> Can you tell how you configured the tool to accomplish this?

The Yggdrasil client is installed on every computer. I'm running Debian. I have no idea how well it works on Mac or Windows. Yggdrasil assigns a key pair to each computer.

On the VPS, the config is modified in two places:

    Listen: [
      tcp://[::]:51350
    ]
This makes the VPS listen for Yggdrasil connections.

    AllowedPublicKeys: [ 
      pubkey1
      pubkey2
      pubkey3
      ...
    ]
This ensures that it only accepts connections from the specified computers. You can also leave that part out. But then any Yggdrasil client out there could connect to your VPS.

Note that this is only the config for the VPS.

I only make one change to the config of the other computers:

    Peers: [
      tcp://hub.mydomain.tld:51350
    ]
This causes them to actively connect to the VPS.

> Does it mean that the VPS has to be in-between all the traffic, or do we punch holes through the NAT for direct connections?

It depends. If the computers can reach each other on a local network, the Yggdrasil clients will automatically find each other and connect. To do this, you wouldn't have had to change anything in the default configuration. you would simply have had to install and start the Yggdrasil client on the computers.

With NAT in between, they wouldn’t connect on their own. But since they’re configured to actively connect to the hub in any case, they can still see each other via the hub and exchange data even in this scenario. Yggdrasil handles routing and NAT traversal. If both paths are available (locally or via the VPS), Yggdrasil defaults to the local path. But in the general case (where all other computers are behind NAT), all traffic would go through the VPS.

Special case: If only one of the two computers is behind NAT and you want a direct connection, then the accessible computer corresponds to the VPS in the configuration above.

This is the first time I am hearing of yggdrasil. I currently have a similar setup using Tailscale. I always thought Wireguard was teh primitive here and Tailscale just made it more convenient in the pointy clicky way. Why Yggdrasil instead of Wireguard which at the outset sounds more standard solution for this need?

Not sure, but it's possible that Tailscale wasn't popular when I found Yggdrasil. That might be the whole answer. I discovered it because I’ve had an interest in mesh networks and alternative networking. I also have a preference for services that I can configure via text and control from the terminal. These things are so seamless on Linux that I’d find GUIs more of a hassle. Text files are easy to transfer between computers. And they’re so wonderfully explicit: you can just read what’s in them.

And I don't like it when I see the word “Pricing” on a project's website. It makes me suspicious. I can rely on gifts to the world like Linux, Debian, PostgreSQL, Apache, Nginx, Caddy, and Yggdrasil without any problems for decades. Commercial software products turn into shit sooner or later. I’m happy to pay for things, but paradoxically, software seems to be good and stay good only when it’s gifted.

I’m vaguely familiar with Tailscale from work. The licensing model restricts usage. The central control plane is closed-source. Someone built an open-source implementation. Then they hired the lead maintainer. It’s the usual business nonsense that could lead to them being bought by Google or Meta, or trying to monetize my metadata, or shoving ads down my throat, or doing something stupid with AI. I’d rather stick with Yggdrasil.

Neat, thanks for sharing! Seems very convenient!