Tail Controller
Headscale admin in your pocket — your nodes, your people, your keys and the whole access policy, from an iPhone
iPhone, iOS 26
Headscale 0.29+
Collects nothing
What it does
Nodes
See what is online, rename a machine, approve its subnet routes or make it an exit node, change its tags, expire its key or remove it
Users
Add a person, rename one, read the machines they own, and delete an account that owns none
Keys
Pre-auth keys for a person or for a set of tags, shown once on the screen they are made on, and API keys created and revoked beside them
Policy
Groups, tags, ACL rules, grants with their network and app capabilities, SSH rules, hosts and node attributes — or the raw document, in a proper editor
A save leaves alone every line it did not change
- A policy is written by hand, so the app splices rather than reprints: comments, blank lines and columns come back exactly as they were
- Headscale keeps no history of the policy, so the app keeps its own — every version it has saved, read as a diff and put back with one tap
- Each position in a rule offers only what Headscale accepts there, which is most of what it refuses a policy for
What you need
- Your own Headscale server, 0.29 or later, and an API key from it —
headscale apikeys create - Plain
http://is fine: a self-hosted server is often reached over a private network, and the app does not lecture you about it - Nothing is collected. The address and the key stay in your device's keychain, and the app talks to no one but your server
Support
- Write to tailcontroller@gecka.info — it is read by the person who wrote the app
- What helps: your Headscale version, what you were doing, and the message the app showed. Headscale's own words are passed through untouched, so quoting them says a lot
- The app needs a Headscale of your own and an API key from it; it cannot do anything without one