Why don’t people just use Wireguard?

Once you get to N = >10 devices, and expect some degree of decentralized communication between them you find yourself maintaining N^2 entries. Every change to the set of public keys, require you updating N entries. Things get worse once you want consistent rules on what-device-should-access-what.

I initially used WireGuard, but as my home lab scaled, it became unwieldy. Some people could work around these limitations with bash scripts, but if you have an heterogeneous environment (esp iOS clients), making programmatic configuration changes to WireGuard becomes trickier.

Today I use Tailscale (with Headscale as the control plane) for all users, and WireGuard as a emergency access to key servers.

Does headscale fully replace the corporate tailscale network? I've been looking at replacing my home wireguard if I can self-host tailscale but haven't had the free time to really figure out how much privacy I can retain by using headscale.

It definitely can. By default it ships with the normal Tailscale DERP map but it also ships with a default-off DERP server. You can turn that on and set your DERP map to only include that one server (or you can fan out a couple if you want). At that point you're not using Tailscale assets at all.

Thanks! Once I have some more time this winter I will take a look at using this to replace my wireguard setup.

For much the same reason most people choose Windows or Mac over Gentoo. Most people set up something like Tailscale to accomplish something rather than create a project and ongoing maintenance burden for themselves, and setting up Wireguard is not terribly friendly to the uninitiated.

WireGuard is one of the easiest things to set up. The total amount of reading you'd need to do to set up WireGuard amounts to half of a page. I spent more time figuring out what firewall rules are needed for WireGuard traffic than actually setting up WireGuard, it's so simple.

I'm going to disagree with you there. It's been a while since I set up anything with WireGuard but "easy" is not a word I would apply to it. A simple tunnel or VPN configuration was close to that but a network comparable to a Tailnet got pretty involved to do properly. By contrast Tailscale was effortless.

Needing to do additional things like figure out firewall rules is exactly what I'm talking about. I enjoy tinkering for fun most of the time but I'm generally looking to tinker on something specific, not every step along the way.

AI has mostly removed the difficulty of Linux configuration for beginners

It's also removed the difficulty of configuring a mikrotik router as well. Mikrotik has a cloud router instance which is much easier to deal with I think than linux. Mostly because there's a UI interface for Mikrotik that makes it a little easier to inspect what's going on.

One of my pet projects I need to get back to is an SDN to make configuration for mikrotik routers easier (particularly with VLAN's, wireguard or VPNS, or routing configuration between ports).

Winbox is nice in a sense because it tells you the true configuration. But what I really want is something that can start with a network diagram (e.g.) and then get the current state of the router, and then validate that against the network config.

How does wireguard helps you with NAT traversal? Reliable NAT traversal on top of wireguard is their moat.

> Reliable NAT traversal on top of wireguard is their moat

And a damned good one at that. I can spend five minutes on a (family) nontechnical user's device and set it up to be able to access the parts of my network it needs to get to, and it's easy enough to use that I can walk them through the troubleshooting over the phone if it ever goes awry. Regardless of where they are or I am.

> How does wireguard helps you with NAT traversal?

It does not. You need a public endpoint, but presumably the $5 VPS or the "homelab" provides that, or it's of little use for things like email, Web, or game servers.

This. Wireguard is a single short text file with keys. It's simple and robust, and setting it up on a client like a laptop or a phone is equally easy. Tailscale or Headscale (the self-hosted version) are massively overengineered for something as basic as accessing your Linux ISOs from your phone.

I'll argue though that the convenience and autonomic management make a big difference in that case because if your Wireguard configuration is busted you might need a working Wireguard to log into your homelab and fix it.

Of course the default behavior that Tailscale forces you to reauthenticate periodically can cause the same problem unless... you turn it off. You know things like that always happen at the worst time.

It’s also entirely impossible to use by itself when both devices you’re trying to connect are behind a NAT or some other restricted network.

That's true, but the $5 VPS should have a public IP, either v4 or v6. Other devices can route their traffic through it, and then every device can reach other devices, regardless of NAT.

It better have v4 if you ever want to use it while traveling. v6 is still not widely enough available on public Wi-Fi networks and even many mobile operators.

On some OSes you could probably also use some additional 4->6 tunnel, but that probably doesn't work stacked under Wireguard on iOS and Android.

But I'd think at that point there'd be arguments for using that vps to instead facilitate a p2p connection... right?

Yes, but only if the VPS becomes a bottleneck. Otherwise self-hosting Headscale does not seem worth it. My guess is that the threshold is at dozens of devices in simultaneous use.

That’s a bit like telling somebody to take a ship instead of an airplane: A nice idea, but not everybody lives at the sea.

I started with Wireguard first, however the setup / maintenance makes it a way bigger project than simply using Tailscale.

arguably that's the entire point of tailscale -- ain't gotta worry about the logistics