Corporate VPN startup Tailscale secures $230 million CAD Series C on back of “surprising” growth

Pennarun confirmed the company had been approached by potential acquirers, but told BetaKit that the company intends to grow as a private company and work towards an initial public offering (IPO).

“Tailscale intends to remain independent and we are on a likely IPO track, although any IPO is several years out,” Pennarun said. “Meanwhile, we have an extremely efficient business model, rapid revenue acceleration, and a long runway that allows us to become profitable when needed, which means we can weather all kinds of economic storms.”

Keep that in mind as you ponder whether and when to switch to self-hosting Headscale.

  • Mordikan@kbin.earth
    link
    fedilink
    arrow-up
    0
    ·
    7 months ago

    Headscale is great if you like networking fun, but that aside I’m not understanding why VC funding is such a black mark to the poster. Tailscale doesn’t generate meaningful revenue streams as its early-stage, so it has to secure funding to continue operations until they achieve high enough revenue to go public. That’s pretty standard in a business life-cycle, though. It seems like the main complaint is that Tailscale is a business.

    • tequinhu@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Yup, I don’t know if that is OP’s intention, but I would agree myself with the complaint that “Tailscale is a business”

      The way I see it, if it’s a business it must generate revenue (either now or down the road), and that is enough to have me worried. I do have a Tailscale registration, and the way they approach email communication is already a yellow flag to me (too many ad emails)

      • Mordikan@kbin.earth
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        That’s not really a justifiable reason, though. The Linux Foundation provides grants and scholarships to the open source community, but they do that through private equity business. So transitively, many open source projects are funded by businesses looking to capitalize on that innovation. Do you consider that when pulling from a git repository? No, that’s overbearing. Additionally Headscale is in part maintained by a Tailscale employee. That would surely create a conflict of interest given Tailscale is solely interested in generating revenue.

        • tequinhu@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          7 months ago

          I get your point, though Tailscale specifically crosses a line for me in this sense:

          • Using code created/maintained by businesses: ok
          • Relying in infrastructure maintained by businesses: not ok

          I am not that big of an enthusiast, but the way I see it, if a company goes rogue and you’re using their open source code, it’s just a matter of forking it (I’m thinking about Emby/Jellyfin as an example) If you rely on their infrastructure (such as Tailscale servers) then you are at the mercy of the companies

          To that end: I’d say that OP is prettt on point by suggesting Headscale, you’re still “using Tailscale” in a sense, but without chaining yourself to the business

          • Avid Amoeba@lemmy.caOP
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            I am not that big of an enthusiast, but the way I see it, if a company goes rogue and you’re using their open source code, it’s just a matter of forking it (I’m thinking about Emby/Jellyfin as an example) If you rely on their infrastructure (such as Tailscale servers) then you are at the mercy of the companies

            🏅

        • Avid Amoeba@lemmy.caOP
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          7 months ago

          That’s not really a justifiable reason, though.

          To you it isn’t, but to some of us it is. For me the standard business cycle is not acceptable because I almost inevitably end up under the bus.

          The Linux Foundation isn’t a comparable example for me since it’s a non-profit. As a result it isn’t subject to the same market pressures for-profit businesses do, let alone VC-funded ones.

          At this point, with everything I know and have experienced about the economy, politics and the world, I am trying to avoid depending on for-profit businesses as much as I can. I know how businesses operate, I know why they operate the way they do, I know what dynamics push them in the directions they go and I’m tired of being run over by the bus. If I ever form a business myself it would either be a non-profit, or a worker co-op, or both, as this will signal everyone who knows what I know what the direction of this business would be about.

          • Mordikan@kbin.earth
            link
            fedilink
            arrow-up
            0
            ·
            7 months ago

            Firstly, I’m not trying to start a flame war with commenters, I genuinely just disagree on something and some people are getting a little hot under the collar by it. The Linux Foundation comment I made because ultimately VC touches more than people think. Even its something that isn’t directly tied to VC, that money filters through groups like LF which is a non-profit and most would argue a quite legitimate organization. The point is there really is no separation or clear line of demarcation on what is “good” funding and what is “bad” funding.

