home.social

#headscale — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #headscale, aggregated by home.social.

fetched live
  1. @rafacampoamor Tu tráfico no pasa por sus servidores casi nunca. Sus servidores son coordinadores de conexiones de tus máquinas. Una vez se establece la conexión entre dos máquinas el tráfico es directo entre ellas salvo en determinados casos. Si tampoco quieres usar sus servidores de coordinación puedes usar #HeadScale como solución autolajada que hace lo mismo totalmente #Free y #OpenSource y que la propia gente de #TailScale apoya

  2. @rafacampoamor Tu tráfico no pasa por sus servidores casi nunca. Sus servidores son coordinadores de conexiones de tus máquinas. Una vez se establece la conexión entre dos máquinas el tráfico es directo entre ellas salvo en determinados casos. Si tampoco quieres usar sus servidores de coordinación puedes usar #HeadScale como solución autolajada que hace lo mismo totalmente #Free y #OpenSource y que la propia gente de #TailScale apoya

  3. has anybody running Headscale ever seen their server get compromised and used to redirect certain DNS lookups thru the Tailscale resolver on clients to a different IP?

    I have no idea if that's what I'm seeing with my setup right now, but my #Tailscale resolver is returning an entirely different IP for a certain DNS lookup than the correct one (which is returned by e.g. Google and Quad9). #Headscale #IOC #infosec

  4. has anybody running Headscale ever seen their server get compromised and used to redirect certain DNS lookups thru the Tailscale resolver on clients to a different IP?

    I have no idea if that's what I'm seeing with my setup right now, but my #Tailscale resolver is returning an entirely different IP for a certain DNS lookup than the correct one (which is returned by e.g. Google and Quad9). #Headscale #IOC #infosec

  5. Headscale: your own tailscale

    Headscale — your own tailscale. Self-hosted control server. Mesh VPN for every device. No account, no device limits. Free and open-source. Install guide, alternatives and screenshots in the directory.

    selfhost.directory/project/hea

    #Headscale #Wireguard #Tailscale #Datahoarder #Tech #Docker #Raspberrypi #Nas #Proxmox

  6. Headscale: your own tailscale

    Headscale — your own tailscale. Self-hosted control server. Mesh VPN for every device. No account, no device limits. Free and open-source. Install guide, alternatives and screenshots in the directory.

    selfhost.directory/project/hea

    #Headscale #Wireguard #Tailscale #Datahoarder #Tech #Docker #Raspberrypi #Nas #Proxmox

  7. Thanks to some fuckwit fascist named Daniel Berntsson @mullvadnet I'm having to spend my nice little four day weekend researching an alternative #VPN provider.

    Anyone know a provider not run by rightwing shitbrains? Particularly needing something I can use as a #headscale / #tailscale exit node, as this is my core use case with #mullvad

    I found this, but #NymVPN hasn't been on my radar. Up till now VPNs were a set it and forget it thing.
    github.com/cofob/tailscale-nym

  8. Thanks to some fuckwit fascist named Daniel Berntsson @mullvadnet I'm having to spend my nice little four day weekend researching an alternative #VPN provider.

    Anyone know a provider not run by rightwing shitbrains? Particularly needing something I can use as a #headscale / #tailscale exit node, as this is my core use case with #mullvad

    I found this, but #NymVPN hasn't been on my radar. Up till now VPNs were a set it and forget it thing.
    github.com/cofob/tailscale-nym

  9. I have since extracted my deployment script into a reusable Forgejo Action, as I needed to re-use it in other pojects.

    Should you also wish to cost a static site on a tailscale node and deploy via a Forgejo workflow, you can check it out:

    code.thms.uk/michael/tailscale

    #Forgejo #Headscale #Tailscale #SelfHost #selfhosting #selfhosted #CI_CD

  10. I have since extracted my deployment script into a reusable Forgejo Action, as I needed to re-use it in other pojects.

    Should you also wish to cost a static site on a tailscale node and deploy via a Forgejo workflow, you can check it out:

    code.thms.uk/michael/tailscale

    #Forgejo #Headscale #Tailscale #SelfHost #selfhosting #selfhosted #CI_CD

  11. Hit a little snag when I wanted to route my mastodon traffic from my new dockerised instance through a Tailscale/Headscale exit node, as tailscale dropped all traffic to my containers.

    Wrote a quick note on how I fixed this:

    blog.thms.uk/2026/06/docker-ta

    #mastoAdmin #docker #tailscale #headscale

  12. Hit a little snag when I wanted to route my mastodon traffic from my new dockerised instance through a Tailscale/Headscale exit node, as tailscale dropped all traffic to my containers.

