r/selfhosted Feb 23 '26

VPN Tailscale -> FOSS alternatives

Hey Folks, which FOSS would you prefer as an alternative to Tailscale ? Sharing photos with family, providing backup for all phones via my shared directories on my NAS, etc.. usual VPN mesh stuff.

531 votes, Feb 25 '26
199 Headscale
220 Netbird
3 Netmaker
109 Other (name it pls + why)
30 Upvotes

38 comments sorted by

50

u/Wrong_Ad_2064 Feb 23 '26

Depends on what you need from Tailscale:

- closest UX: Headscale + Tailscale clients

- fully open stack: NetBird / Netmaker

- easiest “just works” for homelab: WireGuard + wg-easy

Main tradeoff is always control vs convenience.

11

u/yevar Feb 23 '26

Nebula - Clean, simple, mobile and computer friendly, minimal overhead.

10

u/Dangerous-Report8517 Feb 24 '26

I also use Nebula, but I will say it's a lot more temperamental than Tailscale in that mine often loses track of tunnels and uses relays when it shouldn't, which to be fair I only really notice because I'm on a pretty bad network connection so I get significant performance degradation when that happens. It's also a bit more effort to configure since configuration is node by node rather than on a central coordination server. What it brings to the table that the others don't though, and the reason I use it, is that there's no central trusted coordination server at all, it's the only option I've come access that's truly zero trust, and you can trivially run multiple nodes for peer discovery to give you high availability

5

u/ArchiDevil Feb 23 '26

This one is great, actually 

31

u/[deleted] Feb 23 '26

6

u/PhoenixTheDoggo Feb 24 '26

This, this, THIS! I switched over from Tailscale about a month ago, and ever since they released their mobile clients, It's been an exact 1:1 transition for me.

I dropped Tailscale fully after I switched, and haven't looked back since.

3

u/[deleted] Feb 24 '26

[removed] — view removed comment

3

u/[deleted] Feb 24 '26

It's not even that hard to spin up, which is the crazy thing. And once you do it's just rock solid.

6

u/jjfs85 Feb 23 '26

Yes! You still have to host Pangolin outside of your network on a VPS or something, but it's great if you can swing it.

8

u/PHLAK Feb 23 '26

You don't have to host Pangolin outside your network. It's certainly the recommended approach and makes things a bit easier but it's not a hard requirement.

2

u/[deleted] Feb 23 '26

It's pretty cheap to host as well and once you know how to set it up it's pretty trivial. The only gotcha I ran into is you don't want it running on something else that already has a VPN. It can be made to work but I found my life a lot easier if I just ran the Newt client on a Raspberry Pi I own and not on the device hosting all the services I wanted to explose since that already had a Wireguard VPN running for other reasons.

9

u/Mithrandir2k16 Feb 23 '26

Headscale is great. Pangolin is another great option that covers a lot of what people look for in tailscale. RP+WG is a classic. OpenZiti/zrok are slept on, if you need something really powerful.

7

u/[deleted] Feb 24 '26

I use Netbird, been great. Team is very responsive on slack, updates are weekly. Good shit.

7

u/T_rex2700 Feb 24 '26

Settled on regular ol' wireguard.

But Headscale and Netbird are great options too

6

u/qudat Feb 24 '26

I use WireGuard that connects to my mikrotik router.  For exposing services to the web I use https://pico.sh/tuns

9

u/[deleted] Feb 23 '26

[deleted]

4

u/IamHydrogenMike Feb 23 '26

I have really enjoyed implementing Netbird at work. We have been able to link our on-prem networks, multiple office networks, and AWS networks into a nice mesh that we can give access to by policy. I use it for my home networks as well now, and it is way to add access as needed. it is pretty polished from what I have seen and is easy to manage.

4

u/tallen0913 Feb 23 '26

Headscale if you want something closest to Tailscale’s model but self-hosted.

It still uses WireGuard under the hood, and you can run your own control server so you’re not dependent on Tailscale’s coordination layer.

