7 ms·
Tailcat – Like netcat, but over Tailscale’s data plane
- cpuguy83 1mo agoInteresting. I thought about doing this immediately after reading their old blog[1] post on punching through NAT some time ago. Just a combo of never getting around to it and friends talking me out of it b/c of existing alternatives such as wormhole[2]. [1] https://tailscale.com/blog/how-nat-traversal-works https://tailscale.com/blog/how-nat-traversal-works [2] https://github.com/magic-wormhole/magic-wormhole https://github.com/magic-wormhole/magic-wormhole
- petcat 1mo agoI did the homemade version of this for years just with SSH forwarding and nginx reverse proxy
- nateguchi 1mo agobut without nat traversal...
- petcat 1mo agoIs NAT traversal actually that big of a feature? The category of people that would use a tool like this already knows many ways to do it without NAT getting in the way.
- 9dev 1mo agoUnless you have some kind of dynamic DNS with a background daemon, you'll be bothered by NAT eventually. And even then it's hardly as convenient. With Tailscale, I can sit on a rooftop bar in the Medina of Marrakech, connect my phone to the public WIFI, and access my laptop in the hotel WIFI across town. Or production infrastructure on a highly secured server somewhere on the other side of the planet. All without compromising security, and all devices involved just pick the shortest physical link to each other. It's really pretty cool.
- frollogaston 1mo agoIt's not a given that you always have some server without NAT in the way. Even if you do, it might bottleneck or add latency to the two ends trying to talk. I've been there.
- dannyw 1mo agoIf you ever connect over a mobile hotspot, then you need NAT traversal. And if you want something that "just works" across various network environments, you need NAT traversal.
- gz5 1mo agoi like that it removes tailscale proprietary. if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignty? like netbird, openziti, zerotier, etc.
- gonzalohm 1mo agoOr just use wireguard directly. I get it that it's a pain in the ass to configure it, but there are plenty of open source config generators
- bradfitz 1mo ago(Author here) WireGuard doesn't do NAT traversal. That's the main thing this adds. And this also adds a CLI tool + library to do streams over WireGuard w/o installing kernel routings, requiring root, etc.
- mystifyingpoi 1mo ago> pain in the ass to configure it Idk? I found it pretty easy to configure by blindly following the tutorials and copy-pasting keys. The only footgun is the keepalive setting, which will screw up the tunnel if one end is behind NAT, that tripped me hard, but besides this, no issues at all.
- zikduruqe 1mo ago> it's a pain in the ass to configure it Public/private key pairs are hard? It's no more terrible than other projects that require configs.
- gonzalohm 1mo agoFor me the complicated part was understanding the IP assignment for peers and how to set that up correctly
- fodkodrasz 1mo agoIPSec may be a pain... but WireGuard is as simple as it gets in my opinion. Yeah, you may need to know basic IP concepts, like MTU... NAT traversal is a different topic, WG won't help in that, and that can actually be a pain. I guess we should be using IPv6 already, and this tool would be largely redundant already. (not completely, encrypted access to isolated networks is a valid use case)
- TZubiri 1mo ago>"like netcat, but over Tailscale's data plane" Half of the Software offering nowadays seems to be selling vendor lock-in at no added value and then making a profit. Sure there's always some negligible added value, and then they reinvent a whole stack for their ecosystem. In the case of tailscale the added value seems to be avoiding going into your router and activating port forwarding? It looks like negative added value to me. Someone that tells you "don't do NAT traversal, just open a port" would be highly valuable, but saying no doesn't seem to be trendy, and is certainly not an easy sell.
- bradfitz 1mo ago(Author here) There's no vendor lock-in here and no payment or account required. If Tailscale as a company fails, tailcat keeps working if you run your own DERP server. It's just open source code, not a hosted service.
- TZubiri 1mo agoIt's an official tailscale product no? Fwiw, I don't think vendor lock-in is a bad thing, but being open source doesn't mean there's no vendor-lock in. If a client builds their system on top of an open source technology, then switching away from that dependency would have a cost, even if that cost is engineering man-hours. If tailscale does not work out of the box with netcat, and requires a custom additional dependency to work, it raises the question that tailscale will not work out of the box with other tools like tcpdump or stunnel and apache, and I will need to install other custom dependencies like taildump, tailtunned, tailapache. When compared to other solutions that integrate without additional effort, installing vendor-specific dependency forks/clones means that there is an additional vendor lock-in.
