---
title: "什么时候需要 TSLink？只用 Tailscale 与使用 TSLink 的对比"
description: "一个应用用 Tailscale Serve 就够了。对比 Services、应用名称、人员临时访问和浏览器链接，了解 TSLink 的配置要求与适用边界。"
url: "https://tslink.md/zh/docs/when-to-use-tslink"
locale: "zh"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/comparison.md"
---

> Documentation index: https://tslink.md/zh/llms.txt · Installed binary is authoritative: `tslink manifest`.

场景指南：[分享一个应用，而非整台机器](https://tslink.md/zh/docs/share-one-app.md)。

在自己的设备上访问一个应用，Serve 就够了。如果你希望在一台主机的 CLI/MCP 工作流中统一管理每个应用的节点、HTTP/文件的人员访问期限、带门禁的浏览器链接、portal 和后端健康检查，可以考虑 TSLink。Services 和 Tailscale 的 JIT 方案已经解决了其中一部分需求。

TSLink 文档与源码核对日期：**2026 年 10 月 9 日**，对应 TSLink v0.1.1；Tailscale 官方来源的访问日期见文末。本对比未验证接收者首次使用、真实 tailnet 行为或性能。

## 什么时候只用 Tailscale 就够了

* 只想用自己的手机打开一个网页应用；Serve 已经可以做到。[Serve 示例](https://tailscale.com/docs/reference/examples/serve)。
* 同一设备名下的端口或路径适合你的应用，现有访问策略也适合使用者。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Grants 语法](https://tailscale.com/docs/reference/syntax/grants) · [策略语法](https://tailscale.com/docs/reference/syntax/policy-file)。
* 已经在使用带标签主机和审批流程的 Services，尤其是由多台主机提供同一资源时。[Tailscale Services](https://tailscale.com/docs/features/tailscale-services)。

私有访问需要接收者设备安装 Tailscale，且策略允许这条连接。

## 用手机访问一个应用：Serve 或 share

应用已经运行，Tailscale 和 HTTPS 准备就绪后，`tailscale serve 3000` 就够了。Serve 在前台运行；加上 `--bg` 可以在终端关闭后继续提供服务。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Serve 示例](https://tailscale.com/docs/reference/examples/serve)。

使用 TSLink 时，执行 `tslink share 3000`，完成新应用节点的注册及可能需要的设备审批，再获取它返回的准确 URL。参见[首次私有分享](https://tslink.md/zh/docs/quickstart.md)与[应用管理](https://tslink.md/zh/docs/services.md)。

## 多个应用：端口、路径、Services 或 TSLink 节点

普通 Serve 使用设备名下的端口或路径。Services 提供独立名称，适合由多台主机提供的资源；需要配置服务、带标签主机、端点、审批和策略。TSLink 在同一主机的共享守护进程中，为每个应用运行一个内嵌节点；每个新节点都需要注册。

