Tailscale free for open source projects
tailscale.com
tailscale.com
EDIT: https://tailscale.com/kb/1139/tailscale-vs-zerotier/
That is a very fair writeup for a competing product. Nice!
The steps are basically:
“Step 1: Sign up for an account
Step 2: Add a machine to your network
Step 3: Add another machine to your network”
Or you can self-host Tailscale with https://github.com/juanfont/headscale if you want.
So worst case they help with the open source code or bug reports or they get sick of self hosting and pay (or use our hosted one for free).
It is possible for enterprises, though we encourage users to first see if the hosted version will work for them because support is difficult, and thus significantly more expensive, for self-hosting.
Then again, I imagine the keys are generated on the device and the code can be audited to never share them, plus it's WG under the hood.
But except that deploying Wireguard* on a VPS for bypassing censorship/georestrictions is quite nice and cheaper compared to many paid ones.
* Tailscale and Zerotier aren't really needed if you want to route all your traffic thru a single machine, wireguard itself does exactly this.
If possible, just bringing the node/servicenin question "into" the wireguard/tailscale network would be better. But good luck getting a hospital to allow you to connect your tailscale to their patient record db (or what have you - obviously in this case you'd hope they have a solid vpn and give you access.. ).
For the use case of "talk via vm through mullvad exit node" i suppose you could set up Mullvad on the vm, and tailscale on the vm with Mullvad vpn as exit node, then join all your other nodes to tailscale.
Tailscale would replace how you connect to your vm, not mullvad.
It's good for home use, but --- and I am bias I guess because of my background --- where it really shines is corporate connectivity. If I joined a company as a security person and it was running some horrible OpenVPN access VPN for its dev team right now, one of my top action items would be to replace it immediately with Tailscale.
tldr make sure the bastion box can reach the stuff you need it to reach as far as subnets and security groups go, ensure kernel will fwd traffic from WireGuard clients, run WireGuard daemon, and expose it to the outside world via eip. I’m oversimplifying (dns, sec groups, routing client traffic to other subnets) - but hopefully that explains the gist.
I have a small Python script that takes a XLSX file as input and populates a dir with config files and QR code images for each user.
Or you can check out some of the OSS ways to do self-service vpn mgmt with a web UI that authenticates against Google auth. I haven’t deployed this yet but it looks cool https://github.com/subspacecloud/subspace
If you know this sort of tech well it is not hard to deploy and manage yourself. But tailscale has a really killer clientside experience and “just works” so honestly it might be worth the $$$
At some point you’ll probably want to integrate with some identity management , but dozens of users and hundreds of servers are totally fine to manage as yaml in ansible IME.
It's not unlike Tailscale and nebula (that others already mentioned) but I think it deserves to be mentioned.
You can bolt-on SSO fairly easily - just create a certificate signing service. I created https://github.com/unreality/nebula-mesh-admin in a weekend, so its fairly easy to add a SSO flow in.
Nice!