← Field notes

Camera to NAS with Tailscale or Headscale: where the tunnel belongs

A secure reference architecture for routing camera uploads to a private NAS without expecting a camera to run Tailscale or exposing NAS storage ports.

Published · 9 min read

The short answer

Point the camera at a public, camera-compatible ingest endpoint. From there, a paired delivery agent on the NAS, or a cloud delivery worker joined to the same private network, moves the verified asset across Tailscale or a Headscale-coordinated tailnet. The tunnel belongs between two capable computers, not inside the camera.1,2,4

In this workflow, the camera stays an FTP client.

Tailscale assigns addresses and connectivity to devices that run its client. Its documentation also describes subnet routers for devices that cannot run the client, cameras included. A subnet router makes a service reachable. It does not create an FTP server, and it does not teach the camera a new protocol.1,2

For remote delivery, keep the camera flow ordinary. The camera sends to public ingest over a supported FTP-family protocol. Once the file is complete and verified, place a delivery-capable machine on the private network and let it reach the NAS service.

Choose by ownership and operational appetite.

All three patterns can preserve a private NAS. They differ in who initiates transfer and who operates network coordination.

Outbound NAS agent

The agent pairs with the account, requests only its queued assets, writes to an approved local root, verifies placement, and acknowledges completion. It needs no inbound NAS route.

Tailscale-connected delivery worker

Install Tailscale on a supported NAS or nearby relay and on the delivery worker. Apply a policy that permits only the worker to reach the required service and port.1,3

Subnet router beside the NAS

When the NAS cannot run the client, a subnet router can advertise the NAS subnet to the tailnet. Tailscale documents this pattern for devices that cannot run the client.2

Tailscale and Headscale solve coordination, a separate problem from camera ingest.

Tailscale is the managed path. Headscale describes itself as an open-source, self-hosted implementation of the Tailscale control server with a narrow focus on a single tailnet for personal use or a small open-source organization. Headscale still requires Tailscale clients to register nodes.4,5

That makes Headscale an infrastructure-ownership decision, not an ingest shortcut. Choose it, and you own its public control-server availability, upgrades, backups, policy, identity setup, and troubleshooting. The Headscale project frames its focus around self-hosters. It says performance is not its development focus for commercial-scale deployments.6

Decision frame for the private delivery network
ChoiceYou operateBest fit for an early releaseCamera setup changes?
Outbound agent onlyAgent lifecycle and authenticated queueSimplest customer-owned NAS pathNo
Managed TailscaleClients, policy, and device authorizationWhen direct private addressing helps operationsNo
Self-hosted HeadscaleControl server plus clients, policy, identity, upgrades, and recoveryLabs or teams that explicitly need control-plane ownershipNo

The agent needs a smaller permission set than the NAS owner.

A safe agent receives an opaque delivery job. It never receives arbitrary shell commands or an unrestricted filesystem path.

Pairing

Use a short-lived pairing code to mint a revocable agent identity bound to one account.

Filesystem boundary

Configure one local destination root. Resolve and reject any job path that escapes it.

Transfer

Stream to a temporary filename, enforce size limits, calculate the expected checksum, then rename atomically.

Recovery

Persist the job cursor and retry with backoff after power, internet, or NAS interruption.

Observability

Report queued, transferring, verified, delivered, and failed states without exposing private addresses or local paths to other tenants.

Frequently asked questions

Can a mirrorless camera connect directly to Tailscale?

Not unless the camera can run a supported Tailscale client, and typical camera firmware cannot. Tailscale documents subnet routers as the bridge for devices that cannot run the client. Camera to Anywhere keeps the camera on its documented FTP-family path instead.2

Does Tailscale provide the SFTP, SMB, or WebDAV service?

No. Tailscale provides network connectivity. Its documentation states that a destination service, such as SSH or a web server, must still run on the target device.1

Should Camera to Anywhere use Headscale instead of Tailscale?

Not for the first NAS release. An outbound agent avoids needing either control plane. Managed Tailscale is the lower-effort option when private addressing helps. Headscale makes sense only when self-hosting the coordination layer is a real requirement.4,6

Does a private NAS need an open inbound port?

No. An outbound agent can poll or hold an authenticated outbound connection, download its assigned object, verify it, and acknowledge placement. A mesh-VPN design can avoid public port forwarding by keeping the service reachable only inside the private network.

Sources

Sources were last reviewed on . Vendor interfaces and documentation can change; follow the linked source and re-test the exact production workflow.

  1. 01
  2. 02
  3. 03
  4. 04
  5. 05
  6. 06