            • Avid Amoeba@lemmy.caOP
              link
              fedilink
              English
              arrow-up
              0
              ·
              edit-2
              7 months ago

              The point is there really is no separation or clear line of demarcation on what is “good” funding and what is “bad” funding.

              I understand and I disagree. A demarcation emerges from the goal of the funding and its effects. For me, one example of bad funding is funding that drives user acquisition at unsustainable prices by a firm that is also significantly controlled by the funding source. This is predominantly what VC-funding goes to. VC-funding that goes to a non-profit that the VC has no control over, where the VC can’t and does not demand financial return from, is not bad funding in my books. Corporate funding doing the same thing is also not bad funding. Government funding often has the least strings attached as it does not demand direct return, and this also is not bad funding. To top that off citizens can exercise control over government funding via the democratic process, unlike corporate or VC funding, where the vast majority have zero control, and the businesses funded have no accountability to.

              • Mordikan@kbin.earth
                link
                fedilink
                arrow-up
                0
                ·
                7 months ago

                Historically, Accel has never pushed acquisition. On the contrary, they do the opposite. Its why they VC fund over 300 companies, but you’ve never heard of them. That’s not to say they couldn’t, but they haven’t ever acted in that manner previously so logically it would be safe to assume that trend continues with Tailscale. I think that’s important here: its not about ability its about intent. If as a organization you give funding to another organization (even non-profits) you exercise at least some control over them as they are dependent on that money to function. This is actually a point other commenters have made in regards to Headscale. Headscale is maintained by a Tailscale employee. As they fund him personally, they can exercise some control over him as he depends on that money/employment. Again, even their comments circle back to ability vs intent. Tailscale could influence their employee, but would they? That’s where a lot of the VC argument goes. Its just speculation as what a group could do, not what they would do.

                • Archer@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  7 months ago

                  “The trend” is making money no matter what. That means they’re gonna screw you over eventually, the countdown has already begun, and it’s just a matter of time

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        yellow flag to me (too many ad emails)

        Weird. I’m not saying you’re lying, but besides the registration email, and onboarding welcome email, I can’t think of any others I’ve received from Tailscale. In fact, I just did a search of my email client, and those were the only ones I’ve received.

        • tequinhu@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          I do believe my experience in this regard is not representative of everyone, I probably failed to untick some checkbox (regarding communications) and the “too many ad emails” are a handful (in 3 months), which to me is a handful too much (having to untick a box should not be necessary)

    • Ulrich@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      That’s pretty standard in a business life-cycle, though

      I don’t know where people ever got the idea that normal = acceptable. I hear this used to justify all sorts of awful crap. It was only ever normalized because users were apathetic.

      And what about the Linux Foundation? They are funded through private equity. Should you consider switching away because of that?

      Does The Linux Foundation have complete control over Linux?

      • Mordikan@kbin.earth
        link
        fedilink
        arrow-up
        0
        ·
        7 months ago

        So, companies should not be allowed to invest in other companies? Who is allowed to invest in companies then? Only private individuals? But those individuals are apathetic, so they have to be made to? Or if they don’t want to, then since other companies aren’t allowed, wealthy private individuals would need to? Its not normal because its acceptable, its normal because the alternative is fantastical and unrealistic.

        To the other point, does Tailscale have complete control over Wireguard? They don’t control the technology behind that. They do for their control server tech and to some extent Headscale, but that’s not what its built on anymore then what’s built on Linux.

        • Ulrich@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          companies should not be allowed to invest in other companies?

          That’s not what I’m saying. I’m just saying you need to be wary of companies that do because the inevitable end of that train is enshittification. Every. Single. Time.

          does Tailscale have complete control over Wireguard?

          Who’s talking about WireGuard? We were talking about Tailscale.

