The tsconnect wasm build still has osusergo and netgo since its early6f5096fa6, copied from our linux static-linking build flags. They are no-ops on js/wasm: there is no cgo resolver or cgo os/user implementation to disable, so the pure Go paths are used regardless. The omitidna and omitpemdecrypt tags (used by the wasm build and by gocross for darwin and ios) were binary size reduction patches in our github.com/tailscale/go fork, not upstream Go, and did not survive the fork's per-release history reboots: omitpemdecrypt only ever existed on the tailscale.go1.14 and tailscale.go1.15 branches, and omitidna made it through tailscale.go1.17. Both have been unrecognized no-ops since we moved to the go1.18 fork branch (927fc3612, March 2022, first shipped in Tailscale 1.24.0). Also stop passing tailscale_go explicitly: the tailscale/go fork's cmd/go sets that tag itself as of 2026-03-31. Updates #21250 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I10f1244f02a915943ca84e107aff8683b6e771b3
tsconnect
The tsconnect command builds and serves the static site that is generated for the Tailscale Connect JS/WASM client.
Development
To start the development server:
./tool/go run ./cmd/tsconnect dev
The site is served at http://localhost:9090/. JavaScript, CSS and Go wasm package changes can be picked up with a browser reload. Server-side Go changes require the server to be stopped and restarted. In development mode the state the Tailscale client state is stored in sessionStorage and will thus survive page reloads (but not the tab being closed).
Deployment
To build the static assets necessary for serving, run:
./tool/go run ./cmd/tsconnect build
To serve them, run:
./tool/go run ./cmd/tsconnect serve
By default the build output is placed in the dist/ directory and embedded in the binary, but this can be controlled by the -distdir flag. The -addr flag controls the interface and port that the serve listens on.
Library / NPM Package
The client is also available as an NPM package. To build it, run:
./tool/go run ./cmd/tsconnect build-pkg
That places the output in the pkg/ directory, which may then be uploaded to a package registry (or installed from the file path directly).
To do two-sided development (on both the NPM package and code that uses it), run:
./tool/go run ./cmd/tsconnect dev-pkg
This serves the module at http://localhost:9090/pkg/pkg.js and the generated wasm file at http://localhost:9090/pkg/main.wasm. The two files can be used as drop-in replacements for normal imports of the NPM module.