Tailscale ate my network (and I love it)
smackeyacky.blogspot.com
smackeyacky.blogspot.com
[1]: https://aws.amazon.com/premiumsupport/knowledge-center/syste... [2]: https://medium.com/hackernoon/ditch-your-ssh-keys-and-enable...
https://aws.amazon.com/about-aws/whats-new/2022/05/aws-syste... https://docs.aws.amazon.com/systems-manager/latest/userguide...
`ssh aws-bastion` invokes a ProxyCommand that:
1) finds an actual bastion host by tag using ec2 describe-instances
2) generates a short-lived ssh key and adds it to the ssh agent
3) sends the temporary key to the bastion using ec2-instance-connect send-ssh-public-key
4) starts the SSM/ssh session using AWS-StartSSHSession
Since it's SSH, we can port forward, use multiplexing, etc. We use Google as the IdP, via AWS SSO. Bastions periodically sync users from a Google group.
[1] https://www.reddit.com/r/aws/comments/df6uip/ssm_tunnelling_...
https://aws.amazon.com/about-aws/whats-new/2022/05/aws-syste...
Also, intellij's built-in database tools support ssh tunneling, it 'just works' with the ProxyCommand method.
If Tailscale-the-product ever goes rogue or evil, I can always self-host wg or a full on tailscale-equivalent mesh myself. I sleep well knowing this.
If you were looking for an open source, self-hosted implementation of the Tailscale control server (as far as I know, that is the only portion of tailscale that tailscale keeps proprietary, and this is the best open source implementation of it).
Edit: wow, this project has really grown from when I last saw it. It is able to configure the vast majority of tailscales base featureset such as ACLs, magic DNS, taildrop file sharing, and so much more. Incredible.
Edit: Oh no, indeed when you want to sign up you need an sso provider indeed! This is what they say:
Can I sign up with an email address?
We don’t support sign-up with email addresses. By design, Tailscale is not an identity provider: there are no Tailscale passwords.
Using an identity provider is not only more secure than email and password, but it allow us to automatically rotate connection encryption keys, follow security policies set by your team (e.g., 2FA), and more.
It's also a pretty effective way to limit the amount of tailnets a user can have.
I have no idea how the official clients will deal with that, though, but I've never used tailscale myself.
Could you please elaborate on this solution? I'm not sufficiently knowledgeable about OpenID to quite understand what you mean, but I'd like to avoid any of the mentioned SSO providers, as they're all blocked on my systems for personal use.
Added: Found these as per mention in your post:
[0] https://openid.net/connect/
... so I assume you mean that I could install one of [0-2] along with Headscale [3] to get the similar effect of installing Tailscael, just without those annoying SSO providers? I will see if I can find the time for examining that solution. Anything that can keep MS and Goog away is most welcome
Keycloak is quite a complicated system to configure, though, there are easier alternatives out there. If you're just trying to get anything up and running, something simple like Authelia may be better for your use case (disclaimer: I've never tried it, but it seems light weight and other people online seem to recommend it).
Also the iOS client, which is hard-coded to only use the first-party control plane, so you can’t use headscale if you have iOS clients :(
If I didn't have the goal of buying a house in the Bay Area, I would totally try to find a job with Tailscale.
There's no "I'm free once I'm a home owner" thing.
I finally signed up to an account to HN to say emphatically that it's the opposite.
Owning a house is a huge responsibility that takes up the vast majority of my time, and it's a millstone around your neck if you ever think about moving somewhere else.
I seem to be an exception, but I have no need to define who I am by my housing, nor do I need the security of owning my own house. I have also lived on three continents, so I appreciate the ability to pull up stakes and move with very little fuss.
What in the world? This doesn't even come remotely close to passing the sniff test. Is your idea of homeownership like, constant remodeling or something?
I do zero hours of maintenance/upkeep per week, just like you with your rental.
Is your landlord now doing 10-20 hours of maintenance/upkeep per week for every apartment? Of course the answer is no.
In Sweden, homeownership vs apartments is quite a large difference.
The other side of keeping up with maintenance - if you don't have time nor want to, hire away. It will eat a significant chunk of change to hire all the professionals your landlord was hiring, the difference being you are hiring yourself versus being dependent on the landlord.
For the DIYer, tools acquisition is definitely a PITA. Hardware stores have a decent selection mostly of what you need, but it would be nice if there were preset of tool maintenance you could order, maybe even save you money over long term buying it all piecemeal.
