From the newsletter:

We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.

Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.

Potential usage info from the website link - https://tailscale.com/tailcat:

Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.

A technical explanation from the github:

Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale's data plane, without Tailscale's control plane. Tailscale's data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.

License: BSD 3-Clause License

you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 21 hours ago

And this can presumably hopefully finally fucking condemn hamachi to the grave, maybe?


Forward local ports to a tailcat server

To make ports served by a tailcat server available as ordinary local TCP ports (for browsers, database clients, or other tools that do not support SOCKS or stdio), run forward with the server's tailcat address:

$ tailcat serve 8080,3306
# 🐈 Server listening with new address: tcXXXXXXXXX

$ tailcat forward tcXXXXXXXXX 18080:8080 3306

A local port of 0 asks the operating system for a free port; each listener prints its address once it's listening.

To forward local ports to assets on the network reachable by an exit-node server, run the server in exit-node mode and specify each remote IP address and port in the mapping:

$ tailcat serve exit-node
# 🐈 Server listening with new address: tcXXXXXXXXX

$ tailcat forward tcXXXXXXXXX \
    3001:172.23.52.30:3001 \
    17170:172.23.52.31:17170

This forwards 127.0.0.1:3001 to 172.23.52.30:3001 and 127.0.0.1:17170 to 172.23.52.31:17170 through the exit-node server.

By default, listeners bind to 127.0.0.1 and diagnostic logs are suppressed. Pass --verbose before the subcommand to enable verbose networking logs. Use --bind=0.0.0.0 only when clients on other machines should be able to connect:

$ tailcat forward --bind=0.0.0.0 tcXXXXXXXXX 18080:8080

Press Ctrl-C to stop forwarding.

  • source
  • parent