Cloudflare or Tailscale?

Which route did you go for your homeland, a tunnel to your services or setting up tail scale/wireguard and access them on your trailer?

56 points · 63 comments · view on lemmy.world

63 Comments

tofu@lemmy.nocturnal.garden · 17 pts · 103d (2 replies)

I have wireguard, it's supported by my router (Fritzbox).

androidul@lemmy.world · 3 pts · 103d

same here, took me 7m to set this up on OPNsense with FritzBox

frosch@sh.itjust.works · 2 pts · 102d

Nice, I have to take a look if mine supports it, too!

prenatal_confusion@feddit.org · 11 pts · 103d (6 replies)

Pangolin on a vps.

fleem@piefed.zeromedia.vip · 3 pts · 103d (1 reply)

isn't it awesome? i am scared to update it too far for an unknown reason

prenatal_confusion@feddit.org · 3 pts · 103d

It's opensoursrso we should be able to roll back.

frosch@sh.itjust.works · 1 pts · 102d (3 replies)

When I looked into it first, Pangolin seemed a bit overwhelming.

Is it hard to set up?

prenatal_confusion@feddit.org · 2 pts · 102d (2 replies)

No, ridiculously easy with docker.

Then it follows the same principles as cloud flare. Create a site (vpn endpoint), get a docker snippet for a newt (what they call the vpn connector), paste it in the docker compose on your Homeserver and see it come up in the Webinterface.

Then you create a public resource and point it to said site and give it a url.

Done.

Ask me if you have questions

frosch@sh.itjust.works · 1 pts · 102d (1 reply)

Cool, do you get any auth and/or ingress protection?

With cloudflare, you get some auth options, can block AI crawlers (that get recognized...) etc for free

prenatal_confusion@feddit.org · 1 pts · 102d

Yes there is auth on by default for resources. You can use real accounts that need to be created or passwords or pins. And I think some id providers.

hexagonwin@lemmy.today · 8 pts · 103d (11 replies)

tailscale. works perfectly, the only problem is needing a google acc for login

BCsven@lemmy.ca · 3 pts · 103d

And that years back they moved their servers from Canada to the US. That's when I dropped TS and just did wireguard by hand.

zeitverschreib@freundica.de · 2 pts · 102d

@hexagonwin

I think Headscale gives you the option of using your own provider.

@frosch

cunnililgus@sopuli.xyz · 2 pts · 100d

Netbird allows email & TOTP 2FA.

peskypry@lemmy.ml · 1 pts · 103d (1 reply)

You can use GitHub.

potustheplant@feddit.nl · 3 pts · 103d

That's not really a solution.

FauxLiving@lemmy.world · 1 pts · 103d (5 replies)

the only problem is needing a google acc for login

You can use e-mail now.

potustheplant@feddit.nl · 5 pts · 103d

No, you cannot. Putting in your emails just redirects to the identity provider you used when signing up. If you try to create an account you'll see that email's not a option.

hexagonwin@lemmy.today · 1 pts · 103d (3 replies)

is it possible to switch to email from my google acc tied account? or do i need to create a new one?

FauxLiving@lemmy.world · 1 pts · 103d (2 replies)

I haven't looked into it yet, I'm in the same position of using Google to login.

I just noticed that the login page changed.

ScytheDraven47@piefed.zip · 2 pts · 103d (1 reply)

I believe registration is limited to a third party/OIDC. The login page is different to sign-up

FauxLiving@lemmy.world · 2 pts · 102d

third party/OIDC.

Ah, that makes sense

julianwgs@discuss.tchncs.de · 8 pts · 103d

I am very happy with Tailscale

FlexibleToast@lemmy.world · 8 pts · 103d (7 replies)

Pangolin on a free Oracle VPS.

giacomo@lemmy.dbzer0.com · 1 pts · 103d (6 replies)

is there a bandwidth/throughput limit on Oracle VPS?

