‹ BackHN Continuity

Thread

Making Tailscale Faster

250 points · 112 comments · yarapavan

  1. fitblipper · · focus · HN ↗
    I used to LOVE tailscale. Then I put wireguard on my home network exposed to the internet with a dynamic DNS provider and it immediately became irrelevant. Not only is raw wireguard more stable (I don't have to fight the DNS issues on my mobile phones) it feels faster and is amazingly simple to set up.
    1. mnahkies · · focus · HN ↗
      I started with plain wireguard then migrated to tailscale, for my use case:

      - I was able to get my partner onto the tailnet by telling her to install an app and login. She doesn't know or care what wireguard is, but she can now access some of my self hosted services on her phone.

      - I'm able to easily dynamically register machines to the tailnet, such as CI jobs

      - I'm able to self host a DNS resolver and have it just work for devices connected to the tailnet

      I'm sure I could achieve these goals with plain wireguard, but I feel like I was able to outsource significant complexity to tailscale instead.

      1. ctippett · · focus · HN ↗
        I followed a similar trajectory for similar reasons. I was playing with wireguard around 2020 when I learned of Tailscale and since then haven't looked back.

        Just the other day I was able to set my sister up with access to my Plex server and the ability to piggyback on my UK internet connection to stream BBC/Channel 4 content from Australia. It took all of 5 minutes to get it working.

        1. zucked · · focus · HN ↗
          Same trajectory, but I've now migrated a lot of my previous tailscale stuff to Cloudflare tunnels -- it opens up the attack vector a _little_ bit (that can be mitigated) and it's app-free (which made it viable for a lot of my non-tech users). Still love tailscale and use it all the time for remote access to very sensitive stuff (ssh).
          1. ctippett · · focus · HN ↗
            Interesting. I've obviously heard Cloudflare tunnel, but haven't looked into beyond knowing that it exists. Was going "app-free" the primary motivator in your case for the switch?

            I have a few services I've configured static routes for on my router (so my wife can access them without needing to have her phone connected to Tailscale all the time), but other than that it's never been much of a pain point.

            1. zucked · · focus · HN ↗
              Yeah, the app-free nature of tunnels was a huge draw. Cloudflare does effectively MiTM your traffic, so that's a risk you have accept but the tradeoff was worth it for me. Between that an the secondary authentication you can put in front of your services, I felt much better about opening my self-hosted stuff to to relative 'public'.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.