I'd imagine the real time suck would be for planning/research for it all, if you are used to spending your time coding, playing games, or otherwise amusing yourself, yes for the first couple years you will not have any time for these things as you are acquiring your skillset(s).
But that could be said for going back to school, etc. I think it's pretty valuable to be able to maintain your own dwelling apparatus, personally. It means you'll never be without reasonable shelter, so long as you have some access to raw materials, tools.
Lawn maintenance is maybe one or two hours a week at most, and that is mainly because we like to keep it pretty tidy. Then again, we would have needed to do similar maintenance (in the UK) for a rental if we wanted to keep the same standard for the garden.
Houses like anything else have lifetimes, You don't get to be a 200 year old house without having major maintenance done at least a couple times. Buying a poorly maintained, or constructed, old house is a nightmare, if it's bad enough you've discovered why some houses are condemned.
Modern construction often has a longer lifespan and more readily accessible materials, older houses are a mixed bag - some gems that may last hundreds (thousands?) of years, lots of houses that need major repair. Some in the middle too...
Home ownership is as much a comfort as it is a fantasy. There are true perks, eg, you're mostly in control of the regular costs (rent vs mortgage) but it also has downsides, like... basically any hazard and everything location-related.
PS: I feel weirdly kinda honored that you created your account and replied to my comment. Anyway, I'm just being me ;)
> nothing changes once you own the house
Why? What does this mean and is it actually true? The monthly/yearly cost of owning a house is typically much lower than the mortgage payments. If buying a house in cash, the maintenance usually is low enough to consider lower paying jobs. Needing a high salary might enable remodeling but basic taxes and upkeep are very very different from sale price or the payments to a 30 year loan. In my experience something absolutely changes once you fully own the house.
As a renter, this overhead is baked into your lease. As a homeowner, I can simply tap into home equity to do a major repair at single-digit interest rates over a decade. Something you will never be able to do as a renter.
I mean, yes, if you do things yourself it can be significantly less expensive, but most of the housing stock in the bay area is atrocious - good bones and awful everything else. They were thrown up as quickly as possible in the 50s-70s and so there's always something that needs fixing.
$18k+ a year in taxes...
In the country-side that kind of money gets you a 12 bedroom mansion with a pool and a view...
I do a lot of DIY but there are times when you just want it done and done quickly and professionally. We work for a living and don't really have time to deal with a lot of the DIY incremental aspects that happen until you get very good at any given skill. I just redid one of our bathrooms, but I wasn't going to redo the sewer lines solo let alone mid-week while living in the place.
The problem with HCOL is that even if you own you're burning cash due to the lack of time and very, very high cost of services.
But you DO need a high salary in the first place.
And with that big salary, you will buy a NICE house, which will require a lot of maintenance (house keeping, gardening) and taxes.
I think you’re trying to say that an expensive house is more expensive to maintain than a cheap house. That’s true. But the salary required to buy any given house is higher than the salary required to maintain it, for the most part. I’m sure there are counter examples, but on the whole most people who pay off their mortgage experience a pay raise, effectively, which has been my own experience.
Seems like a risky place to invest at this stage.
The way I usually treat it is: Can I pay off this mortgage in the event I don't want to sell the property?
Negative equity is a thing, sure, but if you were always happy to pay the price then the thing you're buying is worth the price, right?
Sometimes people think of things as having value only if they're relative to something else. But value is value, and value is the price that you're willing to pay.
In general, I think it's kind of an interesting heuristic to think about every so often: right now, putting aside practicalities like my current job or where I live, what looks like a cool place to work, even if the specific role was just taking out the garbage.
Right now the answer is "tailscale" and "oxide" for me.
In the past I also liked sourcegraph, too. Not sure what they're up to nowadays.
the idea that you'd pay a subscription fee greater than aws just to avoid a few hours of learning how to set something up is kinda disgusting in comparison.
FWIW I use both SSM Port Forwarding and Tailscale but Tailscale is easier for both tech and non-tech users IMO.
'Installing the agent client side is no more or less tedious than installing the Tailscale client, IMO anyway.
I made two scripts, one in .Net with a GUI for non-devs to grep a server hostname or tag:name in AWS that resolves to an instance ID for SSH or RDP. And another python script doing the same but without the GUI for the dev team. Works a treat.
