Trying to pick a zero trust path

Netbird, zerotier, tailscale/headscale

From my research they all seem to work similarly, is the only difference app availability and personal preference?

I just spun up netbird because it has a self hosted version and I like the logo.

I just started using Cloudflare Zero Trust, I cant be more happy with the service, its free and works perfectly.

There are some differences - Zerotier supports multicast for example, Tailscale doesn’t. Tailscale on the other hand has their Funnel feature, and built-in DNS.

Netbird and Tailscale/Headscale are similar as they are built on Wireguard. They make it easy to get started with a VPN with some aspects of zero trust.

ZeroTier is also an easier to use VPN though it does not use Wireguard.

If you are looking at a zero trust path I would recommend Twingate or NetFoundry/OpenZiti. They implement a closed by default, microsegmented, least privilege, ABAC model which does not use network identifiers. OpenZiti is open source and can be self-hosted. I work on it.

I meant netbird too, just typed headscale twice on accident

I respect this answer more than I can say lmao

I use twingate at work, and agree it’s excellent. But overkill IMO for my homelab

Lol. When they all do the same thing I just pick the one with my favorite name / logo.

My netbird coordination server is on the Oracle cloud free tier and has been working well.