• 4 Posts
  • 17 Comments
Joined 3 years ago
cake
Cake day: July 9th, 2023

help-circle








  • Cloudflare has some opt-in auth. Mail-OTP is a nice balance imo: You can allowlist mail addresses per service/subdomain and set expiry for each. Then for access, you first have to enter the mail address, get the OTP and then access the service.

    So, nobody without access to allowed mail addresses even gets to knock on you door.

    But yeah, that’s why I think about going tail scale: why bother having something exposed when not needed?

    I just think, some services might be nice to provide to friends, too - and having them connect to my tailnet for this is a bit too much friction, I guess