Skip to content
➜cat projects/vps-rescue/README.md
cd ../projects

vps-rescue

An open-source CLI that diagnoses unreachable VPS SSH connections and auto-provisions a Tailscale rescue tunnel on your own tailnet — built for users whose ISP or transit null-routes budget VPS provider IP ranges (Hostinger, Contabo, OVH). Mints a single-use 5-minute pre-authorized Tailscale auth key, generates a paste-able install one-liner that wires in your SSH pubkey, polls until the VPS joins the tailnet, and writes a Host block into ~/.ssh/config. No relay infra, no SaaS, no tunnel data on third-party servers; the API token lives in the OS keychain (macOS Keychain, libsecret, Windows Credential Vault). Published on npm with CI across Node 20/22 on Ubuntu and macOS.

// highlights

  • Diagnoses DNS, TCP, and traceroute failures, then mints an ephemeral Tailscale auth key only when an upstream rescue path is actually needed.
  • Pluggable transport architecture (Tailscale shipping; cloudflared, Tor, ngrok, AWS SSM planned) so the rescue mechanism is not locked to one provider.
  • Designed for zero operator infrastructure: tokens in OS keychain, no telemetry, only two outbound calls — Tailscale API and your VPS.
TypeScriptNode.jsTailscale APIWireGuard@napi-rs/keyringCommanderVitest
github://view_repo (opens in new tab)
➜ repo: vps-rescue[lang: TypeScript, Node.js, Tailscale API, WireGuard, @napi-rs/keyring, Commander, Vitest]