Reaching your apps from outside the house¶
Your apps' addresses are public names — photos.basement-nuc.mesopod.app — that
answer with your server's private address. Anyone can look the name up; only a
machine on your network can reach what it points at.
So remote access is a reachability problem, not a naming one. Nothing about the app, its URL, or its certificate changes. You only need a way to be on the network. Tailscale is the least fiddly one we know of, and it needs no open ports on your router.
1. Install Tailscale on the server¶
curl -fsSL https://tailscale.com/install.sh | sh
2. Advertise your home network¶
Find the subnet your server sits on (ip -4 addr — something like
192.168.1.40/24, whose subnet is 192.168.1.0/24), then:
sudo tailscale up --advertise-routes=192.168.1.0/24
Tailscale prints a link; open it to authenticate the machine. If it warns that
IP forwarding is off, run the two sysctl lines it gives you and re-run the
command.
3. Approve the route¶
In the Tailscale admin console, open the machine, then Edit route settings, and approve the subnet you advertised. Routes do nothing until approved.
4. Accept routes on your other devices¶
- iOS, macOS, Android — subnet routes are used automatically.
- Linux, Windows —
tailscale up --accept-routes.
Now, from anywhere, your laptop resolves photos.basement-nuc.mesopod.app to
192.168.1.40 exactly as it does at home, and Tailscale carries the packets
there. The certificate validates normally.
The DNS caveat¶
Routing is only half of it: the name still has to resolve to that private address wherever you are. Two things break it.
Your current resolver refuses private answers. A hotel, an office network, or a rebind-protecting router will return nothing for a public name that points inside a LAN — the same problem, and the same fix, as install.md's rebind section. Check what you got:
dig +short photos.basement-nuc.mesopod.app
An empty answer means the resolver dropped it, not that the record is missing.
Tailscale is overriding your DNS. If names resolve at home but stop when
Tailscale is up, look at DNS in the Tailscale admin console. Either turn off
Override local DNS, or add a split DNS entry for mesopod.app pointing at
a resolver that passes private answers through — your home router's address
works well here, since the subnet route already reaches it.
What this does not do¶
- It does not make your apps public. That is the point.
- It does not change any app URL, so a link you send yourself still works at home.
- It has nothing to do with Mesopod's own connection. The outpost dials out over HTTPS on its own and doesn't care whether Tailscale is up.