Safe way home, no open ports: two Tailscale delivery options
Remote access to Home Assistant, several sites linked together, your home cameras and NAS wherever you go — all built on the Tailscale private network, with no port to open on the router and no entry point into your home exposed to the internet. Choose Option A (self-hosted) or Option B (managed by WoowTech).
Why your home needs Tailscale
If you have ever opened Home Assistant at home from a phone while you were out, you have probably run into three things: a monthly Nabu Casa bill, router port forwarding that gets scanned the moment you open it, and a DDNS plus reverse proxy setup you no longer dare to touch once it works. Every one of them has a whiff of leaving your home's entry point "out on the public internet".
Tailscale takes another route: install a lightweight client on your phone, your laptop and the Home Assistant host, and they form a private network that is yours alone (a tailnet). You never open a single router port, packets are encrypted end to end (WireGuard), and every device finds the others through a short URL that is easy to remember (MagicDNS).
Self-hosted or managed: two options at a glance
Option A (self-hosted) runs on your HAOS system and is handed over for you to operate. Option B (managed by WoowTech) includes its control plane (which manages your device list):
Option A (self-hosted)
You buy a host that runs Home Assistant OS (a Home Assistant Yellow or Green, or one you build yourself). We come to your home or log in remotely, install the built-in Tailscale add-on, set up ACL / subnet router / Serve / MagicDNS correctly, and hand you the keys at the end. The control plane is the official Tailscale.com.
Good for: a single household, one site, and anyone who wants the official Tailscale SaaS without touching policy hujson themselves.
Option B (managed by WoowTech)
No official Tailscale.com. You open a tenant on the private Headscale coordination server WoowTech runs (on *.woowtech.io), and your devices still connect with the open-source Tailscale client. The device count is not capped by the Tailscale free 3-user / 100-device limit, which makes multiple sites and multiple routes easier to arrange.
Good for: a SOHO business, anyone who wants to stay in control, several sites (home + studio + a relative's house), more than 3 family members or 100 devices, and anyone who would prefer not to hand the device list to a US vendor.
Option A (self-hosted)
You host the HAOS Tailscale add-on on your own system. WoowTech handles the initial setup and hands it over for you to operate with the official Tailscale service. Every item below is included in that setup.
What you get
ha-home).https://ha-home and you are in, with no IP address to memorize.https://ha-home.tail-scale.ts.net), so the browser no longer flags it "Not secure".192.168.1.x directly.What you pay for
The Tailscale free plan (Personal plan) is enough for the vast majority of households: 3 users, 100 devices, unlimited traffic. There is no monthly fee on top.
Option B (managed by WoowTech)
Headscale is the open-source version of the Tailscale control plane. We maintain a Headscale server for you on *.woowtech.io; you open an account on it and you have a private tailnet of your own — while the traffic and the data stay encrypted end to end over direct peer-to-peer connections, and never pass through a WoowTech data center.
What you get
your-name.hs.woowtech.io). We join Home Assistant for you and prepare the preauth keys for the phones and laptops.What you pay for
A monthly or yearly subscription, covering Headscale tenant operations, the DERP relay, 24/7 monitoring and version upgrades. The actual figures depend on how many devices you have and which SLA level you pick; ask WoowTech or your reseller.
Typical scenarios
Three real households, so you can find the one that matches yours.
1. A single-family house, one site
Parents who have retired and moved back to their hometown, a Home Assistant Green on the TV cabinet, two phones and one laptop. They want to turn on the air conditioning and check the door camera while they are out, without paying the Nabu Casa monthly fee and without daring to open a port.
2. A SOHO business owner in two places: home + studio
Daytime at the studio, where there is a NAS holding client files, a printer, and the IoT cameras of the cafe downstairs. At home there is HA, the security cameras and the parents' iPad. They want to pull files off the studio NAS from home, watch the home cameras from the studio, and see both sites' HA on one dashboard.
3. Three generations under one roof + a home studio
Three Home Assistant installs — the parents' house, their own house and an older relative's house — plus a partner's craft studio (a NAS, a printer, no public IP). They want all three houses' HA on one dashboard, and to be able to see each other's cameras in an emergency.
