wesher
wg-meshconf
Our great sponsors
wesher | wg-meshconf | |
---|---|---|
10 | 6 | |
888 | 877 | |
- | - | |
6.1 | 0.0 | |
10 days ago | 18 days ago | |
Go | Python | |
GNU General Public License v3.0 only | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
wesher
-
Would we still create Nebula today?
https://github.com/costela/wesher
Wiresmith: Rust, auto-configs clients into a mesh
-
Does a fully featured WireGuard-protocol based corporate VPN software exist?
Maybe take a look at Wesher https://github.com/costela/wesher
-
Mesh of multiple wg tunnels
I run a Wireguard mesh network with Wesher, and I am pretty sure that there are other projects to automate this. Is there a reason not to use them?
-
Tailscale/golink: A private shortlink service for tailnets
From a purely networking perspective, there are far better solutions than tailscale.
Have a look at full mesh VPNs like:
https://github.com/cjdelisle/cjdns
https://github.com/yggdrasil-network/yggdrasil-go
https://github.com/gsliepen/tinc
https://github.com/costela/wesher
These build actual mesh networks where every node is equal and can serve as a router for other nodes to resolve difficult network topologies (where some nodes might not be connected to the internet, but do have connections to other nodes with an internet connection).
Sending data through multiple routers is also possible. They also deal with nodes disappearing and change routes accordingly.
tailscale (and similar solutions like netbird) still use a bunch of "proxy servers" for that. You can set them up on intermediate nodes, but that have to be dealt with manually (and you get two kinds of nodes).
- Wie würdet ihr derzeit ein persistentes VPN-"Mesh" für ~20 Geräte bauen?
-
How to add new client to wireguard in VPS without getting public IP changed on the client?
There are two factors at play here. The client's public IP actually depends on the gateway they use on accessing the internet. You can disable routing and your clients will keep their public IP and general internet access won't go through the VPS. However, if you want the traffic between "clients" also skip the VPS, then you want a mesh network. wesher and wg-meshconf can help you on configuring them.
-
Anyone using WireGuard for production as SDN?
Have you considered https://github.com/costela/wesher or does this not fit your use case?
-
internal naming conventionds
I use Hashicorp Consul and Hashicorp Nomad for service discovery and task scheduling respectively, with wesher for my internal private management network that Consul, Nomad, etc run on to protect the management interfaces. Fabio bridges the gap between the wesher wireguard VPN and the rest of my home network.
-
Building a Mesh VPN Tool for the Community
How does your solution compare to wesher?
-
Wireguard Mesh Network Options
How does it compare to https://github.com/costela/wesher?
wg-meshconf
- Wireguard mesh between 4 pc similar to Tailscale
-
Updated MinIO NVMe Benchmarks: 2.6Tpbs on Get and 1.6 on Put
my experience, i dont know if this is comparable, but from my memory (i have not made any notes on that), i've tried min.io in december and switched to seaweed a weeks ago, because my usecase was transition from local file storage to DFS + also enable our developers to transition from local filesystem to s3. Since my resources are limited (vsphere VM) with 3 hosts + different disks, i tried to set up a 3 vm cluster with minio first, after i did some research on different systems (ceph, longhorn.io, ..) i wanted to have an easy setup-able system, which supports s3. I relied a lot on what people measured and chose min.io first because it supported mount via s3. Then i tried to copy over about 34 million files (mostly few bytes, but can also be 1Gbyte), with a mass of about 4.2TB. I tried different methods, rsync, cp, cp with parallelism,.. and i took me about 3 days to copy over 300GB of data at best. Then i also found out that it was impossible to list files. We have one single folder with over 300k projects (guid) beneath (growing). After that i gave seaweed a shot. Why i did not used it firsthand was documentation was a bit confusing and it did not gave me all the answers i needed as fast as minio did.
Now, my seaweed setup is a 3 vm cluster with 3 disks per vm (1TB) each. I configured a wireguard mesh (https://github.com/k4yt3x/wg-meshconf) between the VMs and configured master and volumes server to talk to each other via wireguard IPs securely. I also configured ufw to only allow communication between http/gRPC ports. I also configured a filer (using leveldb3) to use wireguard IPs (master and volumes) and let it communicate with some specific servers on the outside (ufw).
After that i mounted the filer via weed.mount on that specific server and tried to copy over the same files/folders. after 2 days i copied over about 1.5 TB of the data via rsync. There was also no problem with file listing and accessing the filer from different machines while uploading stuff. But there is a overhead when reading and creating lots of small files. File listing is even faster than local btrfs file listing.
chris is also very nice and fast fixing bugs.
-
Connect to wireguard server over a wireguard server -> client connection
Hey you should post your wg0.conf If you would like to build a WireGuard mesh try this: https://github.com/k4yt3x/wg-meshconf
-
How to add new client to wireguard in VPS without getting public IP changed on the client?
There are two factors at play here. The client's public IP actually depends on the gateway they use on accessing the internet. You can disable routing and your clients will keep their public IP and general internet access won't go through the VPS. However, if you want the traffic between "clients" also skip the VPS, then you want a mesh network. wesher and wg-meshconf can help you on configuring them.
-
Wiretrustee: WireGuard-Based Mesh Network
Looks great!
I've been using wg-meshconf[1] to assist in setting up Wireguard Mesh Networks on Linux for a while, works amazing!
A massive use case is to setup Kubernetes clusters, where network encryption is extremely important.
[1]: https://github.com/k4yt3x/wg-meshconf
- WireGuard full mesh configuration generator
What are some alternatives?
ergo - An actor-based Framework with network transparency for creating event-driven architecture in Golang. Inspired by Erlang. Zero dependencies.
headscale - An open source, self-hosted implementation of the Tailscale control server
wireguard-vanity-keygen - WireGuard vanity key generator
tinc - a VPN daemon
wiresteward - Wireguard peer manager
cjdns - An encrypted IPv6 network using public-key cryptography for address allocation and a distributed hash table for routing.
kilo - Kilo is a multi-cloud network overlay built on WireGuard and designed for Kubernetes (k8s + wg = kg)
netbird - Connect your devices into a single secure private WireGuard®-based mesh network with SSO/MFA and simple access controls.
drago - ☁️ Securely connect anything with WireGuard® and manage all your networks from a single place.
Netmaker - Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
fabio - Consul Load-Balancing made simple
dsnet - FAST command to manage a centralised wireguard VPN. Think wg-quick but quicker: key generation + address allocation.