A Trip to Greece and a Private VPN Back to Italy
When Fitbit's AI features were unavailable in Greece, I built a private travel VPN with Tailscale, starting at home and experimenting with Oracle Cloud.

Last week I was in Greece when I discovered that the AI features in the app I use with my Google Fitbit Air were unavailable there.
I had not expected a trip within Europe to change which parts of the app I could use. Back in Italy those features were available. In Greece, I could no longer access them.
That sent me looking for a way to route my iPhone’s internet connection through Italy. I ended up building a private VPN with Tailscale, first using the Ubuntu computer at home, then experimenting with a free virtual machine on Oracle Cloud.
With the VPN routing my connection through Italy, the app’s AI features worked correctly again. It also gave me an encrypted tunnel for the traffic I was sending over the hotel’s Wi-Fi.
The Geographic Restriction
Google now calls the companion app Google Health, and its AI coaching feature Google Health Coach. At the time of writing, Google’s country availability documentation includes Italy but does not include Greece.
That matches what I encountered during the trip. It does not explain exactly how Google determines a user’s location or which signals it checks. I could observe the restriction; I could not inspect the logic behind it.
My idea was to change where my internet traffic came out. If I could connect my iPhone to a machine in Italy and use that machine as my internet gateway, remote services would see its public IP address.
I already had a computer at home that could do that job.
The First Exit Node Was at Home
I used the old Ubuntu computer I had repurposed for development. It was already available, and I could manage it remotely.
Tailscale connects devices in a private network called a tailnet. Joining that network normally gives access to the other devices without changing the route used for ordinary internet browsing. For this experiment, I needed an exit node: a device that also forwards internet traffic for another device. Tailscale documents this as a separate, explicit setting.
I deployed Tailscale as a dedicated Docker Compose stack on the Ubuntu machine. The container uses kernel networking through /dev/net/tun, has the NET_ADMIN capability, and stores its identity in a persistent Docker volume. It publishes no ports, and I did not change the router’s port-forwarding rules.
The setup has three distinct steps: advertise the machine as an exit node, approve it in the Tailscale admin console, and select it in the iPhone app. Installing Tailscale and signing in alone does not route browsing through home.
Once I selected the home exit node, the route was:
iPhone in Greece
→ encrypted Tailscale tunnel over the hotel connection
→ Ubuntu exit node at home in Italy
→ internet
This gave me the tunnel back to Italy I was looking for. A useful routing check is to compare the public IP shown on the iPhone with the one shown by a device using the home connection. In my case, the app itself also confirmed the practical result: I could use the AI features again while still in Greece.
Trying Oracle Cloud as a Second Location
The home setup depends on the computer staying on and the home connection staying available. Traffic routed through it also uses that connection’s upload bandwidth.
I wanted to experiment with another exit location in Italy, independent of the equipment at home. Oracle Cloud’s Always Free tier offered a way to try that without adding a recurring compute bill.
I started in the Milan region with an ARM instance, VM.Standard.A1.Flex. Oracle returned:
Out of capacity for shape VM.Standard.A1.Flex in availability domain AD-1
The free allocation existed, but the capacity to create that machine was unavailable when I tried.
I switched to VM.Standard.E2.1.Micro, a small AMD instance, and created an x86 Ubuntu VM. Then I installed Tailscale and enabled persistent IPv4 and IPv6 forwarding, preparing it to act as another exit node.
The client-side idea stays the same: choose a different exit node and send traffic through that machine. The public address would belong to the Oracle VM rather than my home connection. A cloud address can be treated differently from a residential address by the service receiving the traffic, so I would test each exit node separately.
There are also limits to the free experiment. Oracle’s documentation lists 1 GB of RAM and up to 50 Mbps of internet bandwidth for the AMD Micro shape. It also says idle Always Free instances may be reclaimed. I would treat this as an experimental alternative, with the home node still available.
What I Mean by a Private VPN
I control the machine that acts as the internet exit. At home, I also control the physical computer and the connection. On Oracle, I administer the VM while Oracle provides the underlying infrastructure.
Tailscale still provides the coordination service that helps the devices find each other. It uses WireGuard to encrypt traffic between them and can relay encrypted packets when a direct connection is unavailable. Tailscale’s security documentation distinguishes that encrypted traffic from the connection metadata its service receives.
On the hotel network, traffic routed through the exit node travels inside the encrypted tunnel. The local network can still see that I am making a connection and observe its timing and volume, but it cannot read the traffic inside it.
The Tailscale tunnel ends at the exit node. HTTPS continues to protect the connection from there to the destination service. The destination still knows which account I am signed into and receives the information I send to it.
Before the next trip, I can check the home node while I am still in Italy and test the Oracle alternative separately, including the app that prompted the experiment.
References
Share