Tailscale’s human-scale networks are still controlled by Google and Microsoft
iliana.fyi
iliana.fyi
That said, I share OP's concerns as someone who has been evaluating alternatives to Google Workspace and Office 365. It is understandable that they may be prioritizing a B2B model, a decision which may be at odds users like OP and myself. That said, I still recommend it to teams/people who do not share this concern.
I hesitate investing further than my current setup because of this reason and I've been investigating whether Headscale/ZeroTier fit the bill. It is a shame because it is such a great product and it has been a while since I last had an equivalent experience using software.
I can ssh into machines without issue. Configure a firewall port and allow only ssh connections.
I’m curious because Tailscale is on HN every other day. I’d like to give it a try but not sure for what problem I have.
So your SSH server wouldn’t even need to have a public IP. which is yet another guard.
And the proper authentication adds extra layer of identity guarantees so you know who can and can’t access network resources.
- Ditch my previous VPS + Wireguard setup which I had to maintain
- Easily add/remove my own exit nodes as I wish/need (either using my own devices or any VPS)
- Use my beefy desktop as a remote development setup
- Running syncthing/rclone across all of my devices without relying on relay nodes or whatever
- Accessing all of my devices remotely
They just make it dead simple to run your network without worrying as much about opening yourself to the internet. I know you can achieve this without Tailscale but they just make it so easy. Their ACL system is pretty easy to configure and you can even add assertions to it.
They've documented some use cases here https://tailscale.com/kb/guides/
I don’t use Tailscale, I use a competing and currently arguably better product (Netmaker).
Imagine you’re a business building XYZ software product. You build a k8s cluster in one region, but now you need your system also to exist simultaneously in another region for failover reasons. Now you need region A to be able to have replicas in region B in real-time amongst many other requirements and those two networks from each region need to be able to understand and talk to each other with minimal setup and headache. Perhaps network A is set up on DigitalOcean and network B is on AWS or GKE for financial or technical reasons. Example: it’s cheaper to have surplus machine needs on AWS/GKE but you don’t want machines running there all the time because it’s expensive.
Enter Wireguard mesh networking. Ever since kernel Wireguard made it into Linux this is where the endgame has been for cloud deployments. It’s a huge improvement over the previous solutions. Netmaker and Tailscale are two offerings of that solution.
Note that I’m not affiliated with Netmaker at all. Just a quite happy customer.
1. Put WireGuard on a Pi. Create a server config.
2. Open the WireGuard port to the Internet (don't worry, it's invisible)
3. Install WireGuard elsewhere, and generate a client config.
All devices can now talk to each other. Tailscale has a "magic DNS" feature, which is nice, but WireGuard also supports custom DNS in the config.
If that‘s you, you probably don‘t need Tailscale.
But if your scenario is e.g. SSHing from your phone to a Raspberry PI behind a carrier-grade NAT, it‘s definitely worth a look.
Thanks. Can you elaborate on how it's invisible? I was looking at the docs and it looks like it defaults to UDP port 51820. Certainly that's visible no?
Not quite the same. Opening a Wireguard port to the Internet doesn't help if the port is unreachable due to weird NATting.
My home ISP puts me on CGNAT so I have no IPv4 access to my network. If I'm out and on a v4-only network, I can't connect to that Wireguard instance without going through other hoops (like a "bastion" Wireguard peer on a dual-stack host, for instance). With Tailscale, it Just Works.
I admit I wasn't able to understand most of those explanations so I could be wrong. :)
[0] https://tailscale.com/blog/how-nat-traversal-works/
[1] https://tailscale.com/blog/how-tailscale-works/#encrypted-re... under "Encrypted TCP relays (DERP)"
Now when I am at home or travelling, I have direct access to my test database, VMs and remote desktops without having to tunnel those ports.
When they say zero conf they mean it. Truly impressive product. I could get away with the free version but I paid for it I was so impressed.
I'm very much reminded of the infamous dropbox comment: https://news.ycombinator.com/item?id=9224 :)
In any event, if you're working with people who are technical enough to handle Tailscale, you can stick the ssh one-liner in a script file and tell them to double-click it to launch the tunnel. Or use a graphical SSH client with a port-forwarding profile, if that's you like. Tailscale has real advantages, but I'm skeptical of ease of use really being one.
You can be skeptical about ease of use all you want, "Log in with a IdP you already log in to, and then just open the site" is miles easier than "just launch the tunnel via script" and all the debug steps that come invariably when the tunnel malfunctions.
I know this is hard to see when to you, running an ssh tunnel is second nature. But if I gave my family a "graphical SSH client with a port-forwarding profile", they'd rightfully yell at me. These are steps they neither want to nor need to be comfortable with. And, heck, it's easier for me too. One less thing to worry about.
