Agent skill

Headscale Node Lifecycle

by magnus919 in magnus919/agent-skills

Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes.

MITAuto-check passed

Install Headscale Node Lifecycle

skills CLI
$ npx skills add magnus919/agent-skills --skill headscale-node-lifecycle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills headscale-node-lifecycle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tailscale/skills/headscale-node-lifecycle .claude/skills/headscale-node-lifecycle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
headscale-node-lifecycle
GitHub stars
111
Token cost
~1.3k tokens
SKILL.md length
555 words
Files
7 (incl. scripts)
Skills in repo
129
Repo updated
First seen
Licence
MIT

At a glance

Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes.

  • Works in 3 steps: Web auth — user visits a URL to… → Pre-authenticated key (auth key) — a… → CLI / API — direct node registration via…
  • Adding new devices
  • SKILL.md covers Overview, Pre-authenticated Keys, Node Registration and Node Listing, plus 7 more sections
  • Runs Shell scripts from its folder; needs HEADSCALE_API_KEY

What it does

Headscale Node Lifecycle is an agent skill from magnus919/agent-skills. Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes. Use when adding new devices, generating auth keys for automation, or managing node inventory.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `evals/evals.json` and `scripts/hs-approve-nodes.sh`).

The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Adding new devices
  • Generating auth keys for automation
  • Managing node inventory

Example prompts

  • “/headscale-node-lifecycle”

Requirements

  • A Bash shell
  • A credential in HEADSCALE_API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Web auth — user visits a URL to authenticate with an OIDC/OAuth provider
  2. Pre-authenticated key (auth key) — a one-time or reusable key generated by the admin that embeds tags, user, and expiry
  3. CLI / API — direct node registration via headscale commands or REST API calls

What it can do on your machine

Read from SKILL.md and the folder at commit 96fbe07. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HEADSCALE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Headscale Node Lifecycle loads about 1.3k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 555 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 96fbe07, republished under its MIT licence (© magnus919). 555 words, ~1,293 tokens.

Download SKILL.mdSave it as .claude/skills/headscale-node-lifecycle/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
headscale-node-lifecycle
description
Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes. Use when adding new devices, generating auth keys for automation, or managing node inventory.
metadata.category
devops

headscale-node-lifecycle

Overview

Headscale manages nodes in a tailnet with two identity models:

  • Personal nodes — registered under a specific user account (e.g. yourname@domain). The node key is tied to that user's identity.
  • Tagged nodes — belong to the special tagged-devices user (created automatically by Headscale). These nodes are identified by one or more tags (e.g. tag:webserver, tag:monitoring) and are typically used for infrastructure service nodes.

Registration happens through:

  1. Web auth — user visits a URL to authenticate with an OIDC/OAuth provider
  2. Pre-authenticated key (auth key) — a one-time or reusable key generated by the admin that embeds tags, user, and expiry
  3. CLI / API — direct node registration via headscale commands or REST API calls

Pre-authenticated Keys

Auth keys streamline automated node registration. Key attributes:

ParameterDescription
ExpirationDefault: 1 hour. Use 0 for no expiry (not recommended).
ReusableSingle-use by default. Mark reusable for fleet provisioning.
EphemeralEphemeral nodes are removed from the tailnet when they disconnect. Perfect for CI runners and ephemeral workloads.
TagsAssign tags to create a tagged node automatically.

Node Registration

  • Personal nodes: Create an auth key for a user → run tailscale up --auth-key=<key> on the device → approve in Headscale if registration is open.
  • Tagged nodes: Create an auth key with --tags → run tailscale up --auth-key=<key> → the node is auto-approved and tagged.

Node Listing

List nodes filtered by user, tag, or online status. Output includes:

  • Node ID
  • Name (hostname)
  • Tailscale IP address(es)
  • Assigned tags
  • User/owner
  • Online/offline status
  • Last seen timestamp
  • Operating system
  • Tailscale client version

Node Tagging

Tags can be added or replaced on existing nodes. Tags always carry the tag: prefix in Headscale. When adding tags, existing tags are preserved unless --replace is specified.

Node Deletion

To decommission a node permanently:

headscale nodes delete -i <node-id>

Or via the REST API: DELETE /api/v1/node/<node-id>

Decommissioning is irreversible. For ephemeral nodes, disconnection alone is sufficient — the server removes them automatically.

Environment

VariableDescription
HEADSCALE_URLBase URL of the Headscale server (e.g. https://headscale.example.com)
HEADSCALE_API_KEYAPI key from headscale apikeys create

Both env vars are required for API-based operations when the headscale CLI is not available on PATH.

Show full SKILL.md (213 more words)Show less

Gotchas

  • Auth key expiration: Default is 1 hour. If you're provisioning a device and it takes longer, the key expires and registration fails. Set a longer expiry explicitly.
  • Tagged node user: Tagged nodes always belong to the tagged-devices user. Do not try to assign them to a personal user.
  • Connectivity testing: Nodes must be online (Connected: true) to test connectivity. Offline nodes do not respond to ping/ICMP within the tailnet.
  • CLI vs API: When both are available, the CLI is preferred for interactive use. The REST API is preferred for automation scripts.
  • Key reuse: Reusable keys are convenient but less secure. Use with care, especially in production environments.
  • Ephemeral nodes: Setting --ephemeral means the node is fully removed on disconnection — there is no record of it in the tailnet afterward.

