While this is great, especially for smaller self-hosters, as a setup gets more and more dependent on Tailscale, one should think about self-hosting Headscale, and therefore not being over-reliant on services not offered by it. I'm in that boat and I haven't done the Headscale migration yet.
post
- you can create memorable links instead of memorizing port numbers:
jellyfin.foo-bar.ts.net
BTW, I'm doing something similar with standard DNS records that point to an internal Tailscale IP. I can go to https://immich.mydomain.com/ which only works if Tailscale is active. Let's Encrypt works too. Obviously the setup isn't automatic but it's automateable for more adept self-hosters.
Immich needs this, right? I remember it not working on a tailscale funnel path.
I haven't tried funnel but it works using an internal Talscale IP/host and port. E.g. http://the-immich-host:1234/ if the-immich-host is a Tailscale machine.
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
| Fewer Letters | More Letters |
|---|---|
| DNS | Domain Name Service/System |
| HTTP | Hypertext Transfer Protocol, the Web |
| HTTPS | HTTP over SSL |
| IP | Internet Protocol |
| SSL | Secure Sockets Layer, for transparent encryption |
| SSO | Single Sign-On |
| VPN | Virtual Private Network |
6 acronyms in this thread; the most compressed thread commented on today has 10 acronyms.
[Thread #106 for this comm, first seen 20th Feb 2026, 18:41] [FAQ] [Full list] [Contact] [Source code]
Some time ago, I had a sales call with tailscale for a business as a consultant.
If enterprise features are needes, theyre 2x more costly per user than a few other sase providers.
While I love wg and been using that for a long time, I have hard time believing they'll get clients with posted prices. There was some wiggle room, but still.
Personally I'll use tailscale at home as a backup connection as long as its good.
all 30 comments