Somebody is running a whole bunch of infra for me, and has spent a whole lot of time addressing all the edge cases that "one-liner script" doesn't address. I happily pay money for that, any time.
Which ssh one-liner? You can't ssh into a machine that's not publicly reachable without some more hoops. I thought that was one of the points of Tailscale, taking care of the Wireguard "advanced" setup.
This was ostensibly to allow “corporate” accounts to easily group all users together, but the behaviour relies in the backend on a manually maintained (by Tailscale) list of “shared” domains where this auto joining behaviour would be bypassed (eg. @gmail.com) to prevent say all Gmail users being grouped into the same account.
Of course this manual list missed some obscure shared email domains and there were users complaining on GitHub that they were unexpectedly seeing other users/machines in their account.
I hope this terrible design decision has now been fixed in some way but it adds to my slight unease at the authentication model being used (along with the OP’s concerns).
Aside from this Tailscale is a great product, but for something focussed on security these sorts of things need to be given a high priority (if they’re not already).
I don't particularly _want_ another login, but I also don't cherish the thought of losing access to Service A because of the actions of Service B.
Luckily not too many, but it still strikes me just how stupid I was to use that option on any site, instead of an email and password.
It's completely self-hosted, so none of your traffic will go through our servers. You can also use basic auth by default (though there is also OAuth). Finally, as a bonus, it's much faster because you can use kernel WireGuard.
I won't claim it's as user-friendly as Tailscale (yet). It definitely requires more technical knowledge to set up, especially considering it's not a SaaS. But if you're willing to get through the initial setup (Day 0 / Day 1), you should be golden.
A romantic network, or a particular subset of relationships within a romantic network, whose members are closely connected. They can be intimate, familiar, romantic, or sexual in nature , but not limited to. The polycule created is unique to the people involved and the variations, they create.It is usual for a large number of companies (and tech folks) to know what that means, but disproportionately so for the Bay area. The blog poster certainly works for a company I'd call Bay adjacent, so they wrote in a language familiar to them.
It has nothing to do with "only place that matters", but simply explaining that given the context of the writer, it's a high likelihood they assume general familiarity.
I run it on an SFP: https://plumspace.com/products/smart-sfp/
It's cool.
Tl;dr - they baked a computer inside of network connector cuz it’s already huge. To do… stuff. Kinda like bmc
They are russian but shipped from Germany though, so, sanctions maybe they aren't able to sell anymore, dunno.
Tailscale does not need to be all things to all people, and especially not at the free tier for personal use. Adding extra complexity to the product would mean that it would no longer be the easy to use tool that it currently is.
There's BeyondCorp; there's two-way SAML directory binding (i.e. Google can be your enterprise's IdP for other service, or you can use your enterprise's IdP to sign into Google!); there's GCP Application Default Credentials; MFA device bindings; "application passwords" to pass through 2FA requirements; the ability to tell the auth layer to temporarily disable a user's password prompts via the admin dashboard; Google Take-out; Workspace account data export for terminated users; detachable adjunct accounts (e.g. Youtube channels); etc x1000.
Did you know that tucked away within every Google account is a set of AWS-looking credentials, that exist only to allow object-storage clients that only speak the de-facto "S3-compatible" object-storage API, to interact with Google Cloud Storage, authed as a given user? That's the kind of thing that using Google as your IdP gets you.
Github, meanwhile... if you're not using Github Enterprise, you can't even sync team memberships from your enterprise directory, so you have to grant your HR people org admin(!) access, so that they can grant and revoke team memberships during employee onboarding/offboarding.
In this case check out headscale.
[1] hhttps://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Give it a shot! :)
The main difference (to Tailscale) is that ZeroTier doesn't need an identity provider, since each machine needs to be whitelisted in ZT admin panel.
On Tailscale you also need to whitelist machines in the web console. There's probably an automated way to do it as well but I haven't looked into it since I only use it for a few static hosts.
I've migrated from ZT to TS about a year ago because ZT was much slower (network bandwidth-wise) and CPU-intensive than Tailscale on my setup. YMMV.
MagicDNS is such a killer feature, all nodes are really hands off and I don't need to worry about IP addresses anymore
Bug was "[closed] since it's already on the road map" (???) for 1.4, but after 1.4 release it is still unclear if it is even possible.
To be clear, not alleging it wasn't technical. The polyamory <-> shared services thing just wasn't obvious to me since I was unfamiliar with the term.
I don't think it's meant as a metaphor.
Definitely right.
I have to say I was a little afraid at the end that I might have inadvertently offended someone.
This is a better outcome in comparison.
It's ok to not be part of someone elses clique and not know all their terminology!
On both threads it says 4 hours ago. I thought I was going insane because I remember googling Netmaker at the time, and it definitely wasn't today. Clicking into their profile shows the comment '1 day ago'