    Wrote a quick note on how I fixed this:

    blog.thms.uk/2026/06/docker-ta

    #mastoAdmin #docker #tailscale #headscale

  13. Help me out please Fediverse,

    I’m interested in running my own headscale server for the fun of it. I’d probably have 3 users (me, OH, kid), and about a dozen devices (laptops, phones, servers).

    What I don’t understand is how authentication works there. The docs mention Open ID. Do I have to set up an Open ID server and provision accounts for everyone? Can people ‘just use passkeys’? I don’t fully understand that part.

    #headscale #SelfHosting #AskFedi

  14. Help me out please Fediverse,

    I’m interested in running my own headscale server for the fun of it. I’d probably have 3 users (me, OH, kid), and about a dozen devices (laptops, phones, servers).

    What I don’t understand is how authentication works there. The docs mention Open ID. Do I have to set up an Open ID server and provision accounts for everyone? Can people ‘just use passkeys’? I don’t fully understand that part.

    #headscale #SelfHosting #AskFedi

  15. @mkwadee I could never manage to get any external access stuff working with reverse proxies and certificates and authentication (this was pre LLM-days), so I just installed Tailscale. Wow was that easy!

    My homelab services are for me and my family anyway, so I just put Tailscale on their devices and added them to the same Tailnet. Done. I can even host my own control server with Headscale and not touch any Tailscale servers.

  16. @mkwadee I could never manage to get any external access stuff working with reverse proxies and certificates and authentication (this was pre LLM-days), so I just installed Tailscale. Wow was that easy!

    My homelab services are for me and my family anyway, so I just put Tailscale on their devices and added them to the same Tailnet. Done. I can even host my own control server with Headscale and not touch any Tailscale servers.

    #Linux #HomeLab #SelfHost #Tailscale #Headscale

  17. Quite pleased with this.
    1 year uptime of 99.9% for website hosted on our internal LAN served to internet using #Headscale

    #selfhosting

  18. Quite pleased with this.
    1 year uptime of 99.9% for website hosted on our internal LAN served to internet using #Headscale

    #selfhosting

  19. Good morning!

    I have been happily using headscale (self hosted implementation tailscale's management service) for some time. An update was over-due but I was struggling to get things working in a satisfactory way. And I didn't like that my set-up wasn't portable (a lot of manual set-up is required).

    This led me to plan out what my ideal headscale project would look like:
    * Everything runs in docker
    * Containers for headscale, headscale-ui, and caddy
    * Re-implement user names in the MagicDNS (eg "mobile" is a user, resulting in "iain-t480s.mobile.example.com") that was removed in 0.23.0+ versions of headscale
    * Backup and restore procedures
    * Single file configuration

    Over a few cocktails while on holiday, I instructed OpenCode, with the Big Pickle model, to develop this project.

    The result is github.com/bigcalm/headscale-c

    A simple project I can clone to any public facing server and hit the ground running with minimal config set-up.

    A few notes:
    * I have 20 years experience of linux server management, programming, devops, project management, and quality assurance.
    * While OpenCode created all of the file contents, I provided the requirements, code review, testing, feedback, and more testing.
    * This has been an iterative process to create a fully working project that I am happy with. Not a single prompt and ship whatever gets created.
    * I am not a tech bro.
    * Agentic development is a useful tool. But only a tool that I have been able to use due to my prior knowledge.

    The project isn't perfect, but it suits my needs. Maybe it can help somebody else too :)

    #headscale #tailscale #selfhosting #opencode #bigpickle

  20. Good morning!

    I have been happily using headscale (self hosted implementation tailscale's management service) for some time. An update was over-due but I was struggling to get things working in a satisfactory way. And I didn't like that my set-up wasn't portable (a lot of manual set-up is required).

    This led me to plan out what my ideal headscale project would look like:
    * Everything runs in docker
    * Containers for headscale, headscale-ui, and caddy
    * Re-implement user names in the MagicDNS (eg "mobile" is a user, resulting in "iain-t480s.mobile.example.com") that was removed in 0.23.0+ versions of headscale
    * Backup and restore procedures
    * Single file configuration

    Over a few cocktails while on holiday, I instructed OpenCode, with the Big Pickle model, to develop this project.

    The result is github.com/bigcalm/headscale-c

    A simple project I can clone to any public facing server and hit the ground running with minimal config set-up.