          • Mordikan@kbin.earth
            link
            fedilink
            arrow-up
            0
            ·
            7 months ago

            Tailscale builds on top of the Wireguard protocol, LF builds on top of (through grants/scholarships) the Linux OS. You can’t argue that it doesn’t matter that LF doesn’t have control over the underlying technology, but then argue that it does matter in Tailscale’s cause.

            • Ulrich@feddit.org
              link
              fedilink
              English
              arrow-up
              0
              ·
              edit-2
              7 months ago

              It doesn’t matter in either case. Neither of them have control over the underlying technology.

              • Mordikan@kbin.earth
                link
                fedilink
                arrow-up
                0
                ·
                7 months ago

                Does The Linux Foundation have complete control over Linux?

                You’re the one who said it, though.

                • Ulrich@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  7 months ago

                  Yes I did say that. I don’t understand what you’re trying to communicate. TLF does not control Linux. Tailscale does control Tailscale. There’s nothing wrong with using Linux and there’s nothing wrong with using WireGuard. There may be something wrong with using Tailscale. I don’t know how to be more clear about this.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      The problem, though, is that VC-funded projects bite off way more than they can chew from the start and have to enshittify to keep shareholders happy at that level.

      Growth for the sake of growth is a fundamentally broken concept. Tailscale provides a free service that many use. They already offer a paid support tier for companies, like other certain FOSS projects do, so why not call it good there? Grow based on actual customer needs, instead of shareholder bullshit “needs” (line must go up 🙄).

    • Revan343@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      It seems like the main complaint is that Tailscale is a business. And what about the Linux Foundation?

      The Linux Foundation is not a business.

    • Feyd@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Not that it is a business but is a specific kind of business. VC funded startups eyeing an IPO more often than not start doing things users are not happy with. Maybe tailscale won’t, but might as well be aware what kind of company they are acknowledge there is a decent chance of rugpulls

  • Goretantath@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    Didnt even work for me, i use mullvad so if i wanted to use tailscale on my android to connect to my desktop, it wants me to disable mullvad unlike on my desktop…

  • HelloRoot@lemy.lol
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    a long runway that allows us to become profitable when needed

    Switch to self-hosting headscale when they enshittify in an attempt to become profitable, duh

    • three@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Been meaning to do this. Tailscale was just there and easy to implement when I set my stuff up. Is it relatively simple to transition?

    • kratoz29@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      I mainly use Tailscale (and Zerotier) to access my CGNATED LAN, headscale will require me to pay a subscription for a VPS wouldn’t it?

      I really envy the guys who say only use them because they’re lazy to open ports or want a more secure approach, I use them because I NEED them lol.

      If (when?) Tailscale enshitify I’ll stick with ZT a bit until it goes the same way lol, I started using it 1st, I don’t know if ZT came before Tailscale though.

      • not_amm@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Same. I mean, I was already looking to rent a VPS, but at least there’s some time so I can save money until things get weird.

        • kratoz29@lemm.ee
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          Yeah, don’t get me wrong, I can see value of getting a VPS, especially if you are gonna be using it for some other projects, I have had a DO instance in the past and I thinkered with WG back then BTW, but if it is only for remote accessing your home LAN, I don’t feel like paying for it tbh, especially when some users get it for free (public IPv4) and it feels even dumber for me since I have a fully working IPv6 setup!

          BTW my ISP is funny, no firewall at all with it, I almost fainted when I noticed everyone could access my self hosted services with the IPv6 address and I did nothing regarding ports or whatsoever… They were fully accessible once I fired up the projects! I think I read an article about this subject… But I can’t recall when or where… I had to manually set up a firewall, which tbh, you always should do and it is especially easy to do in a Synology NAS.

          Anyway, back to the mesh VPN part, if they enshitify so be it, but in the meantime we still can benefit from it.

        • Vanilla_PuddinFudge@infosec.pub
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          7 months ago

          Same, my Hetzner proxy running NPM, with pivpn and pihole is doing all it needs to do for $3 and some change.

          My only open ports on anything I own are 80, 443 and the wg port I changed on that system. Love it.

    • Showroom7561@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Bookmarking “headscale”!

