From the newsletter:

We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.

Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.

Potential usage info from the website link - https://tailscale.com/tailcat:

Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.

A technical explanation from the github:

Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale's data plane, without Tailscale's control plane. Tailscale's data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.

License: BSD 3-Clause License

you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 19 hours ago* (1 child)

Okay so i think this section is one of the most useful ones for a normal user:


Send and receive files

To receive files, run a drop box and share the printed tailcat address:

$ tailcat recv ~/inbox
# 🐈 Server listening with new address: tcXXXXXXXXX

The sender then runs:

$ tailcat cp report.pdf tcXXXXXXXXX:

tailcat cp runs the system scp with the connection routed through tailcat, so you get its usual progress display, and -r for directory trees. The drop box is write-only: senders can't list the directory, read anything back, or touch existing files.

To offer files instead, serve a directory read-only (the default) or read-write:

$ tailcat serve files                  # current directory, read-only
$ tailcat serve --files=/pub:rw files  # a given directory, read-write
$ tailcat ls -l tcXXXXXXXXX
$ tailcat cp tcXXXXXXXXX:report.pdf .
  • source
  • hideshow 1 child comment
  • [–] 4 points 19 hours ago

    And this can presumably hopefully finally fucking condemn hamachi to the grave, maybe?


    Forward local ports to a tailcat server

    To make ports served by a tailcat server available as ordinary local TCP ports (for browsers, database clients, or other tools that do not support SOCKS or stdio), run forward with the server's tailcat address:

    $ tailcat serve 8080,3306
    # 🐈 Server listening with new address: tcXXXXXXXXX
    
    $ tailcat forward tcXXXXXXXXX 18080:8080 3306
    

    A local port of 0 asks the operating system for a free port; each listener prints its address once it's listening.

    To forward local ports to assets on the network reachable by an exit-node server, run the server in exit-node mode and specify each remote IP address and port in the mapping:

    $ tailcat serve exit-node
    # 🐈 Server listening with new address: tcXXXXXXXXX
    
    $ tailcat forward tcXXXXXXXXX \
        3001:172.23.52.30:3001 \
        17170:172.23.52.31:17170
    

    This forwards 127.0.0.1:3001 to 172.23.52.30:3001 and 127.0.0.1:17170 to 172.23.52.31:17170 through the exit-node server.

    By default, listeners bind to 127.0.0.1 and diagnostic logs are suppressed. Pass --verbose before the subcommand to enable verbose networking logs. Use --bind=0.0.0.0 only when clients on other machines should be able to connect:

    $ tailcat forward --bind=0.0.0.0 tcXXXXXXXXX 18080:8080
    

    Press Ctrl-C to stop forwarding.

  • source
  • parent