【文章标题】:Tailcat: Tailscale Without Tailscale, by Tailscale
【文章标题】:Tailcat:没有Tailscale的Tailscale,来自Tailscale团队

【文章正文】:
Today we’re releasing tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane (WireGuard® + NAT traversal + DERP) without the Tailscale control plane, written by the people who made Tailscale. It’s Tailscale without Tailscale, by Tailscale.
今天我们发布tailcat——一个由Tailscale原班人马打造的组件重组方案,让你能在脱离Tailscale控制平面的情况下,使用开源的Tailscale数据平面(WireGuard® + NAT穿透 + DERP)。这就是来自Tailscale团队的”没有Tailscale的Tailscale”。

Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.
具体来说,tailcat既是一个开源的Go语言包,也是一个使用该包的CLI工具。它能让你运行服务端监听器与客户端,实现双向字节流传输。

That is, it’s like netcat but flowing over Tailscale’s magicsock (WireGuard encryption + NAT traversal + DERP rendezvous/fallback relay).
本质上,这就像是运行在Tailscale magicsock(WireGuard加密+NAT穿透+DERP中继/回退)上的netcat工具。

Notably, tailcat has:

  • no IP addresses
  • no accounts (no logins, no passwords, no SSO)
  • no control plane
  • no users
  • no admins
  • no administrative controls
  • no root or admin OS access requirement
  • no relationship with or dependence on Tailscale as a company (if you run your own cmd/derper DERP server, at least)
    tailcat的显著特性包括:
  • 无需IP地址
  • 无需账户(无登录/密码/单点登录)
  • 无控制平面
  • 无用户体系
  • 无管理员
  • 无管理控制项
  • 无需root或系统管理员权限
  • 与Tailscale公司无关联或依赖(至少在你自建DERP服务器时)

What does “Tailscale” even mean?
When you watch people describe Tailscale to each other online, you see very different interpretations of what “Tailscale” means to them.
究竟什么是”Tailscale”?
当观察人们在网络上的讨论时,你会发现对”Tailscale”的理解千差万别。

One group of people, often seen saying things like “I’ll just run WireGuard myself,” focuses on the WireGuard part and doesn’t consider (or care about) parts like NAT traversal, DERP fallbacks, centrally managed firewall (ACL) rules, SSO login, tagging, MDM policies, audit logging, etc. Maybe they only want or need the WireGuard part on a public IP. That’s fine.
一类人常表示”我自己搭WireGuard就行”,他们只关注WireGuard部分,不考虑(或不关心)NAT穿透、DERP回退、集中式防火墙(ACL)规则、单点登录、标签、移动设备管理策略、审计日志等功能。可能他们只需要公网IP上的WireGuard——这完全合理。

Another group of people talks more about the company, corporate structure, long-term viability, founders, funding stage, pricing, certifications, reliability, responsible handling of security disclosures, etc.
另一类人更关注公司架构、长期存续性、创始人、融资阶段、定价策略、安全认证、可靠性、漏洞披露响应机制等企业级要素。

Another group of people talk about whether Tailscale is open source or not. As a reminder: our core is open source (with a real OSI-approved license!), our DERP server is open source, and our clients are open source on platforms that are themselves open source: Linux and Android. Our server-side control plane is not. A lot of people in this audience appreciate that Headscale (which we love and partially fund development of) exists, either to use today, or use in the future, as a fallback plan.
还有群体热衷于讨论Tailscale是否开源。需要说明:我们的核心代码是开源的(采用OSI认证的真实开源协议!),DERP服务器开源,且在Linux/Android这些开源平台上的客户端也开源。但服务端控制平面不开源。许多用户因此珍视Headscale(我们喜爱并资助其部分开发)的存在,无论是立即采用还是作为未来备选方案。

All of those interpretations are fine. Whether you’re using our official GUI client wrappers around our official control plane, with a corporate SSO identity provider, or you’re at the other extreme, using only tsnet on Linux nodes against your self-hosted Headscale server, there are many ways to wire up and use Tailscale and its many pieces:

