# slopscale > An open source, self-hosted implementation of the Tailscale control server, with a built-in admin console. ## Docs - [Welcome to slopscale](https://aislopware.github.io/slopscale): Slopscale is a fork of headscale, the self-hosted Tailscale control server, that runs one tailnet with an admin console, roles, approval and auditing. ## About - [Frequently Asked Questions](https://aislopware.github.io/slopscale/about/faq): Answers to common questions: supported deployments, the upgrade path, tailnet size, SQLite or PostgreSQL, and recovering from an invalid policy. - [Features](https://aislopware.github.io/slopscale/about/features): Which Tailscale features slopscale supports, what it adds on top such as the admin console and access rules, and what it does not do. - [Client and operating system support](https://aislopware.github.io/slopscale/about/clients): Slopscale supports the last 10 Tailscale client releases on Linux, the BSDs, Windows, Android, macOS, iOS and tvOS, some with extra setup. - [Getting help](https://aislopware.github.io/slopscale/about/help): Ask questions about running slopscale in GitHub discussions, and report bugs as GitHub issues on the aislopware/slopscale repository. - [Releases](https://aislopware.github.io/slopscale/about/releases): Where slopscale releases are published: binaries and Debian packages on GitHub releases, container images on GHCR, and an Atom feed to follow. - [Contributing](https://aislopware.github.io/slopscale/about/contributing): Slopscale takes a new feature only after a design discussion and with integration tests, and welcomes bug and documentation fixes without one. ## Setup - [Requirements](https://aislopware.github.io/slopscale/setup/requirements): What a slopscale server needs: a public address, HTTPS on port 443, the ports the DERP relay and metrics use, and the paths these docs assume. - [Upgrade an existing installation](https://aislopware.github.io/slopscale/setup/upgrade): Upgrade slopscale one minor version at a time: read the release notes, stop the server, back up the database and configuration, update, restart. - [Backup and restore](https://aislopware.github.io/slopscale/setup/backup): Back up the database with slopscale db backup while the server runs, verify and restore a backup, schedule nightly copies, and back up PostgreSQL. ### Installation - [Official releases](https://aislopware.github.io/slopscale/setup/install/official): Install slopscale from the signed apt repository on Debian and Ubuntu, or from a standalone Linux binary with your own user and systemd service. - [Running slopscale in a container](https://aislopware.github.io/slopscale/setup/install/container): Run slopscale from its container image with Docker or Compose: config and data volumes, ports, the health check, and the debug image with a shell. - [Build from source](https://aislopware.github.io/slopscale/setup/install/source): Build slopscale from source with Go, a C compiler for SQLite and Bun for the admin console, or through the Nix flake, with steps for OpenBSD. - [Development builds](https://aislopware.github.io/slopscale/setup/install/main): Development builds are container images built from every push to main and tagged with the commit, for testing only and never for production. ## Usage - [Getting started](https://aislopware.github.io/slopscale/usage/getting-started): First steps with the slopscale CLI: reach the server's socket, create and list users, and register a node through the browser or a pre-auth key. ### Connect a node - [Connecting an Android client](https://aislopware.github.io/slopscale/usage/connect/android): Point the Tailscale Android app at your slopscale server with Use an alternate server, then sign in through the browser or with a pre-auth key. - [Connecting an Apple client](https://aislopware.github.io/slopscale/usage/connect/apple): Connect the Tailscale clients for iOS, macOS and tvOS to your slopscale server by setting a custom coordination server before signing in. - [Connecting a Windows client](https://aislopware.github.io/slopscale/usage/connect/windows): Connect the Tailscale Windows client with tailscale login, keep it running unattended, and reset a registration that keeps expiring. ## Reference - [Configuration](https://aislopware.github.io/slopscale/ref/configuration): Where slopscale finds config.yaml, how SLOPSCALE_ environment variables