6 ms·
WireGuard as VPN Server on Kubernetes with AdBlocking
- miked85 6y agoAlgo [1] is a great option for a personal VPN, and it supports WireGuard + ad blocking. I really don't understand why you would want to use k8s for something like this unless it is just a pet project. [1] https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- PaulWaldman 6y agoCan confirm Algo works great. Easy to setup the VPN while still having the benefits of leveraging Wireguard. Not OP, but maybe it makes sense if you already deploy a set of applications or services on K8s.
- maneesh 6y agogreat unless you want to use it as a vpn to watch Hulu from abroad haha. They require you to use a set of specific providers, which are all blocked by Hulu. I ended up using openVPN on a home raspberry pi, but I want to figure out how to deploy IPSec or ZeroTier rather than OpenVPN
- darkteflon 6y agoI tried this setup for the first time recently (Algo and a Digital Ocean droplet) when traveling and can confirm it was excellent. In particular, you get a surprisingly polished UX for setting everything up in addition to all the usual benefits of WireGuard.
- syoc 6y agoI have a hard time understanding why people use these small script bundles on top of wireguard. The VPN use case is the best documented one with a large amount of guides and the configuration is very simple.
- miked85 6y agoBecause it sets up everything in your VPS as well.
- api 6y agoGetting to the front page? Just Wireguard often will, as will just Kubernetes, but combining the two is a guarantee.
- opqpo 6y agoI believe that Kubernetes is artificially injected in your setup. You can just run your DNS server on the server and advertise it on the VPN address. You can still address it from anywhere in the VPN.
- zelly 6y agoBut then it wouldn't have made the first page
- opqpo 6y agoNever thought of that. But OP maybe liked tinkering with k3s and kilo. But I believe kilo's best use is for cluster to cluster connection. This use case is a bit artificial in my opinion.
- pm90 6y agoI did not downvote you but, serious question: is there a need for this kind of snark? I understand the point that running a kubernetes cluster just for this would probably be hard to justify. But, if you deploy your services to kubernetes already, then this is a nice guide to do so, isn't it? I find it hard to understand this attitude, especially in a forum dedicated to talk about technology.
- aphroz 6y agoBut maybe, like in any social network, there is a bias on what is put in front page. And if you have an interesting project, you might want to add an extra layer of complexity and use Kubernetes in order to gain more visibility.
- comprev 6y agoIt's also a example of a project where you can learn more about a platform. Yes, it could be run outside of k8s, but perhaps the author wanted to add the extra layer of "difficulty".
- coding_coffee 6y ago
- syoc 6y agoThis writeup uses AdGuard for ad blocking, specifically "AdGuard Home". The "How to setup?" link from their homepage pointing to their github repo says that you accept a EULA[0] on clicking the link. The EULA seems to directly contradict their repo GPLv3 license. [1] [0] https://adguard.com/en/eula.html https://adguard.com/en/eula.html [1] https://github.com/AdguardTeam/AdGuardHome/blob/master/LICENSE.txt https://github.com/AdguardTeam/AdGuardHome/blob/master/LICEN...
- ehsankia 6y agoFor people using network level ad blocking, do you ever run into annoyances where there's a site you want to access and just can't? Mostly links that route through an analytics network. First time you click on a twitter link for example, or some referrer store links. And once you're stuck, there's normally nothing you can do. At least on the browser I can temporary turn off an extension, but I've found that network level blockers get in the way sometimes.
- closeparen 6y agoIf you run fancy enough network gear, you can run several SSIDs on different vlans and route them separately.
- shmoogy 6y agoThis is why I don't run pihole or NextDNS at the network level anymore, my wife had too many annoyances with slick deals and other things. Whitelists covered most but not everything.
- yegle 6y agoLooks like the author is using Android. Why not just use AdGuard Home as a DNS-over-TLS server (which is supported on Android P and above)? What's the benefit of plaintext DNS over VPN compare to DNS-over-TLS?
- poorman 6y agoCool, but you can avoid half this setup with Tailscale for free...
- opqpo 6y agoYes you can avoid that open source setup for a buggy and even slower userspace wireguard commercial implementation for only 10$/month per user
- miniyarov 6y agoThere are solutions like Algo and ZudVPN to deploy a private VPN without a hassle. The blog is too technical and has less value for straitforward use. Algo: https://github.com/trailofbits/algo https://github.com/trailofbits/algo ZudVPN: https://zudvpn.com https://zudvpn.com