Tailscale VPN
The practical guide to Tailscale — the zero-config mesh VPN built on WireGuard — how it differs from raw WireGuard, installing it across a real homelab, exit nodes, self-hosted alternatives like Headscale, and honest pricing.

Part 1
What Is Tailscale? A Mesh VPN Explained
Tailscale explained: how its WireGuard-based mesh VPN, coordination server, and NAT traversal actually work, what the free plan includes in 2026, and who it fits.

Part 2
Tailscale vs WireGuard: The Real Difference
Tailscale isn't a WireGuard competitor, it's WireGuard with a coordination server, NAT traversal, ACLs, and exit nodes wrapped around it. A first-hand decision framework for when raw WireGuard is enough and when Tailscale's managed layer earns the tradeoff, with sourced pricing and performance figures.

Part 3
How to Install Tailscale on a Homelab
A subnet route sat approved in the admin console and still didn't work. The real-world install walkthrough across an Ubuntu server, a Raspberry Pi, and a Proxmox host/LXC — auth flow, MagicDNS, ACL tags, and the two gotchas (LXC's missing /dev/net/tun, the two-step route requirement) that actually cost time.