| 要做的事                     | 只用 Tailscale                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | TSLink                                                                                                                                                                                                                                                                                                         |
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 用自己的手机打开一个网页应用           | 应用、Tailscale 和 HTTPS 准备就绪后，`tailscale serve 3000` 就够了；加上 `--bg` 可在终端关闭后继续服务。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Serve 示例](https://tailscale.com/docs/reference/examples/serve)                                                                                                                                                                                                                                                                                                                                                                                            | `tslink share 3000`；新应用节点需要注册，然后获取它的准确 URL。[分享](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/sharing.md)                                                                                                                                                                                                |
| 三个应用，各有名称                | 普通 Serve 使用设备名，通过不同端口或路径区分。Services 提供独立名称：定义服务、使用带标签主机、配置并通告端点、手动或自动批准主机，并在策略中允许访问。也可使用独立 Tailscale 节点。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Services](https://tailscale.com/docs/features/tailscale-services) · [Docker](https://tailscale.com/docs/features/containers/docker/docker-params)                                                                                                                                                                                                                                                                             | 每个应用执行一次 `share --name` 或 `add`；TSLink 在共享守护进程中为每个应用运行一个内嵌节点。逐个注册新节点；可能需要设备审批。[架构](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/architecture.md) · [入门](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/getting-started.md)                                                                         |
| 让一个人访问一个应用，持续七天          | 邀请对方加入 tailnet，或分享主机；将访问限制到应用节点和端口，并排除更宽泛的匹配授权。普通网络规则没有文档记载的到期字段。可使用有期限的 posture 属性、JIT 自动化或定时移除规则。[邀请用户](https://tailscale.com/docs/features/sharing/how-to/invite-any-user) · [设备分享](https://tailscale.com/docs/features/sharing) · [Grants](https://tailscale.com/docs/reference/syntax/grants) · [策略](https://tailscale.com/docs/reference/syntax/policy-file) · [JIT](https://tailscale.com/docs/features/access-control/just-in-time-access) · [Posture 与 Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [集成](https://tailscale.com/docs/integrations/jit-access)             | `tslink people add alice@example.com --apps photos --for 7d`，适用于已注册的私有 HTTP/文件应用，检查实际 Tailscale 登录账号。网络访问必须已经具备；外部人员需要应用邀请。[人员授权](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/people.md)                                                                                                               |
| 无需 Tailscale 的浏览器链接，持续三天 | Funnel 发布互联网端点；文档中的 CLI 没有到期或访客身份认证参数。添加应用认证或门禁，并安排到期关闭。[Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel 概览](https://tailscale.com/docs/features/tailscale-funnel)                                                                                                                                                                                                                                                                                                                                                                                                            | `tslink guest create photos --for 3d --public --print-link`，适用于已上线且具备 Funnel 权限的 HTTP 代理应用。Bearer 门禁检查期限；可选 `--pin`；可逐个撤销链接。[访客链接](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/guest-links.md)                                                                                                         |
| 撤销访问、查看访问记录和应用健康         | 移除所有匹配权限或设备分享；另行关闭 Funnel。已有配置日志和网络流日志；HTTP 请求历史与应用健康需要应用日志和后端探针。[Grants](https://tailscale.com/docs/reference/syntax/grants) · [策略](https://tailscale.com/docs/reference/syntax/policy-file) · [设备分享](https://tailscale.com/docs/features/sharing) · [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel 概览](https://tailscale.com/docs/features/tailscale-funnel) · [日志](https://tailscale.com/docs/features/logging) · [网络流日志](https://tailscale.com/docs/features/logging/network-flow-logs) · [Docker](https://tailscale.com/docs/features/containers/docker/docker-params) | `tslink people remove alice@example.com`（移除整个人）、`tslink guest revoke <id>`、`tslink access log --app photos`；后台检查后端，可选命令/webhook 通知。访客历史识别的是链接，不是人。[访问历史](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/access-log.md) · [健康检查](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/health-and-alerts.md) |
| 让 AI agent 管理            | Tailscale CLI 和 API 可自动化设备、服务配置及策略操作；与自己选用的期限、应用日志和健康检查流程组合使用。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [API](https://tailscale.com/docs/reference/tailscale-api) · [JIT](https://tailscale.com/docs/features/access-control/just-in-time-access) · [Posture 与 Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [集成](https://tailscale.com/docs/integrations/jit-access)                                                                                                                                                                                | 管理命令接受 `--json`；`tslink mcp` 使用 JSON-RPC，支持 owner 或受限的应用范围角色。可能仍需人工注册。受限角色不能创建应用或访客链接；角色不限制 agent 的 shell。[JSON](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/json-automation.md) · [MCP 范围](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/mcp-scopes.md)                                         |

参见 [TSLink 架构](https://tslink.md/zh/docs/architecture.md)及[包含公开隧道的工具对比](https://tslink.md/zh/docs/comparisons.md)。