- parasyte 1mo agoThis isn't due to tailscale not supporting or working with netcat; you can nc to an address on your tailnet just fine. This is using the infrastructure tailscale set up for a different purpose. Rather than requiring a tailnet or even an account anywhere, you can tailcat between any two endpoint. Tailscale is there because it runs the DERP relays which get the client's pubkey to the server, brokers the connection, and coordinates holepunching.
- codruterdei 1mo agoA bit off topic: it’s just insane how I used to watch this guy’s http2 in Go yt video 10 years ago, and he’s still very relevant to this day! Cheers Brad!
- cpuguy83 1mo agoAlso created memcached, livejournal... Brad has a long list of impressive work.
- bradfitz 1mo agoStill working on Go's http2 10 years later :) Recently: https://github.com/golang/go/commit/128a36cf0367c46daff2528de89da4225f001dcd https://github.com/golang/go/commit/128a36cf0367c46daff2528d... https://github.com/golang/go/commit/3c0665e551be23e62167f6257bede071bfbdcacb https://github.com/golang/go/commit/3c0665e551be23e62167f625...
- archietect 1mo agoIt looks like a direct competitor for the recently launched bitbang-cli https://github.com/richlegrand/bitbang-cli https://github.com/richlegrand/bitbang-cli
- fulafel 1mo agoAnd IPv6.
- rugma 1mo agoWush was already doing something similar (using tailscale under the hood) https://github.com/coder/wush https://github.com/coder/wush
- MrDrMcCoy 1mo agoLooks like a Wireguard stunnel replacement, which is very useful!
- megamorf 1mo agoSo this is somewhat similar to Iroh? https://github.com/n0-computer/iroh https://github.com/n0-computer/iroh
- genpfault 1mo agoIn particular: https://github.com/n0-computer/dumbpipe https://github.com/n0-computer/dumbpipe https://github.com/cablehead/pai-sho https://github.com/cablehead/pai-sho
- Arqu 1mo agohttps://github.com/n0-computer/pigeons https://github.com/n0-computer/pigeons offers the same but with SSH. I use it in my homelab extensivelly for access, tunneling smb, postgres and some other minor bits.
- colinmarc 1mo agoI'm a big fan of iroh, but I think iroh's holepunching algorithm is at least partly based on tailscale's, so it's not 100% accurate to say iroh got there first. (Just the "as a library without a control plane" bit.)
- ReactiveJelly 1mo agoIt's all just knockoffs of Skype and BitTorrent :) I'm glad there's a competing Rust and Go implementation now. I like Iroh as a Rust user and having tailcat around doesn't hurt me
- tptacek 1mo agoThis is smart. It's Magic Wormhole but for generalized connectivity, not just file transfer.
- doomrobo 1mo agoYes, though MW has the important distinction that it uses short human-readable session identifiers. This means MW supports file transfer where the out-of-band channel is just a phone call. This is also why it needs PAKE as opposed to the simpler cryptography used in tailcat
- tptacek 1mo agoNot a huge lift to stick a PAKE in this protocol, though I'm dubious that it'd be much of a win. The PAKE + nameplate system in Wormhole makes a lot of sense, because you're doing one very specific thing with that system (moving a file from point A to point B). Here you're booting up servers; you're almost always going to have a non-voice channel to set up with.
- MajesticHobo2 1mo agoYou also don't want adversaries to be able to disrupt long-lived streams with bad password guesses, since I think part of Wormhole's security model is it will terminate the session if the other side gets it wrong.
- ignoramous 1mo ago> This is also why it needs PAKE as opposed to the simpler cryptography used in tailcat May be my idea of simpler cryptography is incorrect, but PAKEs like CPace do seem simpler than public key primitives in Noise.
- tptacek 1mo agoA PAKE is more complicated than Noise. Noise is fussy (for good reasons) but relatively simple.
