Hacker News new | past | comments | ask | show | jobs | submit login

Why is this better than running wireguard directly on a cheap instance .



These over the top services handle node discovery and meshing for you, instead of you having to feed configurations manually down to each device you want to hook up to wireguard.

Convenience features etc


For a non-network person that is surely a convinience. I prefer pushing my configs through ansible and not thinking about it.


But then you cannot scale.

You do not see the problem because you probably manage less than 5 nodes.


Netmaker guy here, and I'll be the first to tell you that if you have a static setup of, let's say 5 machines or less, then there's no need for something as complex as Netmaker. It's really useful for people who have many machines, or machines that will move around dynamically. Or, if you need to route traffic through a NAT gateway. A static setup is fine for technical people and small networks, it's just not scalable. As an analogy, you wouldn't run Kubernetes if you just need to deploy 3 docker containers, but as the complexity grows, you need a management system.


WireGuard to this date prefers A records over AAAA records which means if I'm on an 464xlat network I end up connecting over a ISP's owned proxy.

Many people have complained, and there is zero response to it.

Tailscale does it a LOT better.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: