Best for self-host on your own infrastructure
Try NetBirdNetBird ships under BSD-3 license with both a managed cloud (Free for 100 peers) and a self-host option that runs the management server on your VM. The model is closer to Tailscale's tailnet control plane than to the older OpenVPN-style hub-and-spoke. For teams whose security posture forbids the management plane sitting on a third-party cloud, NetBird matches the intent and Tailscale's hosted-only model is a non-starter.
Strengths
- +BSD-3 license self-host
- +Cloud Free covers 100 peers
- +WireGuard mesh comparable to Tailscale
- +Posture checks plus advanced policies on Team tier
Trade-offs
- −Smaller community than Tailscale
- −Self-host requires comfort with Docker plus a public endpoint
- −Identity provider integrations narrower than Cloudflare Access
- Free cloud
- 100 peers, single network
- Team
- $5/user/mo
- Business
- $12/user/mo
- Self-host
- BSD-3 license, free unlimited
Migration steps
- Decide cloud Free or self-host based on your sovereignty constraints.
- For self-host: deploy via Docker Compose or Helm to a public-IP VM with TLS.
- Migrate clients in waves; both Tailscale and NetBird run side by side without conflict.
- Cut over identity provider rules and decommission Tailscale once peer count is fully on NetBird.
Not for: NetBird is the wrong fit if you depend on Tailscale Funnel for public ingress; that capability is not natively replicated.
Paid plans from $5.00/mo