## 一个人、一个应用、一个截止时间

Tailscale 策略可将访问限制到应用节点和端口，前提是没有更宽泛的匹配授权放行。普通网络规则没有文档记载的直接到期字段；这是根据公开的 [Grants](https://tailscale.com/docs/reference/syntax/grants) 和[策略语法](https://tailscale.com/docs/reference/syntax/policy-file)得出的结论。

Tailscale 已支持通过有期限的 posture 属性（文档注明适用于 Premium/Enterprise）、Slack Accessbot 示例、API 自动化和第三方集成安排自动截止时间。当前处于 beta 的 Tailscale PAM 也记录了限定范围和期限的特权访问。这些功能覆盖了部分临时访问需求。[JIT 概览](https://tailscale.com/docs/features/access-control/just-in-time-access) · [Posture 期限与 Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit) · [集成](https://tailscale.com/docs/integrations/jit-access) · [PAM](https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam)。

对于已注册的私有 HTTP/文件应用，`tslink people add alice@example.com --apps photos --for 7d` 检查对方实际的 Tailscale 登录账号。网络访问必须已经具备。外部人员需要应用邀请：使用已存储的用户本人 API token，加上 `--invite --print-links`，或手动创建应用分享。每个应用都需要接收者单独接受。通过邮件发送的设备邀请可能被不同的 Tailscale 账号接受，但 TSLink 授权检查实际登录账号。[设备分享](https://tailscale.com/docs/features/sharing)。

`tslink people remove alice@example.com` 移除整个人。到期或移除会拒绝后续 HTTP/文件请求；已接受的流和网络分享可能继续存在。参见[人员分享](https://tslink.md/zh/docs/people-sharing.md)与[期限](https://tslink.md/zh/docs/durations.md)。

## 浏览器访客：Funnel 与到期链接

Funnel 发布互联网端点。文档中的 CLI 没有到期或访客身份认证参数；仍可添加应用认证或门禁，并安排到期关闭。[Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel) · [Funnel 概览](https://tailscale.com/docs/features/tailscale-funnel)。

对于已上线且具备 Funnel 权限的 HTTP 代理应用，`tslink guest create photos --for 3d --public --print-link` 创建带 bearer 门禁及期限的浏览器链接。可添加 `--pin`，或用 `tslink guest revoke <id>` 单独撤销链接。

访客链接是公开、可转发的 bearer 链接。PIN 不证明访客身份。这条浏览器流程不能证明原生客户端兼容性。访客链接撤销或到期会取消请求并关闭流；已经授权的有界请求可能完成。参见[访客链接](https://tslink.md/zh/docs/guest-links.md)。

## 访问历史、后端健康与 portal

Tailscale 提供配置日志和网络流日志；文档注明网络流日志适用于 Premium/Enterprise。HTTP 请求历史需要应用日志，应用健康需要后端探针。Docker 的 `/healthz` 检查节点是否获得 tailnet IP，不检查后端应用响应。[日志](https://tailscale.com/docs/features/logging) · [网络流日志](https://tailscale.com/docs/features/logging/network-flow-logs) · [Docker 参数](https://tailscale.com/docs/features/containers/docker/docker-params)。

`tslink access log --app photos` 显示网关历史；访客历史识别链接，不识别人。TSLink 支持后台后端检查；可选命令/webhook 通知需要配置。可选的私有 portal 列出允许访问的应用、地址、健康状态和期限。参见[访问历史](https://tslink.md/zh/docs/access-history.md)、[健康与告警](https://tslink.md/zh/docs/health-and-alerts.md)及 [portal](https://tslink.md/zh/docs/portal-requests.md)。

## Agent 能通过 CLI 或 MCP 管理什么

Tailscale CLI 和 API 可自动化设备、服务配置及策略操作；与自己选用的期限、应用日志和健康检查流程组合使用。[Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve) · [Tailscale API](https://tailscale.com/docs/reference/tailscale-api) · [JIT](https://tailscale.com/docs/features/access-control/just-in-time-access)。

