1 comments

  • linsomniac1 hour ago
    I adore Nebula and half wish I had chosen it instead of Tailscale+Headscale, the one thing about headscale that I really like is how easy it is for users to just grab the client and then login using their gmail account and they&#x27;re on the network. The biggest downside I&#x27;ve found to tailscale is their &quot;network shenanigans&quot; with firewall rules and route tables on Linux. In my testing 3-5 years ago, Nebula worked great in my test environment.<p>I&#x27;m tempted to add Nebula support to WeEncrypt for automated handing out of the certs using a LetsEncrypt-style short lived certs. I could even imagine a fairly easy to build workstation client that would require end-users to login to get their refreshed certs once they expire, like we do with Tailscale+Headscale.<p>That would dove-tail nicely with the existing TLS and SSH signed host keys support. <a href="https:&#x2F;&#x2F;github.com&#x2F;linsomniac&#x2F;weencrypt" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;linsomniac&#x2F;weencrypt</a>
    • ghthor36 minutes ago
      I believe you can disable this and it isn’t really required for TS to work