Comment on Tailscale n00b questions

<- View Parent
Toribor@corndog.social ⁨2⁩ ⁨days⁩ ago

DERP is the service that actually relays packets between tailscale connected devices when they are crossing a NAT (leaving one private network and going across the internet to another private network).

If you host headscale (the self-hosted community version of the tailscale control plane) and use it with tailscale, by default it will still use the public Tailscale DERP servers. Your traffic is still encrypted and not visible to them, but it does still rely on their centralized architecture even though you are hosting the control plane yourself.

That being said, you can also just selfhost DERP or use the embedded DERP that ships with headscale, although there are some other considerations when doing that because it will need to be publicly on the internet, probably with a proper domain name and publicly trusted certificate.

source
Sort:hotnewtop