FlexibleToast@lemmy.world · 2 pts · 102d

Not that I've noticed.

german@pawb.social · 2 pts · 103d (4 replies)

Something like 10TB. I’m an incredibly heavy user and I’d have to quadruple all of my usage, including home, to hit it.

gajahmada@awful.systems · 1 pts · 102d (3 replies)

Yes it's 10TB.

I nearly hit the cap once when I first testing sunshine/moonlight to see how much bandwidth my set up could do and kinda FOMO for the steam deck hype.

It's like 150 mb/s and works so well (for the kind of games I play) that I forgot the egress cap and just play for like a weeks even in the house, I realized and stop at ~ 9TB. My usual usage don't even hit a TB most of the time lol.

german@pawb.social · 1 pts · 101d (2 replies)

How do you monitor the total bandwidth? Last I tried it was super convoluted.

gajahmada@awful.systems · 1 pts · 100d (1 reply)

It is.

I just go to the https://cloud.oracle.com/account-management/cost-analysis page and looks at the current usage every now and then.

german@pawb.social · 1 pts · 98d

Fair. Friend’s account got suspended yesterday btw, you never know when they start hating you, so this is your reminder to check your backups

Illecors@lemmy.cafe · 7 pts · 103d (2 replies)

I do run wireguard on my router, but the main reason is ad blocking, not hiding services. Most services are publicly exposed.

frosch@sh.itjust.works · 1 pts · 102d (1 reply)

Nice, I thought about using wireguard as a private VPN, too. Having my pihole block my mobile data on the go would be neat

Illecors@lemmy.cafe · 1 pts · 102d

It really is!

mlg@lemmy.world · 7 pts · 102d (1 reply)

Wireguard.

Dunno if Cloudflare does effective auth for the tunnel or if you have to set that up yourself, but I don't bother trying to expose services to the internet in any way because some of this stuff was just never designed for proper web security (cough Jellyfin).

It's still worth setting up a wildcard cert with ACME so you get nice https and a real domain.

frosch@sh.itjust.works · 2 pts · 102d

Cloudflare has some opt-in auth. Mail-OTP is a nice balance imo: You can allowlist mail addresses per service/subdomain and set expiry for each. Then for access, you first have to enter the mail address, get the OTP and then access the service.

So, nobody without access to allowed mail addresses even gets to knock on you door.

But yeah, that's why I think about going tail scale: why bother having something exposed when not needed?

I just think, some services might be nice to provide to friends, too - and having them connect to my tailnet for this is a bit too much friction, I guess

frongt@lemmy.zip · 6 pts · 103d (3 replies)

Netbird via a free cloud VM. Works great.

peskypry@lemmy.ml · 2 pts · 103d

Who provides free cloud VM?

frosch@sh.itjust.works · 1 pts · 102d

Nice, I'll look into that!

skyline2@lemmy.dbzer0.com · 0 pts · 103d

This is the way

jlow@slrpnk.net · 5 pts · 103d

Headscale on fly.io

irmadlad@lemmy.world · 5 pts · 103d (2 replies)

How about both? I run the evil Cloudflare Tunnels/Zero Trust with Tailscale as an overlay on the server.

frosch@sh.itjust.works · 2 pts · 102d (1 reply)

I'm a bit stumped, what do you gain from this setup?

Or do you mean just running some services through the tunnel for easy access and "hide" others behind tailscale?

irmadlad@lemmy.world · 1 pts · 102d

what do you gain from this setup?

  • Defense in Depth
  • Network segmentation
  • Fallback
uuj8za@piefed.social · 5 pts · 103d
Decronym@lemmy.decronym.xyz · 4 pts · 103d

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
DNS Domain Name Service/System
IP Internet Protocol
VPN Virtual Private Network
VPS Virtual Private Server (opposed to shared hosting)

[Thread #265 for this comm, first seen 30th Apr 2026, 19:30] [FAQ] [Full list] [Contact] [Source code]

30p87@feddit.org · 4 pts · 103d

Asked my ISP for a public IP, exposed all things that can handle that to the public. Custom Wireguard server for VPN

187OnAnUndercoverCop@programming.dev · 4 pts · 103d

Temp stuff where I could care less about the free tier domain name or things that I just want to funnel to my existing devices: Tailscale

Widespread, prolonged services that will be more actively maintained for a longer amount of time and can just spin off of its own domain/subdomain: Cloudflare

Both are great.