      I only recently started using Tailscale because it makes connecting to my local network through a Windows VM running in Boxes on Linux a hell of a lot easier than figuring out how to set up a networked bridge.

      This sounds like a great alternative, and it looks like it can even work on a Synology NAS.

  • anachrohack@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    What is even the point of tailscale? What can it do that other VPN solutions don’t? I feel like this is a problem that was solved like 20 years ago and still we’re coming up with novel solutions for some reason. At my company they want to start using tailscale and I don’t see why we don’t just set up wireguard on a node in our k8s cluster instead

    • witx@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Because it offers much more than just VPN even though that’s what most users use it for. Read their documentation and you’ll see

    • lepinkainen@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Because I can have 3 phones, 2 tablets, 3 computers and 4 server on the same Tailnet in 15 minutes when starting from scratch

      • anachrohack@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        I guess that’s neat but I don’t think I’ve ever needed more than one connection to a corpo VPN at a time

        • thejml@lemm.ee
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          Tailscale/headscale/wire guard is different from a normal vpn setup.

          VPN: you tunnel into a remote network and all your connections flow through as if you’re on that remote network.

          Tailscale: your devices each run the daemon and basically create a separate, encrypted, dedicated overlay network between them no matter where they are or what network they are on. You can make an exit node where network traffic can exit the overlay network to the local network for a specific cidr, but without that, you’re only devices on the network are the devices connected to the overlay. I can setup a set of severs to be on the Tailscale overlay and only on that network, and it will only serve data with the devices also on the overlay network, and they can be distributed anywhere without any crazy router configuration or port forwarding or NAT or whatever.

    • NuXCOM_90Percent@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      If you are capable of setting up your own personal VPN, you don’t need Tailscale. You still may want to use it though, depending on how much of a novelty Network Fun is for you in your spare time.

      For me, the main advantage to Tailscale et al is that it is on a per device basis. So I can access my SMB shares or Frigate setup remotely while still keeping the rest of my internal network isolated( to the degree I trust the software and network setup). You CAN accomplish that with some fancy firewall rules and vlanning but… yeah.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Tailscale never sat right with me. The convenience was nice, but - like other VC-funded projects - it followed that ever-familiar pattern of an “easy” service popping up out of nowhere and gaining massive popularity seemingly overnight. 🚩🚩🚩

    I can’t say I’m surprised by any of this.

    • potustheplant@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Maybe this is a pet peeve but it’s a vpn tool that forces you to log in with an “identity provider”. Yeah, no thanks.

      • iggy@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        That’s a basic requirement for almost any company. If you’re into hard coding credentials just use wireguard directly.

    • fuckwit_mcbumcrumble@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      Would you rather a difficult and hard to use program?

      Easy to use means people will want to adopt it, and that’s what VC companies want. Nobody wants to pay millions of dollars to make a program that nobody wants to use.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        7 months ago

        My problem isn’t directly with the program - my problem lies with VC funding in general. Because they will come back for their money, and the project will inevitably enshittify and shove out enthusiasts in the never-ending search for infinite money.

        The solution is getting rid of VC bullshit entirely. But we all know that will never happen.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    I’m not that worried as there are alternatives like Netbird. The underlying tech really isn’t hard to replicate since Wireguard is pretty standard.

    I think it would be cool if Tailscale made it into the enterprise arena.

  • cooopsspace@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    7 months ago

    Friendly reminder that Tailscale is VC-funded and driving towards IPO

    You know what’s to come.

    The answer to the question is immediately. Or switch to OpenZiti or Pangolin even.

    • LandedGentry@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      It’s one of the key reasons why everyone here hates plex too so I don’t get why you’re acting like this isn’t a valid concern

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        …and what are current Plex users, that don’t like the direction Plex has taken, doing ? Riding the next horse. When Tailscale gets unbearable with their business practices, there are a lot of other options. Tailscale is just easy and it flippin’ works.

