-offs / Limitations

  • Admin UI is CLI-first (can be paired with third-party web UIs like Headplane)
  • Requires public IP VPS for reliable NAT traversal and coordination

Core Features

▸Full compatibility with official Tailscale mobile, desktop, and CLI clients
▸Unlimited connected devices, users, and pre-shared authentication keys
▸Direct peer-to-peer WireGuard mesh routing with DERP relay fallback
▸Exit nodes support for routing all device traffic securely through a single VPS
▸Access Control Lists (ACLs) and subnet routing capabilities
📄 docker-compose.yml
Production Ready
version: '3.8'
services:
  headscale:
    image: headscale/headscale:latest
    container_name: headscale
    restart: always
    volumes:
      - ./config:/etc/headscale
      - headscale-data:/var/lib/headscale
    ports:
      - "8080:8080"
      - "9080:9080"
    command: headscale serve
volumes:
  headscale-data:

🚀 5-Minute Deployment Guide

  1. 1Spin up a lightweight VPS with a public IPv4/IPv6 address.
  2. 2Install Docker and create config.yaml for Headscale.
  3. 3Start Headscale with `docker compose up -d`.
  4. 4Generate user namespace: `docker exec headscale headscale users create myuser`.
  5. 5Connect clients with `tailscale up --login-server https://headscale.yourdomain.com`.
  6. 6Enjoy zero-trust private mesh networking across all your servers and laptops.

Recommended Cloud VPS for Headscale

Compare all VPS hosts →
Hetzner Cloud€3.79/mo

CX22 (2 vCPU, 4GB RAM, 40GB NVMe)

Minimal RAM overhead; can easily route traffic for 500+ nodes.

Deploy on Hetzner →
DigitalOcean$6.00/mo

Basic Droplet (1 vCPU, 1GB RAM, 25GB SSD)

Solid central coordinator with global data centers.

Claim $200 DO Credit →
Vultr$6.00/mo

Cloud Compute (1 vCPU, 1GB RAM, 25GB NVMe)

Ultra-low latency coordination server.

Deploy on Vultr →

Netmaker

SSPL-1.0⭐ 12.3k+

High-speed automated WireGuard networking for distributed cloud and edge infrastructure.

Min RAM1 GB
Min CPU1 vCPU
GitHub Repo ↗

✅ Advantages

  • Near-native kernel WireGuard throughput
  • Built-in intuitive visual web UI
  • Excellent for connecting multi-cloud Kubernetes clusters

⚠️ Trade-offs / Limitations

  • Slightly higher setup complexity than Headscale
  • Enterprise features require commercial license

Core Features

▸Kernel-level WireGuard speed with automated key generation and rotation
▸Complete web-based UI for managing networks, gateways, and clients
▸Multi-cloud VPC peering and ingress/egress gateway support
▸Zero Trust access control and dynamic relaying
📄 docker-compose.yml
Production Ready
version: '3.8'
services:
  netmaker:
    image: gravitl/netmaker:latest
    container_name: netmaker
    restart: always
    cap_add:
      - NET_ADMIN
    ports:
      - "8081:8081"
      - "51821-51830:51821-51830/udp"
    environment:
      - SERVER_HOST=vpn.yourdomain.com
      - MASTER_KEY=secret_master_key_12345
    volumes:
      - netmaker-data:/etc/netmaker
volumes:
  netmaker-data:

🚀 5-Minute Deployment Guide

  1. 1Provision an Ubuntu 24.04 VPS with public IP.
  2. 2Install Docker Compose and run the Netmaker automated install script.
  3. 3Access the web dashboard and create your private virtual networks.
  4. 4Deploy Netclient agents on your target VMs and client machines.

Recommended Cloud VPS for Netmaker

Compare all VPS hosts →
Hetzner Cloud€3.79/mo

CX22 (2 vCPU, 4GB RAM, 40GB NVMe)

High bandwidth network throughput.

Deploy on Hetzner →
DigitalOcean$6.00/mo

Basic Droplet (1 vCPU, 1GB RAM, 25GB SSD)

Easy setup with $200 free credit.

Claim $200 DO Credit →
Vultr$6.00/mo

Cloud Compute (1 vCPU, 1GB RAM, 25GB NVMe)

Native WireGuard kernel acceleration.

Deploy on Vultr →

Quick Specification Matrix

ToolLicenseMin RAMMin CPUGitHub RepoPrimary Advantage
Tailscale & Cloudflare Zero Trust (Proprietary)Proprietary ClosedManaged CloudManaged CloudN/ATurnkey onboarding with vendor lock-in & paywalls
HeadscaleBSD-3-Clause512 MB1 vCPUjuanfont/headscaleZero device limits or user seat fees
NetmakerSSPL-1.01 GB1 vCPUgravitl/netmakerNear-native kernel WireGuard throughput
Starter Stack Pack — $29

Skip the setup: get the production-ready stack

Don't stitch together configs from five different READMEs. Get all 5 production-hardened Docker Compose stacks — Postgres, Redis, SSL auto-renewal, and backup scripts — ready to deploy in minutes.

⚡n8nVisual workflow automation
📊UmamiPrivacy-first web analytics
🛡️Uptime KumaUptime monitoring & alerts
🔐VaultwardenBitwarden-compatible vault
☁️NextcloudDropbox/Drive replacement
Get the Stack Pack — $29 →

One-time purchase · Instant download · Production-ready

esc
↑↓ navigate↵ open