Skip to content

Headscale Headscale

Description / nameInput element
Container Registry
Container Configuration Root Path
Timezone
User ID
Group ID
Headscale Host Port
Headscale /config Path

Build Status Last Commit

An open source, self-hosted implementation of the Tailscale control server.

Port 8080
Registry ghcr.io/daemonless/headscale
Daemonless daemonless/headscale
Source juanfont/headscale
Website headscale.net

Version Tags

Tag Description Best For
latest Built from the official upstream FreeBSD release binary. Most users — recommended.
pkg Installed from the FreeBSD quarterly package repository. Alternative build.
pkg-latest Installed from the FreeBSD latest package repository. Alternative build.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  headscale:
    image: "ghcr.io/daemonless/headscale:latest"
    container_name: headscale
    environment:
      - PUID=1000  # User ID for the application process
      - PGID=1000  # Group ID for the application process
      - TZ=UTC  # Timezone for the container
    volumes:
      - "/path/to/containers/headscale:/config"
    ports:
      - "8080:8080"
      - "3478:3478"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

1
2
3
4
5
6
7
8
podman run -d --name headscale \
  -p 8080:8080 \
  -p 3478:3478 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -v /path/to/containers/headscale:/config \
  ghcr.io/daemonless/headscale:latest

Save as run.sh, then run sh run.sh.

- name: Deploy headscale
  containers.podman.podman_container:
    name: headscale
    image: "ghcr.io/daemonless/headscale:latest"
    state: started
    restart_policy: always
    env:
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
    ports:
      - "8080:8080"
      - "3478:3478"
    volumes:
      - "/path/to/containers/headscale:/config"

Save as headscale-deploy.yaml, then run ansible-playbook headscale-deploy.yaml.

1
2
3
4
5
6
# .env

DIRECTOR_PROJECT=headscale
PUID=1000
PGID=1000
TZ=UTC
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  headscale:
    name: headscale
    options:
      - container: 'boot args:--pull'
      - expose: '8080:8080 proto:tcp'
      - expose: '3478:3478 proto:udp'
    oci:
      user: root
      environment:
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
    volumes:
      - HEADSCALE_CONFIG_PATH: /config
volumes:
  HEADSCALE_CONFIG_PATH:
    device: '/path/to/containers/headscale'
1
2
3
4
5
6
# Makejail

ARG tag=latest

OPTION overwrite=force
OPTION from=ghcr.io/daemonless/headscale:${tag}

Save the files above, then run appjail-director up.

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="8080:8080 proto:tcp" \
  -o expose="3478:3478 proto:udp" \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -o fstab="/path/to/containers/headscale /config <pseudofs>" \
  ghcr.io/daemonless/headscale:latest headscale

Save as run.sh, then run sh run.sh.

Experimental

Bastille's OCI support is experimental. It requires buildah, shares the host network stack (inherit), and persists image-declared volumes under --data-path.

1
2
3
4
5
6
7
8
9
services:
  headscale:
    image: "ghcr.io/daemonless/headscale:latest"
    container_name: headscale
    network_mode: host  # jail shares host networking
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC

Save as podman-compose.yml, then run bastille up.

1
2
3
4
5
6
bastille create -O \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --data-path /path/to/containers/headscale \
  headscale ghcr.io/daemonless/headscale:latest inherit

Access at: http://localhost:8080

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
PUID 1000 User ID for the application process
PGID 1000 Group ID for the application process
TZ UTC Timezone for the container

Volumes

Path Description
/config Configuration directory

Ports

Port Protocol Description
8080 TCP Control server (HTTP)
3478 UDP Embedded DERP STUN (UDP)

Implementation Details

  • Architectures: amd64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).

Need help? Join our Discord community.