But you've already explained why it's a little tedious and now I've documented and understood why. Tailscale MagicDNS does all this nonsense for you. Yeah ok thanks for rubber ducking me I see your point now. :)'
At most you'd need to add some permissions to the instance's role, maybe.
i can't say about that specific thing but i've been using this daily 24x7 for the last 2 years now. it connects my 20+ pcs and laptops which are geographically apart but because of zerotier, they are in a local lan.
it does not have SSO, relying on the admin accepting/rejecting connected devices by a single checkbox. this is in comparison to tailscale which uses Oath, meaning you have to create and maintain those accounts as well.
Their sales team, when I asked about self-hosing a controller, said it's not necessary because they've never had all the hosted controllers go down, but when I asked about a tweet they sent in May 2020 about their controllers being down, I never got a reply. [1]
My plan was to put ZeroTier on all of our machines and use it as an overlay network that all traffic goes over. But I don't want to open the availability of our network to depending on an external service.
I've all but decided on Nebula, just need to get the deployment worked out. I'm playing with Tailscale right now, and am very impressed. It does have the ability to require MFA on logins that we would like for user VPNs, while still being able to have servers self-authenticate (we respin half of our dev/stg environment every night).
[1] https://twitter.com/ZeroTier/status/1389766385480372225?s=20
Seriously? What equivalents does it have for Route53 and tons of other services?
I can't tell if this is misleading or pointless.
Your comment is pointless and a straw-man argument.
It works but performance is awful. Slow connection times and pushing images has slow throughput.
AWS Client VPN does not offer any means of unattended configuration or mass distribution. All they offer is a self service portal from which you can download the installable, the profile, and directions. Each use has to manually import the profile into their client.
I'm stunned they're missing this as it would prevent any sizable organization from adopting it.
One of the few products I recommend enthusiastically.
To be clear, WireGuard seemed to have the right level of abstraction as a tool for others to build on (just like it built on top of the noise framework), and someone like Tailscale ran with it.
Additionally, there's an open source reimplementation of the control plane called headscale, as well. The Tailscale team has complimented it, but of course it's all on your own if you choose to run it.[1]
[0] https://github.com/tailscale/tailscale
[1] https://github.com/juanfont/headscale
EDIT: Android code is actually entirely open, oops!
Which platforms?
From Debian wiki (https://wiki.debian.org/ReproducibleBuilds):
> Reproducible builds of Debian as a whole is still not a reality, though individual reproducible builds of packages are possible and being done. So while we are making very good progress, it is a stretch to say that Debian is reproducible.
Apart from Debian and NixOS, I'm not aware of any other large-scale efforts to make builds reproducible, so this something you have to assess on a case-by-case basis for every single piece of software you might want to download and install. Not IF the checksums match, but IF the project aims for reproducible builds in the first place.
By the way, if you download an iOS app on an M1 Mac, you can inspect its archive freely, including generating and comparing checksums of each file, disassembling the executable, and so on. So while not every iOS app can be downloaded on a Mac (the developer actually has to opt out), and not everyone has access to an M1 Mac, this is not entirely impossible.
> With iOS you don’t have that ability so you’d have to have complete trust in the developers.
This is not entirely true. I also have a certain degree of trust in the application sandbox provided by the OS, and in the app review process. I know neither is perfect but it's not like everything I install runs with full root.
> The threat model is someone publishing innocent source code but sneaking in something malicious in the version they publish on the App Store, of course.
What is your strategy for applications that do not publish any source code? Do you exclusively use software with source available?
Don't get me wrong, you raise valid and important points, but this is a way bigger fish and "if only Apple did X" is just the first step.
I wasn’t thinking of reproducible builds specifically, more that you’d be able to disassemble the binary if you wanted to check, because…
> if you download an iOS app on an M1 Mac, you can inspect its archive freely, including generating and comparing checksums of each file, disassembling the executable, and so on.
I did not know this. I thought iOS binaries are always encrypted. Why would they make the unencrypted binary available for M1? And now that they did, why would they bother still encrypting the same binary on iOS? (Do they still?)
> I also have a certain degree of trust in the application sandbox provided by the OS, and in the app review process.
I’m not too worried about an app escaping the sandbox and harming the rest of the system either. More that it could do something malicious with the data it has legitimate access to. For example, a password manager sending all your passwords to a 3rd party, a browser app injecting JavaScript into the pages you open, or a VPN app analysing all your traffic.
> What is your strategy for applications that do not publish any source code? Do you exclusively use software with source available?
