I use serve for everything else, just for the clean SSL termination for things that should stay within the telnet, like *arr stacks, immich, etc.
Do you have anything that’ll trigger a notification if there’s suspicious traffic on your local network? I may be overly paranoid about exposing things on my local network to the internet.
I fancy a bit upgrading to a smarter router like unify's with integrated firewall and stuff like like though.
US citizens may not be aware, but due to POTUS "made and maintained in Europe" is becoming more and more important to EU.
Still haven't figured out how to do Termux on Android with netbird ssh yet.
My other simplifier is having everything at home get a .home dns name, and telling Tailscale to route all these via tailnet.
https://tailscale.com/kb/1215/oauth-clients#generating-long-...
Edit: in fact from your original post it sounds like you’re trying to avoid re-issuing auth keys to embedded devices. You don’t need to do this; auth keys should ideally be single-use and are only required to add the node to the network. Once the device is registered, it does not need them any more - there is a per-device key. You can then choose to disable key expiration for that device.
https://tailscale.com/kb/1028/key-expiry#disabling-key-expir...
Having it in F-droid, vetted by their policies is kind of my benchmark for "software that is guaranteed to be not crapware."
That being said I'm rooting for the devs, having an alternative for tailscale+headscale would be nice, because as it stands it's kind of dependant on the goodwill of a for profit company (finite).
I had some weird bugs on a few old servers during the transition, and the support was helpful even though I am a small customer. We eventually switched to user space wireguard on those servers.
oaiey•1h ago