A security-conscious, idempotent Bash installer that installs and provisions Tailscale on Ubuntu Server from Tailscale's official APT repository.
This is an independent community project. It is not affiliated with or endorsed by Tailscale Inc. Tailscale is a trademark of Tailscale Inc.
The official one-line installer is convenient, but production automation
usually needs a reviewable workflow, safe secret handling, repeatable
behavior, CI, and clear operational documentation. This project provides those
pieces without hiding the underlying APT and tailscale commands.
Key features:
- Uses the official, codename-specific Tailscale APT repository
- Never pipes a remote script directly into a shell
- Safe to run repeatedly; no duplicate configuration is created
- Supports interactive login and unattended auth-key provisioning
- Passes auth keys through
--auth-key=file:PATHrather than the process list - Validates Ubuntu, systemd, repository metadata, hostnames, tags, and key-file permissions
- Enables and verifies
tailscaled - Supports Tailscale SSH, subnet-route acceptance, custom hostnames, tags, and a non-root operator
- Keeps full Ubuntu upgrades opt-in
- Ships with dry-run mode, strict Bash settings, a test suite, ShellCheck CI, issue templates, and release automation
- Ubuntu 20.04 or newer
- A Tailscale-supported Ubuntu codename in the official package repository
systemd- Root privileges
- Outbound HTTPS access to Ubuntu mirrors and
pkgs.tailscale.com
Ubuntu 22.04 LTS and 24.04 LTS are the primary targets. Newer supported Ubuntu
releases work dynamically through VERSION_CODENAME.
Clone or download the project, review the script, then run:
chmod +x install.sh
sudo ./install.sh --loginTo install without starting authentication:
sudo ./install.sh
sudo tailscale upThe default run deliberately installs only Tailscale and its small dependencies. It does not upgrade every package on the server.
Create a tagged, pre-authorized auth key in the Tailscale admin console, store it in a root-only file, and run:
sudo install -m 600 /dev/null /run/tailscale-authkey
sudoedit /run/tailscale-authkey
sudo ./install.sh \
--auth-key-file /run/tailscale-authkey \
--hostname app-01 \
--advertise-tags tag:server \
--sshDelete the source key file after successful provisioning if your secret manager does not manage its lifecycle. Prefer one-off, tagged, pre-authorized keys when they fit your deployment.
Preview every planned action:
sudo ./install.sh --dry-run --no-colorAccept advertised subnet routes:
sudo ./install.sh --login --accept-routesAllow a local user to operate tailscaled without sudo:
sudo ./install.sh --login --operator ubuntuUse the unstable Tailscale package track:
sudo ./install.sh --channel unstable --loginUpgrade all installed Ubuntu packages before installation:
sudo ./install.sh --upgrade-system --login| Option | Purpose |
|---|---|
--login |
Start browser-based interactive authentication |
--no-login |
Install only; this is the default |
--auth-key-file PATH |
Authenticate from a file that is not group/world-readable |
--hostname NAME |
Set the node's Tailscale/MagicDNS name |
--advertise-tags TAGS |
Advertise comma-separated tags such as tag:server |
--ssh |
Enable the Tailscale SSH server; tailnet policy still controls access |
--accept-routes |
Accept routes advertised by subnet routers |
--operator USER |
Let an existing local Unix user operate tailscaled |
--channel TRACK |
Use stable or unstable |
--upgrade-system |
Opt in to a full apt-get upgrade |
--dry-run |
Print planned commands without persistent system changes |
--no-color |
Disable ANSI colors |
-h, --help |
Show built-in help |
-v, --version |
Print the installer version |
See Usage for behavior, automation examples, and exit semantics.
- Repository configuration is fetched only over HTTPS from
pkgs.tailscale.com. - The downloaded key must parse as OpenPGP data.
- The downloaded APT source must exactly match the expected official
repository, track, Ubuntu codename, and
signed-bypath. - A supplied auth-key file must be a regular readable file with no group or other permissions.
- The key is supplied as
--auth-key=file:PATH, so its value never lands in command-line arguments or installer logs. TS_AUTHKEYis supported for CI compatibility, but the installer immediately copies it into a temporary0600file and unsets its local copy. A mounted secret file is still preferred.- Enabling Tailscale SSH does not grant access by itself. Your tailnet access policy remains authoritative.
- Disabling key expiry is never done automatically. Do it only for trusted nodes, and only if you accept the risk.
Read Security notes and the project's security policy before a production rollout.
Run the local checks:
make checkCreate a distributable archive:
make packageShellCheck is optional locally but required by CI. See CONTRIBUTING.md for the contribution workflow.
- Usage and automation
- Architecture and execution flow
- Troubleshooting
- Security notes
- Changelog
- Support
- Install Tailscale on Linux
- Tailscale stable packages
tailscale upreference- Set up a Tailscale server
- Tailscale CLI reference
Released under the MIT License.