Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (stable, 2026-09-14), podman (stable, 2026-09-14); Proxmox VM: docker (stable, 2026-09-14), podman (stable, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
headscale:
image: "headscale/headscale:latest"
container_name: njorddeploy-headscale
command: serve
ports:
- "9080:8080"
volumes:
- "./data/headscale/data:/var/lib/headscale"
- "data_root/headscale/config.yaml:/etc/headscale/config.yaml:ro"
environment:
- "HEADSCALE_CONFIG=/etc/headscale/config.yaml"
- "TZ=Etc/UTC"
- "HEADSCALE_SERVER_URL=http://127.0.0.1:9080"
networks:
- njorddeploy_net
user: "0:0"
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
HEADSCALE_WEB_PORT |
9080 |
The external port for Headscale's web UI and API. |
HOST_IP |
127.0.0.1 |
The IP address or domain name where Headscale is externally accessible. Used for the server_url in the configuration. |
TZ |
Etc/UTC |
Specify the timezone for the container (e.g., Europe/London, America/New_York). |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.