Camera to NAS with Tailscale or Headscale: where the tunnel belongs
A secure reference architecture for routing camera uploads to a private NAS without expecting a camera to run Tailscale or exposing NAS storage ports.
The short answer
Point the camera at a public, camera-compatible ingest endpoint. From there, a paired delivery agent on the NAS, or a cloud delivery worker joined to the same private network, moves the verified asset across Tailscale or a Headscale-coordinated tailnet. The tunnel belongs between two capable computers, not inside the camera.1,2,4
In this workflow, the camera stays an FTP client.
Tailscale assigns addresses and connectivity to devices that run its client. Its documentation also describes subnet routers for devices that cannot run the client, cameras included. A subnet router makes a service reachable. It does not create an FTP server, and it does not teach the camera a new protocol.1,2
For remote delivery, keep the camera flow ordinary. The camera sends to public ingest over a supported FTP-family protocol. Once the file is complete and verified, place a delivery-capable machine on the private network and let it reach the NAS service.
Choose by ownership and operational appetite.
All three patterns can preserve a private NAS. They differ in who initiates transfer and who operates network coordination.
Outbound NAS agent
The agent pairs with the account, requests only its queued assets, writes to an approved local root, verifies placement, and acknowledges completion. It needs no inbound NAS route.
Tailscale-connected delivery worker
Install Tailscale on a supported NAS or nearby relay and on the delivery worker. Apply a policy that permits only the worker to reach the required service and port.1,3
Subnet router beside the NAS
When the NAS cannot run the client, a subnet router can advertise the NAS subnet to the tailnet. Tailscale documents this pattern for devices that cannot run the client.2
Tailscale and Headscale solve coordination, a separate problem from camera ingest.
Tailscale is the managed path. Headscale describes itself as an open-source, self-hosted implementation of the Tailscale control server with a narrow focus on a single tailnet for personal use or a small open-source organization. Headscale still requires Tailscale clients to register nodes.4,5
That makes Headscale an infrastructure-ownership decision, not an ingest shortcut. Choose it, and you own its public control-server availability, upgrades, backups, policy, identity setup, and troubleshooting. The Headscale project frames its focus around self-hosters. It says performance is not its development focus for commercial-scale deployments.6
| Choice | You operate | Best fit for an early release | Camera setup changes? |
|---|---|---|---|
| Outbound agent only | Agent lifecycle and authenticated queue | Simplest customer-owned NAS path | No |
| Managed Tailscale | Clients, policy, and device authorization | When direct private addressing helps operations | No |
| Self-hosted Headscale | Control server plus clients, policy, identity, upgrades, and recovery | Labs or teams that explicitly need control-plane ownership | No |
The agent needs a smaller permission set than the NAS owner.
A safe agent receives an opaque delivery job. It never receives arbitrary shell commands or an unrestricted filesystem path.
Pairing
Use a short-lived pairing code to mint a revocable agent identity bound to one account.
Filesystem boundary
Configure one local destination root. Resolve and reject any job path that escapes it.
Transfer
Stream to a temporary filename, enforce size limits, calculate the expected checksum, then rename atomically.
Recovery
Persist the job cursor and retry with backoff after power, internet, or NAS interruption.
Observability
Report queued, transferring, verified, delivered, and failed states without exposing private addresses or local paths to other tenants.
Frequently asked questions
Can a mirrorless camera connect directly to Tailscale?+
Not unless the camera can run a supported Tailscale client, and typical camera firmware cannot. Tailscale documents subnet routers as the bridge for devices that cannot run the client. Camera to Anywhere keeps the camera on its documented FTP-family path instead.2
Does Tailscale provide the SFTP, SMB, or WebDAV service?+
No. Tailscale provides network connectivity. Its documentation states that a destination service, such as SSH or a web server, must still run on the target device.1
Should Camera to Anywhere use Headscale instead of Tailscale?+
Not for the first NAS release. An outbound agent avoids needing either control plane. Managed Tailscale is the lower-effort option when private addressing helps. Headscale makes sense only when self-hosting the coordination layer is a real requirement.4,6
Does a private NAS need an open inbound port?+
No. An outbound agent can poll or hold an authenticated outbound connection, download its assigned object, verify it, and acknowledge placement. A mesh-VPN design can avoid public port forwarding by keeping the service reachable only inside the private network.
Sources
Sources were last reviewed on . Vendor interfaces and documentation can change; follow the linked source and re-test the exact production workflow.
- 01TailscaleConnect to devices ↗
- 02TailscaleSubnet routers ↗
- 03TailscaleTailnet policy syntax ↗
- 04HeadscaleHeadscale project documentation ↗
- 05
- 06HeadscaleHeadscale FAQ ↗
