mirror of
https://github.com/iFargle/headscale-webui.git
synced 2025-12-16 03:29:50 +01:00
169049ace45867495f61fb452c6e186b62671284
…
headscale-webui
This is a simple front-end for a Headscale server.
PR's, questions, bug-fixes, feature requests are welcome!
Allows you to do the following:
- Enable/Disable routes and exit nodes
- Add, move, rename, and remove machines
- Add and remove users/namespaces
- Add and expire PreAuth keys
- Add and remove machine tags
- View machine details
- Hostname
- User associated with the machine
- IP addresses in the Tailnet
- Last seen by the control server
- Last update with the control server
- Creation date
- PreAuth key associated with the machine
- Enable / disable routes and exit nodes
- Add and delete machine tags
Installation:
Docker Compose changes:
- Change the following variables in docker-compose.yml:
- TZ - Change to your timezone. Example: Asia/Tokyo
- HS_SERVER - Change to your headscale's URL
- BASE_PATH - This will be the path your server is served on. Because the Windows Tailscale GUI expects <HS_SERVER/admin>, I usually put this as "/admin"
- KEY - Your encryption key to store your headscale API key on disk. Generate a new one with "openssl rand -base64 32". Do not forget the quotations around the key when entering.
- You will also need to change the volumes:
- /data - Where your encryption key will reside. Can be anywhere writable by UID 1000
- /etc/headscale/ - This is your Headscale configuration file.
- Make sure the host path for /data is readable and writable to UID 1000, otherwise writing the key to disk will fail.
Traefik example with SSL:
- docker-compose labels:
labels:
# Traefik Configs
- "traefik.enable=true"
- "traefik.http.routers.headscale-webui.entrypoints=web-secure"
- "traefik.http.routers.headscale-webui.rule=Host(`headscale.$DOMAIN`) && (PathPrefix(`/$BASE_PATH/`) || PathPrefix(`/$BASE_PATH`))"
- "traefik.http.services.headscale-webui.loadbalancer.server.port=5000"
- "traefik.http.routers.headscale-webui.tls.certresolver=letsencrypt"
- Replace $DOMAIN with your domain and update $BASE_PATH to your BASE_PATH.
- If you do not need SSL, remove the tls.certresolver=letsencrypt line
Nginx example:
- Thanks to @qiangyt for their contributions!
- nginx reverse proxy config:
location /admin {
proxy_pass http://127.0.0.1:5000/admin;
proxy_http_version 1.1;
proxy_set_header Host $server_name;
proxy_buffering off;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
auth_basic "Administrator's Area";
auth_basic_user_file /etc/nginx/htpasswd;
}
Screenshots:
Overview Page:
Users Page:
New Machine Modal:
Machines Page:
Settings Page showing an API Key Test:

Description
Languages
Python
54.2%
JavaScript
27.6%
HTML
16.3%
Dockerfile
1%
CSS
0.9%