pkg.soopen package index

brew / rank 10965

Install tsnet-serve with Homebrew

Expose HTTP applications to a Tailscale Tailnet network. Version 1.3.2 via Homebrew; verified 2026-07-26.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install tsnet-serve

local Homebrew formula metadata

overview

Package summary

Expose HTTP applications to a Tailscale Tailnet network

Commands and aliases

  • tsnet-serve

history

Project history and usage

tsnet-serve was a standalone Go reverse proxy that embedded Tailscale via tsnet so an HTTP backend could appear as its own machine on a tailnet, roughly like `tailscale serve` without being tied to an existing node.

Project history

The README presents tsnet-serve as a lightweight reverse proxy for a tailnet: users give it a hostname, backend URL, and auth key, and the app joins the tailnet as a machine with Tailscale connectivity, TLS, and the same reverse proxy behavior as `tailscale serve`.

The project belongs to the wave of tsnet tooling around Tailscale's Go library. Tailscale's official docs describe tsnet as a way to embed Tailscale inside a Go program so the program can make direct tailnet connections and appear like a separate device. tsnet-serve packaged that pattern as a CLI/container app for people who wanted a private service endpoint without writing Go.

Development was explicitly wound down in July 2025. The repository was archived by its owner on July 5, 2025, and the linked winding-down issue says maintainers were switching to `tsnsrv` because it had the desired features and a complete Nix module.

Adoption history

Official release pages show a short but active release period, with versions such as v1.1.2 through v1.3.2 carrying Funnel fixes, path allow/deny features, request logging, Tailscale dependency bumps, Go toolchain updates, and GoReleaser-based binary releases.

The README documents several distribution surfaces: prebuilt GitHub releases, OCI container images on GitHub Container Registry at `ghcr.io/shayne/tsnet-serve`, and Homebrew. That made the tool easy to use in homelab and package-manager workflows where a container or single binary could turn a local backend into a tailnet service.

How it is used

The primary usage model was `tsnet-serve -hostname ... -backend ...`, optionally setting listen port, Funnel mode, allow/deny path regular expressions, a state directory, and a custom control URL for Headscale. Environment variables such as `TSNS_HOSTNAME`, `TSNS_BACKEND`, `TSNS_LISTEN_PORT`, and `TSNS_FUNNEL` mirrored the flags.

For containers, the README shows a persistent state volume, hostname/backend variables, optional Funnel and control URL variables, and `TS_AUTHKEY` for initial registration. Without an auth key, the app prints a registration link.

Why package nerds care

tsnet-serve matters in the package-nerd niche because it turned Tailscale's embedded-networking library into a one-command appliance: install the formula or run the container, provide a backend, and get a tailnet hostname and certificate.

Its archival is also useful metadata. The project documents a real migration path from a small package-manager-friendly CLI to a successor (`tsnsrv`) once the surrounding Tailscale Serve/Funnel and tsnet tooling matured.

Timeline

  • 2024-07-31: v1.1.2 release fixed Funnel mode and insecure HTTPS backend support.
  • 2024-08-29: v1.1.4 release moved to GoReleaser and bumped the Tailscale dependency.
  • 2025-04-19: v1.2.1 release moved the default state directory and added X-Forwarded headers in Funnel mode.
  • 2025-06-22: v1.3.0 added allow/deny paths and request logs; v1.3.2 followed with a Tailscale bump and signal-handling fix.
  • 2025-07-05: Winding-down issue opened and repository archived, with maintainers pointing users to `tsnsrv`.

Related projects

  • The README links directly to Tailscale Funnel and to `tsnsrv` as the recommended successor. Tailscale's own docs for tsnet, Tailscale Serve, and Funnel explain the platform features that tsnet-serve wrapped.

security posture

Risk level: blue

broad file, network, media, or database tool signal.

Risk classifier

blue risk · medium confidence · tool

Why

  • broad file, network, media, or database tool signal

Signals

  • text:network,http

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 8 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
tsnet-servecliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-04
manager version1.3.2
manager updated2026-07-26
local dataok
upstreamcurrent
latest detectedv1.3.2

https://github.com/shayne/tsnet-serve

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:tsnet-serve
Version1.3.2
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/tsnet-serve
Homepagehttps://github.com/shayne/tsnet-serve
Repositoryhttps://github.com/shayne/tsnet-serve
LicenseMIT
Source archivehttps://github.com/shayne/tsnet-serve/archive/refs/tags/v1.3.2.tar.gz
Last updated2026-07-26T00:51:28+02:00
Pulseupdated
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, arm64_ventura, sonoma, ventura, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nametsnet-serve
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedyes
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation