

3·
2 days agoHeadscale running as it’s own user with tailscale ACLs. Tailscale calls home to headscale via HTTPS and gets the info. Assuming the person doesn’t get root access it’s should be fairly safe. With tailscale ACLs you set up whicu systems can reach where. Also don’t forgot you can use UFW/iptables in each client that way it’s still locked down.
It works, but isn’t nearly as user friendly.