override its keys, and which settings live only in the file, not the database. - [Registration methods](https://aislopware.github.io/slopscale/ref/registration): Register personal and tagged nodes through web authentication or pre-auth keys, how tagged ownership works, and when a node is ephemeral. - [OpenID Connect](https://aislopware.github.io/slopscale/ref/oidc): Sign users in through an OpenID Connect provider: basic setup and PKCE, filters by domain, email or group, group sync, claims, and per-provider notes. - [Routes](https://aislopware.github.io/slopscale/ref/routes): Set up subnet routers and exit nodes, approve routes by hand or with auto approvers, mark global exit nodes in failover order, and route per region. - [Running the service via TLS (optional)](https://aislopware.github.io/slopscale/ref/tls): Serve slopscale over TLS with your own certificate or one from Let's Encrypt, pick the HTTP-01 or TLS-ALPN-01 challenge, and check that renewal works. - [Policy](https://aislopware.github.io/slopscale/ref/policy): Write a Tailscale-style policy file with grants or ACLs: allow-all and deny-all starting points, supported autogroups, node attributes and IP pools. - [DNS](https://aislopware.github.io/slopscale/ref/dns): Change nameservers, split DNS, search domains and extra records at runtime, keep resolvers while an exit node is in use, and split DNS per group. - [DERP](https://aislopware.github.io/slopscale/ref/derp): Run the embedded DERP relay, change relays at runtime, trim or replace Tailscale's DERP map, verify clients, and read relay latency per region. - [API](https://aislopware.github.io/slopscale/ref/api): Create and scope API keys, call the REST API, use the Tailscale-compatible API with OAuth clients, Terraform and Kubernetes, and run the CLI remotely. - [Admin console](https://aislopware.github.io/slopscale/ref/console): Sign in to the built-in admin console through your identity provider, invite users, end console sessions, find each page, and build it from source. - [Branding](https://aislopware.github.io/slopscale/ref/branding): Put your own name, description, light and dark logos and social card on the console, the server's pages and its mail, set in the configuration file. - [Audit log](https://aislopware.github.io/slopscale/ref/audit): Read, filter and export the append-only audit log of API changes and sign-ins from the CLI, the API or the console, and set how long events are kept. - [User roles](https://aislopware.github.io/slopscale/ref/roles): What the owner, admin, network admin, IT admin, auditor and member roles may do in the API and console, how ownership moves, and roles in the policy. - [Device and user approval](https://aislopware.github.io/slopscale/ref/approval): Make new machines and users wait for an administrator with the device and user approval switches, cap key expiry, and approve from the CLI or API. - [Device trust](https://aislopware.github.io/slopscale/ref/device-trust): Suspend a machine without deleting it, and gate traffic on device posture, hardware attestation and MDM or EDR integrations through postures. - [Device management](https://aislopware.github.io/slopscale/ref/device-management): Update a machine's Tailscale client, read its health warnings and diagnostic dumps, and edit its preferences over the control connection it holds. - [Tailnet lock](https://aislopware.github.io/slopscale/ref/tailnet-lock): Turn on tailnet lock from a signing node so machines verify each other's keys, sign new machines, rotate keys, and switch the lock off with a secret. - [Temporary access](https://aislopware.github.io/slopscale/ref/temporary-access): Grant access that ends on its own: expiring access rules and group memberships, requestable groups decided by approvers, and revoking a grant early. - [Node sharing](https://aislopware.github.io/slopscale/ref/sharing): Share one of your nodes with another user's devices without editing the policy, how autogroup:shared admits them, and sharing from the CLI or API. - [Groups and access rules](https://aislopware.github.io/slopscale/ref/access-control): Control access without a policy file: put machines and users into groups, write allow-only access rules between them, and check the access graph. - [Networks](https://aislopware.github.io/slopscale/ref/networks): Hand subnets and exit nodes to chosen groups with networks, narrow them by protocol and