Innernet: open source Rust based Tailscale alternative
blog.tonari.no
blog.tonari.no
I really like the simple client/server architecture, that it's easily self-hostable and there are no servers outside of my control.
The invite system reminds me of the way Tinc[1] handles it, which is great. It's so good to see user friendly tooling on top of WireGuard.
Request to HN floks : I can setup a basic home network, but I want to really learn networking ( Setting up subnets , understanding CIDR, etc ).. Where should I start ?
I also end up using https://gitlab.com/ipcalc/ipcalc a lot, and am definitely planning on similarly making it easier in the terminal to manage and visualize the CIDRs in innernet networks. I'm hoping innernet can become a fun way to learn networking in a safe (and cheap) virtual environment.
This is the best subnet calculator, since you can split and join subnets visually.
I played around with Wireguard directly and having better ergonomics without vendor lock-in is great, i look forward to taking it for a spin.
1. Is it possible to use the same subnet on different innernets?
2. Could you please provide installation instructions for generic linux, as I am looking to host on almalinux and opensuse leap, neither of which use dpkg.
Thanks for sharing!
* I expect anything coming from that peer to have an IP address in AllowedIPs
* I know that a peer's AllowedIPs can only be reached through that specific peer
Also, RFC 1918 lists 2^24 + 2^20 + 2^16 = 17 million IPs. You should normally not have an issue finding networks that don't overlap.
10/8, 172.16/12 and 192.168/16
Also, using the same net on different interfaces would probably confuse your server. Maybe if you do some magic with VRFs you could. (And it doesn't mean you should)
As moviuro mentioned, no, not unless you want to get fancy with independent network namespaces (https://man7.org/linux/man-pages/man8/ip-netns.8.html).
If you want to be more confident of not having an address space conflict, I recommend using a randomly generated private IPv6 block using the RFC 4193 specification: https://en.wikipedia.org/wiki/Private_network#Private_IPv6_a...
> 2. Could you please provide installation instructions for generic linux, as I am looking to host on almalinux and opensuse leap, neither of which use dpkg.
Our Arch PKGBUILD (https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=inner...) may be the simplest existing guide for making your own package for your distro. If it's not a lot of work to add, I'm happy to maintain other package formats, or help you be a maintainer.
Thanks! Looking forward to hearing how it goes for you.
For example, suppose Kermpany had already been up and running for a while with a standard Django website running behind Cloudflare with an admin page at example.com/admin/.
Now the things in the blog post have happened, and Kermpany wants to make sure that only machines on the "humans" CIDR can connect to the routes hosted at example.com/admin/.
What happens next? Does the admin tool move to a new domain?
The manual wireguard solution I know of is to add the example.com IP to the list of AllowedIPs, so the wireguard interface gets used for all requests from the local machine to example.com, and then restrict the /admin/ route in nginx to just the wireguard server's IP. But that takes a lot of bookkeeping and I feel like I'm missing something.
IMO, moving the admin tool to a separate domain (and server!) would be the best option here in terms of security. That way, there are clear boundaries and fewer attack vectors and you also don't need to do as much bookkeeping.
[0]: Ever since someone posted https://news.ycombinator.com/item?id=23540586
Is there anything in particular you'd like to read about?
That's great, looking forward to them! :)
> Is there anything in particular you'd like to read about?
I'd love to get a better impression of what your setup, well, feels like. Specifically, three UX questions have been going through my mind lately – probably because I've been working from home for far too long haha :( and having a portal like yours would be fantastic!
1) How important, in your experience, is it for people to look (or have the impression of looking) into each other's eyes? What ways have you thought of that could accomplish that? Do you maybe even happen to have a solution? My gut feeling has been that being able to hold eye contact would go a long way towards making people on each side of the portal feel "close" to each other. So if this were possible somehow, his would be a game changer.
2) How would one do conference calls with your setup, UI-wise? (Let's assume for a moment that bandwidth is not a constraint.)
3) What about eye contact (question 1) when there's a group on each side of the "portal"? It seems almost impossible to achieve with a 2D screen.
4) General question (I realized I should have asked this first): Where do you currently place the camera? Putting a webcam on top of a 27" monitor already makes holding eye contact challenging but I imagine it's even worse with a large screen where you put the camera at the very top or bottom because the camera will always film you at an angle.
5) In the context of question 2, the question of eye contact seems to be quite complicated, too. I imagine that at the very least one would need arrange all participants of the call in some fixed spatial layout that's the same for everyone but the camera angle still remains a challenge.
If you look closely at the images and videos on our website, you'll be able to spot it. It's often a fun game we play when giving a demo to someone new. Many people take quite awhile to find it and the AV nerds point it out almost instantly, haha
But yes, with the current setup you can't get perfect eye contact in all scenarios. It works surprisingly well in multi-person conversations though, as you can clearly see when someone shifts their focus on you vs. someone else next to you.
