- Sources: primary, discussion
- Summary: Brad Fitzpatrick published tailcat on 2026-08-31, an open source Go package and CLI that uses Tailscale's WireGuard, NAT traversal, and DERP data plane with no control plane, no accounts, no user-visible IP addresses, no admin controls, and no root requirement. A server generates a keypair, picks a DERP server, and emits an address string of the form
tc plus base64 of CBOR over the public key and DERP bootstrap information, shared out of band or through a DNS TXT record, and the client sends a MEOW message over DERP to join the netmap then opens TCP over an embedded userspace stack atop WireGuard. Default mode pipes to stdout like netcat, a client mode runs a local SOCKS server and a child process, and NAT traversal attempts a direct connection with DERP relaying as fallback, rate-limited on Tailscale-hosted DERP and under the operator's own limits when self-hosted. - Why it matters: It gives ephemeral and untrusted machines a NAT-traversing transport with no account and no admin plane, and Fitzpatrick states he wrote it in 2023 and cites sandboxed coding agents as the use case that brought it back.
send feedback on this story