13 ms·
Make your own VPN with Fly.io, tailscale and GitHub
- deleted 3y ago[deleted]
- vakabus 3y agoI've recently built something similar [0], but the complete opposite. I wanted to forward traffic onto my homeserver without a public IPv4. I've tried Tailscale Funnel, but the inability to use custom domains made me look for other solutions. I ended up with a fly.io app acting as a TCP proxy over Tailscale. Considering how crappy the setup is, it's surprisingly reliable. Great job fly.io and Tailscale teams! I haven't had any issues in the month or so I've been using it. [0]: https://github.com/vakabus/flyio-tailscale-gateway https://github.com/vakabus/flyio-tailscale-gateway
- KomoD 3y agoHow much does it cost to run on fly.io? I know fly has some free usage but haven't looked into it much
- vakabus 3y agoYou can have 3 tiny VMs for free and 160GB of outbound traffic which is more than enough for me. So I am paying only 2$ per month for the IPv4.
- gbraad 3y agoWhy the IP? This isn't really necessary, unless you're also considering inbound traffic to be routed to a node into your tailnet. You are more likely to get GeoIP'd in the US due to the IP you get assigned. Note: Asian region does not offer the full 160GB, but only 20GB IIRC, like HKG and NRT.
- imiric 3y agoHave you considered using Wireguard for this? It's relatively straightforward, see: https://www.procustodibus.com/blog/2020/11/wireguard-hub-and-spoke-config/ https://www.procustodibus.com/blog/2020/11/wireguard-hub-and... This way you don't depend on a VPN provider, and can easily host it on any VPS. I suppose it would work on fly.io as well. I use the hub and spoke setup to access my home network over the internet, and Wireguard works great. This also doesn't require any special gateways or DNS setup. All connected hosts just use the DNS server on my main router, which resolves all internal domains.
- WirelessGigabit 3y agoWireguard to this day does not handle IPv6 correctly. When connecting to a domain with A and AAAA records it stupidly prefers the A one. Which works horribly on 464xlat providers, as now you're routing your VPN traffic over a IPv6->IPv4 proxy. While that's fine for outgoing stuff it breaks all incoming stuff as soon as you put your phone to sleep, as nothing can send stuff your way anymore.
- imiric 3y agoAh, that's a shame. How does Tailscale work around it? I don't use IPv6, so this hasn't been an issue for me. It sounds like a relatively simple thing to fix, though.
- PLG88 3y agoTailscale makes outbound connections so it circumvents the need for IPv6 with things like CGNAT. OP, why not use an open source equivalent to Tailscale Funnel? For example, I work on the OpenZiti project and we created zrok.io which is fully open source alternative - https://github.com/openziti/zrok https://github.com/openziti/zrok.
- WirelessGigabit 3y agoI apologize, it's in the DNS handling of Wireguard's iOS app. I've seen it being reported many times but no action.
- gbraad 3y agoHad seen this one before. Not bad. Not so fond it was using Debian ss their base is much bigger than necessary. They also have caddy-tailscale which directly connects a tailnet IP with Caddy as a proxy. The development has stalled as it seems, but works.
- mteigers 3y agoI do something similar but with HAProxy and a micro GCE VM which acts as my edge which hits a Tailscale subnet router and routes to my MetalLB install. Works _really_ well.
- therein 3y agoIt is unfortunate that many GeoIP providers will just use Fly.io's Chicago address even when the nodes are somewhere entirely different in the world. You sometimes get lucky and get something that doesn't resolve to United States, and sometimes the IPv4 is US, while IPv6 is correctly the location, or vice versa.
- KomoD 3y agoSubmit corrections then, just bit annoying
- therein 3y agoDue to the way that they do the IP assignment, they keep changing, though. Fly.io is aware of it but not something that's resolved. https://community.fly.io/t/regional-ips-dont-seem-to-be-in-the-correct-region/2973 https://community.fly.io/t/regional-ips-dont-seem-to-be-in-t... > Geo IP databases are very inaccurate for companies like ours. Some of our IPs are registered with RIPE 3, and thus default to Amsterdam. The geo IP providers might choose to use our corporate address for those instead, but then they’ll show in either Chicago or Delaware. > Meanwhile, we can put IPs anywhere in the world with a one line config change. We won’t, but the IAD IPs could just as easily be routing to Sydney tomorrow. We could even route it everywhere! > traceroute and mtr are the only real way to see where a given connection is being routed. You can usually see city names and airport codes in the intermediate hops. > IP databases don’t actually try to solve this, they’re mostly interested in identifying consumer locations. The ISP’s business address is often good enough for consumer IPs.
