REDDIT 原始帖子

Do I just have to live connected to Tailscale now?

I've got stuff I want to access all the time (like files on SeaDrive and photos on Immich). I don't really like the idea of just being connected to Tailscale all the time, because I really love using adguard's http filtering on my devices (which needs a VPN…

原帖正文r/selfhosted

I've got stuff I want to access all the time (like files on SeaDrive and photos on Immich). I don't really like the idea of just being connected to Tailscale all the time, because I really love using adguard's http filtering on my devices (which needs a VPN of its own) and it seems like it adds some overhead for the 95% of the work that I want to do that doesn't actually need to be on my home network. mTLS seemed like the solution and I set it up using Caddy on my server (domain forwards to home router, router sends to Caddy, Caddy checks the certificate). This setup works great (for Immich and web access to services). Honestly love mTLS, it seems like the ideal solution for everything! I give all my devices a certificate, and if they have it, they can access my stuff. And if they don't, they can't! It's exactly what I want! But now I'm realizing that most apps don't, in fact, support mTLS (SeaDrive client on windows, mobile apps for like, anything) so I'm kind of back to square one. I looked into STunnel to add SSL encryption via a proxy and while that might work on windows, it still doesn't fix android app problems, and I feel like I'm getting a little lost in mTLS sauce at this point. I want to safely expose services to the wider internet. I don't want to use a VPN on my devices to do it. Is there some option I'm missing? Should I just suck it up and connect to Tailscale all the time, or is there a more elegant solution that lets me use a vpn for some apps but keep using adguard? Edit: I know I can use just the DNS portion of Adguard, but the adguard HTTP filtering doesn't just block ad domains, it can strip ads out of the content itself and just rearrange the whitespace so that it's as if it never existed. That's the functionality I'd like to keep, but android won't let me use two VPNs at once, I have to pick. Cloudflare tunnels seems like the closest solution, but I worry the 100mb chunk limit will end up causing annoying problems when trying to transfer larger files

已收录讨论

25 条评论

u/asimovs-auditor

Expand the replies to this comment to learn how AI was used in this post/project.

u/M4xusV4ltr0nOP

At least on Android though, I can't use two VPNs so no Adguard and Tailscale together Edit: I'm talking about the adguard app, which is more than just DNS based adblocking, and needs to register as a VPN to work

u/Shadowxaero

You could run Adguard Home and set it as your DNS provider in tailscale. But in all honestly, just forward port 443. You are already using Caddy as your reverse proxy, Just keep it patched and all of your applications patched. You can also use cloudflared, but, you will run into potential issues with 100MB single file upload limits for apps like Immich. For everything else a cloudflare tunnel will serve you well.

u/Byron_th

You could have your cake if these apps just implemented some basic functionality.

u/M4xusV4ltr0nOP

that's been my takeaway, the technology DOES exist! The Immich app using mTLS works exactly like I want it to, it just seems to be the outlier

u/M4xusV4ltr0nOP

This does seem like the best solution, though I worry that doing file transfers will end up bumping into the 100mb limit of the tunnels

u/RevolutionaryElk7446

Do you have an example of an app that you use? I've got a lot of services and if one doesn't support logins or headers, Authentik at least has a Forward Auth / Proxy provider. Essentially it slates a login and session tracking between the client and server, so the service can be entirely unaware it's behind an authentication.

u/M4xusV4ltr0nOP

Oh yeah, I definitely appreciate the protection from all of the fuckery of the internet. I just wish there were better solutions for the average joe to both stay safe and access their own stuff!

u/M4xusV4ltr0nOP

This seems like the best move. The double login is a little annoying but that just feels a little safer than having all of my family photos resting behind a single Immich password to the whole internet.

u/GolemancerVekk

This really seems like the best solution. You can do this by adding the Adguard Home install to the tailnet, giving it a fixed tailnode IP, adding that IP as a "global nameserver" in Tailscale DNS tab, then enabling "Override DNS servers". This way Tailscale will keep on using its own DNS (100.100.100.100) for the tailnet device names but send everything else to Adguard Home.

u/jdobem

Tailscale only routes what you want, it doesnt need to be an exit node for your generic internet access....

u/Dreevy1152

Adguard should be a DNS configuration, not a second VPN

u/Byron_th

And how do you authenticate with Authelia from some app that doesn't support adding headers or anything?

u/M4xusV4ltr0nOP

I suppose you're right, the services themselves have their own login pages, I just don't love the idea of all of my files on Seafile being protected solely by my password on Seafile login page. It's probaaably fine though

u/RevolutionaryElk7446

Professional method is Port forwarding that aims at a Reverse Proxy that lives in it's own DMZ separate from the services alongside an IDP such as Authentik or Authelia. Tailscale and mTLS are both 'alternative' methods, meaning clients may or may not support it without additional configurations or effort from the client. Only the Port forwarding method is accepted as easily compatible for all as it's the standard.

u/nonlinear_nyc

If you want things personal then use tailscale. If you want to open to wider internet try cloudflare. You talk as if these services are a nuisance, when in fact they are protecting you from all sorts of fuckery. Remember it's ai times,script kids are now full on hackers. Protect yourself.

u/No_Cattle_9565

Why not use cloudflare tunnels?

u/flaming_m0e

I really love using adguard's http filtering on my devices (which needs a VPN of its own) So self host AdGuard Home and point your Tailscale DNS to it?

u/ttlequals0

Use VPN On Demand. So when you aren't on your home network, it will automatically connect.

u/scarbunkle

Put your adguard pc on tailscale, tell tailscale to use it for DNS. That’s what I do with my pihole. One VPN, I get my ad blocker and secure access to my home network

u/autogyrophilia

You can either expose the services to the internet, or use a VPN. Can't have your cake and eat it too. Web pages can use mTLS, but support for embedded clients is very limited still. It's not like unathenticated exploits are something common in these apps.

u/a_nice_warm_lager

I use a reverse proxy called swag that lets me expose just the services I want to my domain in combination with DNS records in Cloudflare. Takes some setting up but worth looking into!

u/mareczek82

You can selfhost Adblock and us it while connected to Tailscale. They even have tutorials how to do it on the YT and blog. Personally I use Pangolin to access my apps. You can have access to apps similar to cloudflare tunnels by creating url or by accessing to your own vpn same as Tailscale. Or mix, whatever you need.

u/ayyush69

Port forward ONLY your proxy manager ports, set up your proxies with a purchased domain, add dns records on cloudflare, DO NOT PROXY IT THROUGH CLOUDFLARE (tos stuff), and now you (and anyone for the matter) can access your immich and seadrive. As long as you set up 2 factor authentication, and then maybe set up fail2ban to stop brute force attacks, you are pretty safe.

u/coderstephen

Agree that mTLS is a great secure solution, but it is poor client support that holds it back, and probably why it is not typically recommended. I use mTLS when I can, but use a WireGuard VPN for services that don't support mTLS in their clients.