Zero Trust VPN with Headscale
Retire the VPN concentrator and the per-user ZTNA bill. A WireGuard mesh your team controls, with the coordination server on your infrastructure.
Overview
Remote access today is either an aging VPN concentrator with a renewal quote and a CVE history, or a zero trust SaaS priced per user per month. Both put a third party between your people and your network: one as a choke point, the other as a control plane you cannot inspect.
Headscale is an open-source, self-hosted implementation of the control server behind the Tailscale WireGuard mesh. Devices connect directly to each other with modern encryption, users keep the familiar official Tailscale apps, and the server deciding who reaches what runs on ZCP in Canada or inside your own environment. ZSoftly designs, implements, and operates it.
What this service covers
- Cost and risk assessment against your current appliance or ZTNA spend
- Headscale deployment on ZCP or your infrastructure, with self-hosted relays
- Migration from legacy VPN concentrators or per-user subscriptions
- SSO and MFA integration, including self-hosted Authentik
- Access policies, audit logging, and managed operations
Sound Familiar?
The remote-access problems that end up on a CISO or CTO desk.
Appliance Renewal Season
The concentrator quote arrived: hardware refresh, per-seat licenses, and support. And it is still the single box every remote packet hairpins through.
VPN CVE in the News
Another emergency patch for an edge appliance. The VPN is your front door, and its CVE history keeps landing on your risk register.
ZTNA Pricing That Scales Wrong
The zero trust SaaS solved access, but the per-user bill grows with every hire and contractor, and your network map lives in a console you do not control.
The Business Case
What changes for your budget, your privacy posture, and your attack surface.
Cost Reduction
One flat infrastructure cost replaces appliance refreshes, per-seat VPN licenses, and per-user ZTNA subscriptions. Contractors, service accounts, and CI runners stop being line items.
Privacy and Sovereignty
The control plane holding your device inventory, users, access rules, and connection logs runs where you decide. No vendor sees your network topology, and residency requirements are met by design.
Smaller Attack Surface
No internet-facing concentrator to exploit. Devices authenticate through your SSO with MFA, connect peer to peer over WireGuard, and reach only what policy allows: least privilege instead of full network access.
How the Options Compare
The three ways to deliver remote access, weighed the way a budget owner weighs them.
| What you are weighing | Legacy VPN appliance | ZTNA SaaS (Tailscale, Twingate, Cloudflare) | Self-hosted Headscale |
|---|---|---|---|
| Cost model | Hardware refresh plus per-seat licenses | Per user, per month, growing with headcount | Flat infrastructure cost, no per-user fees |
| Traffic path | Everything hairpins through one box | Mesh or vendor edge, depending on product | Direct device-to-device WireGuard mesh |
| Who holds your network map | You | The vendor control plane | You |
| Access granularity | Full network once connected | Per-app or per-resource policies | Per-resource ACLs tied to SSO identity |
| Exposed attack surface | Internet-facing appliance with a CVE history | Vendor-operated edge | No inbound ports on user devices; one control server you patch on your schedule |
| Data residency | On premise | Vendor jurisdiction | Your jurisdiction, on ZCP in Canada or your own site |
| User experience | Connect, wait, disconnect | Always-on client apps | The same official Tailscale apps, always on |
Headscale is the open-source implementation of the Tailscale coordination server and works with the official Tailscale client apps. Tailscale Inc. does not sell support for it; ZSoftly provides the implementation and operations.
Where Headscale Fits, and Where It Does Not
The same honest scope line we draw on every platform recommendation. We tell you which tool wins before you commit.
Headscale can replace
- Legacy VPN concentrators for workforce remote access
- Per-user ZTNA and mesh VPN subscriptions
- Site-to-site tunnels between offices, clouds, and data centers
- Jump hosts and bastion VPNs for engineering access
- Per-seat licensing for contractors and service accounts
Keep a dedicated tool for
- Managed SaaS with a vendor SLA and zero operations (Tailscale)
- Full SASE requirements such as web filtering and CASB
- Carrier-grade site-to-site routing at BGP scale
- Tailscale-only extras such as Funnel public sharing
How the Engagement Runs
The old VPN stays up as a fallback until the last wave lands. No cliff-edge cutover.
Assess
Phase 1We map remote access as it stands: appliances, licenses, and who connects to what. You get a cost and risk comparison against the renewal you are trying to avoid.
Pilot
Phase 2Headscale deploys alongside the current VPN. A pilot group connects with the standard Tailscale apps through your SSO. Nothing cuts over yet.
Migrate
Phase 3Teams and sites move in waves, with access policies applied as they land. The old VPN stays as fallback until the final wave, then retires.
Operate
OngoingWe patch, monitor, and support the mesh, or hand your team the runbooks. Access reviews come from the policy file, not a spreadsheet.
Questions Your Board Will Ask
Is Headscale production-ready?
Headscale is mature open source under active development, used in production by teams that want a self-hosted control plane, and it speaks the same protocol as the official Tailscale apps your users install. ZSoftly hardens the deployment, keeps it patched, and stands behind it operationally.
How is this different from buying Tailscale?
Same client apps, same WireGuard mesh. The difference is where the control plane lives and how it is billed. Tailscale runs it as SaaS priced per user; Headscale runs on your infrastructure at a flat cost, and your device inventory, access rules, and connection logs never leave it.
What do employees experience?
They install the standard Tailscale app, sign in through your SSO with MFA, and their tools work. No connect button, no split-tunnel tickets, and access follows their role.
What happens if the control server goes down?
Existing connections keep working; devices talk directly to each other and cached policies stay enforced. New device sign-ins wait until it returns. We deploy with backups, monitoring, and a documented recovery path sized to your tolerance.
Can it use our existing identity provider?
Yes. Headscale delegates login to any OIDC provider, so access rides on your existing SSO and MFA. Pair it with self-hosted Authentik and the whole access stack, identity and network, runs on infrastructure you own.
Put a Number on Retiring Your VPN
Bring your appliance renewal or ZTNA invoice. The assessment shows the flat-cost alternative and the migration path.