- KomoD 3y agoHuh, okay, I assume ipinfo.io's location for fly is more accurate than other geo services then, considering they get location with pinging probes
- reincoder 3y agoThanks for the shoutout. Yes, we get our geolocation data from via probing. [0] [0] https://ipinfo.io/blog/probe-network-how-we-make-sure-our-data-is-accurate/ https://ipinfo.io/blog/probe-network-how-we-make-sure-our-da...
- blacksmith_tb 3y agoIsn't the problem that the exit IPs will be flagged / blocked, meaning at best you'll get a ton of captchas etc.? I have set up personal Wireguard VPNs with Algo[1] before on DO, and while they work fine, they cause a lot of friction for that reason. 1: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- KomoD 3y agoThat is because DO is one of the most abused cloud providers, the reputation on their IPs are awful.
- kawsper 3y agoI've experienced that DO servers sometimes get blocked from speaking to the DO API (because they are running Cloudflare!). It's hilarious to me that DO doesn't trust DO servers (and their customers).
- kgeist 3y agoI've set up OVH with OpenVPN. Sometimes I get captchas, but not very often.
- dizhn 3y agoSimilary good experience with Hetzner (dedicated. my IPS change not more than once every 4-5 years) and Oracle cloud (italy).
- imiric 3y agoI did a similar thing with a cheap VPS and Wireguard. I don't trust Tailscale, and prefer controlling all aspects of my VPN. Right now I'm only using a single node, but it would be trivial to start another in a different region, and automate the whole thing. If someone's interested, this blog was very helpful: https://www.procustodibus.com/tags/wireguard/ https://www.procustodibus.com/tags/wireguard/
- giobox 3y ago> https://github.com/juanfont/headscale https://github.com/juanfont/headscale The tailscale daemon/CLI/client code is already open source and works with the above as the control server. The tailscale team appear to be encouraging development of headscale too: "Our opinion is that Headscale provides a valuable complement to Tailscale: It helps personal users better understand both how Tailscale works and how to run a coordination server at home. As such, Tailscale works with Headscale maintainers when making changes to Tailscale clients that might affect how the Headscale coordination server works, to ensure ongoing compatibility." > https://tailscale.com/opensource/ https://tailscale.com/opensource/ Personally I find WireGuard and tailscale/headscale to be extremely complementary, and with these you don't cede any control vs running WireGuard on its own.
- imiric 3y agoI'm aware of Headscale and Tailscale's stance on open source. I just don't trust it that it's not phoning home or leaking data. In general, I prefer avoiding complex tools in this space. Zerotier, etc. Besides, Wireguard alone already does all I need from a mesh VPN. The UX could be a bit better, but I wouldn't trade ease of use for the peace of mind that my VPN traffic is secure.
- deleted 3y ago[deleted]
- throwaway742 3y agoSame. Wireguard is so easy to set up I don't see why I would need anything else.
- gbraad 3y agoI added updates at https://github.com/spotsnel/tailscale-tailwings https://github.com/spotsnel/tailscale-tailwings to make this more 'practical' by adding Dante to allow slightly more control to just have a browser exit a node, etc.
- linux2647 3y agoTIL the `until` shell syntax: https://github.com/patte/fly-tailscale-exit/blob/main/start.sh https://github.com/patte/fly-tailscale-exit/blob/main/start....
- vrosas 3y agoUntil is great. I use it to remind me if Docker Desktop isn’t running when I try and deploy an app until docker info > /dev/null 2>&1; do echo ”docker isn’t running…” && sleep 2; done
- floodle 3y agoHow is that different from `while !`?
- abwizz 3y ago'until' executes the statement before the condition. while checks the condition first. should have probably let you find this out for your self.
- jraph 3y agoThis is wrong. You must be confusing with the do..while construct we find in some programming languages. until indeed seems like syntax sugar for while !, I don't think there's a difference.
