6 ms·
Would we still create Nebula today?
- woleium 3y agoAside from defined.net, what are the best frontend/management tools for nebula? Last I looked it was all manual config (which is fine for most of us, but limits adoption elsewhere)
- pahae 3y agoI'm not a aware of any other full-fledged solution. There is some opinionated tooling written in Python [0] and Go but nothing coming close to defined.net. This is definitely a point where other overlay solutions look way better. After having searched (and implemented) this myself for work, the only practical solutions I found were 1) smallstep [1] or 2) Terraform (with the nebula provider [2]) and a CM tool of your choice. The latter can be nicely combined with the ansible provider if that's your CM of choice. 0: nebula-cert-py 1: https://smallstep.com/docs/step-ca/integrations/#nebula https://smallstep.com/docs/step-ca/integrations/#nebula 2: https://registry.terraform.io/providers/TelkomIndonesia/nebula/0.3.1 https://registry.terraform.io/providers/TelkomIndonesia/nebu...
- woleium 3y agoAnd some kind of cert renewal tool I guess.
- rhuber 3y ago(*blog post author here) Thanks for sharing this on HN! I'll keep an eye on the comments and try to answer questions that come up.
- donutshop 3y agoLove Nebula, keep up the good work! Do you thing the tech landscape today would have allowed for nebula to be born? Lots of companies now have strict IP agreements they have team members sign.
- rhuber 3y agoThat's a great question! One of the things I enjoyed during my time at Slack was their willingness to contribute to open source projects. We had similar IP clauses, but asking permission to open source things was straightforward. The most important concern (IMO), was considering whether we could commit to properly maintaining a project. Before open sourcing anything, you need to discuss how you'll go about managing an issue and pull request backlog, so that people don't come across "dead" projects under your stewardship. In a high growth startup, I do think something like this could happen again, but as a company grows, there are certainly more layers that can make it difficult to share things openly.
- shawn-butler 3y agoSeeing as Slack was born as a tool inside Glitch which existed only because of a side project called Flickr… I don’t really think it’s the size or layers of a company that prevent; it’s the culture. This culture of creation permeates everything I’ve seen Stewart Butterfield do. At least from the outside. Admirable and extremely profitable.
- harrisonpage 3y agoHey Ryan! Love Nebula, miss you at the day job
- rhuber 3y agoThanks Harrison, hope you're well!
- xoa 3y agoJust wanted to chime in along the others that I also love Nebula, and I'm really grateful to have a mesh option that is modern, truly decentralized and self hostable. Nebula is also just an plain elegant IMO, one of those pieces of software that clicks right away top to bottom. Now I just hope it gains momentum to make it into a wider variety of tools so it becomes ever more accessible. So again, thank you and everyone else who had a hand in it!
- dave78 3y agoNebula is such a great tool. If you haven't tried it yet, you should really give it a shot. It's easy to self host and to set up, and has been absolutely rock solid. I have it on all my devices, plus several Raspberry Pis set up at unattended remote sites that I rarely have access to serving as gateways to internal LANs and they all just work, all the time. Tailscale gets most of the attention on HN, and I'm sure that it's a wonderful product too, but Nebula is a nice, simple, "do one thing well" product.
- SadTrombone 3y agoI've tried Defined recently and it did the job just fine, but the thing about Tailscale (and others in the space like ZeroTier) that put it ahead of something like Defined/Nebula for me is that I don't have to run my own servers/infrastructure for lighthouses and relays. I understand that everyone has their own preferences and some might want to host this themselves for privacy reasons and whatnot, but for me as a single end user I'm glad Tailscale just handles all the infra for me.
- rhuber 3y agoThat's totally reasonable, and I agree that using something hosted entirely by a 3rd party makes sense for some use cases. Our reason goes a bit beyond security concerns, in this case. We built Nebula for large scale deployments, and because of that, we have made decisions that lean into that model for hosting. Our decision to leave lighthouse hosting in the hands of users has one primary rationale: We want users to have complete control their network availability. Any downtime of our service should not impact their network availability. You can even host some of your lighthouses inside of network boundaries to ensure that an internal network functions properly if its connection to the internet is interrupted. Other overlay options may continue to work for some time, but new connections are often not possible, and the network can degrade rapidly. Relays are are a similar story, but with an additional reason: We don't have to limit our customers' relay bandwidth due to cost. When hosting relays on behalf of others, we would be transiting a lot of traffic, which has an associated (sometimes unpredictable) cost. By letting our customers host relays, they can ensure relay traffic is just as fast as direclt connections.
