TSLinkTSLink Docs

Access Local AI over Your Tailscale Network

Give an existing Ollama API a private HTTPS address and connect a permitted device or agent.

View as Markdown

TSLink gives an existing model HTTP API a private HTTPS address. Your backend runs inference; TSLink forwards traffic. A permitted device can use that address in an Ollama client or a compatible application.

Shell examples use bash/zsh and curl.

Check the backend first

Install TSLink and run Ollama separately on the publishing host. Choose and download a local model for local inference. Test its API before sharing:

bash
curl http://localhost:11434/api/tags

The response lists installed models. If it is unreachable, fix the backend first; an empty model list still needs a model before inference.

Register a private model address

Replace the email with your own Tailscale login:

bash
tslink add model --proxy localhost:11434 --allow you@example.com
tslink url model --wait

Complete node enrollment when prompted. The receiving device needs Tailscale and a network policy permitting the connection. Use the exact returned URL; same-name add replaces service settings, so repeat every intended option when changing it.

From a permitted receiving device:

bash
MODEL_URL='PASTE_THE_EXACT_URL_RETURNED_BY_TSLINK'
curl "$MODEL_URL/api/tags"
Your client's settingValue
Ollama server URLThe returned HTTPS origin
Native Ollama API baseThe returned origin plus /api
OpenAI-compatible baseURLThe returned origin plus /v1

Choose an installed model name. Ollama supports a subset of OpenAI-compatible API features; check your client's routes and options. A client's API-key field does not replace the Tailscale access check.

Add a web interface or a teammate

The local-ai-suite template registers separate ollama (localhost:11434) and open-webui (localhost:8080) nodes. Use it as an alternative to the manual model entry above:

bash
tslink template apply local-ai-suite
tslink template apply local-ai-suite --yes
tslink url ollama --wait
tslink url open-webui --wait

Preview first; templates preserve existing entries. Install and configure both applications separately, including Open WebUI's model connection. Recipes offer additional app advice through tslink apps list.

To share a private model service with another person for an hour, use people grants:

bash
tslink people add alice@example.com --apps model --for 1h

Use ollama instead of model if you chose the template. The first people grant scopes that app; configure your own access too.

Keep the data path intentional

TSLink does not load models, implement RAG, index documents or prevent outbound requests. A localhost Ollama API can use a cloud model; a remote agent may process received data elsewhere. Select local models, data stores and application logging according to the data's sensitivity.

TSLink's MCP manages shares; configure agent inference separately with the model address. For an agent on another host, tailnet reachability is still required. Keep model APIs private: Funnel has no TSLink caller identity gate.

HTTP response streaming is supported. Uploads default to a 32 MiB body cap and a 30-second inactivity window, not a total inference deadline. Larger inputs need intentional request limits; backend and client limits also apply.

Related: Agent/MCP setup · Health checks.

Sources: TSLink local AI guide, Ollama model list, Ollama API compatibility.

Table of Contents