Sovereign alternative to Tailscale
Tailscale made mesh VPNs simple, but your network coordination lives on a US-operated server. Headscale speaks the same protocol with the official Tailscale clients, and Bunker hosts its control plane in Europe, on your dedicated instance.
Tailscale builds a private mesh network on top of WireGuard: traffic flows directly, encrypted, machine to machine. What stays centralized is the control plane, the coordination server that hands out the network map, the public keys and the access rules. That server is operated by Tailscale, a US company, and it cannot be self-hosted.
Headscale is the open-source implementation of that coordination server. It talks to the official Tailscale clients, unmodified. Bunker hosts it in Europe, on a dedicated instance: the network map, the device identities and the access rules stay under your control, out of reach of the CLOUD Act.
Point-by-point comparison
| Criterion | Headscale (Bunker) | Tailscale |
|---|---|---|
| Control plane (coordination) | Hosted in Europe by Bunker | SaaS operated by Tailscale (United States) |
| CLOUD Act exposure (network metadata) | Out of reach | Subject (US publisher) |
| Coordination server | Open source (Headscale), self-hostable | Proprietary, not self-hostable |
| Clients (macOS, Windows, Linux, mobile) | Official Tailscale clients, unchanged | Official Tailscale clients |
| Traffic encryption | End-to-end WireGuard | End-to-end WireGuard |
| ACLs, MagicDNS, subnet routers, exit nodes | Yes | Yes |
| Devices and users | No plan cap | Capped on the free tier, plan-based above |
| Dedicated instance | Yes | No, shared control plane |
| On-premise reversibility | Yes, re-internalizable | No |
Where your network coordination lives
With a mesh VPN, two machines end up talking directly, over encrypted WireGuard. But to find each other, they first query a coordination server: it holds the network map, the public keys and the access rules. At Tailscale, that server is operated in the United States. Your network metadata, namely which devices exist, who reaches whom, which routes are open, is centralized there.
Headscale plays that role in open source, and Bunker hosts it in Europe on an instance reserved for you. The network map and the device identities stay in a sovereign infrastructure, with no subprocessor under US jurisdiction.
Sovereignty is decided at the control plane
One point for an honest comparison: in both cases your data flows peer to peer, encrypted by WireGuard, and never passes in clear through a central server. Sovereignty is therefore decided elsewhere, at the control plane.
That control plane concentrates sensitive information: the inventory of machines, the access policies, the topology of your information system. Handed to a US publisher, it falls under the CLOUD Act. Hosted in Europe by Bunker, it stays out of that reach. This is exactly the role of our sovereign Zero Trust network.
When Tailscale still makes sense
Tailscale keeps real strengths: an immediate setup, a polished console, the newest features available on release day, and a generous free tier for personal use or a small team. To prototype fast, with no sovereignty requirement, it is an excellent choice.
Managed Headscale becomes the right call as soon as the control plane must stay in Europe, you want a dedicated instance with no device cap, and the guarantee to bring everything back onto your own infrastructure when the time comes. You keep the Tailscale clients your teams already know.
Frequently asked questions
Is Headscale compatible with the Tailscale clients?
Yes. Headscale is the open-source implementation of the Tailscale coordination server. Your machines use the official Tailscale apps (macOS, Windows, Linux, iOS, Android), configured to point at the Headscale control plane hosted by Bunker. Nothing to rewrite on the client side.
How is this more sovereign than Tailscale?
Traffic is WireGuard-encrypted in both cases. The difference is the control plane: at Tailscale it is operated in the United States and subject to the CLOUD Act; at Bunker it is hosted in Europe, on a dedicated instance, with no subprocessor under US jurisdiction. The network map, the identities and the access rules stay in Europe.
Can I take my network back if I leave Bunker?
Yes. Headscale is open source, so you can reinstall the control plane on your own infrastructure and move your devices over. No proprietary format, no lock-in: that is the principle of our re-internalizable cloud.
Your Zero Trust network, coordinated in Europe
Dedicated Headscale control plane, standard Tailscale clients, no non-EU dependency.
Bunker is not affiliated with Tailscale. "Tailscale" is a trademark of its publisher, referenced here for comparison to designate the competing service.