I can think of a short list of things that are ๐ฃ๐ค๐ฉ supposed to happen:
ย ย ย
Regarding the last item on this list, Tailscale revealed, via an unintentional โ๐ง๐ช๐ณ๐ฆ ๐ต๐ฆ๐ด๐ตโ, just how completely backwards their design is.
Basically, someone signed in with an email like ๐ฏ๐ข๐ฎ๐ฆ@๐ฑ๐ฐ๐ค๐ป๐ต๐ข.๐ฑ๐ญ (a free public email provider similar to gmail) Disturbingly, they found ๐๐ผ๐ง ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐ ๐ณ๐ฟ๐ผ๐บ ๐ฎ ๐ฐ๐ผ๐บ๐ฝ๐น๐ฒ๐๐ฒ ๐๐๐ฟ๐ฎ๐ป๐ด๐ฒ๐ฟ connected to their network.
You can find the full details here
You might ask, โ๐๐ฐ๐ธ ๐ค๐ฐ๐ถ๐ญ๐ฅ ๐ข ๐ด๐ต๐ณ๐ข๐ฏ๐จ๐ฆ๐ณ ๐ด๐ช๐จ๐ฏ ๐ช๐ฏ๐ต๐ฐ ๐ด๐ฐ๐ฎ๐ฆ๐ฐ๐ฏ๐ฆโ๐ด ๐ฏ๐ฆ๐ต๐ธ๐ฐ๐ณ๐ฌ?โ
Simply put, Tailscale assumed that ๐ฑ๐ฐ๐ค๐ป๐ต๐ข.๐ฑ๐ญ was a company/private domain and ๐ด๐ฟ๐ผ๐๐ฝ๐ฒ๐ฑ ๐ฎ๐น๐น ๐๐๐ฒ๐ฟ๐ ๐๐ถ๐๐ต ๐๐ต๐ฎ๐ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ถ๐ป๐๐ผ ๐๐ต๐ฒ ๐๐ฎ๐บ๐ฒ ๐ง๐ฎ๐ถ๐น๐ป๐ฒ๐. Apparently, that domain was not on Tailscaleโs "public domains" list.
This is ๐ฏ๐ฎ๐ฑ for many reasons:
Tailscale did respond and acknowledged the issue saying that they are ๐ฌ๐ค๐ง๐ ๐๐ฃ๐ ๐ค๐ฃ ๐ ๐๐๐ฉ๐ฉ๐๐ง ๐๐๐๐ฃ๐ฉ๐๐ฉ๐ฎ ๐ข๐ค๐๐๐ก to prevent these problems in the future. The only issue is, ๐๐ป๐น๐ฒ๐๐ ๐ฎ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ถ๐ ๐ผ๐ป ๐๐ต๐ฒ๐ถ๐ฟ ๐๐ฝ๐ฒ๐ฐ๐ถ๐ฎ๐น ๐น๐ถ๐๐, it will be regarded the same.
Something we use at Imperfektus is NetFoundry's OpenZiti.
I actually have a teaser trailer from a podcast that explains this exact pain.
Have a watch of the full episode to see more.
I am sure that Michael Kochanik will bite my head off for saying that it is a wireguard replacement (even though that makes it easy to understand), but if you are looking for a ๐ฟ๐ฒ๐ฝ๐น๐ฎ๐ฐ๐ฒ๐บ๐ฒ๐ป๐ ๐ณ๐ผ๐ฟ ๐๐ผ๐๐ฟ ๐น๐ฒ๐ด๐ฎ๐ฐ๐ ๐ฉ๐ฃ๐ก that only does what you tell it, do have a look at ๐ข๐ฝ๐ฒ๐ป๐ญ๐ถ๐๐ถ.
๐ ๐ณ๐ฆ๐ค๐ฆ๐ช๐ท๐ฆ ๐ฏ๐ฐ๐ต๐ฉ๐ช๐ฏ๐จ ๐ฃ๐บ ๐ด๐ข๐บ๐ช๐ฏ๐จ ๐ต๐ฉ๐ช๐ด. I just ๐๐ฟ๐๐น๐ ๐ฏ๐ฒ๐น๐ถ๐ฒ๐๐ฒ ๐ถ๐ป ๐๐ต๐ฒ ๐ฝ๐ฟ๐ผ๐ฑ๐๐ฐ๐.
If you are looking for a ๐บ๐ผ๐ฑ๐ฒ๐ฟ๐ป, ๐ผ๐ฝ๐ฒ๐ป-๐๐ผ๐๐ฟ๐ฐ๐ฒ ๐๐ฒ๐ฟ๐ผ-๐๐ฟ๐๐๐ ๐๐ผ๐น๐๐๐ถ๐ผ๐ป, have a chat with NetFoundry and tell them that I sent you :)