Sweet, that's good to know!
> If you look closely at the images and videos on our website, you'll be able to spot it. It's often a fun game we play when giving a demo to someone new.
Hmmm… you made me have another, closer look this time. :) In one of the photos it looks like on the other party's side there is a projector near the ceiling in the back but then in subsequent photos that projector's light is gone and there's a different, stronger light that seems much closer to their camera/screen. Is this correct?
Also, have you considered/tried using an actual LCD screen? At our company we're currently dabbling with digital signage devices (for entirely different purposes) and the big ones are quite impressive. I could imagine that, in terms of dimensions and appearance, they would work quite well for your purposes.
In those cases those are just normal overhead lights, nothing from a projector. The camera is actually in the screen!
> Also, have you considered/tried using an actual LCD screen? At our company we're currently dabbling with digital signage devices (for entirely different purposes) and the big ones are quite impressive.
Yeah we definitely want to move to panel displays when it becomes more feasible to do so. We haven't yet made a prototype with an LCD screen but I look forward to the day when we can, because projectors are a lot fussier to deal with.
The only thing missing from tailscale for me is being logged into multiple accounts at the same time.
Basically the use of a VPN is to add an extra layer of defense. Instead of finding a security hole in our Kubernetes management interface or samba server, an attacker would first have to compromise a workers system, and only then attack our internal servers.
The best part is that you don’t have to open any ports on your router and it “just works” out of the box.
So even if I’m in a different country I can use the nextcloud app on my phone to connect to my raspberry pi in a secure manner and backup photos, which in turn backs them up to my VPS.
If you tell me "it's easy, just read the docs" then I am going to cry.
I don’t use magicdns yet since it’s in beta.
I believe there is basically a optional network stack path that utilizes NRPT but it’s not the default path, so only MS-blessed code that is actively using NRPT (so the new VPN stack and their DNS server) actually works with it.
Could you elaborate more on what split DNS options are available out of the box on the various systems? I'm genuinely curious what a no-convoluted-nonsense DNS setup looks like for this kind of tool.
To configure split DNS on the server, you'd need an authoritative server listening on the wg interface and update the zone file when peers are added and removed.
To configure the split DNS on the clients:
Linux: systemd-resolverd supports split DNS see https://fedoramagazine.org/systemd-resolved-introduction-to-...
MacOS: Supports similar split DNS by domain/interface, see resolver(5) for the details.
Windows: I'm not a windows person, but it appears that Windows has trouble and you need to play with interface metrics, one solution was to install unbound and use it instead of Windows' native resolver.
Nebula has mobile apps. Might this be possible for Innernet in some distant future? It seems like no if it needs root.
Personally, I'm not surprised in the slightest that messing with networking requires administrative privileges. I don't really understand the use case for rootless nodes or how they're normally managed, but I can see how those are too niche for most networking software to work with.
I've never tried it, but perhaps you van get Innernet to work with the usermode WireGuard client (the one written in Go [2]), that seems to work on Android without any kernel support or root privileges. Innernet is a daemon over the wg command line tool so it might work out of the box?
[1]: https://github.com/slackhq/nebula [2]: https://git.zx2c4.com/wireguard-go/about/
Fortunately, it sounds like that's just an alias, so people who care about "inn" can just spell out "innernet" or make a different alias themselves.
Happy to change the way that alias works if it ends up being a problem.
Tailscale does use considerable CPU on my Mac though.
[0]: https://github.com/tailscale/tailscale/blob/main/net/tstun/t...
macOS is a different story, since there are only userspace implementations at the moment. Innernet currently looks for the official "wireguard-go" implementation, but you can swap out userspace implementations as you like. I'll add an environment variable check to make that easier without needing to recompile.
Is a TCP mode planned? This would be useful for networks where outbound UDP isn't allowed. (hotel wifi, other public wifis)
Do you plan to add automatic key rollover/expiry?
There aren't any current plans to bake in TCP support, but you can rig it up yourself using something like udptunnel.
Related old HN comment with basic instructions: https://news.ycombinator.com/item?id=17847008
Also see: the "TCP Mode" section in https://www.wireguard.com/known-limitations/.
I feel that adding TCP support would push innernet beyond a WireGuard configuration manager and into something a bit more behemoth. I'm quite fond of the fact that innernet doesn't "touch the packets" in its current state.
That said, if a strong need arises over time it's not out of the question, and in the mean time anybody is welcome to add their own wrapper around innernet or fork it to support that.
if you private dns nameservers, DNS queries are made over plaintext.
Magic DNS is not a hard-sell.
You see, kids, back in the day, the internet was not ran exclusively by gigantic mega corporations whose only argument against monopoly was "but but but WE wanted to be the monopoly!" Before Walmart pushed out all the mom-and-pop grocery stores, we had mom-and-pop internet service providers, and they didn't have to be called "artisanal" or "organic" to get anyone to care about them.