    A few notes:
    * I have 20 years experience of linux server management, programming, devops, project management, and quality assurance.
    * While OpenCode created all of the file contents, I provided the requirements, code review, testing, feedback, and more testing.
    * This has been an iterative process to create a fully working project that I am happy with. Not a single prompt and ship whatever gets created.
    * I am not a tech bro.
    * Agentic development is a useful tool. But only a tool that I have been able to use due to my prior knowledge.

    The project isn't perfect, but it suits my needs. Maybe it can help somebody else too :)

    #headscale #tailscale #selfhosting #opencode #bigpickle

  21. #netbird ist ja komplett out of control!

    Ich wollte per #headscale meine VPS mit meiner homeprod verdrahten.
    Netbird ist alles was tailscale per SaaS sein kann, aber #selfhosted.
    Das setup ist irre. FW auf auf den relevanten Ports, DNS aufsetzen, script anwerfen, Fertig.

    Wer wie ich keine Lust auf externe Infrastruktur ausserhalb der eigenen Kontrolle hat und site2site braucht, ich glaube besser gehts nich.

    #diy #homelab #overlaynetwork #wireguard

    danke @staticvoid für den #nerdsnipe

  22. #netbird ist ja komplett out of control!

    Ich wollte per #headscale meine VPS mit meiner homeprod verdrahten.
    Netbird ist alles was tailscale per SaaS sein kann, aber #selfhosted.
    Das setup ist irre. FW auf auf den relevanten Ports, DNS aufsetzen, script anwerfen, Fertig.

    Wer wie ich keine Lust auf externe Infrastruktur ausserhalb der eigenen Kontrolle hat und site2site braucht, ich glaube besser gehts nich.

    #diy #homelab #overlaynetwork #wireguard

    danke @staticvoid für den #nerdsnipe

  23. Wenn man einmal anfängt ...
    Nach Feierabend "bloss" mal eben #crowdsec auf der outpost vps aufsetzen. Ok, geht. Oh, da sieht man ja die ganzen ssh-bruteforces ... Prometheus draussen im Web aufmachen keine so gute Idee, aber will adminp0rn, gibt so schöne Dashboards.

    Zwischendrin @oli nmap Terror machen geschickt, um die alerts zu testen 🤖

    Bis halb 12 #headscale aufgesetzt mit ein paar Stolperern und jetzt ist besser mal Schluss für heute.

    Up next: #tailscale IM docker

  24. Wenn man einmal anfängt ...
    Nach Feierabend "bloss" mal eben #crowdsec auf der outpost vps aufsetzen. Ok, geht. Oh, da sieht man ja die ganzen ssh-bruteforces ... Prometheus draussen im Web aufmachen keine so gute Idee, aber will adminp0rn, gibt so schöne Dashboards.

    Zwischendrin @oli nmap Terror machen geschickt, um die alerts zu testen 🤖

    Bis halb 12 #headscale aufgesetzt mit ein paar Stolperern und jetzt ist besser mal Schluss für heute.

    Up next: #tailscale IM docker

  25. Be me.
    Make a typo `pcke` instead of `pkce` in your NixOS config for headscale.
    Config does not get spellchecked, just converted to yml.
    Kandidm does not reciece pkce challenge.
    Fight for hours over 4 weeks to finally decide to open the generated yml.

    GG.

    #NixOS #HeadScale #KanIDM

  26. Be me.
    Make a typo `pcke` instead of `pkce` in your NixOS config for headscale.
    Config does not get spellchecked, just converted to yml.
    Kandidm does not reciece pkce challenge.
    Fight for hours over 4 weeks to finally decide to open the generated yml.

    GG.

    #NixOS #HeadScale #KanIDM

  27. #Tailscale was really decent, but I think #Headscale needs more time to mature

  28. I tried out #tailscale today, and am making a rocky start to hosting my own #headscale server. I normally dislike #Discord, but made an exception to enter their chat forum - where I eventually got helped with my config troubles. I have a working config now, so I'm grateful for the help I got.
    #InfoSec #OpenSource

  29. I tried out #tailscale today, and am making a rocky start to hosting my own #headscale server. I normally dislike #Discord, but made an exception to enter their chat forum - where I eventually got helped with my config troubles. I have a working config now, so I'm grateful for the help I got.
    #InfoSec #OpenSource