Trigger Conditions

  • "auth key"
  • "preauthkey"
  • "register node"
  • "approve node"
  • "tag node"
  • "node list"
  • "decommission node"

Scripts

hs-create-authkey.sh

Create pre-authenticated keys via Headscale CLI or REST API.

hs-create-authkey.sh --user <user> --tags <tag> --expiration <duration> --reusable --ephemeral [--json] [--dry-run]
hs-list-nodes.sh

List all nodes in the tailnet with status and metadata.

hs-list-nodes.sh [--json] [--user <user>] [--tag <tag>] [--online-only]
hs-approve-nodes.sh

Approve pending node registrations.

hs-approve-nodes.sh [--all] [--auth-id <id>] [--dry-run] [--json]
hs-tag-node.sh

Update tags on an existing node.

hs-tag-node.sh --node <id/name> --tags <tag1,tag2> [--replace | --add] [--dry-run] [--json]

When not to use

Do not use this skill for installing or configuring the Tailscale client (load tailscale-client instead) or for ACL/policy authoring (load tailnet-policy). It covers node registration, tagging, listing, and decommissioning only.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts) in tailscale/skills/headscale-node-lifecycle of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • scripts/hs-approve-nodes.sh
  • scripts/hs-create-authkey.sh
  • scripts/hs-list-nodes.sh
  • scripts/hs-tag-node.sh

Open the folder on GitHubat commit 96fbe07

Compare with similar skills

Headscale Node Lifecycle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Headscale Node Lifecycle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Headscale Node Lifecycle this skillmagnus919/agent-skills111—~1.3kAutomated safety check: PassMIT
ESP32 CSI Node Provisioningruvnet/RuView97k—~579Automated safety check: PassMIT
Gke Node Notreadygoogle/skills21k—~2.9kAutomated safety check: PassApache-2.0
N8n Node Configurationdavila7/claude-code-templates32k1 repos~4kAutomated safety check: PassMIT
Handsontable Node Script Conventionshandsontable/handsontable22k—~1.1kAutomated safety check: PassCustom licence
Brigade Node Connection Diagnosticsspinabot/brigade11k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Builds, flashes and provisions an ESP32-S3 or C6 CSI node for RuView, with checksum-verified flashing, WiFi settings and boot-log evidence that CSI is flowing.

    97k GitHub stars~579 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Gke Node Notready

    google/skills

    Official

    Diagnoses GKE nodes reporting NotReady or Unknown status by inspecting node conditions, events, kubelet/containerd logs, and node metrics, then proposing safe remediations.

    21k GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • N8n Node Configuration

    davila7/claude-code-templates

    Operation-aware node configuration guidance. An agent skill from davila7/claude-code-templates.

    32k GitHub starsUsed in 1 repo~4k tokens
    Productivity & AutomationAuto-check passed
  • Handsontable Node Script Conventions

    handsontable/handsontable

    Conventions for .mjs files in the Handsontable monorepo: native node: imports, top-level await, the tasks.json dispatcher and native modules instead of extra dependencies.

    22k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Diagnoses why a Brigade companion app can't pair or connect, by first identifying the real node-to-gateway route and then fixing auth.

    11k GitHub stars~1.2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Node Check

    SeemSeam/claude_codex_bridge

    Verify one CCB worker node and reject hidden fallback, degradation, scope shrinkage, or missing evidence.

    3.5k GitHub stars~128 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from magnus919/agent-skills

All 129 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    111 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    111 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    111 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    111 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    111 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    111 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Questions about Headscale Node Lifecycle

What does Headscale Node Lifecycle do?

Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes. Headscale Node Lifecycle is an agent skill from magnus919/agent-skills. Manage the full lifecycle of nodes in a Headscale tailnet — generate pre-authenticated keys, register, approve, tag, list, and decommission nodes.

When should I use Headscale Node Lifecycle?

Headscale Node Lifecycle fits situations like: adding new devices; generating auth keys for automation; managing node inventory.

How do I install Headscale Node Lifecycle in Claude Code?

Run `npx skills add magnus919/agent-skills --skill headscale-node-lifecycle -a claude-code`. Or copy the skill folder (tailscale/skills/headscale-node-lifecycle in magnus919/agent-skills) into .claude/skills/headscale-node-lifecycle in your project. Claude Code loads it when a task matches its description.

How do I install Headscale Node Lifecycle in Codex?

Run `npx skills add magnus919/agent-skills --skill headscale-node-lifecycle -a codex`. Or copy the skill folder (tailscale/skills/headscale-node-lifecycle in magnus919/agent-skills) into .agents/skills/headscale-node-lifecycle in your project. Codex loads it when a task matches its description.

Can I use Headscale Node Lifecycle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill headscale-node-lifecycle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/headscale-node-lifecycle, .gemini/skills/headscale-node-lifecycle, .github/skills/headscale-node-lifecycle and .opencode/skills/headscale-node-lifecycle in your project.

What does Headscale Node Lifecycle need to run?

Going by SKILL.md and its folder, Headscale Node Lifecycle needs a shell for the scripts in its folder and credentials named HEADSCALE_API_KEY. Our summary lists: A Bash shell; A credential in HEADSCALE_API_KEY.

Does Headscale Node Lifecycle access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Headscale Node Lifecycle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Headscale Node Lifecycle use?

Headscale Node Lifecycle is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Headscale Node Lifecycle use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Headscale Node Lifecycle?

Skills that share tags, products or a category with Headscale Node Lifecycle: ESP32 CSI Node Provisioning (ruvnet/RuView, 97k stars), Gke Node Notready (google/skills, 21k stars), N8n Node Configuration (davila7/claude-code-templates, 32k stars) and Handsontable Node Script Conventions (handsontable/handsontable, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Headscale Node Lifecycle?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 111 GitHub stars. The repository holds 129 skills in this directory. The repository was last updated on October 6, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.