TheGreenWizard@lemmy.zip · 3 pts · 102d

I'm liking self hosted NetBird atm

utjebe@reddthat.com · 3 pts · 102d (1 reply)

Just Wireguard on a router, but I'm thinking Netbird.

WG can be a bit PITA to set up, but once you do, it just works. What I would to have is more fine grained control over who goes where if I were to expose some of the services to friends.

IratePirate@feddit.org · 1 pts · 102d

wg-easy can greatly simplify your wireguard setup. Allows you to quickly generate access configs for friends and family on the fly (QR-codes, too). You still get access to post-up/-down hooks if you want tp create a more specialised deployment.

Atherel@lemmy.dbzer0.com · 3 pts · 103d

Wireguard

Evil_Incarnate@sopuli.xyz · 2 pts · 103d

Zerotier. I found it easy to set up and use. Free tier gives you one network and ten hosts, I think.

p4rzivalrp2@piefed.social · 2 pts · 102d (2 replies)

Wildcard dns with port 80 & 443 port forwarded to traefik with tinyauth & fail2ban

frosch@sh.itjust.works · 1 pts · 101d (1 reply)

Did you get a static public IP from your ISP?

p4rzivalrp2@piefed.social · 1 pts · 100d

No, I use dynamic dns

Reannlegge@lemmy.ca · 2 pts · 101d (2 replies)

I actually have Wireguard running on a pi zero 2, all it really does is provide me my pihole DNS.

Edit:

I should say I have pihole running on a couple of pi 5’s currently, overkill yes but one of my pi 4’s was sacrificed to the whims of magic smoke another was donated to a friend and another now hosts HAOS, I have a few pi zero 2’s (only one was sacrificial) the one that hosts wireguard has one of my last few working SD cards. The pi 5’s host many other things other than just pihole.

frosch@sh.itjust.works · 2 pts · 101d (1 reply)

Taking do one thing, but do it good to the next level, nice!

I thought about getting a pi zero also just for the pi-hole. But my pi3b holds up pretty good, still

Reannlegge@lemmy.ca · 1 pts · 100d

In the not to distant future I will be retiring wireguard from that pi zero 2 and turning it into a pots server. I have grand ambitions to make a better home lab with a few more pi’s and to help me get away from big tech more.

The only thing google I have is an email I do not use but so I can watch YouTube, but I use unwatched to block ads.

The only thing apple is my iPhone and my iPad, when it becomes time to replace those I will have to figure out graphenOS and some Linux distro for a tablet of some sort.

French75@slrpnk.net · 2 pts · 103d

I used wireguard, then switched to Pangolin. Wireguard was simpler and worked better with mobile apps though. I'll prob switch back for most apps.

Manodor@feddit.org · 1 pts · 103d

Funny thing, I use Tailscale to tunnel the access, but use cloudflare dns for device adress resolution.

hendrik@palaver.p3x.de · 1 pts · 103d

I have a port forwarding without any tunnel to third parties and Wireguard.

HiTekRedNek@lemmy.world · 0 pts · 102d

Both.

I have a free vps providing me a public IPv4 address, connected to my opnsense router via tailscale, and use a simple port forward from the VPs to the router's tailscale IP.

I have certain port/connections coming in either via the tailscale IP or my external IPv6 address all forwarded to my internal Caddy reverse proxy which itself is only running IPv4.

And I use cloudflare for my dynamic DNS resolution of my domain. A records are my public VPS IPv4 and AAAA are my own public IPv6 addresses respectively.

If/when I change to a service provider that doesn't use CGnat for IPv4, I can stop doing the forwarding from my VPS.

That's so we can stream music/video without needing to use the VPN.

But, I also run tailscale on my phone, so I can do admin stuff remotely from it, albeit painfully, on this small screen when things break. 🤣