safe way home
WoowTech · Sales Handbook

Safe way home, no open ports: two Tailscale delivery options

Remote access to Home Assistant, several sites linked together, your home cameras and NAS wherever you go — all built on the Tailscale private network, with no port to open on the router and no entry point into your home exposed to the internet. Choose Option A (self-hosted) or Option B (managed by WoowTech).

0
router ports to open
2
deployment options
100%
private network, end-to-end encrypted

Why your home needs Tailscale

If you have ever opened Home Assistant at home from a phone while you were out, you have probably run into three things: a monthly Nabu Casa bill, router port forwarding that gets scanned the moment you open it, and a DDNS plus reverse proxy setup you no longer dare to touch once it works. Every one of them has a whiff of leaving your home's entry point "out on the public internet".

Tailscale takes another route: install a lightweight client on your phone, your laptop and the Home Assistant host, and they form a private network that is yours alone (a tailnet). You never open a single router port, packets are encrypted end to end (WireGuard), and every device finds the others through a short URL that is easy to remember (MagicDNS).

Concept: The Tailscale free plan is already enough for one family — but once you want ACL-based access control, a subnet router that brings in the whole LAN, Serve to give HA an HTTPS short URL, and several sites linked together, you find that the tool is one thing and the work of configuring it is another. That is why you may want someone to deliver it for you.

Self-hosted or managed: two options at a glance

Option A (self-hosted) runs on your HAOS system and is handed over for you to operate. Option B (managed by WoowTech) includes its control plane (which manages your device list):

Option A (self-hosted)

You buy a host that runs Home Assistant OS (a Home Assistant Yellow or Green, or one you build yourself). We come to your home or log in remotely, install the built-in Tailscale add-on, set up ACL / subnet router / Serve / MagicDNS correctly, and hand you the keys at the end. The control plane is the official Tailscale.com.

Good for: a single household, one site, and anyone who wants the official Tailscale SaaS without touching policy hujson themselves.

Option B (managed by WoowTech)

No official Tailscale.com. You open a tenant on the private Headscale coordination server WoowTech runs (on *.woowtech.io), and your devices still connect with the open-source Tailscale client. The device count is not capped by the Tailscale free 3-user / 100-device limit, which makes multiple sites and multiple routes easier to arrange.

Good for: a SOHO business, anyone who wants to stay in control, several sites (home + studio + a relative's house), more than 3 family members or 100 devices, and anyone who would prefer not to hand the device list to a US vendor.

Tip: You do not have to choose between Option A (self-hosted) and Option B (managed by WoowTech) permanently — run Option A (self-hosted) for three months and move to Option B (managed by WoowTech) later if you want (the tailnet policy can be converted across, and each device has to join again). When we deliver, we back up the policy as a document.

Option A (self-hosted)

You host the HAOS Tailscale add-on on your own system. WoowTech handles the initial setup and hands it over for you to operate with the official Tailscale service. Every item below is included in that setup.

What you get

We install the Tailscale add-on, start it and join the tailnet; the HA host gets a proper device name (for example ha-home).
MagicDNS on — your phone opens https://ha-home and you are in, with no IP address to memorize.
Serve configured — HA gets a short URL with a valid HTTPS certificate (for example https://ha-home.tail-scale.ts.net), so the browser no longer flags it "Not secure".
Subnet router advertised and approved — a phone on the tailnet reaches the cameras, NAS and printer on 192.168.1.x directly.
The ACL policy hujson written out — parents can only open HA, the kids cannot touch the NAS, a contract engineer can only reach the Zigbee gateway, one rule at a time.
Key expiry, device approval and tag policy — an expired login drops off by itself, and a new device only joins once you approve it.
Handover documents: a map of your tailnet, an explanation of the policy, and the recovery steps.

What you pay for

The Tailscale free plan (Personal plan) is enough for the vast majority of households: 3 users, 100 devices, unlimited traffic. There is no monthly fee on top.

Concept: What WoowTech sells is the service of getting Tailscale right for you, not Tailscale itself. The control plane still belongs to Tailscale the company; for their privacy policy and terms of service, go by the official documents.

Option B (managed by WoowTech)

Headscale is the open-source version of the Tailscale control plane. We maintain a Headscale server for you on *.woowtech.io; you open an account on it and you have a private tailnet of your own — while the traffic and the data stay encrypted end to end over direct peer-to-peer connections, and never pass through a WoowTech data center.

