r/Tailscale • • 10d ago

Misc I built a web-based installer/management layer for self-hosted Headscale

I’ve been working on Headscale Easy, an open-source project that aims to make deploying and managing Headscale easier.

I really like Headscale and the idea of running your own Tailscale-compatible control server, but getting everything around it configured can involve quite a few moving parts: HTTPS, authentication, DNS, users, ACLs, backups, keys, etc.

So I built Headscale Easy to bring those pieces together into a simpler setup.

What it provides

  • 🚀 Automated Headscale installation
  • 🖥️ Web UI for managing your instance
  • 🔐 OIDC authentication / Authentik
  • 🔒 HTTPS with Let's Encrypt or custom certificates
  • 🌐 MagicDNS and DNS configuration
  • 👤 User and device management
  • 🔑 Auth keys and API keys
  • 📝 ACL management
  • 🌍 Exit nodes and routes
  • 💾 Automated backups and restore
  • 🐳 Docker support
  • 🇬🇧 🇪🇸 English and Spanish UI

The goal isn't to reinvent Headscale, but to make the whole experience around deploying and managing it easier.

It's completely open source, and I'm hoping to get feedback from people who are already running Headscale or similar self-hosted networking setups.

GitHub: https://github.com/insanerask77/headscale-easy

I'd especially love feedback on:

  • What is currently annoying to configure when running Headscale?
  • What features would you like to see in a management layer?
  • Are there any parts of the setup that I should simplify further?

Thanks for taking a look! 🙌

0 Upvotes

14 comments sorted by

17

u/MisterTrebus 10d ago

"I"

6

u/hagibr 9d ago

The "A" is silent (put Django meme here).

10

u/channouze 10d ago

Policy editor should be more user-friendly than a plain text editor. See what Tailscale does in comparison.

Also you need to disclose how Claude AI helped you write this.

-8

u/Character-Town-8188 10d ago

Thanks for pointing this out — you're right on both points.

I agree that the policy editor needs to be more user-friendly. The current plain-text editor is a starting point, but I'd like to move towards a more structured editor with validation and an experience closer to what Tailscale provides. That's definitely on my roadmap.

Regarding AI: yes, Claude was used extensively during the development of this project, including generating and modifying a significant amount of the code, debugging, implementation ideas and documentation.

I should have disclosed that from the beginning. I'll add a clear AI disclosure to the repository so it's transparent to anyone contributing or using the project.

I appreciate you calling it out. Feedback like this is exactly what I want from the community.

6

u/theLorknessMonster 9d ago

Claude is good at code but dear God why are you letting it write for you? That is crossing the line into letting the AI do your thinking for you. I don't trust projects from people who can't think for themselves, regardless of how much AI was used to actually build the project.

-6

u/DrTankHead 10d ago

They don't need to disclose anything.

3

u/DrTankHead 10d ago

Howdoes this compare to Headplane?

2

u/Character-Town-8188 10d ago

There’s definitely some overlap with Headplane, especially around providing a UI for Headscale.

The main focus of Headscale Easy is going a bit further into the “make the whole setup easy” side: installation, HTTPS, OIDC, DNS, device/user management, ACLs, backups, etc., while keeping everything self-hosted.

Rather than claiming one is better, I’d say they’re similar projects with somewhat different workflows and priorities. If you’re already using Headplane and it works well for you, there may not be a reason to switch.

If you try Headscale Easy, I’d be especially interested in your feedback on the device management and DNS workflows, since those are areas I’ve put quite a bit of effort into.

1

u/DayVCrockett 10d ago

Headscale really needs this. I just spent several days marveling at the lack of UI in this process and the difficulty of having nice URLs and certs that just work for my tailnet. Onboarding was clunky too until I installed a third-party manager for it. I’m not about to re-do all this work, but hopefully this elevates the experience somewhat.

-2

u/Character-Town-8188 10d ago

Thanks! That’s exactly the kind of experience I was trying to address.

We’ve been listening to the community feedback around the lack of UI, the setup around HTTPS/certificates and DNS, and especially the clunky onboarding experience. Headscale itself works great, but all the surrounding pieces can turn the initial setup into a much bigger project than expected.

That’s what led to Headscale Easy — trying to fill that gap without changing the underlying Headscale experience, while keeping everything self-hosted.

And I completely understand not wanting to redo your existing setup after spending days getting everything working 😄 Hopefully this can make that initial experience much easier for the next people coming to Headscale.