TSLink 管理命令接受 `--json`；`tslink mcp` 使用 JSON-RPC，支持 owner 或受限的应用范围角色。可能仍需人工注册。受限角色不能创建应用或访客链接，角色也不限制 agent 的 shell。[CLI 参考](https://tslink.md/zh/docs/commands.md) · [MCP 设置](https://tslink.md/zh/docs/mcp-server.md) · [MCP 范围](https://tslink.md/zh/docs/mcp-scopes.md)。

通过本地 MCP 管理 TSLink，与暴露应用的 MCP 端点是不同任务。后者请参照 [MCP 服务托管](https://tslink.md/zh/docs/mcp-hosting.md)及其客户端要求。

## TSLink 不覆盖什么

* 不安装应用、不隔离工作负载，也不提供多主机故障切换；应用节点共享一台发布主机和一个守护进程。
* 不替代 tailnet 策略或应用登录。原始 TCP 使用 tailnet 策略和后端认证；可直接访问的后端及其他公开入口需要各自的保护。
* 不会让访客链接变成私有链接，也不验证访客身份。链接使用公开 HTTPS，即使设置 PIN 也可以转发。

People 到期或移除会拒绝后续 HTTP/文件请求；已接受的流和网络分享可能继续存在。访客链接撤销或到期会取消请求并关闭流；已经授权的有界请求可能完成。两者都无法收回已交付的数据。访问历史记录网关事件，不是覆盖所有后端访问路径的完整审计。

应用配置请分别参考 [Jellyfin](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#jellyfin)、[Immich](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#immich)、[Home Assistant](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#home-assistant)、[Ollama](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#ollama) 和 [Open WebUI](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/apps.md#open-webui) 的配方。保留应用自身登录；浏览器访问不能证明原生播放器、手机备份或上传兼容性。另见[任务示例](https://tslink.md/zh/docs/use-cases.md)与[本地 AI](https://tslink.md/zh/docs/local-ai.md)。

### 来源与访问日期

以下官方文档均于 **2026-10-07** 访问：

* [Serve CLI](https://tailscale.com/docs/reference/tailscale-cli/serve)。
* [Serve 示例](https://tailscale.com/docs/reference/examples/serve)。
* [Tailscale Services](https://tailscale.com/docs/features/tailscale-services)。
* [设备分享](https://tailscale.com/docs/features/sharing)。
* [邀请任意用户](https://tailscale.com/docs/features/sharing/how-to/invite-any-user)。
* [Grants 语法](https://tailscale.com/docs/reference/syntax/grants)与[策略语法](https://tailscale.com/docs/reference/syntax/policy-file)。普通网络规则没有直接到期字段是根据语法得出的结论；仍可使用 posture 期限和应用自定义能力。
* [JIT 概览](https://tailscale.com/docs/features/access-control/just-in-time-access)、[Posture 期限与 Accessbot](https://tailscale.com/docs/features/tailscale-accessbot-jit)、[ConductorOne/Opal 集成](https://tailscale.com/docs/integrations/jit-access)。
* [Tailscale PAM](https://tailscale.com/docs/privileged-access-management/what-is-tailscale-pam)。Beta 可用状态不等于经过验证的首次使用流程。
* [Funnel CLI](https://tailscale.com/docs/reference/tailscale-cli/funnel)与 [Funnel 概览](https://tailscale.com/docs/features/tailscale-funnel)。没有相关参数的说法仅限于已发布的 CLI 参考；仍可使用应用认证。
* [日志概览](https://tailscale.com/docs/features/logging)。
* [网络流日志](https://tailscale.com/docs/features/logging/network-flow-logs)，文档注明适用于 Premium/Enterprise。
* [Docker 参数](https://tailscale.com/docs/features/containers/docker/docker-params)。Docker 的 `/healthz` 检查节点是否获得 tailnet IP，不检查后端应用响应。
* [Tailscale API](https://tailscale.com/docs/reference/tailscale-api)。

TSLink 边界来源：[产品对比](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/comparison.md#boundaries-that-matter-more-than-a-feature-score)。以上产品链接固定到 v0.1.1。