        • LandedGentry@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          What next horse? There’s plex and there’s fully self hosting with Jellyfin or similar. The gulf is very wide between plex and that.

          • irmadlad@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            7 months ago

            So, I don’t run the arr stack, or any of it’'s components. In fact, I’ve never even test run Plex. However, I hear that Emby is a better replacement coupled with Symfonium to take the place of PlexAmp. That seems to be the ‘next horse’ everyone is switching to, even tho Emby does seem to have some unresolved issues.

            I just find the constant grind against profitability and capitalism to be a bit worn. I guess you could say I am fully ensconced in capitalism as I run three tax paying, for profit businesses. The issues I take with capitalism is unbridled, uncontrolled greed…when we place profit over principal. By all means tho, make yo’ paper son.

            These are my opinions. There are many like them, but these ones are mine.

            • Avid Amoeba@lemmy.caOP
              link
              fedilink
              English
              arrow-up
              0
              ·
              edit-2
              7 months ago

              If there’s no one who can replace you with someone else, if you don’t deliver profit growth that they expect, then there’s a chance for you to apply principle over profit because it’s up to you. Many if not most corporations however can and do replace corporate leadership that doesn’t deliver profit growth with one that does. In these circumstances, leadership can rarely put principle over profit without being replaced. Many if not most of us see the direct effects of this process on our lives, working to get ever more of our incomes and health. This process hasn’t stopped and hasn’t slowed down. The opposite. This is why you’re hearing us grinding against capitalism as we can see the system all around us grinding us down. This is why it’s likely you’ll keep hearing it and it’s likely gonna get louder. I might not have your product in my home. If I do, I might be very happy with it because you’re not trying to get as much money out of me as you can. However I am certain without checking that I have Unilever, Kraft, Nestle, PepsiCo, Google and so on, and I know they are. You probably do too and they’re probably skinning you just as much. This is what capitalism is for us and we will grind against it because our standard of living is falling and it’s not because of people like you. Small businesses have much more in common with us in this, than large corporations, or small corporations funded by large capital of different kinds. I’m an employee of a very large, well known American corporation that has strategically stopped making products that were objectively better for its customers but had lower margins, replacing them with much more expensive, higher margin ones. I’m not getting anything from the difference. Our major shareholders do.

  • Wahots@pawb.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    Are there better alternatives? I was planning on using tailscale until now. :P

    • 4k93n2@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      ive been eyeing up netbird but havnt got around to trying it yet. its fully open source at least, and theyre based in germany is anyone cares about that

      • Avid Amoeba@lemmy.caOP
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        Just looked at NetBird, it looks suspiciously similar to Tailscale in what it does except they also got an open-source control server. They have self-hosting doc right in their web site. Looks interesting. Can’t find much about the company other than it’s based in Berlin and it’s currently private - Wiretrustee UG.

        • nfh@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          7 months ago

          What’s the difference with their open-source control server, from headscale? That it’s officially published by the company?

    • candyman337@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      I use the built in wireguard VPN in my router. If you just need local network access elsewhere it’s usually really easy to setup if your router provides it. I would look into it!

    • milicent_bystandr@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      I use Nebula. It’s lightweight, well-engineered and fully under your control. But you do need a computer with a fixed IP and accessible port. (E.g. a cheap VPS)

      You can also use “managed nebula” if you want to enjoy the same risk of the control point of your network depending on a new business ;-)

    • MangoPenguin@piefed.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      7 months ago

      Wireguard if you’re just using it yourself. Many various ways to manage it, and it’s built in to most routers already.

      Otherwise Headscale with one of the webUIs would be the closest replacement.

    • exu@feditown.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      A bunch really, Headscale with Tailscale client, Nebula VPN, Netmaker, Zerotier.

    • Avid Amoeba@lemmy.caOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      For me personally, the next step is using Headscale - a FOSS replacement of the Tailscale control server. The Tailscale clients are already open source and can be used with Headscale.

      Someone else could give other suggestions.