- ykonstant 3y ago> 'until' executes the statement before the condition. This is not the case. From the Open Group Base Specifications Issue 7, 2018 edition, 2.9.4 Compound Commands, The until loop: The format of the until loop is as follows: until compound-list-1 do compound-list-2 done The compound-list-1 shall be executed, and if it has a zero exit status, the until command completes. Otherwise, the compound-list-2 shall be executed, and the process repeats.
- karatinversion 3y agoIt's not, except it's a bit nicer to type
- christop 3y agoI tried using this or a similar repo to set up a Tailscale exit node on Fly.io before. The downside is that my traffic never went direct; it was always relayed via a Tailscale DERP node, as Fly.io machines were only accessible via anycast, and so a direct connection from Tailscale on my machine to the exit node on Fly.io couldn't be established. So performance wasn't as great (and I felt bad about using up Tailscale's DERP bandwidth, as a free user).
- MuffinFlavored 3y agohow to circumvent this? chisel? UDP hole punching?
- christop 3y agoTailscale works hard to do all this stuff automatically. Possibly you'd have more luck on a network where your client can allow incoming UDP connections on the Tailscale port, and so the exit node would be able to establish a direct connection. But for a Tailscale peer I have running on AWS ECS, I can open the UDP port there, so a direct connection always happens regardless of what sort of network my Tailscale clients are on. I don't know if there's any Fly equivalent to get a direct connection to a UDP port.
- fulafel 3y agoOn AWS you could also enable IPv6.
- patte 3y agoYes, fly.io allows you to expose a UDP port. See the fly.toml [1] in the repo. Make sure the tailscale port is pinned [2] to the exposed port (41641 in that case). I just tested it again and the connections are made directly (after the first 2,3 packages go via DERP): tailscale ping fly-ams pong from fly-ams (100.96.123.32) via DERP(ams) in 15ms pong from fly-ams (100.96.123.32) via [2604:1380:4601:d605:0:6c3b:eed5:1]:41641 in 12ms tailscale status 100.96.123.32 fly-ams patte@ linux active; offers exit node; direct [2604:1380:4601:d605:0:6c3b:eed5:1]:41641 100.101.54.36 fly-hkg patte@ linux active; offers exit node; direct [2605:4c40:95:4eed:0:40f0:67b1:1]:41641 [1]: https://github.com/patte/fly-tailscale-exit/blob/main/fly.toml#L23 https://github.com/patte/fly-tailscale-exit/blob/main/fly.to... [2]: https://github.com/patte/fly-tailscale-exit/blob/main/start.sh#L17 https://github.com/patte/fly-tailscale-exit/blob/main/start....
- WatchDog 3y agoIf you just want to run a simple wireguard vpn from fly.io, without tailscale, I wrote a script to spin one up[0] [0]: https://github.com/magJ/fly-wireguard-vpn-proxy https://github.com/magJ/fly-wireguard-vpn-proxy
- yegor 3y agoDisclosure: I run a commercial VPN service. If all you need is to "change your IP" for some specific purpose, this and many other tutorials out there can accomplish this task for <$5/month. You are in complete control and have to trust no-one. However be aware of the following downsides: 1. You are mapping your traffic 1:1 to the VPN IP address, that you are the sole user of. This will do virtually nothing for pseudo-anonymity as your original ISP assigned IP will be quickly linked to your new VPN IP by every single shady data broker out there as you lose the benefit of "being lost in the crowd" when you share VPN exit IPs with hundreds/thousands of other people. 2. If you do anything shady that results in a LE subpoena or a DMCA, it's like you were not using a VPN at all. The cloud provider will hand over your details instantly. 3. Many sites block data-center ranges. You will not be able to use most streaming services, and random websites like Papa Johns, Home Depot, banks, gov websites, Ticketmaster, etc. Not all ASNs are banned, but many are. Commercial VPNs can (and do) re-route traffic using "residential looking" or actual residential IP addresses to combat this. 4. Performance MAY not be great. VPN providers do quite a bit of Linux kernel tuning in order to get high(er) throughput. Depending on your use case, the above may not matter but if you plan to use this 24/7, be prepared to be annoyed.
- paulddraper 3y agoIf you're the only user, performance should be amazing.