Well _you_ were the one who preferred open source, not me. I was merely pointing out that “open source iOS apps” might as well be called closed source, since I thought it was impossible to know if you’re really running that code on your device.
Disassembling and analysing a binary (even with source available as a reference) is an *extremely* huge leap from comparing checksums. We're mere mortals. Get real ;)
> I did not know this. I thought iOS binaries are always encrypted.
I've just checked a bunch of iOS apps I have installed on my Mac (Apollo, Blink, Bandcamp, Organic Maps, iSH); ran strings, dyld_info, otool, etc on them, no walls. Maybe only the headers, rodata, linker metadata, etc are unencrypted? Should I keep digging?
> Why would they make the unencrypted binary available for M1? And now that they did, why would they bother still encrypting the same binary on iOS? (Do they still?)
No idea. But the binary being distributed on macOS and iOS is the same; or at least, it doesn't need a separate build/upload, apps published before the debut of M1 just work.
My company actually needs to release an update to an iOS app in the near future, perhaps I can take the chance to compare the artifacts.
> More that it could do something malicious with the data it has legitimate access to.
There are two possible scenarios where this happens: the developer being malicious, and a supply chain compromise.
In the first case, the developer risks getting ostracised by both the community, and the Apple overlords (e.g. for violating App Tracking Transparency). It's also a very risky move, since the traffic from the app can be analysed (e.g. on your home router) at any time, without the app ever knowing; and without e.g. certificate pinning, can also be snooped or MITM'd; this puts a timer/window on it. So in practical terms, for this to be remotely useful or worth the risk/effort, this would have to either be a narrowly targeted attack, and/or a one-off smash & grab. Again: not perfect, but the system has countermeasures.
The latter case is something we (as in: the entire industry) are still trying to figure out. Even with a fully OSS supply chain, it's far from ideal: https://drewdevault.com/2022/05/12/Supply-chain-when-will-we... - and again, in case of the App Store, with a third-party (Apple) review step, there is at least the idea of independently verifying the app's legitimacy.
> I was merely pointing out that “open source iOS apps” might as well be called closed source, since I thought it was impossible to know if you’re really running that code on your device.
You've never asked me, what was my own motivation for preferring free/open source software - and made a bunch of assumptions, not all of which held.
However I do share your view, that under certain (actually, very common) circumstances, software that is nominally free/open, can be considered closed in practical terms: and that, in my book, is rampant complexity. If the code is too complex for me to read and fully understand it, what use do I have from source access? Hence, my actual vote is for OpenBSD; but sometimes you just need to compromise to get stuff done.
https://apenwarr.ca/log/20211229 (the gift of it's your problem now)
Just install a new version which would work OR
Have the understanding how I can change the environment so it would work.
The thing is what I don't need to spend my time on solving these things.
I couldn't believe how easy it is to configure. I set it up for work, do a key rotation on a schedule and it's great.
Tailscale I use for home use on my personal laptop + machines and it's fantastic as I don't need to port forward or anything. I changed over from using Wireguard with minimal effort, just changing some IPs over. Probably end up using MagicDNS (their DNS solution), then if I need to change off I'll just change this.
Their free tier is very generous for a single user.
One reason to have gateways etc. was to ensure that gateway couldn’t be taken over by software installs etc. Access was inconvenient but it was somewhat by design.
Maybe due to this attack vector shifted from directed access to automatic scanning of ever expanding vulnerabilities.
Now, as services stops being accessible from external networks once again they can be accessed in convenient ways thus bringing the old vectors back. Sometimes even giving false sense of security.
ZeroTier can do other protocols like NetBIOS, so you can use it to run LAN games that don't use TCP/IP.
I can now go to sleep without having to worry about random bots trying to mine crypto on my machines. To add to the goodness, one does not have to worry about either SSH-keys or remember cryptic passwords.
FWIW, setting up something like tailscale is remarkably simple (I'm using PHP here to keep it simple):
In sshd_config:
AuthorizedKeysCommand /auth_ssh %u
AuthorizedKeysCommandUser nobody
And in auth_ssh, verify that the user is allowed to connect to that server, then look it up on github (my public keys: https://github.com/withinboredom.keys).If you want to allow any github user you allow to connect various permissions, check out libnss-ato.
These are all 1 or 2 lines of configuration and are not hard. You just have to know they exist.
Regarding the strangeness; yes I was lazy and had password based ssh and was in constant fear that someone might pop my box.
