anasfanani

Magisk Tailscaled

v2.0.0.1guide

Magisk/KernelSU module for running Tailscale on rooted Android devices. The easiest, most secure way to use WireGuard and 2FA.

★536 stars
•Networking & Proxies•by anasfanani•BSD-3-Clause•Updated Nov 4, 2025
Platforms:
✓ Magisk✓ KernelSU
Download v2.0.0.1Starting download...GitHub Source
Magisk-Tailscaled-v2.0.0.1-full.zip

Overview

Magisk Tailscaled packages Tailscale for rooted Android devices. The upstream README describes it as a third-party module that starts tailscaled after boot and lets a rooted Android device join a Tailscale network.

This is not the official Tailscale Android application. The project specifically documents userspace networking and says the module can be used alongside an Android VPN. Network behavior remains dependent on the device ROM, root manager, and local routing configuration.

Compatibility and limitations

The upstream documentation lists Magisk as a requirement and confirms KernelSU support. The installer handles arm and arm64; other architectures are rejected by the installer unless a user supplies compatible binaries manually.

The documented limitations are important:

  • The daemon runs with -tun=userspace-networking.
  • MagicDNS is documented as not working.
  • Subnet routes require manual iptables/routing edits in the tunnel scripts.
  • Some Tailscale features may not work correctly in the Android/Linux environment.
  • The module is not affiliated with the official Tailscale project.

No Android version range is asserted here because the upstream documentation does not provide one.

Installation

  1. Download the current ZIP from the upstream release page.

  2. Flash it through Magisk Manager or KernelSU Manager.

  3. Reboot the device.

  4. Open a root terminal and authenticate:

    su -c tailscale login
  5. Open the authorization URL shown by Tailscale.

  6. If Android DNS handling interferes with the setup, the upstream quick start suggests:

    su -c tailscale set --accept-dns=false

The installer selects arm or arm64 content. If the release package does not already contain the required binaries, its installer downloads matching Tailscale and jq dependencies from the upstream projects, so installation needs network access.

Runtime layout and commands

The module stores its working data below /data/adb/tailscale/. The state file is documented at:

/data/adb/tailscale/tmp/tailscaled.state

Logs are written to:

/data/adb/tailscale/run/tailscaled.log

The release provides these command roles:

  • tailscale: the main client CLI
  • tailscaled: the daemon
  • tailscaled.service: start, stop, restart, and inspect the daemon
  • tailscaled.tun: manage the userspace tunnel helper

Check the node address with:

su -c tailscale ip

Check daemon state with:

su -c tailscaled.service status

Troubleshooting

If the device cannot reach another tailnet node:

  1. Confirm both services are running:

    su -c tailscaled.service status
    su -c tailscaled.tun status
  2. Test the Tailscale path:

    su -c "tailscale ping YOUR_TAILNET_IP"
  3. Inspect /data/adb/tailscale/run/tailscaled.log.

  4. Test the documented local SOCKS5 proxy on port 1099 before changing routing rules.

For subnet routes, review the upstream tailscaled.tun.up and tailscaled.tun.down scripts and add only routes appropriate for the local network. Do not assume that a route working on one ROM or interface will work on another.

Sources

Frequently Asked Questions

Does this module provide the same networking mode as the official Linux Tailscale client?

No. The upstream documentation says this module runs tailscaled with -tun=userspace-networking. Its tailscale0 interface and routing behavior therefore differ from the normal Linux TUN setup.

Why can I not reach another tailnet device directly?

The upstream troubleshooting notes require tailscaled.service and tailscaled.tun to be running and use a local SOCKS5 proxy on port 1099. Check the module log at /data/adb/tailscale/run/tailscaled.log and test connectivity with tailscale ping and the documented curl proxy checks.

Does the module support MagicDNS and subnet routes?

The upstream README states that MagicDNS is currently not working. Subnet routes require manually defining routes in tailscaled.tun.up and tailscaled.tun.down, so they are not plug-and-play.

Why did installation fail outside a root manager?

The release installer explicitly requires Magisk Manager or KernelSU Manager and aborts when BOOTMODE is not enabled. Recovery installation is not supported by the installer.