En el siguiente #tutorial les muestro como crear una #vpn #mesh y utilizarla con los equipos que desees sin restricciones gracias a #headscale y #tailscale sobre tu propio servidor o #selfhosted. Algo que me pareció muy útil para estos tiempos...

Miralo en : https://luiszambrana.ar/como-instalar-una-vpn-mesh-con-headscale-y-tailscale/

Si te gusto compartilo con los tuyos!!!

I kind of like Tailscale. Once you get the hang of it, it’s really easy to use, and a lot of it feels almost magical (TLS certificates for internal services, direct connections with hole punching, ACLs/built-in firewall).
And the clients for FLOSS operating systems (i.e., Linux and Android for me, also available on F-Droid) are also FLOSS, so I can use the app without any issues.
*Only* the server is proprietary, though there is also a FLOSS reimplementation available.

#Tailscale #Headscale

@martin I have the same issue when I started using #headscale , so I write a blog post with my use of ACL

https://www.lucasjanin.com/2025/01/03/headscale-tailscale-in-a-self-hosted-environment

Headscale & Tailscale - Lucas Janin

Documentation of my journey with Headscale and Tailscale in a self-hosted environment covers the differences between a VPN server and Tailscale, Headscale, Docker Compose configuration, the Headplane interface, access control through #ACL, integration with Nginx Proxy Manager, exit nodes, routes, and installation on macOS, iOS, Linux, Debian, Proxmox LXC, Synology NAS, and Home Assistant.

Lucas Janin
Headscale's documentation of ACLs is funny:
Simple example:
- block all
- allow all
Complex example:
- a network of half a dozen servers, a handful of users, and a bunch of ACLs
Can I get some in-between examples please?
https://headscale.net/stable/ref/acls/
#headscale
Self-hosted Tailscale: веб-интерфейс и вход без паролей https://www.juev.org/2026/03/13/headscale-headplane-oidc/
#headscale #headplane #pocketid #oidc
I still haven't understood the benefit of smtg like #Headscale (#Tailscale) vs plain old #WireGuard, and now apparently there's a new kid in town called #NetBird lol. I watched a tutorial on self-hosting Headscale (i.e. to reduce dependency/reliance on Tailscale), but when they demonstrated its use case... setting it up looks more complicated than what you would've done on WG, and what u achieve seems exactly the same. I'm sure I'm missing something tho.

Celebrating #DigitalIndependenceDay with a practical win: for 2+ years I’ve run #Headscale as a self-hosted, #OSS control plane for #Tailscale clients. Beside classic #VPN use cases (untrusted networks, #geoblocking), this self-hosted alternative to "#VPN as a service" enables #privacy and reduces exposed #metadata. The full mesh #WireGuard network offers great performance and low latency, connecting your satellite services.

https://di.day

#did #diday #didit #ididit #dut #dutgemacht

Home — Digital Independence Day

An jedem ersten Sonntag im Monat veranstalten wir den Digital Independence Day. Wir holen uns unser freies digitales Leben zurück und wechseln zu demokratiefreundlichen digitalen Alternativen.

hehe, eindelijk de acls gefixed voor mijn tailnet
ik kan nu ssh-en vanaf iedere node naar iedere node
🤓

#headscale #tailscale

I’ve been running #Tailscale for a while-internal server and clients up, and it works brilliantly. Host as many services as you want, all encrypted and without exposing them to the internet. DNS and endpoints just work, making it easy to share with family or friends. Access rules give you full control.
For those more comfortable with the bash and self-hosting, #Headscale is the open-source, self-hosted option with the same functionality.
#SelfHosting #Networking #Privacy
https://tailscale.com/
Tailscale | Secure Connectivity for AI, IoT & Multi-Cloud

The connectivity platform for devs, IT, and security teams. Zero Trust identity-based access that deploys in minutes and scales to every resource. Start free.

Got issues while keeping #nextdns as global #dns #server in my #tailnet running #headscale.
If I switch to #cloudflare resolver, everything works as expected, but I don't like it this way.
I aslo tried #ad-guard but looks like being not supported at all under headscale.

Any suggestion?

*banging head against wall*

#selfhosting #homelab