From the newsletter:
We’ve recently released tailcat, a remix of pieces of Tailscale that gives you a way to use the open-source Tailscale data plane without the Tailscale control plane, written by the people who made Tailscale.
Specifically, tailcat is both an open-source Go package and a CLI tool using that package. It lets you run a server-side listener and a client to connect to that server, moving bidirectional bytes back and forth.
Potential usage info from the website link - https://tailscale.com/tailcat:
Setting up a tailnet makes sense when you need governable access, identity, and policy. Sometimes you don’t. You might need to SSH into a development environment for an hour. Give an agent access to a test machine for one task. Connect a game session. Move a file between two machines. Tailcat gives you a secure connection without requiring either side to become part of a larger network.
A technical explanation from the github:
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.
License: BSD 3-Clause License
Tailcat is a remix of Tailscale open source pieces to act like netcat, but over Tailscale’s data plane, without Tailscale’s control plane. Tailscale’s data plane (magicsock, internally) gives you point-to-point WireGuard®-encrypted tunnels between two machines with DERP as the NAT-hole-punching communication side channel and the ultimate relay-of-last-resort if NAT traversal fails. Instead of using the Tailscale control plane, all tailcat connection metadata is exchanged out of band, however you want.

This GIF reminds me that I kept saying “who loves orange soda? Kel loves orange soda!” Do my significant other.
So… Wireguard?
It sounds more like netcat maybe? Less server client architecture more peer to peer?
Yeah seems more like nectat. From the name I would guess that’s the intent.
My first reaction was that it’s similar to dumbpipe (which is also inspired by netcat). Variety is good I guess.
ELI5? I barely understood original Tailscale.
Tailscale is a private treehouse. Everyone gets an official member badge, has their name on the roster, and can walk in anytime to hang out, share toys, and see everone else in the club.
Tailcat is two tin cans tied together with a string. There is no club, no badges, and no rules. You give one can to someone, whisper a secret through the string, and as soon as you hang up, it’s gone.
Are girls allowed?
Only if you invite them. But be warned, they have cooties.

Excellent I am five years old and I completely understand this analogy
Soooo, netbird?
Not quite:
Netbird is a treehouse you build and maintain yourself. You’re the club leader: you set the rules, issue the badges, keep the roster, and decide who gets in. No one runs it for you. You have to build it, keep it up, and handle the maintenance. It’s still a real club with a real roster and persistent membership, just like Tailscale’s treehouse, except you’re the one who has to insure the roof doesn’t leak.
Easy VPN is how I see it. Like zero config, very smooth and pretty slick
With normal Tailscale they host the management end of things, you host the servers, their system negotiates directly connecting them together.
I think this lets you host that management connection yourself. But I’m kinda confused just wtf is going on.
I think this lets you host that management connection yourself.
No, but if you wanted to do that, headscale is the answer
There is no management connection. It’s just managed locally but has their UDP hole punching feature
Scales are rough… Cats are fluffy and smooth :D !
Never mind me, wait for a better ELI :D






