5 ms·
Just a quick heads up, colleagues of mine could not successfully host headscale themselves. In the end, they saw the value and bought tailscale access. Configu
by selfmodruntime 3y ago
Just a quick heads up, colleagues of mine could not successfully host headscale themselves. In the end, they saw the value and bought tailscale access.
Configuring wireguard really is that hard. Tailscale is easily worth it
- watermelon0 3y agoIIRC, Wireguard is exclusively managed by Tailscale clients, and not by the server (headscale in this case).
- j45 3y agoAny details? Could be adjacent self-hosting issues compared to headscale itself. Considering it can also run in a docker container, it’s next to trivial to install locally to try out https://headscale.net/running-headscale-container/ https://headscale.net/running-headscale-container/
- hnarn 3y ago> colleagues of mine could not successfully host headscale themselves it’d be interesting to know why, I use it frequently at work and it’s worked pretty well so far.
- eddieroger 3y agoYour (their) mileage may vary. I set up Headscale with external auth and it's been a dream, the kind where I don't really have to think too much about it. The only little gotcha is that sometimes getting the iOS client to read the server url from settings can be tricky. But once authed, it "just works" for me.
- snapplebobapple 3y agoIt wasn't hard to setup headscale (or netbird for that matter). I have setup both to test at home fairly easily. They aren't appropriate for a corporate setting though. I actually want to pay somebody for this because I want the support when some change causes this to eat it at 4 in the morning with the business day about to start with a strong requirement for it to be working.
- linsomniac 3y agoFYI: I've been self-hosting headscale for 9 months or so, and it's pretty brilliant. I didn't find it very hard to set up. A dedicated DERP server was pretty hard to set up, but most of that was I was trying to host it behind our office load balancer, and that's no bueno. But once I put it on a dedicated IP,my secondary DERP was pretty easy. But, if you are going to self-host, seriously consider Nebula instead of tailscale. Unless you need non-technical users accessing it, tailscale has a better story there. (edit) The biggest downside of headscale is I don't feel confident I can update ACLs without having a high likelihood of taking down the entire tailnet until I can get it fixed.