Skip to content

Reaching your apps from outside the house

Your apps' addresses are public names — photos.basement-nuc.mesopod.app — that answer with your server's private address. Anyone can look the name up; only a machine on your network can reach what it points at.

So remote access is a reachability problem, not a naming one. Nothing about the app, its URL, or its certificate changes. You only need a way to be on the network. Tailscale is the least fiddly one we know of, and it needs no open ports on your router.

1. Install Tailscale on the server

curl -fsSL https://tailscale.com/install.sh | sh

2. Advertise your home network

Find the subnet your server sits on (ip -4 addr — something like 192.168.1.40/24, whose subnet is 192.168.1.0/24), then:

sudo tailscale up --advertise-routes=192.168.1.0/24

Tailscale prints a link; open it to authenticate the machine. If it warns that IP forwarding is off, run the two sysctl lines it gives you and re-run the command.

3. Approve the route

In the Tailscale admin console, open the machine, then Edit route settings, and approve the subnet you advertised. Routes do nothing until approved.

4. Accept routes on your other devices

  • iOS, macOS, Android — subnet routes are used automatically.
  • Linux, Windows — tailscale up --accept-routes.

Now, from anywhere, your laptop resolves photos.basement-nuc.mesopod.app to 192.168.1.40 exactly as it does at home, and Tailscale carries the packets there. The certificate validates normally.

The DNS caveat

Routing is only half of it: the name still has to resolve to that private address wherever you are. Two things break it.

Your current resolver refuses private answers. A hotel, an office network, or a rebind-protecting router will return nothing for a public name that points inside a LAN — the same problem, and the same fix, as install.md's rebind section. Check what you got:

dig +short photos.basement-nuc.mesopod.app

An empty answer means the resolver dropped it, not that the record is missing.

Tailscale is overriding your DNS. If names resolve at home but stop when Tailscale is up, look at DNS in the Tailscale admin console. Either turn off Override local DNS, or add a split DNS entry for mesopod.app pointing at a resolver that passes private answers through — your home router's address works well here, since the subnet route already reaches it.

What this does not do

  • It does not make your apps public. That is the point.
  • It does not change any app URL, so a link you send yourself still works at home.
  • It has nothing to do with Mesopod's own connection. The outpost dials out over HTTPS on its own and doesn't care whether Tailscale is up.