A fork of tailscale/tailscale-rs.
tailscale-rs is a work-in-progress Tailscale library written in Rust, with language bindings to
C, Elixir, and Python.
Note
This project is not associated with Tailscale Inc. — it is an independent, unofficial fork. See Legal.
Caution
This software is unstable and insecure.
I welcome enthusiasm and interest, but please do not build production software using these libraries or rely on it for data privacy until I've had a chance to batten down some hatches and complete a third-party audit.
See Caveats for more details.
- TCP and UDP sockets on the tailnet from an in-process WireGuard data plane.
- Direct peer-to-peer connections through NAT traversal (STUN, Disco,
CallMeMaybe), falling back to DERP relays. - MagicDNS and split DNS, fail-closed by default.
- Using subnet routers and exit nodes (opt-in), with the exit node changeable at runtime.
- Tailscale Serve handlers:
Proxy,Text,TcpForward,PathandRedirect. - Tailnet Lock peer signature enforcement (partial, see SECURITY.md).
- An optional Go-style
tsnet::Serverfacade. - C, Elixir and Python bindings. Talks to the Go client,
tsnetandlibtailscale.
Inside a binary crate, with Rust 1.94.1 or newer:
cargo add geiserx_tailscale --rename tailscale
TS_RS_EXPERIMENT=this_is_unstable_software cargo runThe crate is published as geiserx_tailscale and imported as tailscale, and every program linked against it needs TS_RS_EXPERIMENT set as above. A UDP client sample and the tsnet facade are in Getting started, and more in examples/.
- Getting started: dependency setup, a code sample, the
tsnetfacade and its Go mapping - How it works: control plane, WireGuard data plane and DERP
- Status: what is implemented, coming soon and unsupported
- Caveats, versioning and platform support, including MSRV and edition
- Language bindings: C, Elixir, Python
- ARCHITECTURE.md, CONTRIBUTING.md, SECURITY.md, CHANGELOG.md
- Design notes: tsnet facade, tsnet parity, parity roadmap, cryptography, releasing
This project is not associated with Tailscale Inc. It is an independent, unofficial fork. "Tailscale" is a trademark of Tailscale Inc.; it is used here only to describe interoperability and the upstream project this is forked from.
WireGuard is a registered trademark of Jason A. Donenfeld.