4 ms·
Another similar project to Tailscale, for those in the market: https://github.com/slackhq/nebula https://github.com/slackhq/nebula Crazy simple, fully open so
by mediocregopher 5y ago
Another similar project to Tailscale, for those in the market:
https://github.com/slackhq/nebula https://github.com/slackhq/nebula
Crazy simple, fully open source, trivial to self-host. Maybe not as featureful as Tailscale, but imo that can be a feature unto itself.
- flyinprogrammer 5y agoInteresting, what are you using for cert management?
- JeremyNT 5y agoI've been using Nebula for personal use and it's really great. I have a free Oracle Cloud vm as my "lighthouse." The advantage of Nebula is that it's dead simple. Generate a keypair, copy it over, copy the config file, and go. It can do mesh routing for the vpn and traverse nat magically. You can delegate dns to the lighthouse and name resolution just works too. That simplicity is awesome for personal use, and maybe it's good enough for a small operation, but I'm guessing it doesn't have all the bells and whistles you'd want for medium or larger companies.
- rcrowley 5y agoNebula transits every EC2-to-EC2 packet at Slack, across lots of AWS regions and tens of thousands of hosts. It’s probably doing petabits of traffic per second. And it’s a safer, more expressive firewall than EC2 security groups. So, yes, it works for personal use-cases but it works for truly gigantic applications, too.
- JeremyNT 5y agoThe big thing I see missing is the management piece, which is what makes Tailscale compelling. If you're just running Nebula as an individual user, or for a small org, there wouldn't be much overhead. Otherwise, for larger deployments, you need to "roll your own" solution to manage configs outside of Nebula itself. You'd also want this to be self-service in some way - so road warriors can rotate their own certs, with auth backed by some kind of central SSO system. The last I looked, Nebula didn't offer this stuff.
- mikevm 5y agoHow well does it handle public WiFi? Some hotspots may block any non-HTTP traffic, or traffic on nonstandard ports. IIRC ZeroTier will use relays when UDP traffic is blocked.
- stock_toaster 5y agoinnernet[1] is another similar one [1]: https://github.com/tonarino/innernet https://github.com/tonarino/innernet
- deleted 5y ago[deleted]
- radus 5y agoRelated, here's a surprisingly balanced comparison of Nebula and Tailscale, on tailscale.com: https://tailscale.com/kb/1148/tailscale-vs-nebula/ https://tailscale.com/kb/1148/tailscale-vs-nebula/. > If you’re a system administrator or technical person looking for a completely open source, free peer-to-peer mesh VPN, and you’re willing to run a certificate authority and the control plane yourself, try out Nebula. > If you’re looking for a polished, user-friendly peer-to-peer mesh VPN with a hosted control plane and integration with existing identity providers, give Tailscale a try.
- cormacrelf 5y agoHm — there’s a middle ground here that’s missing. I’d like to see a managed mesh allow for disabling its key distribution for certain nodes. They don’t create wireguard peers for any but a predefined shortlist of public keys, but still accept route updates from those peers. The threat model is someone adding peers to the control plane, including as a result of control plane takeover or the identity provider failing. These special nodes can’t then be made to talk to anybody they can’t authenticate, no matter what you do on the control plane. It assumes private keys are safe. Obviously this is a client side setting, which shouldn’t have any control plane API, just like the current Tailscale options to eg accept no incoming traffic. This comes from my experience with ZeroTier, which I wrote about here: https://news.ycombinator.com/item?id=28426664 https://news.ycombinator.com/item?id=28426664 Then you can run your own Wireguard key distribution if you like, but ideally you just distribute manually for a few nodes and leave it at that.
- cormacrelf 5y agoTiny usability improvement for small networks: “freeze” mode where the current set of peer public keys is frozen and no new peers can be added. Tie this to a (G)UI on each node to accept new peers anyway with user interaction using Signal style key visualisation, and you’re cooking with gas. Probably not worth it though, virtually nobody with three devices total and the time to do this manually really needs it.
- makeworld 5y agoYggdrasil is not the same as either of these, but it can do similar things. https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/
- lifty 5y agoDoesn’t Yggdrasil use WireGuard these days?
- symkat 5y agoI've really liked nebula and have been working on a web frontend. Basically define a network and nodes and it uses nebula to generate certificates and has scripts for installing. https://github.com/symkat/MeshMage https://github.com/symkat/MeshMage
- redninja83 5y agoNebula is great - super simple to set up and get started if you have a VM to use as a lighthouse. Lots of cloud providers free tiers are have enough resources to host a lighthouse as well. Certificate management is its one weakness at the moment. There are a growing number of projects floating around attempting to solve that though: - https://github.com/unreality/nebula-mesh-admin https://github.com/unreality/nebula-mesh-admin - https://github.com/b177y/starship https://github.com/b177y/starship - https://github.com/symkat/MeshMage https://github.com/symkat/MeshMage Plus im sure defined networks has their own solution in the works as well.
- manigandham 5y agoNebula creators also started their own organization called Defined Networking to focus more on this networking: https://www.defined.net/ https://www.defined.net/
- victorhooi 5y agoOne thing I can't figure out with Nebula is - how do you join multiple different networks? For example, I have a personal laptop - I want to join two different networks, that are for two different purposes, and be able to talk to hosts in each? (But hosts in each should not be able to talk to hosts in the other)
- GekkePrutser 5y agoTinc is also pretty good and predates both by about a decade :) Ps if we're listing alternatives zerotier is also one
- ignoramous 5y agoAlso: WireTrustee: https://news.ycombinator.com/item?id=27672715 https://news.ycombinator.com/item?id=27672715 Netmaker: https://github.com/gravitl/netmaker https://github.com/gravitl/netmaker Defined.net (from makers of Slack Nebula): https://www.defined.net/ https://www.defined.net/