ben-grande / qusal

Salt Formulas for Qubes OS.
14 stars 6 forks source link

Add Tailscale formula #42

Open ben-grande opened 3 months ago

ben-grande commented 3 months ago

Current problem (if any)

Remote management on restricted network is difficult:

Proposed solution

Add tailscale.

Adding tailscale to a qube can be a security concern. Your OpenID provider can authenticate to your machine, but your can also use your own OpenID instance. Using Tailscale does not open ports to the internet, only your configured nodes can access it, so less dangerous than opening ports on your router in this metric.

The installation will of course be optional and restricted to the qubes you want to have it.

The value to a user, and who that user might be

Users can remotely manage remote qubes and non-qubes more easily without having to setup their tunnel, be it self-hosted VPN, VPS with SSH Tunnel or Hidden service with Onion Authentication.

.

kennethrrosen commented 3 months ago

Might be more appropriate here. https://github.com/ben-grande/qusal/issues/34#issuecomment-2021312862

ben-grande commented 1 day ago

Just an update on this. I have produced what I would say is an almost finished formula. I have not released it cause I didn't test as I didn't create a Tailscale account.

kennethrrosen commented 1 day ago

@ben-grande Happy to test with my account if that would be helpful.