Cproxy: Per app transparent proxy built on Linux cgroup net_cls
github.com
github.com
One use-case that I still haven't found a workable solution for: P2P applications over UDP, where I want all incoming and outgoing connections to be tunneled through a remote endpoint (typically over VPN).
And example for how to achieve that in some way (I guess with for, say, Bitcoin, Ethereum or Bittorrent, would be simply amazing.
dokodemo-door is something I never heard about before and looks like the other half of that puzzle, as the readme notes. Going to have to look at it closer.
https://www.v2ray.com/en/configuration/protocols/dokodemo.ht...
It's more the routing that is the issue which, unless I'm mistaken, falls out of scope for Tailscale (assuming one already has the VPN part sorted).
https://tailscale.com/blog/sharing-over-tailscale/
[0] Well, they aren't an ISP yet, but I wouldn't put it past them because of the founding team's previous experience leading Google Fiber.
I want to have incoming and outgoing UDP from a particular process/container reachable externally, but routed through a different peer. Maybe I wasn't clear, but I'm talking about public, unathenticated and untrusted P2P networks.
I've looksed over their repos and documentation and see nothing (apart from general "anything is possible" marketing handwaving) indicating it's less work than on any other topology/protocol.
If you read the parent issue to what you're posting (which is also not exactly what I'm asking for, I need something more granular wrt routing), you can see clearly from the discussion that this is completely orthogonal to what Tailscale is aiming to achieve.