TSLinkTSLink Docs

File Sharing

How to expose directories for file sharing over your tailnet

View as Markdown

Overview

TSLink can serve any local directory over HTTPS on your Tailscale network. This is useful for sharing documents, build artifacts, media files, or any collection of files with teammates or your own devices.

Sharing a Directory

Use tslink add with the --dir flag:

bash
tslink add <name> --dir <path>

Examples:

bash
# Share a documents folder
tslink add docs --dir ~/Documents/shared

# Share build output
tslink add builds --dir /var/www/builds

# Share a project's public assets
tslink add assets --dir ~/projects/my-app/public

Accessing Shared Files

add ensures the gateway is running. Complete any enrollment handoff, then run tslink url docs --wait and open its exact URL from a device allowed by your tailnet policy:

Code
https://docs.<your-tailnet>.ts.net

TSLink serves a file listing page at the root URL. You can navigate directories and download files directly through your browser.

URL Path

Files are served at the root URL of the file service:

Code
https://docs.<your-tailnet>.ts.net/

Use separate service names when you need separate shared directories.

Use Cases

Team File Sharing

Share project resources with your team without uploading to cloud storage:

bash
tslink add team-resources --dir ~/team/resources
tslink url team-resources --wait

After enrollment and URL readiness, permitted tailnet team members can browse and download files.

Development Artifacts

Share build artifacts or test reports with colleagues:

bash
tslink add test-reports --dir ./coverage
tslink add builds --dir ./dist

Media Library

Make a local media library accessible across your devices:

bash
tslink add media --dir /Volumes/External/media

Access your files from your phone, tablet, or any other device on your tailnet.

Temporary Sharing

Need to share files quickly? Add a directory, share the link, then remove it when done:

bash
# Start sharing
tslink add temp --dir ~/Desktop/send-these

# When done
tslink remove temp

Restricted Sharing

Limit file access to specific users or tagged devices. The --allow flag supports both email addresses and ACL tags, and you can specify multiple values:

bash
# Single user
tslink add confidential --dir ~/Documents/private --allow user@company.com

# Multiple identities
tslink add confidential --dir ~/Documents/private --allow user@company.com,tag:admin

# Combine with tags for ACL-based access
tslink add team-docs --dir ~/team/docs --allow tag:engineering --tags tag:internal

Only the specified identities will be able to access the shared directory. Unauthorized requests receive a 403 Forbidden response.

Ephemeral Sharing

Use --ephemeral to request an ephemeral node. Control-plane cleanup follows inactivity; stopping the gateway is not proof that the remote device is gone. The local registry entry remains until removed. This is useful for one-off file transfers or short-lived sharing sessions:

bash
# Request temporary node lifetime; verify remote cleanup separately
tslink add temp-share --dir ~/Desktop/handoff --ephemeral

# Combine ephemeral with access control for secure one-time sharing
tslink add handoff --dir ~/Desktop/deliverables --ephemeral --allow colleague@company.com

Multiple Directories

You can share multiple directories as separate services, each with its own hostname and access controls:

bash
tslink add public-docs --dir ~/Documents/public
tslink add team-files --dir ~/team/shared --allow tag:engineering
tslink add build-output --dir ./dist --ephemeral

Important Notes

  • The directory path must exist on the machine running TSLink.
  • Paths inside, equal to, or containing TSLink's config directory are refused with path_exposes_config_dir to protect credentials and node keys.
  • Files are served read-only — remote users can download but not upload or modify files.
  • The directory is served over HTTPS on the tailnet listener with automatic TLS certificates, and the tailnet transport to the file service is WireGuard-encrypted (file reads happen locally on the host).
  • All access is restricted to authenticated devices on your Tailscale network by default — files are never exposed to the public internet. Funnel is proxy-only and requires --funnel --public.
  • Use --allow to restrict access to specific identities for sensitive directories, enforcing least-privilege access.
  • Subdirectories are served recursively.
  • Funnel (--funnel --public) is not available for file services — it is only supported for proxy services and is explicit public exposure.

People and deadlines

File services also support people grants with deadlines. Give only the intended private file app to a verified Tailscale login; outsiders need an accepted app-device invitation. Revocation stops new requests, not completed downloads or accepted streams. File services cannot use public Funnel.

Table of Contents