port, and let peers relay traffic through a machine of your own. - [Services](https://aislopware.github.io/slopscale/ref/services): Give a service its own addresses and MagicDNS name, served by one or more tagged machines: announce, approve and advertise hosts, then open it in the policy. - [Apps](https://aislopware.github.io/slopscale/ref/apps): Route traffic for chosen domains through tagged app connector nodes: define apps, how learned and static routes and split DNS work, and manage them. - [Webhooks](https://aislopware.github.io/slopscale/ref/webhooks): Post signed Tailscale-format events to your own receiver, or notify Slack, Teams, Discord, Telegram, ntfy or email when machines, users or policy change. - [Log streaming](https://aislopware.github.io/slopscale/ref/log-streaming): Ship the audit log to Splunk, Elastic, Datadog, Axiom, Loki or any HTTP collector as it is written, and how batches are retried or dropped. - [Traffic monitor](https://aislopware.github.io/slopscale/ref/traffic): Count what each machine sends through exit nodes, subnet routers and app connectors with the slopscale-flowd agent, name destinations, and log DNS. - [SSH session recording](https://aislopware.github.io/slopscale/ref/ssh-recording): Record Tailscale SSH sessions as asciinema files with the embedded recorder or tsrecorder, enforce recording per rule, and list or download recordings. - [HTTPS certificates](https://aislopware.github.io/slopscale/ref/https-certificates): Let machines get Let's Encrypt certificates for their MagicDNS names, with slopscale publishing DNS-01 challenges via Cloudflare, RFC 2136 or a command. - [Funnel](https://aislopware.github.io/slopscale/ref/funnel): Expose a machine's service to the internet with tailscale funnel through an ingress node you run, with the attribute, certificates and DNS it needs. - [Identity tokens](https://aislopware.github.io/slopscale/ref/identity-tokens): Issue signed identity tokens with tailscale id-token, so machines log in to AWS, Google Cloud, Vault or other OpenID verifiers without a stored secret. - [Tags](https://aislopware.github.io/slopscale/ref/tags): Apply tags when a node registers, change a node's tags from the CLI, and convert a node between personal ownership and tags in either direction. - [Debugging and troubleshooting](https://aislopware.github.io/slopscale/ref/debug): Troubleshoot a tailnet with the Tailscale client's debug commands, slopscale's application and database logging, and the private metrics endpoint. ### Integration - [Running Slopscale behind a reverse proxy](https://aislopware.github.io/slopscale/ref/integration/reverse-proxy): Run slopscale behind a reverse proxy that passes the control protocol's WebSocket upgrade, with trusted proxies and Apache, Caddy and Nginx examples. ## Agent skills - [slopscale](https://aislopware.github.io/slopscale/.well-known/agent-skills/slopscale/SKILL.md): Read the slopscale docs instead of answering from memory. An open source, self-hosted implementation of the Tailscale control server, with a built-in admin console. Use when a task involves slopscale: how it works, how to set it up or configure it, or its API. ## Agent resources - [llms-full.txt](https://aislopware.github.io/slopscale/llms-full.txt): The full Markdown of every page in one file. - [Page Markdown](https://aislopware.github.io/slopscale/index.md): Append `.md` to any page URL to fetch that page as raw Markdown. - [JSON API](https://aislopware.github.io/slopscale/api/docs/pages.json): Page index of the JSON docs API; each entry links the page's JSON and Markdown forms. Described by the OpenAPI document at https://aislopware.github.io/slopscale/openapi.json. - [Agent skills](https://aislopware.github.io/slopscale/.well-known/agent-skills/index.json): Agent Skills discovery index of the skills this site publishes. - [API catalog](https://aislopware.github.io/slopscale/.well-known/api-catalog): RFC 9727 linkset of the APIs documented here. - [AI catalog](https://aislopware.github.io/slopscale/.well-known/ai-catalog.json): ARD manifest of the agent-facing resources on this site (MCP server, skills, APIs). - [agent-readability.json](https://aislopware.github.io/slopscale/agent-readability.json): Manifest of every agent-facing artifact on this site. - [Sitemap](https://aislopware.github.io/slopscale/sitemap.xml): Every indexable page URL with its last-modified date.