Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
apenwarr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
apenwarr
5y ago
The localapi is indeed an http server built into the tailscaled process, which is written in Go. Since we already had an http client in there, the net new code to add an http server is quite low. And it doesn’t take any battery unless it’s
32.
▲
by
apenwarr
5y ago
There’s an open source project called headscale (not written by or officially supported by tailscale’s team, but we like it) which you can point tailscale’s clients at. Then your whole system is open source. You can also avoid using a centr
33.
▲
by
apenwarr
5y ago
MacOS, iOS, and Linux clients can use your native OS updates. Windows needs to be updated by hand or with something like chocolatey or MDM. But more importantly, we have a policy of not breaking old clients if we can possibly avoid it. So f
34.
▲
by
apenwarr
5y ago
A trivial example is networks that totally block UDP and only allow TCP traffic on port 443, say. Tailscale has an article called How NAT Traversal Works with considerably more gory details if you’re interested.
35.
▲
by
apenwarr
5y ago
In Tailscale, much like in SDN or SD-WAN, we think of the network in two parts, the control plane and the data plane. The data plane is how the bulk of your packets get sent from one place to another, which in Tailscale is peer-to-peer (as
36.
▲
by
apenwarr
5y ago
The idea is to get there eventually, and taildrop is the first example/experiment in that area. In theory a bunch of individuals on the free plan should be able to build arbitrarily complex networks by using the (also free) node sharin
37.
▲
by
apenwarr
5y ago
Post author here. I'm happy to answer any questions / respond to any rants if you like.
38.
▲
by
apenwarr
6y ago
[I work at Tailscale] I only mean scalable for our very specific and weird access patterns, which involves frequently read-iterating through a large section of the keyspace to calculate and distribute network+firewall updates. Our database
39.
▲
by
apenwarr
6y ago
That would have been considerably less scalable. etcd has some interesting scaling characteristics. I posted some followup notes on twitter here: https://twitter.com/apenwarr/status/1349453076541927425
40.
▲
by
apenwarr
6y ago
The original book is about an IBM mainframe OS that was a second system effect project, but which eventually succeeded. The point isn’t that every rewrite fails, it’s that it makes things really painful and is rarely worth it. The Mozilla r
41.
▲
by
apenwarr
6y ago
> Your empathy is appreciated but unaccepted, this is not the goal. Again, the goal is to debate a point and find a correct answer. Ironically but very relevantly to this conversation, it seems we disagree on the goal. :)
42.
▲
by
apenwarr
6y ago
You keep talking about “optimal,” but algorithms and data are only good for optimizing, not for defining what you mean by “optimal” in the first place. Logic and engineering can achieve goals, but they can’t help you choose what goals to ac
43.
▲
by
apenwarr
6y ago
Kubernetes is the biggest and worst second system effect I’ve seen in years.
44.
▲
by
apenwarr
6y ago
You could solve item #2 by simply having the kernel lie about the recursive parents of each mount point. Basically, when you mount a filesystem, anyone asking for the mtime of a parent (even across filesystems) will return max(real_mtime, r
45.
▲
by
apenwarr
6y ago
You're assuming the inodes of all the parent directories would be flushed to disk every time they change. This is already not the case. It would be just a matter of touching the data structure in memory and eventually flushing it out.
46.
▲
by
apenwarr
6y ago
[Tailscale founder here] If you're using a mac, you can just install Tailscale from the app store, which does not require root (thanks to the "magic" of Apple's extension signing). Another experiment we're doing is
47.
▲
by
apenwarr
6y ago
[Tailscale founder] One thing you can do here is use tailscale to connect all your devices together, including that VPS, and then set up a reverse proxy on the VPS that forwards queries to your various devices over tailscale.
48.
▲
by
apenwarr
6y ago
[Author here] As others have pointed out, it wasn't originally a sales pitch and we later pivoted to something else. I agree it came across in a kind of annoying way. I've added a new update at the end to describe what happened, f
49.
▲
by
apenwarr
6y ago
Why do you need automatic fallback? You simply define in the config file, for each peer, which protocol version to use. Then it's up to the config file distribution process - whatever it is that you do - to make the appropriate version
50.
▲
by
apenwarr
6y ago
Persistent data structures (like git) are way harder to update than non-persistent structures (like ephemeral network packets). Hypothetical WireGuard v2 packets will simply not parse as WireGuard v1 packets; they can't be decrypted
51.
▲
by
apenwarr
7y ago
(Tailscale co-founder) I'm with you on this! The NAT problem drives me nuts. That's one of the core concepts behind tailscale. Unfortunately I don't think the "open source NAT traversal as a library" idea will work;
52.
▲
by
apenwarr
7y ago
(Tailscale co-founder) Everyone at tailscale agrees 100% with all your comments here. We're eager to someday have a chance to stop optimizing NAT traversal so that we can make magic DNS work. But we also know we have to get the core ro
53.
▲
by
apenwarr
7y ago
(Tailscale co-founder) This question goes through my mind a lot. I personally want it for myself. However there's a "weakest link" problem in identity management: if you have N identity managers merged together, then your acc
54.
▲
by
apenwarr
7y ago
Cool! Maybe it's more doable than we thought.
55.
▲
by
apenwarr
7y ago
It originally said "a few", not "few", which was intended to have a slightly different meaning, but I've edited it to remove that because you're right and it's not important :) Unfortunately non-technical
56.
▲
by
apenwarr
7y ago
I quite like Keybase. Do they offer an oauth2 or SAML login feature nowadays that somehow integrates with your strong device authentication?
57.
▲
by
apenwarr
7y ago
I really love the privacy- and security-centric design of Sign In with Apple, but so far it only works if you have Apple hardware, right? Tailscale's selling point is you can use it on all your devices (modulo Android support which isn
58.
▲
by
apenwarr
7y ago
It's easy to make a basic password login system, and very technical people use password managers, long passwords, etc. But there's a long "tail" (ha ha) of people who don't use long passwords, who will reuse their p
59.
▲
by
apenwarr
7y ago
(I'm a Tailscale co-founder) The idea is to avoid building yet another commercial service that holds onto your username and password. People have enough identities already. More details here: https://tailscale.com/blog&
60.
▲
by
apenwarr
7y ago
(I'm from Tailscale) You've nailed the problem statement, but we are trying to find a better solution. The current "zero trust networking" trend is actually not about distrusting the endpoints; it's about distrustin
More ›