Hey. I’m currently using Tailscale with a self hosted control server(headscale). The problem’s that when the control server goes down for several days(Internet outage, here, in Iran), the clients get lost. And I have to come up with a new control server.
So I’m looking for a solution similar to Tailscale+Headscale, but with decentralized control server and relay.
Note that raw wireguard is not a solution. As some clients are(or might be) behind NATs. And then they will either need hole punching or a relay.
I recently started using rayfish:
Its new and very active, but also the dev uses AI. Its hard to tell where it might go but its de-centralized, it doesn’t need a control server and simply works device to device.
Whenever I heard about Iran my mind immediately goes to Tor. (You can run TCP over it) I’m sure there are better options but Tor is certainly the most robust.
yggdrasil
Yggdrasil is a fun one - I used to have it installed on all my boxes and would use it to ssh into everything. It saved my bacon a few times when internet connectivity for one device went out but because it meshed locally with other devices on the lan that still had internet, traffic got rerouted automatically. LAN peering uses broadcast discovery using ipv6 link local addresses, so it works even if the router dies and you don’t have dhcp handing out addresses.
I just set up a couple instances in the cloud and put a list of their connection details along with a few publicly run nodes as backups into the configs of each. As long as enough stays up for a path to exist you can reach it.
I’m not sure it is censorship resistant
What’s your threat model? No matter what, hole-punching will require some sort of relay. Yggdrasil’s likelier than Iroh to have available community servers if you need a hole punched in an adversarial context.



