9 ms·
PiVPN v4.6.0: The End
- Takennickname 2y agoLiterally installed it yesterday for the first time. Damn.
- lukevp 2y agoCrazy to abandon a 6.4k star project that presumably many people are actively using… I know maintenance of OSS projects can be burdensome but there’s usually some in the community that are eager to chip in with PR reviews and handling issues. I’m surprised they aren’t interested in pivoting the product in the same general direction but giving it some novel features or something.
- jprete 2y agoAfter the sshd debacle, and in the context of GenAI becoming ever better at impersonation at scale, I don't think anyone working on a security-relevant project should simply hand off to an enthusiastic community member they don't know well.
- cocoa19 2y agoDo you remember when Raymond Hill ceded control of uBlock to another guy? This new guy started asking for donations (for himself) and then sold the project to AdBlock. That was truly disgusting. That’s what prompted Raymond to create uBlock Origin.
- loloquwowndueo 2y agoWhy is it crazy? If it no longer aligns with the maintainer’s interests or energy, doesn’t provide compensation, he’s within his right to archive it and move on. And people in the community can fork it if they need to.
- baq 2y agoIt’s crazy to maintain such a project, shutting it down is the only sane option. Chapeau bas for keeping it going for so long. The internet of old was built by irrational hobbyists like these guys.
- ocdtrekkie 2y agoMy guess is they think the alternative already meets their needs. If someone else is already doing it better, why not just use that?
- codetrotter 2y agoIf it were me I would shut it down too after I no longer had energy to maintain it. Just handing responsibility over to someone else for something like a VPN project is definitely high risk. Remember the xz debacle last week? Same kind of people who backdoored xz would love to get maintainership of a VPN project for sure.
- yokoprime 2y agoCrap, i’ve been running pivpn as a LXC since its so light weight
- oneplane 2y agoThis is the best way to conclude a project like this, I wish more clear cut "this is the end" choices were made. An ecosystem with zombie projects isn't healthy.
- stavros 2y agoWhy? I wish people would put their projects in something like https://www.codeshelter.co https://www.codeshelter.co so anyone who's interested can maintain them, instead of just killing them.
- 8n4vidtmkvmk 2y agoIsn't xz a prime example of why we don't just hand over the reigns anymore? Like the guy said, they can just fork it.
- bornfreddy 2y agoDo you, as the project maintainer and possibly even founder, trust these people?
- stavros 2y agoThe maintainers are vetted before joining, and are removed if they do something untoward, but when the choice is between killing the project or giving it to some random person, Code Shelter provides a better alternative.
- sthlmb 2y agoWhat if they pass the joining process but then later sneak something in that goes undetected until things go boom? There are alternatives, you can fork the original project, and things will go on. As others have said too, you can just update the underlying software and there's a good chance that the wrapper itself will continue functioning, providing there are no giant breaking changes and by that point, a fork or alternative will likely have handled it.
- xyst 2y agoSetting reminder to migrate rpi in closet off of pivpn. Might just setup a nixOS arm image with wg instead
- FerretFred 2y agoThat's such a shame - I've used PiVPN many times and it's just made life so straightforward. Big, BIG thanks to all involved, and you'll be missed!
- postpawl 2y agoIt’s probably better to just use the wireguard docker container setup instructions now: https://github.com/linuxserver/docker-wireguard?tab=readme-ov-file#docker-compose-recommended-click-here-for-more-info https://github.com/linuxserver/docker-wireguard?tab=readme-o...
- unethical_ban 2y agoThanks to the maintainers of the project. It is a handy tool, a good wrapper around setting up simple wireguard quickly. And it pairs with pihole really well. I migrated to OPNSense for my DNS and I haven't needed VPN for a little bit. But I kind of disagree that there is no place for a simple CLI tool for wireguard user management. I was going to make a comment about how unreasonable it is to shut the project down instead of letting someone else take it over. But two things come to mind: First, yes, people can fork it and develop it on their own. Second, right after xz, maybe it would seem unwise to endorse a stranger taking over your security project. PS: PiVPN isn't wireguard itself. Assuming WG's command line doesn't change radically for a while, PiVPN is still completely usable and people don't need to rush to get off it.
- poisonborz 2y agoEh, I just wanted to migrate to this, a lot of threads recommend it as the best way to effortlessly set up Wireguard. WG-easy, Headscale have their own set of problems. I guess there will be forks.
