The Yakshed Archive

All members of the Olde Yakshed have moved to yakshed.social. This is a read-only archive. See a live version of this post.

@bascht said on 2022-11-08:

Alright, let me tell you how this is now actually a good thing:

I had a spare unused TLD lying around (don't ask) and just switched OpnSense to announce it as the new local domain.

Now that I have a proper separation of outer and inner zones, I can start issuing proper TLS certificates for internal services. 💖

@bascht said on 2022-11-08:

Since I already had a working Wireguard setup, this essentially means: All the benefits of Tailscale, without Tailscale. All local devices are discoverable and remotely reachable via their own DHCP hostnames + the tld. In case it's needed, I can use any old acme client and put a valid SSL certificate in front of them.

I'm in awe.