What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
You can ask an LLM to set up a wireguard network for you with an idempotent bash script to deploy everything. You'll need a $5 VPS to bounce everything through. Works an absolute treat.
I saw all the Netbird recs here so looked into it briefly. Depends I guess on what you use Tailscale for. Tailscale Funnel is easy and stable. Self-hosted on Netbird is ... a bit more involved.
Netbird, been using it for about 6 months now with no complaints. Fully OSS, mobile clients, etc.
self-hosted open source alternative Headscale/Headplane. Uses the Tailscale client without their SaaS being involved.
Same! Although, for Headplane you may need at least 1GB of RAM.
Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.
What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
It's a VPN essentially but just works easily and affordably. We don't stress on managing keys, secrets etc and it's SSO friendly.
How do you know their client won't send them the metadata anyway?
It is open source
Sanctum! Entirely free and open-source and PQ-secure.
https://sanctorum.se
tl;dr
> no mobile clients
I’ve no need for them personally so they don’t exist in the official repo.
I know of some people however who hacked up their own using the sanctum library (https://github.com/jorisvink/libkyrka)
That is a bummer.
Netbird has a self hosted option
You can ask an LLM to set up a wireguard network for you with an idempotent bash script to deploy everything. You'll need a $5 VPS to bounce everything through. Works an absolute treat.
Is that the prompt you would use, or is there more to it?
The wireguard docs are pretty good, and it's probably worth it at least a little to actually understand what it does.
https://www.wireguard.com/quickstart/
Actually I wish they would be a lot more verbose and explain the details a little bit better.
Yep and the LLM can help explain, but it is actually super straightforward. Public key cryptography and the text file configs are tiny.
[dead]
You could try with that as a prompt. I have a repo set up with all of my sysadmin scripts and so the LLM had that as additional context.
Netbird!
I saw all the Netbird recs here so looked into it briefly. Depends I guess on what you use Tailscale for. Tailscale Funnel is easy and stable. Self-hosted on Netbird is ... a bit more involved.
Definitely a place for both services, IMO.