Getting Started
Quick Start
# Pull the image
docker pull sudocarlos/tailrelay:latest
# Run the container
docker run -d --name tailrelay \
-v /path/to/data:/var/lib/tailscale \
-e TS_HOSTNAME=myserver \
-p 8021:8021 \
--net bridge \
sudocarlos/tailrelay:latest
# Access the Web UI and follow the Tailscale login link
open http://localhost:8021
Prerequisites
- A Tailscale account with an active Tailnet (tailscale.com)
- HTTPS certificates enabled in the Tailscale Admin console
- Docker or Podman installed
Tailscale Setup
- Log into the Tailscale Admin console and open DNS to enable MagicDNS.
- Tailnets created on or after October 20, 2022 have MagicDNS enabled by default.
- Review MagicDNS to understand how it works.
- Verify or set your Tailnet name.
- Scroll down and enable HTTPS under HTTPS Certificates.
Using a Custom Control Server (Headscale)
If you run a self-hosted Headscale instance instead
of Tailscale's coordination server, set its URL in the Control Server
field on the Tailscale page's connection status card before logging in. This
is applied as tailscale login --login-server=<url> (or
tailscale up --authkey=<key> --login-server=<url> for the auth-key flow)
and persists across container restarts.
Leave the field empty to use Tailscale's official control plane. Since a device is bound to whichever control server it first authenticated with, switching an already-connected device requires logging out first.
StartOS Deployment
Tailrelay is available as a StartOS package via sudocarlos/tailrelay-startos.
Sideloading:
- Download the latest
tailrelay.s9pkfrom the tailrelay-startos releases page, or clone the repo and runmaketo build it yourself. - In the StartOS web UI menu, navigate to System → Sideload Service.
- Drag and drop or select the
tailrelay.s9pkfile to install. - Once installed, navigate to Services → Tailrelay and click Start.
Next Steps
- Authentication — how the Web UI is secured.
- API Reference — the full HTTP/JSON API.
- Troubleshooting — common issues and fixes.