- yegor 3y agoProbably, in theory, yes.
- noman-land 3y agoThank you for putting all these points down so I can just link people to this comment.
- raincom 3y agoDoes a commercial VPN service help to access American banking websites from abroad? Often times, banks just lock accounts when accessed from foreign IPs. I understand banks' concern about hacking. Or just spin up wireguard on home based router, then VPN into home network?
- janalsncm 3y agoI have set up Outline on AWS for when I travel. It’s shadowsocks so it works well in some countries.
- scottgg 3y agoI recently did the same thing with AWS, using the CDK to make it easy to add and remove regions [1]. I use it to hop my traffic around as required. [1] https://blog.scottgerring.com/automating-tailscale-exit-nodes-on-aws/ https://blog.scottgerring.com/automating-tailscale-exit-node...
- lopkeny12ko 3y agoThis is cool, but you should really understand what you're in for if you choose to do this. In particular, running your own VPN does not enhance your privacy posture, and in fact makes it much worse, because your little cloud VPS is uniquely yours and yours only. You become much more fingerprintable, and any sufficiently determined sysadmin can easily manually trace your cloud instance's IP back to you.
- fukawi2 3y agoThis is great to escape untrusted/unknown local networks like a dodgy coffee shop or something. But definitely no protection against state level threats, etc.
- popcalc 3y ago>dodgy coffee shop This is why TLS exists. Just set up DNS over HTTPS and you'll be fine :)
- lytedev 3y agoWhen did virtual private network come to be conflated with pseudo-anonymous Internet access? The sponsorships and ad campaigns all over the internet?
- seanp2k2 3y agoYeah, marketing. Also, I had the same point / question: what do you really get out of this aside from possibly confounding local network attackers if you’re e.g. out at a coffee shop? This seems like a really bad idea if you’re doing something that would get you a DMCA strike, as now their automated systems can just email legal@vps-provider and get them to give up your billing info to sue you.
- 5e92cb50239222b 3y agoCensorship circumvention? Not everyone on this planet lives in your particular country. I also trust third-party VPNs and VPS providers (however dodgy they may be) a lot more than I trust my own ISP. That fact alone will tell you all you need to know.
- revskill 3y agoSo i could use this to setup my own private cloud on a distributed environments where my servers are far from each other ?
- slig 3y agoAFAIK, you just need tailscale for that.
- minhazm 3y agoOutline[1] is significantly easier to use. They have out of the box support for AWS, GCP and Digital Ocean. You can have your own VPN setup on digital ocean for $5 a month, and you can generate keys and share the VPN with friends/family who then only need to download the Outline app on their device. I have zero affiliation with outline but it's an incredibly useful tool, I was looking to build something similar when I discovered it. [1] http://getoutline.org http://getoutline.org
- forgingahead 3y agoIs this a script to set up a cloud provider box as a VPN to tunnel your traffic through, or something else? Outline is part of Jigsaw, which is a part of Google. Is it truly private?[0][1] [0]: https://getoutline.org/faq/ https://getoutline.org/faq/ under the "Outline Brand" section [1]: https://github.com/Jigsaw-Code/?q=outline https://github.com/Jigsaw-Code/?q=outline Jigsaw's Github with the Google affiliation.
- minhazm 3y agoIt's private in that it's your own VM you're running the VPN on. No one else has access to it. Whether you trust Google or not, it's all open source[1]. [1] https://github.com/Jigsaw-Code/outline-server https://github.com/Jigsaw-Code/outline-server
- gbraad 3y agoperhaps easier to setup, but not in use and a single exit point. the setup given allows to easily scale into other regions. also, authentication is done using tailscale, so no sharing if config or keys. just invite them to your tailnet of share the server to their tailnet.
- minhazm 3y agoIt's also very easy to use, it's just a normal VPN. You open the app and hit connect and you're connected. Outline is also very easy to add new regions to, you can deploy a VPN anywhere AWS, GCP, or Digital Ocean have data centers in, and you can use the one liner install script to install it in other cloud providers. Tailscale is cool for sure but it also requires a third party involved in this. Outline has no third party server component. For almost everyone Outline is much easier to setup and use. > so no sharing if config or keys. just invite them to your tailnet of share the server to their tailnet. It's the same level of effort as outline. Outline manager has a button that generates an invite that someone else just puts into the outline client and now they have access to your VPN. You can revoke keys and do all the things you'd expect to be able to do, but again with no third party involved.