      • Jo Miran@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        7 months ago

        I’ve been meaning to switch from Tailscale to Headscale but I have been to busy. Do you have any instructions, write-ups/walk-thrus you could recommend to set this up? I have three sites with 1GB internet I can use. One has a whole house UPS but dynamic IP, another has a static IP but no UPS, and the third is Google fiber with no UPS, but I can use the app to get the current IP anytime. I also own a number of domain names I could use.

        • Avid Amoeba@lemmy.caOP
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          7 months ago

          No writeups. I tried following the Headscale doc for a test last year. Set it up on the smallest DigitalOcean VM. Worked fine. Didn’t use a UI, had to add new clients via CLI on the server. When I set it up for real, I’d likely setup a UI as well and put it in a cloud outside of the US. It would work at home too but any other connection would die if my home internet dies or the power does. E.g. accessing one laptop from another, or accessing the off-site backup location.

  • Robust Mirror@aussie.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    So I asked chatgpt for alternatives and I liked the look of ZeroTier, does this sound right to people with more knowledge than me, and would people recommend it in general?


    Spoiler

    Perfect! Here’s everything you need — broken down into three stages, from quick setup to full self-hosted control.


    🧩 Part 1: Install and Connect ZeroTier

    ✅ Step 1: Create a ZeroTier account

    Go to https://my.zerotier.com/

    Sign up (only to create your private network — it’s free)

    Click “Create a Network”

    Give it a name

    Note the Network ID

    ✅ Step 2: Install ZeroTier on your devices

    🖥️ On your PC (Windows/Linux/Mac):

    Download from: https://www.zerotier.com/download

    Install and run

    Join your network with:

    zerotier-cli join <your-network-id>

    (or click in the tray app if using the GUI)

    📱 On your Android phone:

    Install the ZeroTier One app from Google Play

    Open the app, paste the network ID, tap Join

    ✅ Step 3: Authorise your devices

    Go back to my.zerotier.com

    Under your network, you’ll see your PC and phone listed

    Tick “Auth” to allow them on the network

    Note the IPs assigned (e.g. 10.147.17.34)


    🎶 Part 2: Access Jellyfin + Symphonium Over ZeroTier

    ✅ Step 1: On your PC (Jellyfin server):

    Open Jellyfin settings → Dashboard → Network

    Ensure “Allow remote connections” is enabled (This just means other IPs — not the internet — can connect)

    ✅ Step 2: On your phone (Symphonium):

    Open Symphonium

    Add a new Jellyfin library

    For the server address, enter:

    http://<zerotier-ip-of-your-PC>:8096

    e.g. http://10.147.17.34:8096/

    It should connect exactly as it does on home Wi-Fi!

    No public ports, no tailscale, no cost 🎉


    🛠️ Part 3: Optional – Self-Host Your Own ZeroTier Controller

    Only needed if you want to avoid using their cloud control plane. Not needed for basic private use.

    ✅ Requirements:

    A Linux machine (can be your PC or a VPS if you change your mind)

    Some CLI familiarity

    Quick Guide:

    1. Install Docker

    2. Run:

    docker run -d
    –name zerotier-controller
    -p 9993:9993/udp
    -v zerotier-one:/var/lib/zerotier-one
    zyclonite/zerotier-controller

    1. You’ll now control your own ZeroTier networks, not theirs.

    Docs: https://github.com/zyclonite/zerotier-controller

    🔐 Even if you stick with their hosted controller, your traffic is still end-to-end encrypted. Self-hosting just removes the cloud coordination step.


    ✅ TL;DR:

    Task Done

    ZeroTier installed and devices connected ✅ Jellyfin accessible via ZeroTier IP ✅ Public internet avoided ✅ Self-hosting ZeroTier controller (optional) Available when ready

    Let me know if you’d like help testing connection, optimising for battery/wake-on-LAN, or even integrating LAN fallback + ZeroTier for seamless home/away streaming.


    Then asking if I can use a pi as a controller for the optional step 3:


    Spoiler

    Yes — an old Raspberry Pi running Raspberry Pi OS is perfectly capable of hosting a ZeroTier controller! It’s low-power, quiet, and ideal for self-hosted network services.