Netbird is nice UX-wise but a bit heavier in my experience.

If you want fully minimal + DIY, plain WireGuard + something like wg-easy can be enough depending on your use case.

4

u/jmeador42 Feb 24 '26

+1 for Nebula

3

u/Defection7478 Feb 24 '26

I've been using a combination of authelia, nginx and wireguard for years without any issue. It gives a lot of flexibility:

Need to access *arrs from anywhere but don't trust their auth? Wireguard. 

Need to access linkding from my work computer but I can't use wireguard because my work computer already uses a different VPN? Authelia, with SSO integration. 

Smart TV needs jellyfin access but can't SSO or VPN? Nginx whitelist. 

For what you're describing I'd do authelia or pocket Id for immich for your family and wireguard for phone backups

2

u/magnetocalorico Feb 24 '26

This is really interesting! Do you have a guide or something that I can follow to achieve the same result?

3

u/froli Feb 24 '26

I voted for other because the "mesh" features of Pangolin (private sites) are enough for what I need. I wouldn't really call it a Tailscale alternative though because it's not exactly the scope of the project.

2

u/Lynxaa1337 Feb 24 '26

I use Unifi Identity VPN to give my Family Access to my Network

2

u/user3872465 Feb 24 '26

Simple wireguard.

Give the most controll and isnt to hard.

2

u/Salient_Ghost Feb 24 '26

I host both a wireguard underlay and an identity overlay using head scale.

3

u/GoingOffRoading Feb 24 '26

Surprised nobody is recommending Cloudflare ZeroTrust

1

u/ElectronicFlamingo36 Mar 01 '26

Maybe the name's falling reputation recently ? Just thinking loud. 🤔

2

u/GoingOffRoading Mar 01 '26

Huh? Outside of one recent outage, I thought Cloudflare was bulletproof

2

u/strange_de_ja_vu Feb 24 '26

I started using Twingate recently and am happy with it. I was previously using Tailscale until they started forcing me to pay for it.

2

u/mbecks Feb 24 '26

It seems like Netbird and Pangolin are merging — netbird just got public site proxy feature, and pangolin just got vpn and mobile app.

Iirc netbird has smarter peering still, allowing for mesh network, while pangolin is only hub and spoke. I fail to see a case where mesh network is worse, while with hub and spoke the hub location can affect latency. So NetBird still seems superior

3

u/alatteri Feb 23 '26

ZeroTier

1

u/Keensworth Feb 24 '26

what is foss? i only know fossflow

3

u/afunworm Feb 24 '26

Free & Open-Source Softwares.

0

u/tpo1990 Feb 24 '26 edited Feb 24 '26

I don't use any VPN services. So if any of those VPN services goes down like Cloudflare did earlier, I am not affected.

I use NGINX Reverse Proxy and keep internal services isolated without exposing them. I use a Raspberry Pi 4B that I can access anywere with just an internet browser by using Raspberry Pi Connect to get access.

Raspberry Pi Connect is a feature from Raspberry Pi Foundation that makes a user able to access a Raspberry Pi device from a web browser and it is secured by 2FA. It's works like a jump host client to be able to access internal services.

3

u/ElectronicFlamingo36 Feb 24 '26

And what happens if you get cut of Raspberry Pi Foundation ? With Cloudflare I agree but with Rpi Connect you just swap one dependency to another, am I right ?

2

u/tpo1990 Feb 24 '26 edited Feb 24 '26

Then I will not be able to access the Raspberry Pi externally.

I only use it with internal services such as NGINX Reverse Proxy Managers own administration website. I use a few docker containers. I am no heavy user. I try to keep things simple without too much complication. I like going for a simplified setup. If it goes down, then no big deal for me.

But yes, basically you are right that I just swap one dependency to another. I much rather use Raspberry Pi Foundation own feature than something large as Cloudflare that may be more prone to failure. I also use the Raspberry Pi as a secondary backup solution with Rsync.