- seanp2k2 3y agoThis seems like a bad idea for torrenting. Using a service with a billing account in your name seems like a really easy way to get subpoenaed and taken to court. The benefit of services like Mullvad is the “small fish in an ocean” aspect that you lose with running your own VPS.
- Zetice 3y agoEither this is not in your threat model or you're seeding prolifically, which even then only means you're a whale in an ocean.
- deleted 3y ago[deleted]
- ChoHag 3y ago[dead]
- occamschainsaw 3y agoI use a combination of Tailscale and Nord Meshnet on Raspberry Pis that I have set up at my home and family home in different countries as my personal VPN. Home country does not have a good relationship with VPNs and the commercial VPN services discontinued their servers there. So now I get a clean residential IP from my family home when I want to surf from that country.
- asim 3y agoTIL the complexity of VPN is still higher than my desire to self host. I've run OpenVPN in very complex configurations across multiple datacenters for companies, I've worked on distributed systems and networking tech for decades but honestly all of this is still very much in the, too painful to setup, state. I'm playing around with Tailscale Funnel now and the tsnet package in Go, that's pretty nice. Embedding headscale or running it separately seems like a huge effort but I like that I can programmatically build things on Tailscale. More and more I'm just thinking stuff like what Signal did with a proxy server makes sense. Run a bunch of proxies, hide the complexity. Maybe default it in the browser. Maybe I'm old, who knows.
- PLG88 3y agoIf you like tsnet, you will probably like the open source project I work on called OpenZiti. Its an open source overlay network that allows you to embed zero trust networking and SDN into almost anything - https://github.com/openziti https://github.com/openziti. This includes tunnelers for all popular OSs as well as SDKs for many languages incl. Go, Java, Python, C, C#, Node, ect ect.
- asim 3y agoNice, thanks for sharing! I'm sort of interested in what the tech could enable if it's invisibly deployed and used within an app.
- rubatuga 3y agoIf you care about simplicity, you should try our managed public IP address service called Hoppy. We give you clean IPv4 /32 and IPv6 /56 blocks, and don't block ports allowing you to even host a mail server. https://hoppy.network https://hoppy.network
- KomoD 3y agoClean meaning? And 1TB for $8/mo is pretty bad imo, bad speeds too Also not clear where its located
- isoprophlex 3y agoIs anyone aware of a tailscale-supporting router? In order to easily watch region-restricted content, I want to put all entertainment devices in my house on a separate wifi router, and run all traffic through a chosen tailscale exit node.
- maxboone 3y agoThere's tailscale support for OpenWRT, or if you want something beefier you can install it on VyOS.
- isoprophlex 3y agoI didn't know! An openWRT router with tailscale is perfect... thanks!
- OJFord 3y agoI'm not, but you could use vanilla Wireguard either directly to the exit node, or to another device (a little Pi or something) running Tailscale as a ..relay node I think they call it.
- isoprophlex 3y agoThanks, that's a nice trick for watching from a computer... i have dumb / closed devices, and devices belonging to kids that I don't want to touch. Hence the whole separate-wifi-AP thing.
- OJFord 3y agoSorry, I glossed over it, but not just from a computer - many more routers have Wireguard support than Tailscale (if any do at all, I don't know). So you could do exactly as you planned, just with the router -> exit node (or router -> some Tailscale relay as an extra step to provide that interface) as plain Wireguard.
- doublepg23 3y agoI believe the GL iNet portable ones can. They’re made for travel. https://docs.gl-inet.com/en/4/tutorials/tailscale/ https://docs.gl-inet.com/en/4/tutorials/tailscale/
- tester457 3y agoCool but what is the threat model here? Why do this?
- dolmen 3y agoSome people are subscribing to Netflix in Argentina because it's cheaper. Or in Ireland for a wider catalog.
- glonq 3y agoI thought about using a VPN for better privacy, but with browser fingerprinting so rampant now, I figured that this would be pointless.
- thinkpad13 3y agoI hope they will not stop us for doing this