I've switched all my devices to it and frankly, it's wonderful. Private VPN, tunnel, VLAN, auth, sharing, all-in-one.
One thing I can't get over is that it's pricing is "per user". That makes sense our user-oriented VPNs (dev workstations, home machines, and phones), but doesn't feel like it's oriented towards server use. My end use case is probably 80% securing server connectivity across sites.
Alternatives I've looked at include: ZeroTier, Slack Nebula, OpenVPN Cloud, and PriTunl.
ATM, I'm using ZeroTier for my home use and quite happy with it. I had hopes of being able to deploy something for work as well, which is why I leaned towards ZeroTier. For home use, TailScale's pricing wasn't a concern.
If you're a larger business, the pricing seems... fine? I don't know what their enterprising pricing is like, but the next-highest tier appears to cap at $10k/yr, which seems like a trivial cost to anyone operating at that scale.
Consider also that you don't need to run tailscale on every host -- though you could. Depending on your architecture, a single gateway instance in each VPC could be sufficient. In other words, I could probably scale the two non-enterprise tiers very, very far, at least until you had close to ~500 employees, in which case you probably want to strike a deal for custom support and SAML SSO anyways.
Alternatively, at $LAST_JOB we just ran our own OpenVPN servers and in-house beyondcorp authwalls. There was honestly not a lot of complexity in there. We had <3000 employees.
> That makes sense our user-oriented VPNs (dev workstations, home machines, and phones), but doesn't feel like it's oriented towards server use.
Just to be clear, you don't pay per-server. Just for logins.
> My end use case is probably 80% securing server connectivity across sites.
100% is not by any means an unachievable goal in, say, a quarter or two. Any reason why you don't want that 20% tail?
For example, I can use my desktop at home as an exit node for my phone, so I can configure my network hardware (router, switch, AP) from my phone, from anywhere.
Then, ZeroTier does have a free tier, with open-source clients for every platform I care about. Yes, they are limited to version 1.x, but maintained nevertheless.
I like ZeroTier because: It was dead simple to set up, the web management UI is good, the "public" networks seemed like they might be nice for CI/CD servers to connect into some infrastructure to deploy (though that didn't work out because CI/CD docker didn't have flags allowing ZeroTier to work, but I did just get SSH over userspace ZeroTier working). It's super easy to set up in all the environments I've looked at.
The only thing I could wish for would be an auto reconnect feature, been thinking about wrapping it in a shell loop to handle it but it requires sudo so I’ve been putting it of, I don’t like having a long running script with sudo.