Open source · AGPL · one binary
Unleash your Containers
as Tailscale Services
Add labels to your Docker containers. DockTail handles the rest.
Native Tailscale Services · not per-container devices · same tailnet ACLs
services:
myapp:
image: nginx:latest
# No ports needed!
labels:
- "docktail.service.enable=true"
- "docktail.service.name=myapp"
- "docktail.service.port=80" DockTail vs alternatives
DockTail gives Docker containers the native Tailscale Services model without turning each app into another Tailscale device.
| DockTail | TSDProxy | ScaleTail | tsbridge | Plain Services | |
|---|---|---|---|---|---|
| Native Tailscale Services | ✅ | ❌ | ❌ | ❌ | ✅ |
| Configured via Docker labels | ✅ | ✅ | ❌ | ✅ | ❌ |
| Apps do not consume separate Tailscale device slots iDockTail advertises apps as services from one tagged host instead of creating a separate Tailscale device identity per app. Exact plan limits depend on Tailscale. | ✅ | ❌ | ❌ | ❌ | ✅ |
| No app port publishing | ✅ | ⚠️iDepends on proxy and Docker network setup. | ⚠️iDepends on the sidecar template and app network setup. | ⚠️iDepends on proxy and Docker network setup. | ⚠️iYou configure how the service host reaches the backend yourself. |
| Automatic Docker reconciliation | ✅ | ✅ | ❌ | ✅ | ❌ |
| Low manual setup after install | ✅ | ✅ | ⚠️iScaleTail is template-based, so each app usually starts from its own Compose recipe. | ✅ | ❌ |
Features
Auto Discovery
Monitors Docker events in real-time. Start a labeled container and it appears on your Tailnet within seconds.
Direct IP Proxy
No port publishing required. Routes directly to container IPs on the Docker network, adapting automatically on restart.
Funnel Support
Expose any container to the public internet via Tailscale Funnel. One label takes you from private to public.
How it works
Add docktail.* labels to your container
DockTail detects and advertises to Tailscale
Access via http://service
Stop checking if it's still up.
Monitor every DockTail host and service from one dashboard. Cloud reads local checks, Docker events, and Tailscale control-plane state together to name the layer that broke — the container, its exposure on the tailnet, or the host — not just that something's down.
Diagram: DockTail Cloud watches every hop of a published service — host, container, local reachability, and tailnet exposure — across every host in the fleet.
- host up heartbeat · vitals
- container oom killed docker event
- local refused tcp check :3000
- tailnet approved control plane
OOM-killed by Docker, exit 137. The tailnet still advertises the service, so re-publishing it changes nothing. 40 log lines captured at the moment of failure.