innernet
wg-meshconf
Our great sponsors
innernet | wg-meshconf | |
---|---|---|
60 | 6 | |
4,817 | 876 | |
1.0% | - | |
5.8 | 0.0 | |
15 days ago | 6 days ago | |
Rust | Python | |
MIT License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
innernet
- Would we still create Nebula today?
-
Tailscale increased free plan user limit form 1 to 3 and device cap to 100 also... unlimited subnets
Innernet is a barebone alternative. https://github.com/tonarino/innernet
-
Tips & Tricks for Productivity with Android E-Ink Devices (Obsidian, Syncthing, Weylus, RustDesk, Termux, KDE Connect, ZeroTier)
Very relatable! At first, I struggled for days trying to make Netmaker or Innernet functional for my personal home server (Raspberry Pi behind multiple routers). But then I stumbled upon ZeroTier, and everything worked seamlessly within a couple of hours. Tailscale was actually the next one on my list because I heard many positive things about it over at r/selfhosted (especially about headscale). However, I did not end up testing it after ZeroTier worked.
- Globally distributed Elixir over Tailscale
-
Dynamic configuration for allowed IPs
Not if you are running wireguard without any management client/server like Netmaker or innernet or any of the many others like them.
-
Tailscale Funnel
Or why not the open source tool innernet? https://github.com/tonarino/innernet
-
Ask HN: Working in a VR Headset
I wonder if this might improve over a more modern transport, if you were using an IPSec VPN.
Wireguard is enabling us to re-think what's possible over a VPN. Here's an example of what I mean. The network stack is based on Wireguard, with https://github.com/tonarino/innernet providing the topology and identity provisioning.
-
Planning to make a video on cool Rust apps focused on the end user. Make recommendations!
Virtual Private Network: Innernet, MASQ
-
Adding wireguard VPN to my network?
Tailscale is comparable to Zerotier, but built on top of Wireguard. That might be better for some (but not me). Innernet is also built on top of Wireguard, but is open source.
-
Hacker News top posts: Sep 21, 2022
Tonarino/innernet: A private network system that uses WireGuard under the hood\ (0 comments)
wg-meshconf
- Wireguard mesh between 4 pc similar to Tailscale
-
Updated MinIO NVMe Benchmarks: 2.6Tpbs on Get and 1.6 on Put
my experience, i dont know if this is comparable, but from my memory (i have not made any notes on that), i've tried min.io in december and switched to seaweed a weeks ago, because my usecase was transition from local file storage to DFS + also enable our developers to transition from local filesystem to s3. Since my resources are limited (vsphere VM) with 3 hosts + different disks, i tried to set up a 3 vm cluster with minio first, after i did some research on different systems (ceph, longhorn.io, ..) i wanted to have an easy setup-able system, which supports s3. I relied a lot on what people measured and chose min.io first because it supported mount via s3. Then i tried to copy over about 34 million files (mostly few bytes, but can also be 1Gbyte), with a mass of about 4.2TB. I tried different methods, rsync, cp, cp with parallelism,.. and i took me about 3 days to copy over 300GB of data at best. Then i also found out that it was impossible to list files. We have one single folder with over 300k projects (guid) beneath (growing). After that i gave seaweed a shot. Why i did not used it firsthand was documentation was a bit confusing and it did not gave me all the answers i needed as fast as minio did.
Now, my seaweed setup is a 3 vm cluster with 3 disks per vm (1TB) each. I configured a wireguard mesh (https://github.com/k4yt3x/wg-meshconf) between the VMs and configured master and volumes server to talk to each other via wireguard IPs securely. I also configured ufw to only allow communication between http/gRPC ports. I also configured a filer (using leveldb3) to use wireguard IPs (master and volumes) and let it communicate with some specific servers on the outside (ufw).
After that i mounted the filer via weed.mount on that specific server and tried to copy over the same files/folders. after 2 days i copied over about 1.5 TB of the data via rsync. There was also no problem with file listing and accessing the filer from different machines while uploading stuff. But there is a overhead when reading and creating lots of small files. File listing is even faster than local btrfs file listing.
chris is also very nice and fast fixing bugs.
-
How to add new client to wireguard in VPS without getting public IP changed on the client?
There are two factors at play here. The client's public IP actually depends on the gateway they use on accessing the internet. You can disable routing and your clients will keep their public IP and general internet access won't go through the VPS. However, if you want the traffic between "clients" also skip the VPS, then you want a mesh network. wesher and wg-meshconf can help you on configuring them.
-
Wiretrustee: WireGuard-Based Mesh Network
Looks great!
I've been using wg-meshconf[1] to assist in setting up Wireguard Mesh Networks on Linux for a while, works amazing!
A massive use case is to setup Kubernetes clusters, where network encryption is extremely important.
What are some alternatives?
Netmaker - Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
tailscale - The easiest, most secure way to use WireGuard and 2FA.
headscale - An open source, self-hosted implementation of the Tailscale control server
wesher - wireguard overlay mesh network manager
ZeroTier - A Smart Ethernet Switch for Earth
netbird - Connect your devices into a single secure private WireGuard®-based mesh network with SSO/MFA and simple access controls.
frp - A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
tinc - a VPN daemon
caddy-docker-proxy - Caddy as a reverse proxy for Docker
Nebula - A scalable overlay networking tool with a focus on performance, simplicity and security
AdGuardHome - Network-wide ads & trackers blocking DNS server