Tailscale
Install an agent on every machine to reach or a subnet router, and its routes Describe the access in a policy Get infrastructure to agree After that: everything is reachable, for everyone, from anywhere, permanently.
Tailscale answers the same need through the network: an agent on every machine, and everything becomes reachable. That is excellent. When you are allowed to deploy it. Kestro goes through the doors that already exist, your SSH keys and your cloud access, and asks nobody’s permission.
macOS 11+ · Windows soon
Two ways to reach the same database
These are not two versions of the same product: they are two different decisions, and one of them commits your infrastructure.
Tailscale
Install an agent on every machine to reach or a subnet router, and its routes Describe the access in a policy Get infrastructure to agree After that: everything is reachable, for everyone, from anywhere, permanently.
Kestro
Nothing to install on your servers. Your SSH keys, your gcloud, your aws. No policy to write, no approval to obtain. The door opens when you need it, from your machine, and closes when you say so. $ psql "$(kestro url notes-db)"
Point by point
| Tailscale | Kestro | |
|---|---|---|
| To install on the machines you reach | an agent, or a subnet router | nothing |
| Decision required | an infrastructure change, so an approval | none: you use the access you already have |
| What authenticates | your identity provider and a policy | your SSH keys, gcloud, aws, untouched |
| Scope | the whole team, permanently | your machine, when you decide |
| Works while your Mac is off | yes, the network stays | no |
| Access log | yes | no |
| On a machine you do not administer | no, without an agent there is no node | yes, if ssh or your cloud tool reaches it |
| Cloud SQL, IAP, Session Manager | moot: the network replaces them | yes, through your official tools |
| Platforms | nearly all of them | macOS only |
| Cost | free plan for personal use, then per user | €29.99$29.99£25.99CHF 25.90CA$40.99A$45.99 once |
Checked on 4 August 2026, from Tailscale’s public documentation.
What Kestro brings
Tailscale makes machines reachable. What remains is opening the right door, at the right moment, and knowing which one is open.
Deploying an agent onto production is a team decision, often slow, sometimes refused. Opening a tunnel with the keys you were already given is not one: it is the access you already hold, used differently.
Cloud SQL through the official proxy, a VM through IAP, an EC2 through Session Manager: these are the paths Google and AWS document, with their logging and their IAM. Kestro uses them rather than routing around them.
A private network makes everything reachable all the time, which is the point, and means you no longer know what you are connected to. Here each door is a row, production carries a red edge, and “Close all” shuts them in one gesture.
Your repositories and their branch, the docker compose services, your pinned scripts, the addresses you watch: same panel, same shortcut.
On your machine
Your connections run from your computer to your servers, never through us.
Nothing to create, no password.
SSH, Google Cloud, AWS: Kestro uses your own tools, locally.
We don’t know what you open, or when.
Your licence renews with us. Nothing else leaves.
When Tailscale is the right choice
These are two tools answering the same question from opposite ends. Here are the cases where the other end is the right one.
A service that must reach another service, a machine that must stay reachable overnight, an on-call rota: Kestro stops with your session. A private network does not.
Giving ten people revocable access, with a log and a policy, is exactly what Tailscale does and exactly what Kestro does not. We have no accounts, no administration, no audit log: it is a personal tool.
Kestro only runs on macOS 11 and later. The Windows version is in the works; there is no Linux version planned.
Pricing
A tool you open forty times a day shouldn’t send an invoice every month.
Kestro licence
1 computer · one-time
Or download it for free first →
Refunded within 14 days, no questions asked.
Questions we get asked
Yes, and it is a common case. If your team has deployed a private network, your machines are reachable and Kestro treats it as any other network: an SSH tunnel to an internal address works the same. The two compete over nothing: one makes the machine reachable, the other opens the door and tells you it is open.
It opens nothing new: it uses the access you already have (your SSH keys, your gcloud session, your aws profile) and copies none of it. A tunnel lasts as long as you leave it open, against a network reachable at all times. What is missing, though, is real: there is no access policy, no audit log, no central revocation. For personal use that is moot; for ten people on production it is exactly what you need, and Tailscale is what you want.
No, nothing. That is the fundamental difference between the two approaches. Kestro uses the doors that already exist: sshd, the Cloud SQL proxy, IAP, Session Manager. If you can connect to a machine today from your terminal, Kestro can too, and nothing changes on the server side.
That is the case that brings us the most email. A contractor, a client, infrastructure you do not manage, a security team that has not decided: what is left is the access you were given. Kestro works with that, and asks nobody’s permission.
No, and it does not ask for an account either. You download, you get 7 full days. No card is asked for until you decide to buy.