Agent skill

Headscale Deploy

by magnus919 in magnus919/agent-skills

Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker.

MITAuto-check: notesDevOps & Cloud

Install Headscale Deploy

skills CLI
$ npx skills add magnus919/agent-skills --skill headscale-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills headscale-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tailscale/skills/headscale-deploy .claude/skills/headscale-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
headscale-deploy
GitHub stars
116
Token cost
~1.3k tokens
SKILL.md length
481 words
Files
6 (incl. scripts)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker.

  • Works in 6 steps: Detecting platform (linux/amd64,… → Downloading the release tarball from… → Installing the binary to /usr/local/bin → …
  • Setting up a new Headscale instance
  • SKILL.md covers Overview, Prerequisites, Deployment Methods and Configuration, plus 4 more sections
  • Runs Shell scripts from its folder; calls curl and docker

What it does

Headscale Deploy is an agent skill from magnus919/agent-skills. Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker. Use when setting up a new Headscale instance, troubleshooting deployment issues, or configuring server settings.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `README.md`, `evals/evals.json` and `scripts/configure-derp.sh`). Compatibility notes: linux, docker

It sits in DevOps & Cloud, covering Deployment and Containers. It works with Linux and Docker. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Setting up a new Headscale instance
  • Troubleshooting deployment issues
  • Configuring server settings

Example prompts

  • “/headscale-deploy”

Requirements

  • A Bash shell
  • Docker
  • Compatibility (from SKILL.md): linux, docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Detecting platform (linux/amd64, linux/arm64)
  2. Downloading the release tarball from GitHub
  3. Installing the binary to /usr/local/bin
  4. Creating the headscale system user
  5. Writing a systemd unit file
  6. Creating default config at /etc/headscale/config.yaml

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    linux, docker

    From compatibility in the SKILL.md frontmatter.

Context cost

Headscale Deploy loads about 1.3k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 481 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:27
    - Root or sudo access on the target machine

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 481 words, ~1,252 tokens.

Download SKILL.mdSave it as .claude/skills/headscale-deploy/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
headscale-deploy
description
Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker. Use when setting up a new Headscale instance, troubleshooting deployment issues, or configuring server settings.
compatibility
linux, docker
license
MIT
metadata.tags
headscale, tailscale, wireguard, vpn, deployment, devops
metadata.spec-version
1.0

headscale-deploy

Overview

Headscale is an open-source, self-hosted implementation of the Tailscale control server. It allows you to run your own coordination plane for WireGuard-based mesh networking, giving you full control over your tailnet without relying on Tailscale's SaaS infrastructure. The Tailscale client connects to Headscale transparently — no client modifications needed.

Use this skill to deploy Headscale from scratch, configure server settings, manage DERP relay infrastructure, and diagnose deployment issues.

Prerequisites

  • Linux server (x86_64 or aarch64) or Docker host with compose support
  • DNS record pointing to the server (A/AAAA record for server_url)
  • Ports 80/443 accessible from the internet (or your tailnet's ingress point)
  • Port 3478/udp for STUN (optional, needed for NAT traversal)
  • Root or sudo access on the target machine

Deployment Methods

The fastest and most maintainable approach. Use install-headscale.sh with --docker flag to generate a compose file and systemd drop-in, or create manually:

yaml
version: "3.9"
services:
  headscale:
    image: headscale/headscale:latest
    container_name: headscale
    restart: unless-stopped
    ports:
      - "8080:8080"
      - "3478:3478/udp"
    volumes:
      - ./data:/var/lib/headscale
      - ./config:/etc/headscale
    command: headscale serve
Binary Install

Direct binary installation on the host for lightweight or container-free environments. The install-headscale.sh script handles:

  1. Detecting platform (linux/amd64, linux/arm64)
  2. Downloading the release tarball from GitHub
  3. Installing the binary to /usr/local/bin
  4. Creating the headscale system user
  5. Writing a systemd unit file
  6. Creating default config at /etc/headscale/config.yaml

Configuration

Key config.yaml options:

OptionDescriptionExample
server_urlPublic URL of your Headscale instancehttps://headscale.example.com:443
listen_addrLocal bind address0.0.0.0:8080
metrics_listen_addrPrometheus metrics endpoint127.0.0.1:9090
dns_config.base_domainMagicDNS domain suffixexample.com
dns_config.magic_dnsEnable MagicDNStrue
derp.server.enabledEnable embedded DERP relayfalse
derp.server.region_idNumeric region ID999
derp.server.region_nameHuman-readable region name"my-headscale"
derp.urlsExternal DERP map URLs[]
db_typeDatabase backend: sqlite3 or postgressqlite3
tls_letsencrypt_hostnameAuto TLS via Let's Encrypt""
tls_cert_path / tls_key_pathManual TLS cert paths""

