Elektrine lite

← Feed

@zrail@hachyderm.io

Post #614517

2026-03-08 12:40 UTC

Last night instead of going to bed I forgot about daylight saving time and added a statically defined #ipv6 #wireguard mesh between my #homelab servers. Now I can use that instead of #tailscale for the secure data plane. Tailscale is great and I'll probably keep it for the management plane. The way it aggressively idles connections combined with the first packet seemingly always hitting a DERP server makes stuff feel a lot slower than it should. #selfhosted @homelab

Replies (3)

  • @zrail@hachyderm.io 2026-03-11 02:19

    Migrated a few more things onto the mesh overlay, specifically metrics scrapes and the MQTT connection for my HVAC integration. I also changed how the underlay network gets set up a little bit. Now every host uses an identical radvd config to advertise the same #IPv6 prefix. Still trying to figure out a little bit of weirdness around preferred lifetime, though. @homelab #homelab #selfhosted

    Open ##1406367

  • @rachel@transitory.social 2026-03-08 12:53

    @zrail@hachyderm.io @homelab@fedigroups.social I'm currently using cilium for wireguard between talos k8s nodes, but not their kubespan offering because of conflicts with certain cilium features. The node to node traffic (as opposed to pod traffic) uses wireguard for the remote nodes only. That traffic is entirely secured via TLS so I'm not as worried about the local nodes

    Open ##1406368

  • @train@hachyderm.io 2026-03-08 16:38

    @zrail @homelab I also was firmly on shove data over Tailscale and then I stopped as well. I still use it for mgmt of a VPs and it’s brilliant for that. The back haul for the VPs now is wiregaurd.

    Open ##1406370