Security and privacy
Tailscale's security design rests on two things: WireGuard end-to-end encryption (which not even we can decrypt) and an ACL that is closed by default under least privilege (unless you say a connection is allowed, devices cannot see each other). Our managed-delivery process actually puts both in place.
- No open ports: we do not touch a single port on the router. Seen from the internet, your IP address has nothing open at all.
- Least privilege by default: the policy as delivered already says parents can only open HA and a contract engineer only touches the part they are responsible for. We do not take the shortcut of allowing everything.
- Key expiry on: a phone or laptop that has not logged in for 90 days drops off by itself, so when you change phones you need not worry about the old device still being on the list.
- Device approval on: a new device only gets in once you approve it in the admin console. That stops a stranger who has an auth key from joining the tailnet.
- Serve, not Funnel: the HTTPS short URL for HA is tailnet-only, so HA never ends up on the public internet by accident.
- Option B (managed by WoowTech) extras: the control plane itself runs on WoowTech's private servers (two nodes, Singapore and Taiwan), the database is backed up daily and encrypted, and if you cancel we hand you a full export.
Compared with the alternatives you may be considering
| Nabu Casa | Router port forwarding | WoowTech Tailscale option | |
|---|---|---|---|
| Cost structure | A monthly fee, for as long as you want remote access | Free, but you buy an SSL certificate and do the research | Option A (self-hosted): a one-off setup fee; Option B (managed by WoowTech): a monthly fee that includes operations |
| Exposed to the internet | Relayed through Nabu Casa, not directly exposed | Directly exposed — scanned, and passwords guessed at | Not exposed at all, encrypted end to end |
| Multi-site connectivity | Not possible | Set up site by site, with a policy that is hard to manage | Native to Option B (managed by WoowTech), with the policy managed in one place |
| Reach your NAS/cameras | Only relayed through HA | A port opened for every device (extremely dangerous) | A subnet router brings in the whole LAN at once |
| HTTPS short URL for HA | Yes (*.ui.nabu.casa) |
You build the reverse proxy plus Let's Encrypt yourself | Serve gives you a valid HTTPS certificate automatically, on a short URL that is easy to remember |
| Works for non-technical family | Yes, close to one click | Almost never | Install the Tailscale app, scan a QR code and you are in |
Pricing and delivery process
The price depends on the number of sites, the number of devices, how complex the ACL is, and whether on-site installation is included. What follows gives you a sense of the order a managed delivery runs in; for the actual figures, ask WoowTech or your reseller.
-
Discovery call (30 minutes, free)
How many sites, how many people in the household, which NAS / cameras / printers you want to bring in, whether you want to share with friends. By the end of the call we decide between Option A (self-hosted) and Option B (managed by WoowTech).
-
Quote and statement of work
It lists what we deliver, the SLA, what you provide (access to HA, the list of family members, admin rights on the router), and the acceptance criteria.
-
Remote or on-site installation (half a day)
Option A (self-hosted) can usually be finished remotely; if Option B (managed by WoowTech) includes a multi-site subnet router, we schedule an on-site visit.
-
Acceptance and family training (1 hour)
Every family member installs the Tailscale app and scans a QR code to come online. We run through connecting to the house from outside once with you, and leave a cheat sheet behind.
-
30-day follow-up visit and handover documents
A topology map of your tailnet, the policy explained in plain language, the entry point to the Headscale or Tailscale admin console, and the disaster recovery steps.
FAQ
I already use Nabu Casa. Do I still need Tailscale?
Will family members who are not technical struggle to install it?
After choosing Option B (managed by WoowTech), can I go back to Option A (self-hosted)?
If the Headscale server goes down, does my home lose connectivity?
Can you set it up for me alone, without letting the family join?
What if Tailscale the company shuts down one day?
Should I prepare anything before booking the call?
Next step
Still deciding between Option A (self-hosted) and Option B (managed by WoowTech)? Start with a 30-minute call
Tell us how many sites you have, how many people in the household, and which devices you want to connect, and we will work out which route fits. It is free, and there is no hard sell.
Contact via <contact channel — link pending owner input>