- LoganDark 1mo agoWhat's the risk of malware using this for C&C or otherwise? Hackers love communication channels that are difficult to take down individually.
- MajesticHobo2 1mo agoThey say it's rate-limited, so at least it probably won't scale to large botnets or similar...
- mikepurvis 1mo agoI enjoy that they supply a nix install/environment, similar to the main tailscale/tailscale repo. Is nix widespread or the standard dev environment at tailscale, or is it like a 10% option and most people just use Docker or whatever?
- bradfitz 1mo agoIt's not our standard dev environment but some of us use Nix. We don't really use Docker much, though. Mostly just "go test" etc.
- innocent_name 1mo agoHow do you guys deal with nix & go cache? i hate when nix cold starts builds, tests without go cache.
- aerzen 1mo agoI'd guess that there is an insignificant minority of people who strongly prefer nix over anything else. And it might be because it is easy to provide and maintain compared to a .deb package.
- mikepurvis 1mo agoMaintaining and providing a deb is pretty easy too; the real killer for a nix flake I think it's how dirt simple it is to provide infinite testing builds for different branches.
- aerzen 1mo agoWell, for .deb there is the dependency problem. Even if your deb is just a release of a project, you can only use versions of dependencies that are in debian repository. Or include it all in your .deb, which becomes hard to maintain. By "infinite branches" you probably mean that a nix derivation / flake is a recipe that can build any version of the project?
- aseipp 1mo agoJust yesterday I was complaining that I wanted to SSH back to my homenet while at the office, on my office (not home) tailnet. I wrote something based on Iroh to do this, but it's one shot (ie not particularly generalized). Might be able to throw it away or redesign it with some inspiration from this! Thanks.
- bradfitz 1mo agoThere's an example in the README how to do exactly that :)
- codegladiator 1mo agowhy not try out some existing project already on top of iroh ? I see a bunch here on awesome-iroh page https://github.com/n0-computer/awesome-iroh https://github.com/n0-computer/awesome-iroh
- dfish 1mo agoyou could try rayfish.xyz, it is compatible with tailscale nowadays so you can run both tailscale and rayfish
- maisem 1mo agoI solved this problem by building/running a custom tailscale client that connects to two tailnets at the same time (https://github.com/maisem/tailmix https://github.com/maisem/tailmix)
- linsomniac 1mo agoI was just wondering yesterday if it'd be possible to have a tailscale client, or multiple tailscale clients in their own network namespaces, that could connect to multiple networks. The slightly tricky part would be managing a local NAT that blends the two networks, and also does MagicDNS to answer on those NATed IPs. If routes conflicted, I guess you'd have to pick one? Seems very doable though.
- linsomniac 1mo ago
- 1970-01-01 1mo agoAs 'cattail' is not officially taken, I have to assume they are oblivious to having a little fun.
- kemotep 1mo agoKeeps with the tradition of netcat alternatives like powercat, socat, cryptcat.
- pbohun 1mo agoThis is so cool! I mean, we really wouldn't need it if we had 100% ipv6 (no cgnat), but this is the next best thing. I think people underestimate the innovation that could happen if we had trivial p2p.
- ipdashc 1mo agoLooks dope, though I'm surprised, is Tailscale fine with their DERP servers being used by non-customers like this? (Yes, it's a Tailscale project, but doesn't require login.) I vaguely assumed there was an auth step before you could use one as a relay. They mention a rate limit, but still
- smw 1mo agoRepo suggests that they're running their own (rate-limited) DERP servers. edit: Which are probably tailscale's, as it's under tailscale/ github org?
- deleted 1mo ago[deleted]
- bradfitz 1mo agoYes, it's been our CEO Avery's position for ~6.5 years now that we should run DERP servers on the internet for the public good. (rate-limited) But these are a separate fleet (https://tailcat.dev/derpmap.json https://tailcat.dev/derpmap.json) separate from our usual ones, and not using "tailscale.com" in DNS or SNI anywhere.
- ipdashc 1mo agoFair enough. Thank you!
- mrsssnake 1mo agoTool like this exposes big problem with the current shape of the Internet, I believe. Everything should be possible with just plain netcat and IP stack. Someone asks about NAT holepunching, encryption, static IDs, permissions, etc., yes this is what Internet lacks and why every P2P app reinvents it over and over again.