I believe they are all based upon variations of the same java ssh library and exhibit the same behavior. They all connect to tailscale ssh using 'none' authentication but after connecting don't display anything which means I can't get the URL tailscale ssh presents to do its authentication.
Edit: I was just able to work around the issue by installing Termux and using openssh in that environment to do my initial ssh authentication. Afterwards my normal ssh app works.
I was just able to work around the issue by installing Termux which provides a small Linux environment on your phone. I was able to use openssh in the Termux environment to connect and get the authentication URL. After that my preferred ssh app can connect without issue.
Curretly I am running a tiny VPS as a wireguard server, but I do not trust it to be part of my network. Therfore I run one wireguard tunnel to be able to access my router (has no public ip) and second tunnel inside the first to connect through the router to my home network.
Theoretically, it should be possi le with single wireguard tunnel if I set a route to home router via wireguard gateway - but I never managed to make wireguard encrypt a packet if it came from the same wg interface. Can anybody help?
Some features that are basically effortless and made me choose it over WireGuard and other VPN solutions: easy provisioning, key exchange, IP assignment, ACLs
Initially, I had tried setting up Nebula, but I am unable to get a static IP address for the beacon (a requirement for any of these mesh VPNs), hence why I went with Tailscale which acts as a beacon for you. I think I'll try ZeroTier next.
I've been running Tailscale on all my devices for a couple months now, and I haven't noticed any impact on battery life. I just checked my phone (Android) and it's reporting 1% usage.
I would report an issue if you're seeing numbers that high.
- https://www.reddit.com/r/Tailscale/comments/pm49t9/tailscale...
- https://forum.tailscale.com/t/high-battery-usage-in-ios/1152
It means that you can close all the open ports on your VPC security groups without changing the configuration of how your external systems access the internal AWS services.
It was probably obvious to everybody else, but after I worked that out, Tailscale became my network.
See: https://lobste.rs/s/v4obi8/how_does_tailscale_s_magicdns_wor...
I also set custom hosts file entries for non-mobile devices and kablam, no magic needed (for personal use, anyhow).
Have you had issues with it otherwise?
EDIT actually I do have one gotcha. There’s a switch in the admin panel to override real dns. In theory if you changed that option and your machines were currently using private dns on route53 to find each other you might be in trouble (don’t ask me how I know).
Note, I know nothing about Headscale; I’m happy to pay for Tailscale and support the team behind it.
Tailscale is a really great service and it's so easy to teach someone else how to use it, compared to like every other VPN ever!
There’s no way it’s DNS
It was DNS
The only thing worst than “It was DNS”, is “It was DNS, but in this rare and weird edge case only so it never showed up when you tried to debug it”…
I mean, I’m impressed by that capability. But I’m horrified by the potential future support implications. Who’d want to be debugging a problem with “magic DNS” at 2am on a Sunday morning while Prod is down and the entire C suite is half drunk, tired and angry, and breathing down your neck?
My takeaway from this is that the author was either lazy or lacked the knowledge to create an automation script that could've done that automatically (the add/remove) based on location. If that's the whole reason for this tailscale praise, kinda of takes away the tailscail actual usefulness and why it exists in first place.
Imo this is incredibly handy, as if I want to expose a device to my Tailscale network, I don’t want to have to think about finding an IP address range that won’t conflict with the various local network ranges that my Tailscale devices are on. Especially if you’re using Tailscale in various corporate environments where 10.0.0.0/8 is used a lot.
Now I can just expose e.g 192.168.122.0/24 to my Tailscale network but it’s exposed as a unique IPv6 /120 prefix.
I have my private network right now. As a plus, devices can make direct connection when they are in restrictive corporate networks (allowing only 443/tcp). Less third parties involved. Seems more secure for personal use.
Sure, it’s not a mesh network, but that doesn’t matter if VPS and devices are in the same region.
But I get that mesh VPN products can be valuable to small businesses: ease of use, ACLs, SSO, central management.
