Have been messing with tonight as a potential solution to get devs inside an AWS VPC without having to fuck around with SSH.

It was actually rather easy, all told. Spin up a t2.micro, enable forwarding, install and auth the Tailscale service, and tell it to advertise the VPC subnets. And, viola, Tailscale clients had nothing else to do.

Supposedly, it should even work if I take that t2.micro and remove its public IP address, which… actually sounds harder than setting up Tailscale. 😆 stackoverflow.com/a/54153371

Update: works perfectly on that EC2 instance without a public IP address. As expected. 🥳

