Tailscale on NixOS: A New Minecraft Server in Ten Minutes
tailscale.com
tailscale.com
# wait for tailscaled to settle
sleep 2
This is going to break one day. They're already using systemd units - why not make tailscale notify when it's done with the startup? We have better tools than old initd - let's use them.As well, maybe a little over-picky, but I’m not a fan of “22” in the firewall config. I assume there’s something like config.ssh.port
`go-systemd` is already an indirect dependency of `tailscale` so this doesn't contribute to dependency footprint either if that's a concern.
Perhaps we should open a ticket (or a pull-request?)
Am I too grumpy?
- edit: Is it because it's not possible to have a good Minecraft gaming experience without it? I am really curious to understand why would people need that extra layer zero config vpn?
God I wish ipv6 had taken off. P2P has taken a huge hit because of NAT.
Also the firewall won't provide the same security, here afaik it also handle auth for you (only approved clients can connect), so you don't have to worry about how secure the auth is on the server you're exposing.
(for most people doing all those things securily would likely take much longer than 10min, and unless they're very technically savy I'm not sure how much secure it would be)
Anyone else have other reasons in minds why it's useful?
As for whether you need it for a Minecraft server.. well I wouldn't personally have questioned it, we're on a site called hacker news after all. If anything I'd love more posts like this from people who are tinkering with things.
If you remove the DigitalOcean part though and add in a home PC you do then get the benefits of being able to just connect. No port forwards, no faff.
If we're really really unironically asking why.. because Tailscale wants more customers, it's what companies do.
It gets easier?!
I love how easy Wireguard is, stock, so perhaps I'll try Tailscale.
Also, a good reason to do this would be to play with friends easily, sometimes NAT and other things make it hard to connect to a gaming server, and also servers like Minecraft run a lot of code from inexperienced devs, so probably lots of security concerns there. Setting up a firewall to do that is a bit harder, you need to know your friends IPs and such.
You can set an allowlist of mojang account identifiers in your server.properties.
I don't know how airtight that is, though, and I guess if you're running a public server on the default port 25565, you can expect to receive a bunch of connection attempts from people you don't know that will ultimately be unsuccessful but will take some CPU to reject (just like SSH on port 22).
It's probably less likely to receive UDP traffic on tailscale's default port these days than TCP on 25565. Even then, I would bet that it's cheaper to discard the tailscale/wireguard packets that you don't trust / aren't authenticated than it is for minecraft.jar to either fail to authn a client with mojang's servers or authenticate a client and then see that it's not in the allow list.
> You can also use node sharing to invite people you trust to your server. Generate an invite link in the admin panel and they can use that to join your adventure.
Though I did try to find the node sharing link generator in my control panel and failed - maybe it isn't available for non paying customers or maybe I'm just not very good at looking for stuff!
It seems to be in an invite only beta. Maybe the article was scheduled and mistimed?
I wouldn't say mistimed so much as "we were excited to get the post up". Node sharing is indeed in invite-only beta, though we're planning on opening that up very soon. Apologies for any frustration/confusion.
But you can try it's package manager nix and it's package set nixpkgs in any other Linux distribution.
> Because Nix (the package manager) & Nixpkgs (the Nix packages collection) can both be installed on any (most?) Linux distributions, they can be used to install NixOS in various creative ways. You can, for instance:
> 2. Install NixOS on the same partition (in place!), from your existing non-NixOS Linux distribution using NIXOS_LUSTRATE.
> /etc/NIXOS_LUSTRATE tells the NixOS bootup scripts to move everything that's in the root partition to /old-root. This will move your existing distribution out of the way in the very early stages of the NixOS bootup.
which is what the nixos-infect script does, because DO doesn't have native NixOS images.
does this do something else?
Lots of kids and people without public IPs they can write NAT rules for setup Minecraft servers at home etc. This is the classic example that can be solved with ZeroTier, TailScale etc.
And you might decide to use this instead of Zerotier because you don't trust the protocol behind Zerotier, being some weird custom thing, but Tailscale is just a fancy management layer over Wireguard.
I still prefer Wireguard or Zerotier depending on my own use cases - I don't see how tailscale adds value (for me)
I will be running self hosted services that we use and available anywhere in the world (with a connection) that I don't need a VPS for.
I am waiting for broader availability of their sharing feature: my extended family can each have their own networks and then I can expose self hosted services to them (ie photos, recipes, updates/posts, etc).
So it would give you most of the same benifits.
In this case I think the advantage is that minecraft server dont have to listen to a public ip adress.