- MajesticHobo2 1mo agonotabug wontfix; that's the end-to-end principle in action. Bring your own all of that.
- bradfitz 1mo agoOne fun use case: a coworker just whipped up this Minecraft mod using tailcat as its transport: https://github.com/tailscale/tailcat-for-minecraft https://github.com/tailscale/tailcat-for-minecraft (just a cute demo, not intended for release or ongoing maintenance)
- awakeasleep 1mo agoIt would be amazing to have something like this for bedrock so people with consoles without online subscriptions could join a self hosted bedrock mc server
- nullsanity 1mo agoThey can! They just need a real computer, the real Minecraft game (Java), and then they can! it's so easy when you don't play the shitty mobile clone.
- tucnak 1mo agoWhy is this downvoted? Bedrock is literally dog shit clone for iPad kids. This is not even controversial, it's just fact.
- water-drummer 1mo agoWoah this is cool! I've been making a mesh vpn like radmin vpn or hamachi that does not need a central authority server and most importantly, can run on all major OS thanks to wireguard-go.
- spockz 1mo agoHow much Tailscale is this still if the transport is based on wireguard, the control plane is something new with the keys based on the wireguard keys? Genuinely confused.
- zrail 1mo agoI dug into it a bit because I had the same question. The network layer here is wrapping around the Tailscale daemon's magicsock, which is the thing that does all the DERPing and NAT hole punching. Tailcat builds sort of a fake control plane that does a one way key exchange over DERP (the Meow message type) between client and server, then both sides do the normal CallMeMaybe dance to connect.
- tomxor 1mo agoI think this is best described as a one-shot control plane, the single use address/key (same thing) is shared out of band, so it's far more minimal than the TS control plane. The examples show the concrete use cases... Basically giving you the wiregaurd + DERP quality tunnel but as a one shot point to point cli tool. Which is a nice upgrade from the alternative "in a pinch" tools. RE "how much tailscale" I guess it's the DERP bit + this minimal point to point control plane. Without which it's significantly more configuration to get the wiregaurd tunnel working, or impossible because of NAT, unless both machines are on the same ipv6 network. TS basically sell the full control plane with Auth and ACL style management etc as their product so this doesn't really compete.
- forrestthewoods 1mo agoI have a really dumb ignorant question. What is a data plane? What is a control plane? I don’t genuinely understand what these words mean :(
- ulimn 1mo agoDoes this help? This is what I read on the topic a few weeks ago: https://tailscale.com/docs/concepts/control-data-planes https://tailscale.com/docs/concepts/control-data-planes
- clavicle1009 1mo agoNetbird is the more mature version of this: fully open-source, self-sufficient, works like a charm, supports reverse proxying out-of-the-box, and much more. No reason to ever return to the Tail family.
- runtime_terror 1mo agoLinks: https://netbird.io/ https://netbird.io/ https://github.com/netbirdio/netbird https://github.com/netbirdio/netbird
- idoescompooters 1mo agoExcept the public relays are paywalled...
- ekarulf 1mo agoI use mosh over WebSockets to have a long lived connection to my home network. I bet I could simplify out the WebSocket-to-UDP proxy by leaning into tailcat's dataplane and just speak straight UDP.
- LarsKrimi 1mo agoNeat idea in its core but its still tailscale underneath The only thing that convinces me that tailscale isn't a CIA op is how badly it works for real uses
- 9bot 1mo ago[dead]
- stillpointlab 1mo agoI've spent time finally learning what tailscale is and how it works and I'm impressed. It's a rare thing in the technology world but I'm glad I finally took the time. I literally just figured out how tsnet fits into the picture (an in-process Go based entire network stack that gets the process to act as a node in the tailnet) and so that helps me understand this (everything in tsnet excepting the control plane). It's very impressive that they can do this in a reliable way.
- deleted 1mo ago[deleted]
- wxw 1mo agoI just set up Tailscale as I've been hosting more personal apps off a small Hetzner VM and wanted a really simple personal networking solution. Works great, would recommend.
