Free course

Tailscale Course

Build and operate a private Tailscale network with identity, access policies, MagicDNS, SSH, subnet routers, exit nodes, automation, and practical troubleshooting.

7 modules · 35 lessons · No signup

Prerequisites: VPN, Shell Commands, Linux Basics and SSH

~~~

Your progress

of lessons completed.

Course completed.

What you'll learn

Connect a laptop and Linux server, restrict access with grants, publish a private service, add routed resources, automate enrollment, and diagnose the complete path.

Take this course offline

Subscribe to my newsletter to get every free book and course in PDF and EPUB format.

Get the downloads

Course contents

  1. Tailscale foundations

    Understand tailnets, identity, WireGuard, control and data planes, direct paths, and DERP relays.

    1. Understand the problem Tailscale solves
    2. Meet the tailnet
    3. Separate the control and data planes
    4. Understand direct connections and DERP
    5. Check your understanding: tailscale foundations
  2. Connect your tailnet

    Create a tailnet, add a laptop and Linux server, inspect addresses, and use MagicDNS.

    1. Create a practice tailnet
    2. Connect your laptop
    3. Connect a Linux server
    4. Use MagicDNS and test the path
    5. Check your understanding: connect your tailnet
  3. Control access

    Replace broad connectivity with grants, groups, tags, tests, and least-privilege rules.

    1. Move from connectivity to authorization
    2. Write your first grant
    3. Organize people and services
    4. Test policy before trusting it
    5. Check your understanding: control access
  4. Services and SSH

    Reach private services, configure Tailscale SSH, use Serve, and choose sharing boundaries.

    1. Keep a service private
    2. Configure Tailscale SSH
    3. Require reauthentication for sensitive SSH
    4. Choose Serve, sharing, or Funnel
    5. Check your understanding: services and ssh
  5. Subnets and exit nodes

    Advertise private routes, approve them, route Internet traffic, and avoid route and DNS surprises.

    1. Understand subnet routers
    2. Advertise and approve a subnet route
    3. Understand exit nodes
    4. Configure and test an exit node
    5. Check your understanding: subnets and exit nodes
  6. Automation and device trust

    Enroll servers safely with auth keys, tags, expiry, approval, OAuth clients, and revocation.

    1. Choose an authentication method
    2. Enroll a tagged server safely
    3. Use OAuth clients for repeated automation
    4. Manage expiry and device approval
    5. Check your understanding: automation and device trust
  7. Operate and choose

    Diagnose paths, maintain the tailnet, respond to device loss, and choose when Tailscale fits.

    1. Troubleshoot by layer
    2. Interpret direct and relayed performance
    3. Operate the tailnet safely
    4. Choose when Tailscale fits
    5. Check your understanding: operate and choose