logoalt Hacker News

n6242today at 8:03 AM5 repliesview on HN

It's the only reason I want to replace Tailscale with something else or look into self-host when have a bit of time during my vacation. They only allow login through a third party, which is a big no for me.


Replies

corney91today at 8:14 AM

Tbf to Tailscale they allow any OIDC provider[1]. I wish this was more normalised, then we could have one login everywhere regardless of who hosts it (even if it's yourself).

[1] https://tailscale.com/docs/integrations/identity/custom-oidc

dolmentoday at 1:30 PM

While that isn't convenient is you don't want to use the public identity providers, it should make you think about what makes your identity on the Internet, and consider to have your own identity provider on a DNS domain you control.

zalebztoday at 12:04 PM

I created my own AWS Cognito userpool just for tailscale. I recall the webfinger redirect was frustrating to get right but I refused to use Google/Apple as a gatekeeper to my own network so I had all the motivation to get it working.

noduermetoday at 9:48 AM

This is what headscale does, right? Manage private logins and keys for your tailnet from a vps? I haven't played with it but seems straightforward

aidostoday at 8:09 AM

I think you can use a passkey now.

show 1 reply