this post was submitted on 05 Feb 2024
30 points (94.1% liked)

Selfhosted

40296 readers
379 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

So for the past few years (?) I have been using wireguard to vpn into (effectively) my firewall and a dynamic dns setup to access that remotely. But with the shitshow that is google domains and the like, this seems like a good opportunity to look into a few of the alternatives. I am not entirely opposed to just going in and changing the dns server once I figure out what I am going to do on that front, but wireguard has always been a bit of a mess to set up for less "tech savvy" people who need access to the home network.

Every so often I see some cloud based solutions get suggested. Which is sketchy but I already have a few alerts set up to be able to remotely shut my network down if wireguard is acting up when it shouldn't be and shutting down a VM is a lot less of a "do I really need to do this?" than shutting off the entire network. But most of those solutions seem built around selling seats which means they want you to add individual devices rather than just setting up a tunnel.

So is wireguard still the gold standard? Or is there a more user friendly solution that will let me compromise a bit but also have a setup that doesn't require me to be physically on site to fix the inevitable hiccups because it takes hours of reading articles to understand the setup?

Thanks

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 8 points 9 months ago (1 children)
[–] NuXCOM_90Percent 2 points 9 months ago (2 children)

I think that is the seat based one I see recommended all the time.

I understand that hub and spoke models are inherently questionable security wise and switching to a mesh based approach is probably the answer. But it tends to make for a mess of needing to make sure my various "homelab" servers are aware and so forth.

[–] [email protected] 4 points 9 months ago* (last edited 9 months ago)

Might want to check ZeroTier too. They don't have as much features as Tailscale, but have more relaxed limit. If you can't decide, you can use both Tailscale and ZeroTier at the same time without issue.

[–] [email protected] 4 points 9 months ago (2 children)

There's a "hub" mode where your endpoint inside the network grants access to the whole network like a standard VPN server.

[–] [email protected] 1 points 9 months ago* (last edited 9 months ago)

You won't realise the full value of Tailscale's features this way though - for example, you'll miss out on the ability to share an individual device with someone else, the ability to configure ACLs between particular devices (e.g. allow someone access to just a particular port on a server, while allowing yourself full access), and Tailscale SSH.

[–] NuXCOM_90Percent 1 points 9 months ago (1 children)

Oooooooh.

Thanks. Will take a look to try and figure out their terminology for this.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago) (1 children)