What you get

A private tenant (for example your-name.hs.woowtech.io). We join Home Assistant for you and prepare the preauth keys for the phones and laptops.
The same ACL policy, subnet router, MagicDNS and Serve work — what you get is all but identical to Option A (self-hosted), except that the control plane is managed by WoowTech.
No cap on the device count — home, studio, a relative's house and every family phone linked up at once, without the official Tailscale ceiling of 3 users.
The DERP relay runs on WoowTech's own nodes (low latency in <relay region — owner confirmation required>), and it can be configured to fall back to the public Tailscale DERP.
Cross-site subnet router topology: the tailnet at home can see the studio LAN and the other way round, with a policy fine-grained enough to say that the studio NAS is reachable only from the laptop in the study at home.
Handover documents: a Headscale CLI quick reference, the tenant export and backup steps, and the disaster recovery SLA.

What you pay for

A monthly or yearly subscription, covering Headscale tenant operations, the DERP relay, 24/7 monitoring and version upgrades. The actual figures depend on how many devices you have and which SLA level you pick; ask WoowTech or your reseller.

Why choose Headscale? Three common reasons: (1) the free Tailscale limit of 3 users is not enough for separate family and studio accounts; (2) you need a production-grade subnet router topology across several physical sites; (3) you would rather not keep your device list in a US vendor's database. If any one of the three applies, Option B (managed by WoowTech) is worth considering.

Typical scenarios

Three real households, so you can find the one that matches yours.

1. A single-family house, one site

Parents who have retired and moved back to their hometown, a Home Assistant Green on the TV cabinet, two phones and one laptop. They want to turn on the air conditioning and check the door camera while they are out, without paying the Nabu Casa monthly fee and without daring to open a port.

Typical customerPicks Option A (self-hosted): one delivery fee, and after that the official Tailscale free plan up to its full allowance.

2. A SOHO business owner in two places: home + studio

Daytime at the studio, where there is a NAS holding client files, a printer, and the IoT cameras of the cafe downstairs. At home there is HA, the security cameras and the parents' iPad. They want to pull files off the studio NAS from home, watch the home cameras from the studio, and see both sites' HA on one dashboard.

Typical customerPicks Option B (managed by WoowTech): a subnet router at each of the two sites, and a policy that says only the owner may cross between sites. The free plan does not have room for this many devices.

3. Three generations under one roof + a home studio

Three Home Assistant installs — the parents' house, their own house and an older relative's house — plus a partner's craft studio (a NAS, a printer, no public IP). They want all three houses' HA on one dashboard, and to be able to see each other's cameras in an emergency.

Typical customerPicks Option B (managed by WoowTech): 4 sites and 10+ family devices do not fit in the official free plan at all; a private Headscale has no such limit.

Security and privacy

Tailscale's security design rests on two things: WireGuard end-to-end encryption (which not even we can decrypt) and an ACL that is closed by default under least privilege (unless you say a connection is allowed, devices cannot see each other). Our managed-delivery process actually puts both in place.

  • No open ports: we do not touch a single port on the router. Seen from the internet, your IP address has nothing open at all.
  • Least privilege by default: the policy as delivered already says parents can only open HA and a contract engineer only touches the part they are responsible for. We do not take the shortcut of allowing everything.
  • Key expiry on: a phone or laptop that has not logged in for 90 days drops off by itself, so when you change phones you need not worry about the old device still being on the list.
  • Device approval on: a new device only gets in once you approve it in the admin console. That stops a stranger who has an auth key from joining the tailnet.
  • Serve, not Funnel: the HTTPS short URL for HA is tailnet-only, so HA never ends up on the public internet by accident.
  • Option B (managed by WoowTech) extras: the control plane itself runs on WoowTech's private servers (two nodes, Singapore and Taiwan), the database is backed up daily and encrypted, and if you cancel we hand you a full export.

