Why TSLink Uses Tailscale
How tsnet supports private local-service sharing, what Tailscale already provides, and where TSLink's named registry and agent handoff fit.
A local preview is usually reachable only from the machine where it runs. Tailscale lets another permitted device reach a private node without opening a public inbound port. TSLink embeds tsnet so each registered service can have its own tailnet node and name.
What Tailscale already offers
Tailscale Serve can privately share a local service or file. Tailscale Services also provides named service identities with an administrative setup flow. Funnel is for deliberate public exposure.
TSLink's current focus is managing several named local services from a registry and returning structured CLI JSON or MCP results. For example, tslink share 3000 --name preview --json can hand an agent either an exact private URL or a needs_login result with an authorization URL for a person to open.
Where the boundary sits
Each TSLink service gets a separate tsnet network identity. That affects tailnet reachability, but it does not sandbox the local process. Proxy and file HTTP services use Tailscale HTTPS listeners; raw TCP has no TSLink HTTP identity headers or TLS termination. The hop from the TSLink node to a local backend may be plaintext. Tailscale policy still governs node reachability, and the application may need its own authentication.
TSLink keeps a service private unless public Funnel exposure is explicitly requested with both --funnel and --public. Its proxy/file HTTP --allow filter can narrow access by caller identity, but it does not replace tailnet policy.
More Posts
Private Local Services for Coding Agents
Share an existing app or generated file, hand back an exact URL or needs_login step, and choose the right TSLink CLI or MCP interface.
Who Can Open a Shared Local Service?
A practical access-boundary guide for a privately shared TSLink service: tailnet policy, optional HTTP --allow, raw TCP, and public Funnel.
Host an HTTP MCP Server on Your Private Tailnet
A concrete TSLink proxy path for a third-party HTTP MCP server, with tailnet access, backend authentication, and Funnel boundaries.