- Tailscale’s coordination server
- Tailscale’s cloud provider
- anyone who compromises the coordination server
- SSO provider you have chosen
- SSO’s cloud provider
- anyone who compromises the SSO provider
All you need is
sudo tailscale up --advertise-routes=10.0.0.0/24,10.0.1.0/24
Then you can get to anything via it's internal IP address. I have a bluetooth router on my network that I don't want to install Tailscale on. It's on a permanent address of 192.168.1.13I do this on the router inside my office subnet:
sudo tailscale up --advertise-routes=192.168.1.0/24
I do this on my home debian machine (lets say it's on 10.1.1.13): sudo tailscale up --accept-routes
From my home network I can now open the web management page on 192.168.1.13. You can go further with DNS stuff but you don't have to.Nevertheless, I still hope they will revisit support for proper linux kernel wireguard sometime in the near future. This would allow to ditch separate meshing technologies for connecting server nodes (and routing into separate subnets via a tailscale subrouter node). Best of both worlds - ease of use and performance.
I really only started to have a look at other tools (like netmaker, netbird, innernet, wesher) because of these performance caveats (wireguard-go).
So unless you're fine with that limitation, look elsewhere for now.
I'm currently trying out innernet, mostly for the interconnected server nodes (k8s, not for actual real users). Seems to work fine (double NAT + single public coordination server).
Unrelated to Wireguard: I really liked Nebulas certificate-based client setup and its reduntant lighthouses (public coordination servers). May be an alternative if you want something at least a little faster than wireguard-go based implementations.
You use it to connect your home network for example, on your laptop when you are out and about.
Any internet routing is purely done by your own isp provider (if you chose to tunnel internet traffic through tailscale)
Behind the scenes, it uses WireGuard which provides the vpn tunnel to your own network.
Tailscale also provides an authentication layer (ie username/login/passwords)
Unless I'm misunderstanding you, I don't think it does (having to use a a third party to sign in is one of the main reasons I haven't tried it yet). From https://tailscale.com/kb/1013/sso-providers/: "Tailscale never handles authentication itself."
That said, I love it and use it extensively from my iPad to work on a personal Gnome desktop via RDP.
P2P client:
On iOS/windows/macos it doesn't make sense to complain about closed source code running on your machine; on linux/bsd/android the client is open source.
Control plane:
A compatible open source server is available & you can self host; the tailscale-hosted control plane is closed source and could, in theory, instruct your devices to connect to additional peers.
> and the company
The company has several high-profile employees with excellent reputations, which is typically a good sign of legitimacy.
I’m sure people said that about Larry and Sergey back in the day…
Issues with customer support? Sure. Issues with shutting down some products HN loves? Sure. Getting hacked or being insecure? No, in fact they probably have one of the leading security teams (Project Zero) in the industry.
I made the mistake of doing this, it seemed to be working fine, and then all of a sudden to add a new node it needed access to my company's GitHub repositories in order to continue. (no way to continue without accepting)
So I could either give them access to sensitive company information, or remove my github account from my company, neither of which I wanted to do.
I just stopped using TailScale, I've been meaning to set it up again with a different login, but the experience left a bad taste in my mouth.
- it has been unnoticeably reliable. We were early-ish adopters right as COVID hit; we’re a hardware company and have it on a handful of very remote devices/sporadic power and LTE devices as well as our development machines. The ARM binary _just worked_ on the embedded kit and I often remote in even while the payload is being flown. Automatically picks up right away when in network range, and I don’t ever wonder if I’m going to be able to connect to something
- it’s wonderfully simple to set up. Download the client, sign in using your org’s SSO (or personal email, but that’s for _only you_ and you can’t share with other users), and your machine just magically joins the network, gets assigned a fixed IP, and you’re on the network with everyone else.
during the covid shutdown I had to spend long periods of time away from my apartment (I decided to lock down with my family 3000km away from where I lived alone)
I had only a small window of time to set up some kind of tunnel back to my apt/set up some kind of remote access. I just installed tailscale on an old mac mini, connected a dinky spare usb webcam, and started photobooth just as I had to leave to catch one of the few flights that hadn't been cancelled due to lockdowns and restrictions.
It worked awesome. I could remote in, use the mac to access my backup hard drive, and watch the photobooth camera. The only thing I didn't forsee was the webcam was useless during the night cause I didn't leave a light on so photobooth would just show me a black screen.
During the day though, the camera showed me my worldly possessions and helped me monitor my apartment so in case anything happened I could call the superintendant of my apartment. It worked really well, and worked for 3 months until the connection died. I only had 1 month left so I left it alone.
4 months after leaving my apartment, I went back and found out the mac mini suffered from hardware failure (would no longer power on), so the tailscale vpn worked and was more reliable/more solid than the hardware it was running on.
After that experience, I am sold on tailscale. They're awesome.