    figassis
    I love Tailscale, but this post gives me the creeps. The internet succeeded because it was built on standards and was completely free. With Tailscale, I get wireguard is open source and we have things like Headscale. But the whole everyone gets an IP, doesn’t it depend on Tailscale owning a massive ip address space? We can all wait until full ipv6 rollout, or we can depend on centralized ipv4, and servers and proprietary stuff. Maybe a bit hypocritical?
    jgalt212
    If you had to move off of tailscale, what would you move to?
    OJFord
    Zerotier is I think the obvious answer? I haven't used it though; it's more proprietary, not less.
    Fnoord
    I use WireGuard. As you add more keypairs, it becomes a bit of a nightmare to maintain, though Vim with syntax highlighting helps a lot.

    Because of this, I'll be switching to Headscale + Tailscale.

    ssl-3
    AFAIK, Zerotier is about equally proprietary, more-free (as in beer), and has been doing the node-to-node mesh thing instead of spoke-and-hub longer than Tailscale has been in existence.

    And if I remember correctly, ZT was initially created to provide something like this "New Internet" concept that Tailscale has apparently recently discovered, except they called it "Earth" and abandoned it in 2023.

    (Some things don't change, I guess.)

    yjftsjthsd-h
    I think nebula is the obvious FOSS competitor? With the unfortunate exception of the Android client being closed source.
    sph
    I use Nebula because its iOS client does not drain my battery. Tailscale has had that known bug for years and they never managed to fix it, which is a major deal breaker.
    viraptor
    Kinda? It works great in practice. You can run your own controllers if you want which completely disconnects you from the proprietary service. But the code is BSL.
    OJFord
    I didn't mean to suggest it doesn't work well, as I said I've not used it.

    It's still proprietary if you self-host it, I was thinking in particular that tailscale uses Wireguard and Zerotier uses something custom, i.e. proprietary. Note that the context was:

    > The internet succeeded because it was built on standards and was completely free. With Tailscale, I get wireguard is open source and we have things like Headscale. But [...]

    to which the commenter I replied to asked of alternatives. So I wasn't saying tailscale great and open and standards compliant, and Zerotier not; I was saying it's the obvious competitor but if that's your problem with tailscale then it's if anything worse in that regard.

    p_l
    Tailscale does p2p, not hub-spoke, with additional DERP system which combines various NAT bypasses with worst case hair pinning over HTTPS - you can host all components yourself.
    dandanua
    I think Nebula is much much closer to the "new internet". Lighthouse nodes can serve as untrusted brokers that help to connect everyone securely. No need in a central authority with God-like importance, as the Tailscale CEO obviously wants to have.
    jacooper
    They have released a slew of updates recently to fix this, and they did a complete rewrite of the Android app
    mrbluecoat
    NetBird is a promising option. OpenZiti is another. ZeroTier hasn't evolved much, IMHO. Would also love to see someone breathe new life into
    ssl-3
    You're absolutely correct.

    I didn't intend to leave to implication the fact that Tailscale is node-to-node, or that it is is not hub-and-spoke.

    (I even had this up in a browser tab when I wrote that previous comment:

    chgs
    It depends on your use case. I use wg back to two geographically independent locations, keys are managed via our ipam.

    I don’t need EW traffic over the VPN, very NS based. Something like Headscale or another SDWan solution (automatically establishing vpn routes) would make sense if I needed to transport a lot of traffic E-W, that’s just not a requirement

    PLG88
    OpenZiti would be another - I work on the project. 1 issue with Nebula is the provisioning new clients with identities. Its not completely open sourced by the Nebula company.