I'd advise to use headscale on a vps somewhere. Its tailscale but selfhosted.
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Not OP, but thanks for sharing about headscale. I wasn't aware this existed. Probably won't make a switch to it anytime soon, personally. I have way too much connected on tailscale right now.
Another thing is if where you want to access it from has a IPv6 then you can just connect via IPv6.
Tailscale or zerotier or a similar tool is the right one for the job.
I'm in the same boat so I setup a $2.50/mo VPS and that's my gateway. It took a little bit to get the nftables on vps to work right. I'd recomemned tailscale or similar if you want easy, though I've not ever used them myself.
Can you point me to your vps provider?
I sent you a message They are bit bare bones compared to other host but I haven't had any issues with them in over a year. On the wireguard side you're looking for a spoke and hub setup.
This covers it fairly well. https://www.procustodibus.com/blog/2020/11/wireguard-hub-and-spoke-config/
Good luck.
What would be the added latency. I was thinking of doing something like this and I could get a 3$ month VPS about 30km from where I live. I was thinking of doing something like that for remote gaming on my powerful desktop. Annoyingly I have cgnat and a IPv6 from where I live and no IPv6 from where I want to access it.
At best it will add whatever the extra hop is and any network congestion. My VPS host is 2200km away. I should find a closer one.... but it adds 160ms with some spikes in the 200-300 range. This is round trip 4400km roughly All things considered not too bad. My VPS is a 1vCPU, 1GB ram, 1Gbit unmetered, only as wireguard server. Hope that helps.
The VPS I would book would be the same and the CPU is a unnamed intel 2.6 ghz, so that sounds good.
I’ve gotten decent results with NAT traversal tricks, but the only way I’ve gotten it to perform reliably is with a relay fall back.
This is exactly what you get with tailscale.
You need to expose the ports you want to access on an external, publicly accessible server like a cheap vps. Then you can use wireguard to forward the traffic to your Pi.
I haven't done it in a long while, so I can't explain it well enough, try searching for "vps wireguard gateway". That should bring up some blog posts that will explain the process better. I used a VPS I got on the AWS free tier, you really don't need anything expensive.