Verification

After deployment, verify the instance is healthy:

bash
# Quick health check
curl -s https://headscale.example.com/health

# Comprehensive diagnostics
headscale-health-check.sh --json

# Check registered nodes
headscale nodes list

# Verify API access
headscale apikeys list
Show full SKILL.md (200 more words)Show less

Gotchas

  • SQLite vs PostgreSQL: SQLite is fine for small tailnets (<100 nodes). For larger deployments or high-availability, use PostgreSQL. Plan your choice upfront — migration is non-trivial.
  • TLS certificate management: Let's Encrypt auto-provisioning is convenient but requires port 80 to be accessible for the HTTP-01 challenge. Use a reverse proxy (Caddy, Nginx, Traefik) for more flexibility.
  • Port conflicts: If port 8080 or 3478 is already in use, change listen_addr in config. Ensure no other service binds port 3478/udp for STUN.
  • DERP configuration: The embedded DERP relay works for small deployments. For production, set up dedicated DERP nodes to avoid single-region bottlenecks.
  • Configuration reload: Headscale does not hot-reload config. Restart the service after config changes: systemctl restart headscale or docker compose restart.
  • Database backups: Always back up /var/lib/headscale/db.sqlite3 (or your PostgreSQL DB) regularly.

Trigger Conditions

Use this skill when the user says any of:

  • "deploy headscale"
  • "install headscale"
  • "setup headscale server"
  • "headscale config"
  • "headscale configuration"
  • "headscale deployment"
  • "headscale health"
  • "headscale derp"
  • "self-hosted tailscale"
  • "tailscale control server"

When not to use

Do not use this skill for client-side setup (load tailscale-client instead), for ACL/policy authoring (load tailnet-policy), or for day-to-day management of an already-running server. It covers initial deployment and server configuration only.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in tailscale/skills/headscale-deploy of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • scripts/configure-derp.sh
  • scripts/headscale-health-check.sh
  • scripts/install-headscale.sh

Open the folder on GitHubat commit c545c2b

Compare with similar skills

Headscale Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Headscale Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Headscale Deploy this skillmagnus919/agent-skills116—~1.3kAutomated safety check: NotesMIT
Setup Workshopbrevdev/workshop-build-an-agent146—~2.3kAutomated safety check: NotesApache-2.0
Investigate Production Container Restartsblotcms/blot2k—~4.7kAutomated safety check: PassAGPL-3.0
Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package188—~2.4kAutomated safety check: NotesMIT
Self-Hosted n8n Deploymentczlonkowski/n8n-skills6.4k—~3.5kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0

Similar skills

  • Setup Workshop

    brevdev/workshop-build-an-agent

    This skill should be used when the user wants to set up, install, deploy, bootstrap, or "spin up" the Build-an-Agent workshop (a.k.a.

    146 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Work out why the blot-container-{blue,green,yellow} Docker containers from the most recent production deployment have restarted — distinguishing a normal deploy-triggered restart from a crash (V8…

    2k GitHub stars~4.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frappe Ops Deployment

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.

    188 GitHub stars~2.4k tokensUpdated 22 days ago
    DevOps & CloudAuto-check: notes
  • Self-Hosted n8n Deployment

    czlonkowski/n8n-skills

    Deploys a production n8n instance to a fresh Linux server over SSH with Docker Compose and Caddy HTTPS, in single or queue mode, and covers updates, backups and hardening.

    6.4k GitHub stars~3.5k tokensUpdated 23 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Headscale Deploy

What does Headscale Deploy do?

Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker. Headscale Deploy is an agent skill from magnus919/agent-skills. Deploy, configure, and maintain a self-hosted Headscale control server on Linux or Docker.

When should I use Headscale Deploy?

Headscale Deploy fits situations like: setting up a new Headscale instance; troubleshooting deployment issues; configuring server settings.

How do I install Headscale Deploy in Claude Code?

Run `npx skills add magnus919/agent-skills --skill headscale-deploy -a claude-code`. Or copy the skill folder (tailscale/skills/headscale-deploy in magnus919/agent-skills) into .claude/skills/headscale-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Headscale Deploy in Codex?

Run `npx skills add magnus919/agent-skills --skill headscale-deploy -a codex`. Or copy the skill folder (tailscale/skills/headscale-deploy in magnus919/agent-skills) into .agents/skills/headscale-deploy in your project. Codex loads it when a task matches its description.

Can I use Headscale Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill headscale-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/headscale-deploy, .gemini/skills/headscale-deploy, .github/skills/headscale-deploy and .opencode/skills/headscale-deploy in your project.

What does Headscale Deploy need to run?

Going by SKILL.md and its folder, Headscale Deploy needs a shell for the scripts in its folder and the command-line tools its instructions call (curl and docker). Our summary lists: A Bash shell; Docker. Compatibility (from SKILL.md): linux, docker.

Does Headscale Deploy access the network?

SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Headscale Deploy safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Headscale Deploy use?

Headscale Deploy is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Headscale Deploy use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Headscale Deploy?

Skills that share tags, products or a category with Headscale Deploy: Setup Workshop (brevdev/workshop-build-an-agent, 146 stars), Investigate Production Container Restarts (blotcms/blot, 2k stars), Frappe Ops Deployment (Impertio-Studio/Frappe_Claude_Skill_Package, 188 stars) and Self-Hosted n8n Deployment (czlonkowski/n8n-skills, 6.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Headscale Deploy?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.