Hi peeps, a little lost in the self-hosting world right now, and hoping someone can point me in the right direction.

I’ve just set up all the *arr apps that i want and need for media, music and books. And am at the step where i am supposed to bind a VPN to my qBittorrent. However, I am ofc running everything behind the beloved Tailscale. But just realised I am not allowed to run tailscale at the same time as another VPN(ProtonVPN in my case).

How do i get past this cross-road? I really want to stick with using Tailscale for accessing my services.

Is a reverse proxy something i should look into instead? I need my server to sit behind a VPN…

Appreciate any tips or tricks for how other people solved this buckle.

  • charizardcharz@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 year ago

    Tailscale was updated with direct support for Mullvad, but since you already have Proton I’m guessing you wouldn’t want to switch.

    If you’re using containers, you can have one container with your VPN and route traffic from specific containers through the VPN container. You can then have tailscale on the host system.

    There’s a quick guide on setting up the VPN part here. Tailscaile you set up normally.

    • ShinyBook@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Have you figured out how to use the Mullvad VPN from Tailscale for a similar setup like you’ve linked? I cannot figure out how to get a tailscale docker container to properly connect to an exit node.

      • keyez@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        I use a binhex-privoxyvpn container with a mullvad wireguard config in there. That’s for my server and containers at least.

      • charizardcharz@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        I have Tailscale directly installed on the host and I don’t use Mullvad so I haven’t tried that setup myself.

        Looks like you would need to set the TS_EXTRA_ARGS environment variable in your container to --exit-node= --exit-node-allow-lan-access=true with the exit node name or ip of the Mullvad node. I haven’t tried this myself though.

      • charizardcharz@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I haven’t used that feature so I can’t really say, but I don’t see how it would affect it. You’re not modifying anything on the tailscale side and you’re not adding nodes to your tailnet, you only have the same one for the host system.

        • notfromhere@lemmy.one
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 year ago

          I subscribed to the mullvad addon to try it out and saw about 30+ mullvad nodes waiting to be signed, probably signed due to the lock. That got me thinking I probably want to configure the NACL so the mullvad nodes I allow on my tailnet are not able to initiate any connections to my other nodes. I didn’t see any documentation on my setup so cancelled the mullvad addon until I have time to dig into it more.