From the newsletter:

We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.

Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.

Potential usage info from the website link - https://tailscale.com/tailcat:

Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.

A technical explanation from the github:

Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.

License: BSD 3-Clause License

  • Swedneck@discuss.tchncs.de
    link
    fedilink
    arrow-up
    1
    ·
    4 days ago

    And this can presumably hopefully finally fucking condemn hamachi to the grave, maybe?


    Forward local ports to a tailcat server

    To make ports served by a tailcat server available as ordinary local TCP ports (for browsers, database clients, or other tools that do not support SOCKS or stdio), run forward with the server’s tailcat address:

    $ tailcat serve 8080,3306
    # 🐈 Server listening with new address: tcXXXXXXXXX
    
    $ tailcat forward tcXXXXXXXXX 18080:8080 3306
    

    A local port of 0 asks the operating system for a free port; each listener prints its address once it’s listening.

    To forward local ports to assets on the network reachable by an exit-node server, run the server in exit-node mode and specify each remote IP address and port in the mapping:

    $ tailcat serve exit-node
    # 🐈 Server listening with new address: tcXXXXXXXXX
    
    $ tailcat forward tcXXXXXXXXX \
        3001:172.23.52.30:3001 \
        17170:172.23.52.31:17170
    

    This forwards 127.0.0.1:3001 to 172.23.52.30:3001 and 127.0.0.1:17170 to 172.23.52.31:17170 through the exit-node server.

    By default, listeners bind to 127.0.0.1 and diagnostic logs are suppressed. Pass --verbose before the subcommand to enable verbose networking logs. Use --bind=0.0.0.0 only when clients on other machines should be able to connect:

    $ tailcat forward --bind=0.0.0.0 tcXXXXXXXXX 18080:8080
    

    Press Ctrl-C to stop forwarding.