Headscale: Open-source implementation of the Tailscale control server
github.com
github.com
https://github.com/slackhq/nebula
Crazy simple, fully open source, trivial to self-host. Maybe not as featureful as Tailscale, but imo that can be a feature unto itself.
The advantage of Nebula is that it's dead simple. Generate a keypair, copy it over, copy the config file, and go. It can do mesh routing for the vpn and traverse nat magically. You can delegate dns to the lighthouse and name resolution just works too.
That simplicity is awesome for personal use, and maybe it's good enough for a small operation, but I'm guessing it doesn't have all the bells and whistles you'd want for medium or larger companies.
So, yes, it works for personal use-cases but it works for truly gigantic applications, too.
You'd also want this to be self-service in some way - so road warriors can rotate their own certs, with auth backed by some kind of central SSO system. The last I looked, Nebula didn't offer this stuff.
> If you’re a system administrator or technical person looking for a completely open source, free peer-to-peer mesh VPN, and you’re willing to run a certificate authority and the control plane yourself, try out Nebula.
> If you’re looking for a polished, user-friendly peer-to-peer mesh VPN with a hosted control plane and integration with existing identity providers, give Tailscale a try.
The threat model is someone adding peers to the control plane, including as a result of control plane takeover or the identity provider failing. These special nodes can’t then be made to talk to anybody they can’t authenticate, no matter what you do on the control plane. It assumes private keys are safe. Obviously this is a client side setting, which shouldn’t have any control plane API, just like the current Tailscale options to eg accept no incoming traffic. This comes from my experience with ZeroTier, which I wrote about here: https://news.ycombinator.com/item?id=28426664
Then you can run your own Wireguard key distribution if you like, but ideally you just distribute manually for a few nodes and leave it at that.
Certificate management is its one weakness at the moment. There are a growing number of projects floating around attempting to solve that though:
- https://github.com/unreality/nebula-mesh-admin
- https://github.com/b177y/starship
- https://github.com/symkat/MeshMage
Plus im sure defined networks has their own solution in the works as well.
For example, I have a personal laptop - I want to join two different networks, that are for two different purposes, and be able to talk to hosts in each? (But hosts in each should not be able to talk to hosts in the other)
You can run multiple instances though.
Ps if we're listing alternatives zerotier is also one
WireTrustee: https://news.ycombinator.com/item?id=27672715
Netmaker: https://github.com/gravitl/netmaker
Defined.net (from makers of Slack Nebula): https://www.defined.net/
- https://github.com/key-networks/ztncui (the most popular one, GUI)
I don't use Tailscale because I don't trust their key distribution, and this open source project would solve that, but it might undermine Tailscale's sustainability.
This would be a shame because Tailscale is working well with the open source community: open source clients, working well with distros, working well with Linux DNS stack, supporting a more P2P secure Internet, and documenting their well through it.
Both look like great products, I just don't need what they're offering enough to accept their downsides.
So many users will not have even considered the paid version anyway, and their participation will give tailscale a higher marketshare and thus more viability.
Also, Tailscale offers OAuth through large corporate providers; I'm not sure Headscale is going to support that. (Actually, this is why I don't use Tailscale for my private network: I don't want to depend on an external OAuth provider.)
Companies looking into this will pay Tailscale.com service. You really need commercial support if you plan a large enterprise deployment. Tailscale even now offers a self-hosted version of their service - for those with concerns about using the public SaaS.
The question is this. Say, I use one of the above to form a private mesh network for the nodes that an organization needs to have access to. So far so good. But on the machine side I would still want to have key (ideally certificate) based authentication, and some user management, such that access can be revoked. Is this an anti-pattern? Or do people use something like Go Teleport in combination with a zero trust mesh network?
An organization uses Tailscale. There's 'server102' that is connected to the Tailscale network that all users of the `devops` team have access to. A new employee, Anne, joins the company. Sysadmins set up her SSO account, as well as makes her part of `devops` on Tailscale.
Anne gets her company computer, sets it up, connects to Tailscale, fires up her shell, types in `ssh anne@server102`, presses Enter.
What happens?
cool. netflow for encrypted mesh networking. still vulnerable if both nodes are compromised via a sidechannel and collude on their logs, but that's also getting pretty radical in terms of an attack vector.
what about actually logging the contents? i've seen big commercial systems that look pretty much like distributed wireshark, with capture points, storage systems and pretty guis for inspection... not sure how prevalent and useful they are, but having a step deeper than netflow style logs can be useful, both for debugging and security purposes. i suppose you could do this double entry for that as well, but that seems a pretty high cost if the tunnels are high bandwidth?
In the more distant past, I used sshuttle to create “one way” poor man’s VPN; it is slow, but it was enough to saturate the remote connections I had at the time; and —- unlike many other systems at the time —- I knew I could trust the cryptography and key distribution, which piggybacks ssh.
At the minimum,I want to have connections going only one way between sine hosts, or no way in the case of two edge devices - and possibly also list specific ports and protocols. Sshuttle only provided directionality - and not intentionally either…
Sshuttle was conceived and written by Avery Pennarun, who later went to co-create … tailscale.
It's a fully meshed network based on wireguard, it's open source including the web ui
You can add a new machine, so to set up the third machine takes 10 minutes, the fourth takes 10, the fifth 10, etc
If machine 3 wants to talk to machine 6, packets are routed via the single central "vpn concentrator" machine.
However to really benefit from wireguard, you don't want to tunnel all the traffic through a single machine - both from a security perspective and performance perspective.
To add 3 machines is fine, you need to set up 3 tunnels, from machine 1-2, 2-3 and 1-3.
A fourth machine needs 3 new tunnels - 1-4, 2-4 and 3-4. A fifth machine needs 4 new tunnels.
You then need to manage all those keys and cycle through them (you should change private keys regularly)
Things like tailscale automate all this. You want to add 19th a machine, you simply add one entry and it handles the rest.
That's how our larger on-prem customers use the iOS client when they run their own in-house control plane server.
A simple setting in the app would be far easier yeah. I would suspect that the ease of people bypassing the paid service is probably not a priority for them ;)
Personally I never even tried tailscale as I try to avoid Google. I definitely don't want to use my Google account to log into it and give Google more information.
But tinc serves my usecase well. The peer injection is a bit of a worry there too though. Especially because tinc peers are able to add any peers on their own (it's a feature meant to provide easier configuration).
I tried nebula extensively too but it didn't add enough over tinc to make it worthwhile switching especially now that tinc has an Android app.
Adding dns-over-https so your ISP can not collect where you're going.
As far as google etc collecting your info, it will work the same as long as you're using their service, with/without VPN.
I do use VPN(tailscale) for work so I can access corporate internal network, but for general surfing purpose, do I really need vpn these days.
I still posit the alternative to Tailscale is simply just wireguard. I don't see huge value in hosting my own Tailscale over just using Tailscale.
> Lack of “feature parity” is a strange term for something that completely replicates a third party service but requires self-hosting.
It doesn't completely replicate it though, does it? No iOS app, no file sending -- heck the entire premise of Tailscale is oriented around SSO as they are explicitly not an IdP.
I don't mean to knock this effort -- it's great! -- but even if I were to switch to this today, there is a ton of missing functionality, and I'd need to do a ton of work beyond the scope of Headscale just to get this running in my corp.