selfhostedworld.com logoselfhostedworld.com

Try describing what you need:

Best open-source alternatives to Tailscale

Self-hosted mesh VPNs and secure remote access instead of Tailscale.

Tailscale uses WireGuard to build private networks between devices and servers, adding single sign-on and access controls. Teams replace it to run their own coordination servers and remove dependencies on hosted control planes. Self-hosted, open-source networking tools provide comparable mesh and remote-access setups under your control.

6 alternatives listed

Best for your setup

  • Novice

    wg-easy27.1k
    • Single container
    • Ships a Compose file

    91/100 fitHow well this app matches homelab novices, 0 to 100

    See all
  • Expert

    netbird29.9k
    • Several SSO sign-in methods
    • REST or GraphQL API

    90/100 fitHow well this app matches homelab experts, 0 to 100

    See all
  • Hacker

    EasyTier14.0k
    • CLI or plugin support
    • Many ways to install

    81/100 fitHow well this app matches homelab hackers, 0 to 100

    See all
  1. 1wg-easy logo
    27.1k
    GNU Affero General Public License v3.0Open Source — No Paywall

    WireGuard Easy is a self-hosted web application for setting up and administering WireGuard on Linux hosts. It is aimed at people who want a simpler way to deploy a VPN server while still being able to manage clients through a browser-based interface. The project combines the WireGuard VPN service with a web UI that lets administrators create, edit, enable, disable, and inspect clients. It also surfaces operational details such as client connection status, traffic charts, QR codes, downloadable configuration files, and Prometheus metrics. The README emphasizes Docker-based deployment, with Docker Compose as the recommended path, plus support for docker run and Podman. Authentication-related capabilities include OIDC and 2FA, and the documentation is hosted on a separate project site.

    Offline CapableMulti-UserDockerDocker ComposeBinarySource

    Features:

    • WireGuard + web UI
    • client management
    • QR code display
    • client configuration download
    • connection statistics

    +5 more

    Auth:oidc-sso2fa
  2. 2netbird logo
    29.9k
    BSD 3-Clause "New" or "Revised" LicenseOpen Source — No Paywall

    NetBird is a self-hostable and cloud-hosted networking platform that creates encrypted WireGuard overlays for connecting machines without exposing ports or configuring complex firewall rules. It is aimed at organizations and homelab users who want centralized access control, peer discovery, and secure remote access across mixed infrastructure. The project combines an agent on each machine with management, signal, and relay services to establish peer-to-peer tunnels when possible and fall back to relayed connectivity when NAT traversal fails. It also includes admin UI management, access policies, DNS routing, device posture checks, SSH/RDP access in the browser, automation integrations, and identity-provider support for team-based administration.

    Cloud OptionalMulti-UserDockerSource

    Features:

    • Kernel WireGuard
    • peer-to-peer connections
    • connection relay fallback
    • routes to external networks
    • domain-based DNS routes

    +5 more

    Auth:oidc-ssosamlldapoauth2fa
  3. 3EasyTier logo
    14.0k
    GNU Lesser General Public License v3.0Open Source — No Paywall

    EasyTier is a decentralized virtual private network project designed to connect devices directly without relying on centralized coordination services. It targets users who need a secure, cross-platform mesh-style VPN for ad hoc connectivity, subnet sharing, and remote access across mixed environments such as desktop, mobile, and embedded systems. The project provides multiple ways to operate and manage networks, including a web console, command-line tools, and client applications. It supports NAT traversal, routing optimization, subnet proxying, and WireGuard integration, and it can be deployed with prebuilt binaries, package-based installation, Docker, or source builds. The README also highlights a self-hosted public shared-node model for discovery and relay when direct peer-to-peer connectivity is not available.

