🇬🇧 New article in my blog: Self-hosted Tailscale, Part 1: Headscale and clients
https://blog.fidelramos.net/software/tailscale-1-headscale-and-clients
🇪🇦 Nuevo artículo en mi blog: Tailscale autoalojado, Parte 1: Headscale y clientes
https://blog.fidelramos.net/es/software/tailscale-1-headscale-and-clients

I had been hearing a lot of people raving about Tailscale as a solution for interconnecting devices, or in other words for creating your own mesh VPN. It does seem great on paper: easy to set up, fast and lightweight, based on an open protocol (WireGuard), works everywhere, solves the …
Spent some time messing around with Headscale (self-hosted implementation of the Tailscale control server).
I couldn't get "raw" WireGuard to work the way I wanted through nested firewalls and CGNAT so this seems like a good way to blow all that complexity out of the water. Less complexity is usually more reliable.
Headscale is pretty neat. Painless install on Debian.
Configuring Linux and Windows nodes is simple too - at least from a basic connectivity point of view.
I need to figure out how I'm going to deal with multi-homed DNS scenarios for clients. Something with very little thought and work through yet. Ha.
Now the hard part, picking apart the security and edge cases to use it regularly.
#Headscale #Tailscale #VPN #CGNAT #WireGuard #HomeLab #SelfHosted #SelfHosting #VPS
Jetzt habe ich #CryptPad installiert (per Docker, auf meinen kleinen 2 CPU / 2 GB #ionos Mietserver, der mein #Headscale VPN macht), weiß aber immer noch nicht, was ich eigentlich damit will.
Vielleicht Einkaufsliste, aber dafür fehlt eine praktische, mobile App (gibt wohl gar keine Third-Party-Clients).
Vielleicht die Datei mit den Stromzählerständen von Apple Numbers umziehen?
Vorher aber erstmal ein Backup einrichten (in existierendes #Restic einbinden; SFTP zu #Hetzner Storagebox).
Habe ein How to upgrade Headscale / Headplane geschrieben um schmerzfrei auf die letzte Version upzudaten.
https://2tap2.be/headscale-upgrade/
#headscale is an open source, #selfhosted implementation of the #Tailscale control server.
#headplane is a feature-complete Web UI for Headscale.
Wie ich Headscale und Headplane zusammen installiert habe, habe ich sehr ausführlich [hier](https://2tap2.be/headscale/) beschrieben. Nun ist die Anleitung knapp ein Jahr alt und es wird mal Zeit, den ganzen Stack auf die neueste Version zu bringen. Aktuell ist das bei Headscale **v0.28** und Headplane **v0.6.2**.
The Easter Weekend Project:
Set up a cheap rental server (wanted to do #Hetzner, I like their cloud offering and used it to practice the setup, but went with the very aggressively priced low-end #ionos instead; 2€/month) with encrypted #ZFS to run #Headscale via #DockerCompose (with #Dockhand for the pretty UI).
This gives me a personal-use VPN „intranet“ to remotely access my growing self-hosted (#OnPrem #MacMini) zoo (#HomeAssistant, #PaperlessNGX, #VaultWarden, #Gitea) in a secure way.
En el siguiente #tutorial les muestro como crear una #vpn #mesh y utilizarla con los equipos que desees sin restricciones gracias a #headscale y #tailscale sobre tu propio servidor o #selfhosted. Algo que me pareció muy útil para estos tiempos...
Miralo en : https://luiszambrana.ar/como-instalar-una-vpn-mesh-con-headscale-y-tailscale/
Si te gusto compartilo con los tuyos!!!