4 ms·
i like that it removes tailscale proprietary. if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignt
by gz5 1mo ago
i like that it removes tailscale proprietary.
if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignty?
like netbird, openziti, zerotier, etc.
- gonzalohm 1mo agoOr just use wireguard directly. I get it that it's a pain in the ass to configure it, but there are plenty of open source config generators
- bradfitz 1mo ago(Author here) WireGuard doesn't do NAT traversal. That's the main thing this adds. And this also adds a CLI tool + library to do streams over WireGuard w/o installing kernel routings, requiring root, etc.
- mystifyingpoi 1mo ago> pain in the ass to configure it Idk? I found it pretty easy to configure by blindly following the tutorials and copy-pasting keys. The only footgun is the keepalive setting, which will screw up the tunnel if one end is behind NAT, that tripped me hard, but besides this, no issues at all.
- zikduruqe 1mo ago> it's a pain in the ass to configure it Public/private key pairs are hard? It's no more terrible than other projects that require configs.
- gonzalohm 1mo agoFor me the complicated part was understanding the IP assignment for peers and how to set that up correctly
- fodkodrasz 1mo agoIPSec may be a pain... but WireGuard is as simple as it gets in my opinion. Yeah, you may need to know basic IP concepts, like MTU... NAT traversal is a different topic, WG won't help in that, and that can actually be a pain. I guess we should be using IPv6 already, and this tool would be largely redundant already. (not completely, encrypted access to isolated networks is a valid use case)
- derkades 1mo agoEven without NAT, the same hole punching techniques must be used for IPv6 since there is usually a firewall blocking inbound traffic. Only in CGNAT type scenarios where the network behind NAT is still "WAN" will be helped by IPv6.
- jcgl 1mo agoThis point applied to normal NAT as well as CGNAT specifically. And hole punching gets a lot simpler when you’re behind NAT since you don’t need any kind of rendezvous server to determine port mappings. In other words, IPv6 does help substantially—the same hole punching techniques are not needed.
- podocarp 1mo agoWG is totally fine for home labs etc. But pushing configs to the server or networm when onboarding a new peer, making sure the new peer IP doesn't collide with someone else, etc. Can be quite annoying sometimes. NAT is honestly smaller of an issue and rarely encountered, but it's useful for example to expose services on my laptop to my phone, kind of like ngrok. That can be quite hard on vanilla wireguard. For me the biggest thing tailscale/netbird solves is still the automatic handling of the peers, acls, or in other words automating fireguard config.
- bradfitz 1mo ago(Author here) The DERP server is already open source and tailcat can use any DERP server you run: https://github.com/tailscale/tailscale/tree/main/cmd/derper#derp https://github.com/tailscale/tailscale/tree/main/cmd/derper#... We just provide some default ones (https://tailcat.dev/derpmap.json https://tailcat.dev/derpmap.json) to get started if you're not bandwidth-sensitive. But you don't have to use them. Update: I added more explicit docs about this to https://github.com/tailscale/tailcat#bring-your-own-derp-relay https://github.com/tailscale/tailcat#bring-your-own-derp-rel...
- aitchnyu 1mo agoUmm, we have a full opensource Tailscale stack now?
- raggi 1mo agoalways have! our darwin and windows clients are closed source, but they wrap the oss implementation in github.com/tailscale/tailscale and you can see and even use all the same hooks yourself. the control plane is closed source, but headscale is an open source alternative that we embrace and encourage people to use if it meets their needs/desires
- deleted 1mo ago[deleted]