- byteknight 2y agoShameless plug for an alternative? > WireHole is a combination of WireGuard, Pi-hole, and Unbound in a docker-compose project with the intent of enabling users to quickly and easily create a personally managed full or split-tunnel WireGuard VPN with ad blocking capabilities thanks to Pi-hole, and DNS caching, additional privacy options, and upstream providers via Unbound. https://github.com/IAmStoxe/wirehole https://github.com/IAmStoxe/wirehole
- pogue 2y agoSounds very cool, thanks for the recommendation! Lots of videos on YT with setup guides too!
- jimmyl02 2y agocurious to hear does anyone know what the mentioned alternatives are? a super simple to use wireguard control plane is super valuable and PiVPN seemed to fit that gap perfectly unfortunate that it's come to an end but it's nice to hear the maintainer moving on in such a positive way :)
- Havoc 2y agowg-easy comes to mind
- Handy-Man 2y ago+1, it's amazing
- deleted 2y ago[deleted]
- pogue 2y agohttps://news.ycombinator.com/item?id=39953873 https://news.ycombinator.com/item?id=39953873
- vundercind 2y agoAfter meaning for years to spend the 2-3 hours I’d need to set up wire guard and get all my devices on it that I’d want on it (it’s a bit fiddly and time consuming, and inevitably with projects like that, there’s some dumb problem that comes up that wastes a bunch of time) I just did the free tier of Tailscale. Server, two Apple TVs, a couple phones, a tablet, and a laptop all on it in like 15 minutes flat. With one of the Apple TVs configured to act as a gateway, too. Should’ve just done that to begin with.
- Ballas 2y ago2-3hours? Just try wg-easy, it should not take more than 10minutes.
- postpawl 2y agoDocker-wireguard: https://github.com/linuxserver/docker-wireguard?tab=readme-ov-file#docker-compose-recommended-click-here-for-more-info https://github.com/linuxserver/docker-wireguard?tab=readme-o... You set the number of peers and it generates that number of folders with certificates and QR codes for you.
- Hamuko 2y agoAnyone got a recommendation for a router with Wireguard support baked in? I've been running PiVPN on a separate box but since I need a new router anyways and it's not going to be supported, that might be a viable replacement.
- gamesbrainiac 2y agoGLiNet routers have that. So do the Asus ROG routers, but they don't have NAT acceleration.
- spr-alex 2y agoYou can give us a try, https://github.com/spr-networks/super https://github.com/spr-networks/super, https://supernetworks.org/ https://supernetworks.org/. Wireguard is well integrated. We also have a tailscale plugin, and more vpn plugins on the way
- opello 2y agoUbiquiti UDM-Pro has it, but I'm not sure how they're regarded in popular opinion these days. I've had good luck with everything but the PoE on mine, and they gave me a free injector to fix that.
- Takennickname 2y agoOpnsense has it. Never got it to work though.
- Scipio_Afri 2y agoPfsense has it
- logicziller 2y agoRecently we needed a customer in a different country to be able to connect to a wireguard instance and I didn't want to deal with the support headache of walking them through the flashing process. While I was looking for devices that come with OpenWRT preinstalled, I came across FriendlyElec that looked quite decent. Eventually we ended up building a custom Raspberry Pi image.
- 2y ago
- nickjj 2y agoThis really goes to show you how valuable a good experience / API is. PiVPN is so easy to use. You run 1 command and pass in the name of the config to generate and you're done. Now you can take that config and use it client side. I've used it on Debian servers (not a Raspberry Pi) and it's been flawless to onboard a bunch of folks into using a VPN (work related). IMO there's no way this project will fail, someone will fork it.
- solarkraft 2y ago> "But I want and can maintain it, can I take it over?" Let me put it plain and simple: No! I don't know you, I don't trust you! Fork it and carry on! They learned a good lesson from the liblzma situation.
- baq 2y agoMaybe. ‘Fork it’ means a bad actor can… fork it and advertise as a successor.
- junon 2y agoThen it's up to the consumer to judge that themselves. One component of the liblzma backdoor was that distros were already linking to those tarballs. That wouldn't happen here as the repo will essentially freeze.
- nextlevelwizard 2y agoBetter than the alternative