    Cloud OptionalOffline CapableDockerPackage ManagerBinarySource

    Features:

    • decentralized networking
    • cross-platform support
    • AES-GCM/WireGuard encryption
    • NAT traversal
    • subnet proxy

    +5 more

  4. Apache License 2.0Open Source — No Paywall

    OpenZiti is a zero-trust networking platform designed to hide services from unauthorized access while securing every connection with authenticated identity and end-to-end encryption. It is aimed at teams that need to connect users, services, devices, and workloads across networks without exposing open ports or relying on traditional VPNs. The project supports several deployment styles, including network-level access, host-based tunneling, and application-embedded SDK integration. That makes it suitable for both existing brownfield services and new greenfield applications, as well as environments spanning cloud, on-premises, Kubernetes, IoT, and hybrid infrastructure. Its controller provides identity management, policy enforcement, a REST API, and a web admin console, while edge routers carry encrypted traffic through the overlay network.

    Multi-UserDockerSourceBinary

    Features:

    • Zero-trust overlay networking
    • Dark services
    • Cryptographic identity for users, services, devices, and workloads
    • End-to-end encryption
    • Policy-driven access control

    +5 more

  5. Apache License 2.0Open Core — Some Features Paid

    Firezone is an open source platform for managing secure remote access across organizations. It is designed as a zero-trust alternative to traditional VPNs, using group-based policies to grant access to individual applications, subnets, or broader network resources. The README positions it as suitable for teams and organizations that need centralized, least-privileged access control with encrypted connectivity. The project is a monorepo containing the full product stack, including an admin portal and control plane, WireGuard-based gateways, a relay for hole punching, and cross-platform clients for desktop and mobile. It supports managed cloud usage as well as self-hosted experimentation, and it integrates with identity providers such as Google Workspace, Okta, Entra ID, and OIDC for user and group synchronization. The README also highlights audit logging, scalable gateway deployment, and a snappy admin UI for configuration.

    Cloud OptionalMulti-UserDockerSource

    Features:

    • zero-trust remote access
    • peer-to-peer encrypted tunnels
    • group-based access policies
    • application and subnet access control
    • automatic load balancing

    +5 more

    Auth:oidc-ssooauthlocal
  6. 6Pangolin logo
    23.1k
    GNU Affero General Public License v3.0Open Core — Some Features Paid

    Pangolin is an open-source remote access platform aimed at teams and organizations that need secure, zero-trust connectivity to internal services. It is positioned as a way to expose web apps and private resources without opening public ports, using identity-aware access controls and tunneled connectivity built on WireGuard. The project supports both browser-based access to web applications and client-based access to resources such as SSH, databases, RDP, and entire network ranges. It also includes site connectors for NAT traversal, routing and load balancing, health checking, automatic SSL certificate handling, and role-based access control. The README indicates options for cloud use, self-hosting, and an enterprise edition, with clients available for major desktop and mobile platforms.

    Cloud OptionalMulti-UserDockerSource

    Features:

    • site connectors
    • NAT traversal
    • browser-based reverse proxy access
    • client-based private resource access
    • automatic SSL certificates

    +5 more

    Auth:oidc-ssolocal

What to look for in a Tailscale alternative

Determine whether you need a full mesh between devices or access through a single gateway. Check client operating system support, single sign-on options, and access rules. Hosting the control server requires maintenance, backups, and a stable public address.

Other SaaS alternatives

  • 4 alternatives

    Self-hosted tunnels and reverse proxies instead of ngrok.

    OpenZiti, rathole, sish

    +1 more
  • 67 alternatives

    An all-in-one workspace for notes, docs, and databases.

    AFFiNE, Memos, AFFiNE Community Edition

    +64 more
  • 49 alternatives

    A cloud file sync and sharing service.

    Immich, Syncthing, Cloudreve

    +46 more
  • 36 alternatives

    A long-running personal note-taking and clipping app.

    Memos, Joplin, Logseq

    +33 more
  • 35 alternatives

    The ubiquitous team messaging and collaboration platform.

    Rocket.Chat, Zulip, The Lounge

    +32 more
  • 32 alternatives

    A cloud project and task management platform for teams.

    AppFlowy, Plane, Wekan

    +29 more
Browse all alternatives