• 0 Posts
  • 26 Comments
Joined 1 year ago
cake
Cake day: July 6th, 2023

help-circle








  • I don’t think I’ve ever come across a DNS provider that blocks wildcards.

    I’ve been using wildcard DNS and certificates to accompany them both at home and professional in large scale services (think hundreds to thousands of applications) for many years without an issue.

    The problem described in that forum is real (and in fact is pretty much how the recent attack on Fritz!Box users works) but in practice I’ve never seen it being an issue in a service VM or container. A very easy way to avoid it completely is to just not declare your host domain the same as the one in DNS.











  • I run it on my router which has the CG-NAT IP address.

    Whilst you’re right that it could clash, it’s very unlikely (a 1 in 4194302 chance), I imagine Tailscale would detect the clash and change IPs though I could be wrong as it never happened to me (and probably never will - though in all fairness it will eventually happen to someone).