Live data from Hacker News

Tailscale Peer Relays

tailscale.com

91–100 of 118 posts

Re: Tailscale Peer Relays

#91

Tailscale playing catchup to netbird...

What is the equivalent feature of netbird? Can you link the documentation please?

I couldn't find a specialised page for it. But here they mention that the relay service can be self hosted: https://docs.netbird.io/about-netbird/how-netbird-works#rela...

Re: Tailscale Peer Relays

#92
post #72
post #37

Earlier quoted context omitted.

A $2.5/month vps solves this issue.

It does not. I push hundreds of TB across my private mesh.

When networks get used for unethical or criminal workloads, reliability problems aren’t the tooling's fault. A tiny VPS does the job fine for the rest of us.

Re: Tailscale Peer Relays

#93

Earlier quoted context omitted.

Yeah, such extension is natural and it comes up frequently in the context of overlay networks. The defining question here is if you are OK with relaying other people's CP traffic.

"within the tailnet." So, the "other people" are people you've authorized to be on your tailnet, at least in this conversation.

Ah, my bad. You are right, I missed that bit.

Re: Tailscale Peer Relays

#94

> We believe our new Tailscale Peer Relays connectivity option—unique to Tailscale—gives customers the best performance and flexibility. Seems pretty similar to some of the stuff ZeroTier was doing years ago. Hard to claim it's unique to Tailscale. Charging for it above and beyond the per user costs seems overboard as well.

I've used ZeroTier in the past and I don't recall a feature similar to this being part of their offering. What I do remember is home brewed crypto, incredibly poor single threaded performance, and a glacial development pace. Any thread about Tailscale inevitably brings up alternatives, but having tried many of them in the past, I've yet to find one that actually competes across all the features and performance. The comparisons to other solutions tend to give me "why do you need Dropbox when FTP exists?" vibes.

Re: Tailscale Peer Relays

#96

Earlier quoted context omitted.

Yeah, Tailscale is really cool. The only thing I wish is that they didn't tie auth to either a big tech monopoly (Google, github etc) or running your own IDP service. I would love to use Tailscale for some self hosted stuff I have, but hesitate to start exposing something like an identity management tool because that's a high value target. And of course, I don't really want to let Google et al be in control of my VPN…

They support Passkeys. This is exactly how I continue using them after moving away from Google Workspaces.

Oh wow, I had totally missed this[0]! Is it possible to migrate an existing SSO account (with associated tailnet) to a passkey one?

[0]: https://tailscale.com/blog/passkeys

Re: Tailscale Peer Relays

#97

Earlier quoted context omitted.

tailscale appears to be a paid product with a free tier, nebula (while DIY) is free

there is an open source control plane called headscale which covers almost all of the features for free (while DIY)

People keep saying that, but haven't we learned already that eventually Tailscale gets bought, then priorities change, then they make incompatible changes because they're need to grow, and headscale either can't keep up, or gets pushed away by Tailscale themselves, and we're back to using $TailscaleCompetitor who promises to not do the same thing.

Just don't rely on centralized for-profit entities, rely on stuff produced by non-profits and foundations, that you know isn't gonna screw you over as soon as they need money.

Re: Tailscale Peer Relays

#98
post #92
post #72

Earlier quoted context omitted.

It does not. I push hundreds of TB across my private mesh.

When networks get used for unethical or criminal workloads, reliability problems aren’t the tooling's fault. A tiny VPS does the job fine for the rest of us.

What are you talking about? Nothing I am pushing across my mesh is unethical or criminal, from whence these baseless accusations?

Re: Tailscale Peer Relays

#99
Is it possible to specify the external ipv4 and ipv6 address? There are scenarios where the eggress traffic uses a different address to ingress, or the host has multiple internet-connected addresses but only one has a firewall permitting traffic to the nominated port.
Post reply on HN