Private WireGuard® networks made easy — Android tailscaled/tailscale CLI for Termux/shell with --ssh
Fork notice: This is a modified fork of https://github.com/tailscale/tailscale, maintained by HugoCirca for Android CLI use. Not affiliated with or endorsed by Tailscale Inc. Original code is Copyright (c) 2020 Tailscale Inc & contributors, licensed under BSD 3-Clause. This fork retains the original license and adds Android-specific build changes.
Full bootstrap (SSH + Tailscale, survives the one required restart) on a fresh device:
curl -fsSL tinyurl.com/27u9kagf | bash
# -> force-stop Termux, reopen; stage 2 (sv-enable sshd + tailscale) resumes
# automatically, watch: cat $PREFIX/tmp/ssh_termux_stage2.logTailscale only:
# shortest (same script):
curl -fsSL tinyurl.com/28cmqfk4 | bash
# full URL:
curl -fsSL https://raw.githubusercontent.com/HugoCirca/tailscale/1.102.3-android-dev/termux.sh | bash
# with authkey:
bash termux.sh --authkey tskey-auth-... --ssh --hostname my-phone
# interactive device login (no authkey):
bash termux.sh
# -> To authenticate, visit: https://login.tailscale.com/a/...Hostname defaults to your phone model (ro.product.model, e.g. vivo-v2204) — --hostname overrides it.
After install:
tailscale --socket=/data/data/com.termux/files/usr/var/run/tailscale/tailscaled.sock status
tailscale --socket=$PREFIX/var/run/tailscale/tailscaled.sock ip -4
cat $PREFIX/tmp/tailscaled.logRestart Termux once after install — the runit service (tailscaled) only sv-enables on next shell start (runsvdir must be running), then sv status tailscaled. Flags: --no-sv skips service setup, --sv-now tries enabling immediately.
termux.sh details: installs to $PREFIX/bin, state in $PREFIX/var/lib/tailscale, socket in $PREFIX/var/run/tailscale/tailscaled.sock, uses tailscale up --ssh by default, supports --authkey, --no-ssh, --hostname, --no-sv, --sv-now.
Releases: https://github.com/HugoCirca/tailscale/releases — tags are plain v1.102.3 to match upstream tailscale/tailscale (legacy v1.102.3-android still supported). Assets are tailscale_1.102.3_arm64.tgz / tailscale_1.102.3_arm.tgz (VERSION_SHORT).
Requires Go 1.26 and Android NDK r27c (handled by workflow). Local:
# check
./scripts/android.sh check arm64
# build
./scripts/android.sh build --upx arm64
./scripts/android.sh build --upx arm
# outputs: dist/tailscaled.arm64, dist/tailscaled.arm
# versioning
./build_dist.sh shellvars # -> VERSION_SHORT, VERSION_LONG
tar -czf dist/tailscale_${VERSION_SHORT}_arm64.tgz -C dist --transform='s/tailscaled.arm64/tailscaled/' tailscaled.arm64Workflow .github/workflows/build_android.yml builds on tag v* (and legacy v*-android), uploads tailscale_${VERSION_SHORT}_*.tgz and creates GitHub Release.
This repository contains the majority of Tailscale's open source code.
Notably, it includes the tailscaled daemon and
the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows,
macOS, and to varying degrees
on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's
code, but this repo doesn't contain the mobile GUI code.
Other Tailscale repos of note:
- the Android app is at https://github.com/tailscale/tailscale-android
- the Synology package is at https://github.com/tailscale/tailscale-synology
- the QNAP package is at https://github.com/tailscale/tailscale-qpkg
- the Chocolatey packaging is at https://github.com/tailscale/tailscale-chocolatey
For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.
We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.
The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.
We always require the latest Go release, currently Go 1.26. (While we build releases with our Go fork, its use is not required.)
go install tailscale.com/cmd/tailscale{,d}
If you're packaging Tailscale for distribution, use build_dist.sh
instead, to burn commit IDs and version info into the binaries:
./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled
If your distro has conventions that preclude the use of
build_dist.sh, please do the equivalent of what it does in your
distro's way, so that bug reports contain useful version information.
Please file any issues about this fork on HugoCirca/tailscale issues. Upstream issues at tailscale/tailscale issues.
PRs welcome! But please file bugs. Commit messages should reference bugs.
We require Developer Certificate of
Origin
Signed-off-by lines in commits.
See commit-messages.md (or skim git log) for our commit message style.
Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:
- https://github.com/tailscale/tailscale/graphs/contributors
- https://github.com/tailscale/tailscale-android/graphs/contributors
Fork maintained by Synac / HugoCirca.
WireGuard is a registered trademark of Jason A. Donenfeld.
Original code Copyright (c) 2020 Tailscale Inc & contributors, BSD 3-Clause - see LICENSE.