Technologically, it's based on Wireguard. Wireguard is fast; really fast, especially compared to OpenVPN. Using cutting edge cryptography and a new UDP protocol, Wireguard connections feel roughly zero-overhead (they're not, of course.) Connections are peer-to-peer and you usually will get pretty close to the fastest reasonable route between any two devices, whether you're on LAN or overseas, whether there's a strong NAT in front or not.
They've also engineered a lot of things carefully, instead of just cobbling together existing end-user tools in Rube Goldberg arrangements. (Not saying there isn't use of existing code; there totally is. But it's all very nicely integrated from what I can see.) Doing things "the hard way" can lead to more complicated software, but the way they've architected things makes the possibilities for expanding the utility of Tailscale to be nearly limitless. It's also amazingly entertaining to read about. Seriously, just read about how their web browser SSH client works:
TailScale seems to have a better ui and more tooling (File sharing, SSH, ...). Even though those recently led to RCE[0]
Historically you had enterprise-grade VPNs that cost a lot of money, or OpenVPN. Both ran over IPSec or SSL, and neither were super straightforward to config/maintain, nor were they particularly performant.
Then came wireguard, which is awesome, but wireguard is just a transport. It doesn't have all the UX niceties built on top of it, like registering clients or generating / distributing keys. Tailscale does a lot of that lifting for you, so you can easily and quickly get a working VPN, at a low cost, with good performance.
Personally I manage wireguard myself, but I also self-host my own VMs, storage server, applications, etc.
Tailscale is like taking your car in for an oil change instead of doing it yourself, plenty of people find that worth it.
Personally, I use it to connect my home devices as if they were always together on the same LAN, even when they're not. E.g. Raspberry Pi, home NAS, "home" server that's actually in a different physical location, etc. All accessible anywhere at any time, even (say) from my laptop in a moving vehicle, without connections dropping even when my IP changes. It really is like magic.
At work, we use it so that remote employees can access locally-hosted applications, office NAS, etc. ACLs make it easy to employ the principle of least privilege, so that having a route into the office LAN doesn't immediately mean any and every device is compromised.
We've been able to do this with existing VPNs for a long, long time, but tailscale is by far the most painless offering I've ever used and I migrated away from OpenVPN completely.
One of my use cases for Tailscale was connectivity between my primary NAS and an off-site NAS I use for backups. Being able to bring my NAS to the same site/network I had set-up the off-site NAS and just have things work over the LAN without reconfiguring anything was a wonderful surprise.
(Yes, I’m aware I could save some overhead by reconfiguring but looking at the network traffic monitor I was happy enough with the throughput I got though Tailscale’s LAN routing)
Without Tailscale I would need a way to publish my routers current WAN address somehow (probably with DDNS), create a port forward rule on my ISPs router/modem and then setup a VPN server to listen to those connections.
Not to mention that the current ISP doesn't even allow me to login to their modem and setup port forwarding.
- I have a SOHO setup at home: several PCs/ my work laptop, raspberry pi, synology and ubiquiti. It means I can access ubiquiti console and synology via network as opposed to be some janky proxy that those company's provide.
- taildrop is great for sending screenshots and files from my phone to (can't wait until they let me send URLs/links/txt like KDEConnect)
- I also have a raspberry pi setup in an ABNB in another country. When I'm traveling I can use my house as a proxy for US based services and the reverse is true - if I want my browsing to look like my IP address in another country I can.
- Running a Jupyterlab instance on my desktop PC (WSL) and use it through my laptop from anywhere. Can also be accessible through phone/tablet if needed
- Simple routing of other services my PC exposes (Jellyfin for now)
- Access dev services running on my laptop through my phone without checking IP all the time
- Good replacement for AirDrop using Taildrop file sharing. AirDrop errors out if I try to use it on a "public" network (ex: University Wi-Fi)
Managing personal devices.
One day I had to go to the office and only then did I notice my keepass hadn't synced in months. My home PC was sleeping so I SSH'd to my Openwrt box, got the MAC for my PC and used etherwake to start it. From there I used RDP to login and get an updated password. All from my phone.
I run it on every device I own, plus a few at my parents' place. This way I can access my PC and my NAS from my phone, and my NAS from my PC, even though the NAS is behind my home router and the PC and the phone can be connected to a bunch of different networks.