Compared with the alternatives you may be considering

Nabu Casa Router port forwarding WoowTech Tailscale option
Cost structure A monthly fee, for as long as you want remote access Free, but you buy an SSL certificate and do the research Option A (self-hosted): a one-off setup fee; Option B (managed by WoowTech): a monthly fee that includes operations
Exposed to the internet Relayed through Nabu Casa, not directly exposed Directly exposed — scanned, and passwords guessed at Not exposed at all, encrypted end to end
Multi-site connectivity Not possible Set up site by site, with a policy that is hard to manage Native to Option B (managed by WoowTech), with the policy managed in one place
Reach your NAS/cameras Only relayed through HA A port opened for every device (extremely dangerous) A subnet router brings in the whole LAN at once
HTTPS short URL for HA Yes (*.ui.nabu.casa) You build the reverse proxy plus Let's Encrypt yourself Serve gives you a valid HTTPS certificate automatically, on a short URL that is easy to remember
Works for non-technical family Yes, close to one click Almost never Install the Tailscale app, scan a QR code and you are in

Pricing and delivery process

The price depends on the number of sites, the number of devices, how complex the ACL is, and whether on-site installation is included. What follows gives you a sense of the order a managed delivery runs in; for the actual figures, ask WoowTech or your reseller.

  1. Discovery call (30 minutes, free)

    How many sites, how many people in the household, which NAS / cameras / printers you want to bring in, whether you want to share with friends. By the end of the call we decide between Option A (self-hosted) and Option B (managed by WoowTech).

  2. Quote and statement of work

    It lists what we deliver, the SLA, what you provide (access to HA, the list of family members, admin rights on the router), and the acceptance criteria.

  3. Remote or on-site installation (half a day)

    Option A (self-hosted) can usually be finished remotely; if Option B (managed by WoowTech) includes a multi-site subnet router, we schedule an on-site visit.

  4. Acceptance and family training (1 hour)

    Every family member installs the Tailscale app and scans a QR code to come online. We run through connecting to the house from outside once with you, and leave a cheat sheet behind.

  5. 30-day follow-up visit and handover documents

    A topology map of your tailnet, the policy explained in plain language, the entry point to the Headscale or Tailscale admin console, and the disaster recovery steps.

Pricing: Ask WoowTech or your reseller. Option A (self-hosted) has a one-off setup fee; Option B (managed by WoowTech) has a monthly or yearly fee (covering Headscale tenant operations, the DERP relay and version upgrades). Several sites, on-site work and training for a larger family are quoted separately.

FAQ

I already use Nabu Casa. Do I still need Tailscale?
It depends on what you need. If you only want to open HA from outside, Nabu Casa is enough. If you want to reach a NAS, cameras or a printer directly from outside, to link several sites, or to drop the monthly fee, Tailscale suits you better. The two can also run side by side.
Will family members who are not technical struggle to install it?
On iOS, Android, Windows and macOS, the Tailscale app is at the install-it-and-scan-a-QR-code level. Our delivery scope includes walking family members through the install on site and confirming that they can connect. Later, when an older relative changes phones, message us on <contact channel — owner input required> and we will issue a fresh QR code remotely.
After choosing Option B (managed by WoowTech), can I go back to Option A (self-hosted)?
Yes. The Headscale policy is highly compatible with official Tailscale, and the migration is mainly a matter of each device joining again (scanning a new QR code). When we deliver, we back up the policy as a document, so you can move at any time.
If the Headscale server goes down, does my home lose connectivity?
Normally devices connect directly peer to peer and nothing goes through Headscale — the control plane is only used when a new device joins, when the policy changes and when a key expires. If it really does go down, devices that are already connected keep working until key expiry; our SLA target is a fix within 30 minutes, and we provide an emergency migration path that falls back to the public Tailscale.
Can you set it up for me alone, without letting the family join?
Of course. The ACL policy is the answer to exactly this — who is in the tailnet and who can see whom are both configurable. We can even set up a temporary account that an engineer uses while tuning and that is revoked automatically after handover.
What if Tailscale the company shuts down one day?
Two safeguards: (1) the Tailscale client is open-source software and the WireGuard protocol is an industry standard, so the client still works even if the company is gone; (2) Headscale is an open-source server compatible with the official one — which makes Option B (managed by WoowTech) the natural fallback if you are worried about vendor lock-in with Option A (self-hosted).
Should I prepare anything before booking the call?
It helps to be clear on three things first: (a) how many sites you have (how many houses and offices); (b) which non-HA devices you want to reach remotely (NAS / cameras / printer / self-hosted Docker); (c) how many people will use it (a rough number is fine). Those three help decide between Option A (self-hosted) and Option B (managed by WoowTech), and which price band you land in.

Next step

talk to us

Still deciding between Option A (self-hosted) and Option B (managed by WoowTech)? Start with a 30-minute call

Tell us how many sites you have, how many people in the household, and which devices you want to connect, and we will work out which route fits. It is free, and there is no hard sell.

Contact via <contact channel — link pending owner input>