4 ms·
> I understand that [Headscale] is (unofficially?) supported by Tailscale these days I'm not sure if it clears the bar of official, but it seems to be not-unof
by LambdaComplex 3y ago
> I understand that [Headscale] is (unofficially?) supported by Tailscale these days
I'm not sure if it clears the bar of official, but it seems to be not-unofficial. They were planning on open-sourcing a coordination server once they cleaned the code up, but then decided that there was no point in doing so due to Headscale. On top of that, one of the primary maintainers of Headscale works at Tailscale now.
Source: https://tailscale.com/blog/opensource/ https://tailscale.com/blog/opensource/
- 1vuio0pswjnm7 3y agoSounds like someone may have thought the code for Headscale "coordination" server was higher quality than the code for Tailscale "coordination" server. If the later needed to be "cleaned up". Maybe there were things in that code Tailscale did not want the public to see. Funny how Wireguard's original pitch was that it was smaller and simpler than OpenVPN or other alternatives. Now people are commercialising some complex GUI on top of it. More "features" on a steady basis. Some of them might be closed source but pay no mind. "Worse is better".
- SadTrombone 3y agoThere's absolutely nothing stopping you from just using WireGuard if you want to. I don't understand the mentality of complaining about a completely separate entity offering extra features just because you don't personally have a need/want for them.
- cchance 3y agoI don't get the issue with having a tight secure underlying vpn protocol, and others building on top of it to improve deployment and setup/management side of it.
- SadTrombone 3y agoAgreed. I don't think people recognize how much of a pain cert management/orchestration can be, and Tailscale's value adds like MagicDNS and managing/creating SSH keys for logging into servers are significant QoL improvements. Sure, you can do that stuff on your own, but I simply don't want to.
- mbreese 3y agoI do run my own Wireguard VPN at home. It’s not terrible for a few clients with a set home dyndns or static IP. It has basically taught me how the small building blocks for Wireguard work. And how for anything remotely more difficult or multi-user I’d absolutely want something more robust handling the orchestration and management of the network. It is very hard to get right and can be very complicated to keep everything in sync. There is definitely value to what Tailscale, et al deliver. I’m happy that I can run a simple version myself, but only after doing that can you really appreciate where the dragons be.
- dgb23 3y ago> Maybe there were things in that code Tailscale did not want the public to see. There are a ton of things you do in closed source “only my small team touches it” vs open source. Even if it’s just comments, notes files and stuff like that. For example I often leave project notes in comments and address people etc.
- dcow 3y agoI don’t really think your comment is a fair take. While it very well may be “actually what happened”, there are a lot of other reasons to hire from and foster your community rather than try to compete with them. It’s possible Headscale just does a better job at capturing a clean boundary between a public open source tool and a proprietary backend and Tailscale might have just liked what they saw, said well this is essentially how we’d do it, and made the smart decision to put the person on payroll instead of taking advantage of the community. Furthermore IDK what your gripe is about management tools popping up on top of Wireguard. That’s what Jason wanted, for one. The downstream application use cases are kept out of the secure and simple core. Two just use vanilla Wireguard if you don’t need Tailscale. Are you an OpenVPN shill?