What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
Same! Although, for Headplane you may need at least 1GB of RAM.
Headscale turns the $5 VPS into the thing that connects my laptop to my other compute resources while I am out and about.
What's the advantage of Tailscale anyway? I guess ease of use compared to say setting up IPSEC? I haven't played with it yet but from what I read it's just wireguard with a bit of proprietary "one click and sell your soul" magic around it?
Tailscale automates wireguard key distribution and then layers routing, DNS, network ACLs, and other niceties on top.
For example, you can create a token that grants VPN access with inbound SSH as the only allowed traffic. Add that as a secret to GitHub Actions and now you can ad-hoc debug failing CI via `tailscale ssh`.
It's a VPN essentially but just works easily and affordably. We don't stress on managing keys, secrets etc and it's SSO friendly.
How do you know their client won't send them the metadata anyway?
It is open source