4 ms·
Can you elaborate? What role does Tailscale play? I selfhost and have heard about Tailscale but couldn't figure out how it's used.
by vvpan 10mo ago
Can you elaborate? What role does Tailscale play? I selfhost and have heard about Tailscale but couldn't figure out how it's used.
- AnonC 10mo agoNot GP. My guess is that they’re self hosting this at home (not on a server that’s on the internet), and Tailscale easily and securely allows them to access this when they’re elsewhere.
- Sanzig 10mo agoEven if you are self hosting in the cloud or on a rented box, Tailscale is still really nice from a security perspective. No need to expose anything to the internet, and you can easily mix and match remotely hosted and home servers since they all are on the same Tailnet.
- lucb1e 10mo agoI host at home and can access the things at home just fine by having the server as DMZ in the router, or whatever it is called these days. This doesn't really answer what Tailscale does more than port forwarding. If it punches NAT, that sounds like it actually makes you rely on a third party to host your STUN, i.e. you're not self hosting the Tailscale server?
- AnonC 10mo agoYes, it does NAT traversal. If you don’t trust Tailscale servers, you can host the open source equivalent, Headscale (headscale.net) and use the open source Tailscale clients.
- digitalDM 10mo agoIn my words, I use Tailscale at home but not for this (yet). Tailscale is a simple mesh network that joins my home computers and phones while on separate networks. Like a VPN, but only the phone to PC traffic flows on that virtual private network.
- tjpnz 10mo agoTailscale gives me access to my home network when I'm not at home. I can be on a train, in another country even, and watch shows streamed off the Raspberry Pi in my home office.
- lucb1e 10mo agoThat's called a VPN Is this like "Band-Aid" that used to be a brand name but now people just use it generically?
- Sanzig 10mo agoTailscale is a bit more than a VPN. It operates in a mesh configuration rather than a traditional VPN concentrator setup. Tailscale's control plane orchestrates NAT traversal for devices on the Tailnet (through techniques like UDP hole punching) and allows them to establish direct Wireguard tunnels between them. That way, there's no VPN concentrator bottleneck because there's no concentrator at all, every device establishes tunnels to every other device.
- dawnerd 10mo agoTailscale can give you domains + ssl for local services with basically no effort.
- UltraSane 10mo agoWith tailscale on your server and endpoints you can access the server from anywhere without even having to open any ports. It is like magic.
- lucb1e 10mo agoIf you don't open ports, how can it reach your internal services to allow you access to them?
- UltraSane 10mo agoby using a wireguard tunnel and NAT traversal https://tailscale.com/blog/how-nat-traversal-works https://tailscale.com/blog/how-nat-traversal-works
- lucb1e 10mo agoAh, by using their servers: > How do we break the deadlock? That’s where STUN comes in. [...] In Tailscale, our coordination server and fleet of DERP (Detour Encrypted Routing Protocol) servers act as our side channel
- UltraSane 10mo agoYes, NAT traversal is used widely. It is only needed at the start of the connection to get both firewalls to open ports. The encrypted wireguard tunnel is point to point
- nickthegreek 10mo agoTailscale routes my mobile device dns through my pile back at the home. I have nginx setup with easy to remember domains (photos.my domain.com) that work when i’m away as well without exposing anything to the open internet.
- lucb1e 10mo agoWhy not call it VPN if that's what it is? In your case, it sounds like configuring your "pile" (is that a DNS server, short for pihole maybe?) on your phone would do the same thing, but if the goal is to not expose anything to the open internet, a VPN would be the thing that does that
- nickthegreek 10mo agoyour internet traffic isn’t routed through it like a traditional vpn.