ZeroTier Controller (self-hosted) on a Mac
Run your own ZeroTier network controller (no Central) · VPN
Every zerotier-one install can also be the network controller for its own networks — the fully self-hosted alternative to my.zerotier.com, with no seat limits and no third party holding your membership list. It ships with a REST API on 127.0.0.1:9993 (authenticated from authtoken.secret) but no local admin UI, which is the gap FrontierStack's ZeroTier Controller pane fills: controller status and identity, the networks it owns, the member-authorisation queue with one-click authorise/deauthorise, and a security audit (API exposure, identity/token file permissions, backup readiness). Administration runs over SSH against the controller's own loopback, so the API never has to be exposed. Run it on an always-on Linux server/VM/container with UDP 9993 reachable for peers; keep TCP 9993 on loopback. Back up identity.secret, identity.public and controller.d (encrypted, off-box) — the network IDs derive from the identity, so losing it orphans every network.
Run ZeroTier Controller (self-hosted) with FrontierStack
FrontierStack lists ZeroTier Controller (self-hosted) in its VPN catalog. Install or connect it from one place, then monitor its status, ports and certificate, secure it with the firewall and Malware Audit, and back it up.
Run it all from one Mac app.
FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.
Download FrontierStack