Tailcat

(github.com)

130 points | by nderjung 1 hour ago

10 comments

  • tptacek 3 minutes ago
    This is smart. It's Magic Wormhole but for generalized connectivity, not just file transfer.
  • megamorf 12 minutes ago
    So this is somewhat similar to Iroh?

    https://github.com/n0-computer/iroh

  • archietect 29 minutes ago
    It looks like a direct competitor for the recently launched bitbang-cli

    https://github.com/richlegrand/bitbang-cli

  • MrDrMcCoy 14 minutes ago
    Looks like a Wireguard stunnel replacement, which is very useful!
  • rugma 16 minutes ago
    Wush was already doing something similar (using tailscale under the hood)

    https://github.com/coder/wush

  • cpuguy83 1 hour ago
    Interesting. I thought about doing this immediately after reading their old blog[1] post on punching through NAT some time ago.

    Just a combo of never getting around to it and friends talking me out of it b/c of existing alternatives such as wormhole[2].

    [1] https://tailscale.com/blog/how-nat-traversal-works

    [2] https://github.com/magic-wormhole/magic-wormhole

  • codruterdei 34 minutes ago
    A bit off topic: it’s just insane how I used to watch this guy’s http2 in Go yt video 10 years ago, and he’s still very relevant to this day! Cheers Brad!
  • petcat 51 minutes ago
    I did the homemade version of this for years just with SSH forwarding and nginx reverse proxy
    • nateguchi 39 minutes ago
      but without nat traversal...
  • gz5 49 minutes ago
    i like that it removes tailscale proprietary.

    if that is goal then why not go 100% open source to eliminate the ts derp control as well and get full sovereignty?

    like netbird, openziti, zerotier, etc.

    • bradfitz 43 minutes ago
      (Author here)

      The DERP server is already open source and tailcat can use any DERP server you run: https://github.com/tailscale/tailscale/tree/main/cmd/derper#...

      We just provide some default ones (https://tailcat.dev/derpmap.json) to get started if you're not bandwidth-sensitive. But you don't have to use them.

      Update: I added more explicit docs about this to https://github.com/tailscale/tailcat#bring-your-own-derp-rel...

    • gonzalohm 41 minutes ago
      Or just use wireguard directly. I get it that it's a pain in the ass to configure it, but there are plenty of open source config generators
      • bradfitz 39 minutes ago
        (Author here)

        WireGuard doesn't do NAT traversal. That's the main thing this adds. And this also adds a CLI tool + library to do streams over WireGuard w/o installing kernel routings, requiring root, etc.

      • mystifyingpoi 30 minutes ago
        > pain in the ass to configure it

        Idk? I found it pretty easy to configure by blindly following the tutorials and copy-pasting keys. The only footgun is the keepalive setting, which will screw up the tunnel if one end is behind NAT, that tripped me hard, but besides this, no issues at all.

  • TZubiri 43 minutes ago
    >"like netcat, but over Tailscale's data plane"

    Half of the Software offering nowadays seems to be selling vendor lock-in at no added value and then making a profit.

    Sure there's always some negligible added value, and then they reinvent a whole stack for their ecosystem. In the case of tailscale the added value seems to be avoiding going into your router and activating port forwarding? It looks like negative added value to me. Someone that tells you "don't do NAT traversal, just open a port" would be highly valuable, but saying no doesn't seem to be trendy, and is certainly not an easy sell.

    • bradfitz 41 minutes ago
      (Author here)

      There's no vendor lock-in here and no payment or account required. If Tailscale as a company fails, tailcat keeps working if you run your own DERP server. It's just open source code, not a hosted service.

    • mystifyingpoi 20 minutes ago
      > In the case of tailscale the added value seems to be avoiding going into your router and activating port forwarding?

      Well, ignoring the tone... kinda yeah? I mean, if port forwarding works for you, and you have public IPv4, and you have no CGNAT, and you need a connection only between 2 hosts, then port forwarding is actually a half-decent idea. However, it's not what Tailscale excels at.

    • MattCruikshank 41 minutes ago
      ...this is a github repo. Pointing to an open source project. That is not forced to use any vendor-specific systems to function.