Menu
Tutorial navigation
On this page

Self-hosting

Connect to your homelab remotely with Tailscale

Install Tailscale on a Raspberry Pi and securely access your homelab from another device without port forwarding.

beginnerPublished Updated
  • tailscale
  • raspberry-pi
  • homelab
  • networking

Prerequisites

You need:

  • a Raspberry Pi running Raspberry Pi OS or another Debian-based Linux distribution
  • terminal access to the Raspberry Pi

Check that the Raspberry Pi can access the Internet:

bash
curl https://tailscale.com

You should receive an HTML response from the Tailscale website.

Install Tailscale

Connect to your Raspberry Pi and install Tailscale using the official installation script:

bash
curl -fsSL https://tailscale.com/install.sh | sh

After installation, confirm that Tailscale is available:

bash
tailscale version

Connect the Raspberry Pi

Connect the Raspberry Pi to your Tailscale network:

bash
sudo tailscale up

Tailscale will print an authentication URL like this:

text
To authenticate, visit:

    https://login.tailscale.com/a/...

Complete the authentication and return to the Raspberry Pi and check its status:

bash
tailscale status

Your Raspberry Pi should now appear as a device in your tailnet.

Find the Tailscale address

Every device connected to Tailscale receives its own Tailscale IP address.

Display the IPv4 address of the Raspberry Pi:

bash
tailscale ip -4

The result will look similar to:

text
100.84.23.17

You can also see connected devices with:

bash
tailscale status

Connect another device

Install Tailscale on the computer you want to use to access the Raspberry Pi.

Download the appropriate client from:

https://tailscale.com/download

Sign in using the same Tailscale account. Later you can add other accounts to the same tailnet.

After connecting, check that the Raspberry Pi appears:

bash
tailscale status

Both devices should now be members of the same Tailscale network.

Test the connection

From your laptop or other client device, test connectivity with:

bash
tailscale ping raspberrypi

You can also use the Raspberry Pi’s Tailscale IP:

bash
tailscale ping 100.84.23.17

Replace the example address with the value returned earlier by:

bash
tailscale ip -4

A successful response looks similar to:

text
pong from raspberrypi (100.84.23.17) via 192.168.1.68:41641 in 5ms

Connect with SSH

If SSH is already enabled on the Raspberry Pi, you can use it through the Tailscale network.

From your other device, run:

bash
ssh [email protected]

Replace pi with the username configured on your Raspberry Pi and replace the IP address with your Raspberry Pi’s Tailscale address.

If MagicDNS is available in your tailnet, you can usually use the device name instead:

bash
ssh pi@raspberrypi

SSH authentication still works normally. For example, if your Raspberry Pi uses SSH keys, your existing SSH key will still be required.

Access a homelab service

Tailscale is not limited to SSH. You can also access services running on the Raspberry Pi.

For example, start a temporary web server:

bash
mkdir -p ~/tailscale-test
cd ~/tailscale-test
echo "Hello from my homelab" > index.html
python3 -m http.server 8080

Leave the terminal open.

From another device connected to the same tailnet, open:

text
http://100.84.23.17:8080

Replace the address with the Raspberry Pi’s Tailscale IP.

You should see:

text
Hello from my homelab

You can also test it with curl:

bash
curl http://100.84.23.17:8080

At this point, you can access services in your homelab even when you are outside your local network. As long as both devices are connected to Tailscale, you can reach a service using the Tailscale IP of the machine running it and the appropriate port.

For example:

text
http://100.84.23.17:8080

This works, but remembering IP addresses and port numbers becomes inconvenient as you add more services. A common next step is to use a reverse proxy such as Caddy. Caddy can route easy-to-remember addresses to the correct service, so instead of using an address like:

text
http://100.84.23.17:8080

you can later use addresses such as:

text
https://service_name.your_domain

For example:

text
https://wiki.your_domain
https://cloud.your_domain
https://admin.your_domain

Tailscale provides the private connection to your homelab, while Caddy can provide convenient URLs and route requests to the correct internal services.

A basic Tailscale homelab only needs Tailscale installed on the server and client devices. More advanced features such as subnet routers and exit nodes can be added later when you need access to devices that cannot run Tailscale themselves.