- dannyw 1mo agoIt's really excellent. I've been using Tailscale for a number of years, just for my home network and with a single user, and the service is excellent, and the free tier is incredibly generous. I'm hoping that my Mullvad subscription (through Tailscale) contributes a little bit at least. Two excellent companies. I like that there is Headscale as an open-source offering too. I don't use it, but the fact that it exists makes me a lot more comfortable (similar to Bitwarden etc).
- zackify 1mo agosuper sick, already setup a derp server. dns node key for fun on one and two machines that connect, with systemd to keep tailcat serving ssh running
- humanlity 1mo agoThat's how I dreamed, Thanks tailscale
- Schlagbohrer 1mo agoThe Tor network and Onion protocols used to be used for this type of thing 10 or 15 years ago, exposing a home service with a .onion address and then gaining secure private access over the global internet infrastructure that way. But I haven't even seen any Tor related headlines for ages.
- gsallesl 1mo ago[dead]
- larnon 1mo agoI do use Tailscale myself to connect many of my devices. So I am a bit confused, what does this add over regular Tailscale? Excuse my lack of knowledge in this area.
- 1vuio0pswjnm7 1mo agoPeers might not want to use third party rendezvous servers or relay servers It appears that Tailscale attempts to persuade peers not to run own "DERP" servers (cf. encouraging peers to run own servers) "In general, you should not need to or want to run this code. The overwhelming majority of Tailscale users (both individuals and companies) do not." "Running your own DERP services requires exeprtise [sic] in multi-layer network and application diagnostics. As the DERP runs multiple protocols at multiple layers and is not a regular HTTP(s) server you will need expertise in correlative analysis to diagnose the most tricky problems. There is no "plain text" or "open" mode of operation for DERP." https://github.com/tailscale/tailscale/tree/main/cmd/derper https://github.com/tailscale/tailscale/tree/main/cmd/derper Unclear why the company markets peer-to-peer networking but wants traffic going to their own third party servers In contrast, Nebula, another Go peer-to-peer project encourages peers to run their own rendezvous server ("lighthouse") https://github.com/slackhq/nebula https://github.com/slackhq/nebula "To set up a Nebula network, you'll need: 2. (Optional, but you really should..) At least one discovery node with a routable IP address, which we call a lighthouse." The comparison to nc seems off. Original netcat has no required third party dependencies, no recommended third party dependencies, and not enough complexity to be linked to a company selling associated SaaS or consulting
- sfllaw 1mo ago> Unclear why the company markets peer-to-peer networking but wants traffic going to their own third party servers At Tailscale, we do not _want_ traffic through our servers. What we do want is for Tailscale to Just Work without your needing to set up any infrastructure. That’s why we run the DERP relay network as a fallback of last resort, for when a direct connection is not possible. And the tailscaled client tries very hard to make that direct connection. If and only if you need to run your own infrastructure, then we provide peer relays which are significantly less onerous than running a DERP server: https://tailscale.com/docs/features/peer-relay https://tailscale.com/docs/features/peer-relay This note exists in the README because people would assume that hosting a DERP server was a hard requirement for using Tailscale. Or they would assume that an production Tailscale network would eventually operate a DERP server. People who run their own DERP servers usually have data sovereignty or strict metadata requirements.
- mintflow 1mo agobeing built a iroh based distributed notes app for myself use and see tailcat come out, trying to replace iroh with this to do some experiment because i really love how tailscale works and invest much time to the stack True appriciated of open source this, combine the tailscale open source client core with this, i think it can unlock more stuffs
- deleted 1mo ago[deleted]
- fongka2 1mo agoHello, i am building a open client-based platfrom that really fun, the whole system(js for now) once start then you can pick the target(friends?) to trust(oneway/equal), then users will sync inside the trust network, to make your app and eveyrthing up to date autoly, but the problem is the P2P isnt a way for 4G/5G user, i plugged IPFS stuff inside for, to let user can share their life like video just like internet but not a signle server, so i see Tailcat today i am thinking if i plug this inside, is that evil to you guys? you know i'am asian, our internet is going to Terminator skynet, i have finish a free,open, for everyone's working pure serverless system(but NAT problem)
- fongka2 1mo ago[dead]