    Here’s how to get it up and running.


    🛠️ Self-Hosting a ZeroTier Controller on Raspberry Pi (PiOS)

    ✅ Requirements:

    Raspberry Pi with PiOS Lite or Full (Debian-based)

    Internet access (Ethernet or Wi-Fi)

    Static IP on your LAN (recommended)

    Port UDP 9993 open on your LAN (only needed if other clients are connecting over LAN)


    🔧 Step-by-Step: Install Docker and the Controller

    1. Update and install Docker

    Open a terminal on your Pi or SSH in:

    sudo apt update && sudo apt upgrade -y curl -sSL https://get.docker.com/ | sh sudo usermod -aG docker $USER

    Log out and back in (or reboot) to activate Docker group access.


    1. Run the ZeroTier controller in Docker

    docker volume create zerotier-one

    docker run -d
    –name zerotier-controller
    –restart unless-stopped
    -p 9993:9993/udp
    -v zerotier-one:/var/lib/zerotier-one
    zyclonite/zerotier-controller

    This starts the controller and creates a persistent volume.


    1. Initialise the Controller

    After a few seconds, you’ll have config files generated inside the container volume. To extract your identity.secret and create/manage networks, you can either:

    Option A: Exec into the container

    docker exec -it zerotier-controller bash

    Then use the zerotier-cli inside the container:

    zerotier-cli status zerotier-cli listnetworks zerotier-cli createnetwork

    Option B: Install the CLI on your Pi (outside Docker)

    This gives you easier long-term control, but it’s optional. Let me know if you want help setting this up.


    1. Connect clients to your Pi’s controller

    On each device (PC, phone, etc.):

    Install ZeroTier as normal

    Instead of the default control plane, point the client to your Pi

    This requires updating the local.conf to override the default controller (ask if you’d like help with that — it’s a little involved but totally doable).


    🧪 Notes & Tips

    Your Pi can stay on your LAN. It doesn’t need a public IP if your devices are already on the same network or are able to relay.

    If you do want this to work outside your LAN, you’d need to:

    Port forward UDP 9993 (if your router allows it), or

    Run a small VPS relay or drop it entirely and let ZeroTier do relaying automatically (works 95% of the time)


    ✅ Summary

    Task Possible on Pi? Notes

    Host ZeroTier controller ✅ Lightweight and runs well Use with Jellyfin via ZeroTier ✅ No public exposure needed Use Docker ✅ Simplifies setup Avoid external services ✅ No Tailscale, no cloud

    Let me know if you’d like:

    Help setting up the network manually on the Pi

    Step-by-step for configuring your clients to talk to your own controller

    Instructions for adding DNS, wake-on-LAN, or file access over ZeroTier too

    Your Pi just became your private VPN brain 🧠💻

  • milicent_bystandr@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    7 months ago

    Tailscale is great. The principle concern to me is that your super easy mesh network depends on Tailscale so if they want it they have control, and if they change their pricing or options you depend on them, and though they can’t see the data you send they can see the topology of your network and where all your computers/devices are.

    I use Nebula, which is more work to set up and doesn’t have some of the features, not But if you slap the ‘lighthouse’ (administrating node) on a cheap VPS it works great. And it has some advantages. But Nebula also troubles me: though it’s fully open source and fully in your control, the documentation isn’t great. Instead, you can now get “managed nebula”, which puts you in the same problem as Tailscale: the company sees and controls your network topology. I fear the company (Defined Networking) is trying to push things that way. Even their android app you can’t fully configure unless you use their ‘managed’ service.

    For now, Nebula is great, and my preferred mesh network (I looked into all the main ones). And for Tailscale you can run the administration server yourself with Headscale and be fully in your control.


    Actually I wish Tailscale the best as a profitable business. They’ve created a fantastic service and system. But for me, I’d rather my network be in my own hands and for my own eyes. And, as is OP’s main point, once they have enough dependent users, the service might turn much worse.