  • Its WireGuard + NAT traversal + DERP fallback data plane
  • Its control plane
  • Its company (paying us to run and support things for you)
  • Its open source code
    所有这些理解都成立。无论你是通过企业SSO身份提供商使用官方控制平面+GUI客户端,还是另一个极端——仅在你自建的Headscale服务器上通过Linux节点的tsnet来使用,Tailscale及其组件都有多种连接使用方式:
  • WireGuard+NAT穿透+DERP回退的数据平面
  • 控制平面
  • 商业公司(付费让我们运维支持)
  • 开源代码

tailcat gives you another way to use a subset of Tailscale.
tailcat提供了另一种使用Tailscale功能子集的方式。

How it works
Let’s say you want to run a tailcat server. Here’s what it does:

  • generates a keypair (either ephemeral or named & reused)
  • picks a DERP server (either one you specify, or an auto-selected bandwidth-limited Tailscale-run one)
  • generates a tailcat address, which is a string of the form: tc + base64(CBOR( public key + DERP bootstrap info ))
  • you then share that address string with somebody out of band, either directly, or by putting it in a DNS TXT record, and sharing that DNS hostname out of band
    运作原理
    假设要运行tailcat服务端,其工作流程如下:
  • 生成密钥对(临时或命名复用)
  • 选择DERP服务器(可指定或自动选择带宽受限的Tailscale运营节点)
  • 生成tailcat地址,格式为:tc + base64(CBOR(公钥+DERP引导信息))
  • 通过带外方式分享该地址字符串(直接传递或存入DNS TXT记录后分享域名)

The client side is about the same:

  • pick a key (ephemeral or locally named & reused)
  • connect to the rendezvous DERP server specified in the tailcat address
  • send a MEOW message to the server’s public key over DERP to add yourself to the netmap
    客户端流程类似:
  • 选择密钥(临时或本地命名复用)
  • 连接至tailcat地址中指定的DERP会合服务器
  • 通过DERP向服务端公钥发送MEOW消息加入网络映射

At that point, if the server is cool with that client’s public key (it can be optionally locked down), then it replies with a happy MEOW reply.
此时若服务端接受该客户端公钥(可配置白名单),则会回复成功的MEOW响应。

The client then proceeds to make a TCP connection to the other side using an embedded userspace TCP stack atop WireGuard. There are actual IP addresses on the wire (IPv6 ones derived from your public key), but they’re never visible to users. Your operating system is never involved at the TCP layer and never sees the synthetic tailcat IPs. All your operating system does is send the DERP TCP messages and/or NAT-punched UDP WireGuard messages.
客户端随后通过WireGuard之上的嵌入式用户态TCP栈建立连接。虽然线路上存在真实IP地址(根据公钥衍生的IPv6地址),但对用户完全透明。操作系统完全不参与TCP层,也看不到合成的tailcat IP。系统仅负责发送DERP TCP消息和/或NAT打洞后的WireGuard UDP数据包。

Because it goes over Tailscale’s magicsock data plane, NAT traversal automatically kicks in and tries to get a direct connection, so data transfer (WireGuard UDP packets) ends up going directly between the client and server, without a DERP relay involved. But if both sides are behind a hard NAT without any port mapping services available, the data packets are relayed over DERP as a fallback. If you use Tailscale-hosted DERP servers, those are rate-limited (bandwidth costs us money). But if you run your own DERP server, you can control any rate limiting.
由于基于Tailscale的magicsock数据平面,NAT穿透会自动生效以尝试建立直连,因此数据传输(WireGuard UDP包)最终会直接在客户端与服务端间进行,无需DERP中继。但若双方位于严格NAT后且无端口映射服务,则通过DERP回退中继。使用Tailscale托管的DERP服务器时会限速(带宽消耗成本),但自建DERP服务器时可自主控制限速策略。

In the default mode where you don’t specify a port number on the tailcat server, the default is to just pipe the received data to the server’s stdout, like netcat. But it can also run in a client mode, where it runs a SOCKS server on an ephemeral l
默认模式下(不指定服务端端口时),接收数据会直接输出到服务端stdout,类似netcat。但它也能运行在客户端模式,在临时…(原文截断)

🔗 知识库双向关联