Tela
For years I ran a mostly functioning personal cloud on my home fibre connection, stitched together from Tailscale, Cloudflare Tunnel and a lot of Docker containers. It worked well enough until I needed to reach it from my locked-down company laptop, where I couldn't install a VPN client or much of anything else. I started sketching a fix while waiting for a flight out of Manila, and by the time the plane landed I had the design for Tela. The name is Filipino for “fabric.”
What it does
Tela lets you reach TCP services on your own machines, whether that's SSH, remote desktop, a database or a web app, through an encrypted WireGuard tunnel. Most remote-access tools need at least one of these: a VPN that takes administrator rights to install, inbound firewall rules on the target machine, an account with a particular cloud vendor, or a kernel driver. Tela needs none of them.
There are three pieces:
- telad, a small agent that runs on the machine you want to reach and connects out to a hub.
- telahubd, the hub, which is the only thing that needs a public address, on a single port.
- tela, the client, which also connects out to the hub. There's a desktop app called TelaVisor if you'd rather not use the command line.
The hub pairs the client with the agent and relays the traffic between them, but it can't read that traffic, because the encryption runs end to end. If somebody compromises the hub, they learn who is talking to whom, but not what they're saying.
A few things I'm pleased with
- WireGuard runs entirely in user space, so nothing needs a TUN device, a driver or admin rights. That's the property that lets it work on a managed corporate laptop.
- Connections start over WebSocket and upgrade to a UDP relay or a direct peer-to-peer link when the network allows it, falling back gracefully when it doesn't.
- It has a built-in HTTP gateway that routes by path, one-time pairing codes for adding machines, role-based tokens, and a sandboxed file share you can mount over WebDAV.
- Each of the three programs is a single binary with no dependencies, for Windows, Linux and macOS, and each one can install itself as a service.
It's honest to say what it isn't, too. Tela carries TCP only, and for bulk transfers it's slower than kernel WireGuard. It's built for reaching your services, not for moving terabytes.
Tela and Awan Saya
Tela is the engine. The platform I'm building on top of it is Awan Saya, which is Malay for “my cloud”: a directory of hubs, identity, and a dashboard for managing it all. The relationship is roughly the one between Docker and Kubernetes, or between git and GitHub.
Details
- Written in Go; TelaVisor uses Wails.
- The current stable release is 0.16, and the wire protocol is frozen ahead of 1.0.
- Licensed under Apache 2.0.
The documentation, including a full book, is at telaproject.org, and the code is on GitHub: github.com/paulmooreparks/tela.