Skip to content
CAI
Produce a survey ↗Verify a survey

juanfont/headscale

Headscale is an open-source, self-hosted implementation of the Tailscale control plane, managing network topology, authentication, and access policies. It provides a comprehensive API (v1/v2) and CLI for administering users, devices, and keys, while enforcing strict security through OAuth2 and scope-based access control. The system also handles dynamic DNS, route auto-approval, and DERP map management to facilitate secure peer-to-peer connectivity.

64.5

Adequate · 1 August 2026

54k

lines of production code

Go

primary language

2

bus factor · 267 authors in all

3

measurements over time

CAI band scale
CAI trend line

How it got here

2020–2023 · API key management and integration testing

This period focused on implementing secure API key and OAuth2 authentication flows, including database support, type definitions, and CLI commands. The work also established a robust integration testing framework using Docker containers and standardized test utilities, while fixing policy matching and refactoring the DERP map loading logic.

17 changes

2024–2025 · Policy engine and infrastructure modernization

This period focused on overhauling the policy engine with a new v2 implementation and automatic route approval, while simultaneously modernizing the web interface and build infrastructure. Significant improvements were made to node state management, SQLite configuration, and integration testing, alongside the introduction of NixOS packaging support.

15 changes

2026 · API v2 and policy v2 development

This period focused on implementing the v2 API and policy engine, introducing a Huma-based code-first API with OAuth scope enforcement and Tailscale-compatible endpoints. Significant effort was also dedicated to the policy v2 compatibility tests, adding extensive test data for ACLs, routing, SSH, and node attributes to ensure correct behavior.

17 changes

CAI lens gauges

Survey your own repository

juanfont/headscale was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point the surveyor at a repository you know and see whether you agree with it.

Survey a repository

About this page

  • The description of this project is derived from its own commit history, not from its README.
  • The score is its highest published measurement, taken on 1 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 565fd254d0 — the exact code this score is about.
  • Scored under rubric rubric-2026.08.18. Score the same commit under that rubric and you get the same number.
CAI link cards