  30. Today I applied to do a 30-minute presentation for Bsides 2026. I offered to do a presentation and demo of Wireguard, where Wireguard is used in a TailScale/Headscale sort of way, but somewhat simpler. My solution is much more "pure-play" Wireguard - I wrote no software beyond using the conveniences provided by PiVPN. My "secret sauce" lies in being able to understand, and hand-edit wireguard conf files beyond a simplistic use. My solution has no "mesh" - it just uses a subnet where each node on the subnet is a working Wireguard client. My solution has no AI. I consider this to be a feature, not a bug. My solution uses conventional DNS, there is no "Magic DNS". My solution has no 2FA. It just uses Wireguard's default encryption methods, as are part of the mainline Linux kernel. The advantage to this is that all clients and server components are Open Source, whereas the Tailscale clients (Windows and macOS/iOS) are closed source.
    #Wireguard #Tailscale #Headscale #infosec #VPN #OpenSource #linux @bsidesyxe

  31. Today I applied to do a 30-minute presentation for Bsides 2026. I offered to do a presentation and demo of Wireguard, where Wireguard is used in a TailScale/Headscale sort of way, but somewhat simpler. My solution is much more "pure-play" Wireguard - I wrote no software beyond using the conveniences provided by PiVPN. My "secret sauce" lies in being able to understand, and hand-edit wireguard conf files beyond a simplistic use. My solution has no "mesh" - it just uses a subnet where each node on the subnet is a working Wireguard client. My solution has no AI. I consider this to be a feature, not a bug. My solution uses conventional DNS, there is no "Magic DNS". My solution has no 2FA. It just uses Wireguard's default encryption methods, as are part of the mainline Linux kernel. The advantage to this is that all clients and server components are Open Source, whereas the Tailscale clients (Windows and macOS/iOS) are closed source.
    #Wireguard #Tailscale #Headscale #infosec #VPN #OpenSource #linux @bsidesyxe

  32. En el siguiente #tutorial les muestro como crear una #vpn #mesh y utilizarla con los equipos que desees sin restricciones gracias a #headscale y #tailscale sobre tu propio servidor o #selfhosted. Algo que me pareció muy útil para estos tiempos...

    Miralo en : luiszambrana.ar/como-instalar-

    Si te gusto compartilo con los tuyos!!!

  33. En el siguiente #tutorial les muestro como crear una #vpn #mesh y utilizarla con los equipos que desees sin restricciones gracias a #headscale y #tailscale sobre tu propio servidor o #selfhosted. Algo que me pareció muy útil para estos tiempos...

    Miralo en : luiszambrana.ar/como-instalar-

    Si te gusto compartilo con los tuyos!!!

  34. Headscale's documentation of ACLs is funny:
    Simple example:
    - block all
    - allow all
    Complex example:
    - a network of half a dozen servers, a handful of users, and a bunch of ACLs
    Can I get some in-between examples please?
    headscale.net/stable/ref/acls/
    #headscale

  35. I still haven't understood the benefit of smtg like #Headscale (#Tailscale) vs plain old #WireGuard, and now apparently there's a new kid in town called #NetBird lol. I watched a tutorial on self-hosting Headscale (i.e. to reduce dependency/reliance on Tailscale), but when they demonstrated its use case... setting it up looks more complicated than what you would've done on WG, and what u achieve seems exactly the same. I'm sure I'm missing something tho.

  36. I’ve been running #Tailscale for a while-internal server and clients up, and it works brilliantly. Host as many services as you want, all encrypted and without exposing them to the internet. DNS and endpoints just work, making it easy to share with family or friends. Access rules give you full control.
    For those more comfortable with the bash and self-hosting, #Headscale is the open-source, self-hosted option with the same functionality.
    #SelfHosting #Networking #Privacy
    tailscale.com/

  37. Anyone with networking experience in the field? Would love to chat. Looking to self host something, give back to the community, cold storage server, remote runner, 7 nodes in different locations.

    #networking #security #cyberSecurity #fediverse #selfHosting #server #kubernetes #headscale #Tailscale #wireguard #peertube #hosting #network #fedi #engineering

  38. While I was away, I finally got NetBird back up and running, and damn it was hard but it’s worth the effort

    Setting it up with PocketID for authentication was probably the most headachy thing I could’ve pulled off, but now that it’s done and stable, I ain’t touching it

    If you are looking for a stable and fully self hosted Tailscale replacement, I highly recommend !

    #tailscale #headscale #netbird #vpn #wireguard #selfhosted #selfhosting #homelab #pocketid #kubernetes #k3s

  39. ✅ HeadScale configured to use OIDC
    ❌HeadPlane configured to use OIDC¹

    ¹ i need to set up HeadPlane anyway and thus, i need to set up my server to use flakes

    #HeadScale #HeadPlane #TailScale #NixOS #OIDC