- FL410 3y agoBig fan of Nebula, especially Defined, which makes it real easy to setup/maintain
- jdoss 3y agoI am using Defined.net to manage my nebula deployment in my datacenter rack and it has made operationalizing an overlay network a breeze. It's like having my own basic private VPC with security groups (roles) without a cloud provider. They added in tag support [1] a few months ago which I have yet to try out but it looks very promising. The defined.net API [2] is very easy to use for host management and I am able to auto enroll new hosts and remove them after I deprovision them. I also made a GitHub Action [3] which I use to allow for my Actions to communicate with resources on my overlay network. [1] https://docs.defined.net/guides/creating-firewalls-using-roles/#tags https://docs.defined.net/guides/creating-firewalls-using-rol... [2] https://docs.defined.net/api/host-create/ https://docs.defined.net/api/host-create/ [3] https://github.com/quickvm/action-dnclient https://github.com/quickvm/action-dnclient
- apitman 3y agoWe have a section for overlay networks on the tunneling list[0] I maintain. This is a very interesting space with some excellent software. I certainly have my gripes about the closed nature of Slack itself, in particular using a closed protocol when the model is clearly "federated" between multiple servers internally. That said, the contribution of something on the scale and quality of Nebula back to the open source community is hard to argue with. [0]: https://github.com/anderspitman/awesome-tunneling#overlay-networks-and-other-advanced-tools https://github.com/anderspitman/awesome-tunneling#overlay-ne...
- lenova 3y agoIn the self-hosted space, I've been really enjoying playing around with decentralized encrypted overlay mesh networks like Nebula. Here's the current list of my faves (all Wireguard based). Open-source projects not-quite-prod-ready: - WebMesh: Golang, decentralized nodes https://github.com/webmeshproj https://github.com/webmeshproj - InnerNet: Rust, with subnet ACLs https://github.com/tonarino/innernet https://github.com/tonarino/innernet - Wesher: Golang, simple mesh with pre-shared key https://github.com/costela/wesher https://github.com/costela/wesher - Wiresmith: Rust, auto-configs clients into a mesh https://github.com/svenstaro/wiresmith https://github.com/svenstaro/wiresmith Open source projects with company-backed SaaS offerings: - Netbird: Golang, full-fledged solution (desktop clients, DNS, SSO, STUN/TURN, etc) https://github.com/netbirdio/netbird https://github.com/netbirdio/netbird - Netmaker: Golang, full-fledge solution https://github.com/gravitl/netmaker https://github.com/gravitl/netmaker Honorable mention: - SuperHighway84 - more of a Usenet-inspired darknet, but I love the concept + the author's personal website: https://github.com/mrusme/superhighway84 https://github.com/mrusme/superhighway84 https://マリウス.com/superhighway84 https://xn--gckvb8fzb.com/superhighway84
- brendoncarroll 3y agoI'll throw in INET256 https://github.com/inet256 https://github.com/inet256 It's a specification for identity based networking. There is a meshnet and a centralized implementation. You can layer IPv6, IPv4, or application traffic on top of any compatible implementation.
- imiric 3y agoNo love for tinc[1]? It's the granddaddy of mesh networking, long before Wireguard, and while it's not quite zeroconf, it's very simple to setup and maintain. It also runs on everything. [1]: https://tinc-vpn.org/ https://tinc-vpn.org/
- wkat4242 3y agoYeah it's still my go-to because it's fully self hosted. Nebula can be too but it uses certs that can expire whereas tinc just uses keys. And really I've been using tinc for almost a decade and I didn't really see the benefit of changing. It's rock-solid. With the exception of one thing: I use some central nodes on cloud VPSes and they can access everything. As far as I know a nebula lighthouse can't access any of the clients. So I've been meaning to give nebula another try. But zerotier and tailscale aren't options for me because they rely on their cloud infrastructure. I only want stuff that's fully self-hosted. There's a great tinc android client these days too.
- jiveturkey 3y agovery interesting soft sell. they don't name any competitors, or specifically compare the alternate approaches taken by them, which is IMHO not the greatest SEO but what do I know. maybe they do that elsewhere on the site.
- woleium 3y agoIt may be a surprise that not all posts are advermarketingpr, although it does feel like that some days.
- linsomniac 3y agoI really like a lot of Tailscale, but I just finished implementing it for my company using headscale (I couldn't get the funding to buy from Tailscale). This is across ~200 machines. I'll be honest: If I could do it again, I'd use Nebula. The primary issues I have are that Tailscale has a lot of magic which I can see some cases it being nice, but it does make some of the routing and firewalling I'm doing on machines, and in particular the thing where it sets up Tailscale routes to network routes as higher priority than local interfaces leads to problems in my environment. The other thing is just Headscale itself, it works quite well but does have some rough edges. It's entirely too easy to kill your whole mesh by flubbing an ACL, and currently restarting headscale to pick up ACL changes is taking 3-5 minutes. I do, however, really prefer the Tailscale ACLs over Nebula's. One thing that led me to Tailscale was the ability for it to relay around network routing problems, and it looks like Nebula has added that since I started. Around the time I was evaluating Nebula vs. Tailscale we had a ~1 day network routing issue where some of my users were blackhole routed in Comcast, and Tailscale just worked around it.
- radlad 3y agoHey there - I'm an employee at [redacted] and was wondering if you'd be open to answering some questions about your experience evaluating Nebula and related products? If so, please shoot me an email at [redacted]. Thanks!
- BatgnomeDwarf 3y agoCan Nebula work with VPN exit nodes (similar to tailscale + mullvad)