Self-hosting
Connect to your homelab remotely with Tailscale
Install Tailscale on a Raspberry Pi and securely access your homelab from another device without port forwarding.
Prerequisites
You need:
- a Raspberry Pi running Raspberry Pi OS or another Debian-based Linux distribution
- terminal access to the Raspberry Pi
Check that the Raspberry Pi can access the Internet:
curl https://tailscale.comYou should receive an HTML response from the Tailscale website.
Install Tailscale
Connect to your Raspberry Pi and install Tailscale using the official installation script:
curl -fsSL https://tailscale.com/install.sh | shAfter installation, confirm that Tailscale is available:
tailscale versionConnect the Raspberry Pi
Connect the Raspberry Pi to your Tailscale network:
sudo tailscale upTailscale will print an authentication URL like this:
To authenticate, visit:
https://login.tailscale.com/a/...Complete the authentication and return to the Raspberry Pi and check its status:
tailscale statusYour Raspberry Pi should now appear as a device in your tailnet.
Find the Tailscale address
Every device connected to Tailscale receives its own Tailscale IP address.
Display the IPv4 address of the Raspberry Pi:
tailscale ip -4The result will look similar to:
100.84.23.17You can also see connected devices with:
tailscale statusConnect another device
Install Tailscale on the computer you want to use to access the Raspberry Pi.
Download the appropriate client from:
https://tailscale.com/download
Sign in using the same Tailscale account. Later you can add other accounts to the same tailnet.
After connecting, check that the Raspberry Pi appears:
tailscale statusBoth devices should now be members of the same Tailscale network.
Test the connection
From your laptop or other client device, test connectivity with:
tailscale ping raspberrypiYou can also use the Raspberry Pi’s Tailscale IP:
tailscale ping 100.84.23.17Replace the example address with the value returned earlier by:
tailscale ip -4A successful response looks similar to:
pong from raspberrypi (100.84.23.17) via 192.168.1.68:41641 in 5msConnect with SSH
If SSH is already enabled on the Raspberry Pi, you can use it through the Tailscale network.
From your other device, run:
Replace pi with the username configured on your Raspberry Pi and replace the IP address with your Raspberry Pi’s Tailscale address.
If MagicDNS is available in your tailnet, you can usually use the device name instead:
ssh pi@raspberrypiSSH authentication still works normally. For example, if your Raspberry Pi uses SSH keys, your existing SSH key will still be required.
Access a homelab service
Tailscale is not limited to SSH. You can also access services running on the Raspberry Pi.
For example, start a temporary web server:
mkdir -p ~/tailscale-test
cd ~/tailscale-test
echo "Hello from my homelab" > index.html
python3 -m http.server 8080Leave the terminal open.
From another device connected to the same tailnet, open:
http://100.84.23.17:8080Replace the address with the Raspberry Pi’s Tailscale IP.
You should see:
Hello from my homelabYou can also test it with curl:
curl http://100.84.23.17:8080At this point, you can access services in your homelab even when you are outside your local network. As long as both devices are connected to Tailscale, you can reach a service using the Tailscale IP of the machine running it and the appropriate port.
For example:
http://100.84.23.17:8080This works, but remembering IP addresses and port numbers becomes inconvenient as you add more services. A common next step is to use a reverse proxy such as Caddy. Caddy can route easy-to-remember addresses to the correct service, so instead of using an address like:
http://100.84.23.17:8080you can later use addresses such as:
https://service_name.your_domainFor example:
https://wiki.your_domain
https://cloud.your_domain
https://admin.your_domainTailscale provides the private connection to your homelab, while Caddy can provide convenient URLs and route requests to the correct internal services.
A basic Tailscale homelab only needs Tailscale installed on the server and client devices. More advanced features such as subnet routers and exit nodes can be added later when you need access to devices that cannot run Tailscale themselves.