Skip to content

Tailscale

M.R. Dula edited this page Oct 5, 2026 · 1 revision

Tailscale

v0.1.6 note. Live Ops shows a tailnet-serve card only when tailscale serve is active on the host, or the hub network is tailscale / funnel. A MagicDNS name in the database is not enough. Stale cards are deleted on the next GET /v1/gateways.

Railway and other public HTTPS hosts do not use Tailscale Serve. Pair against the public URL. See Railway.


Why raw 100.x fails

LAN (192.168.x) can work while the Tailscale interface is firewalled. http://100.x.x.x:8765 then times out from other tailnet nodes.

Fix: Tailscale Serve proxies https://<magicdns> to the local hub port.

tailscale serve --bg 8765
tailscale serve status

Serve-only (localhost bind)

export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode serve --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale serve --bg 8765

Clients:

https://<hostname>.tailnet-xxxx.ts.net
Authorization: Bearer $OPENGATEWAY_AUTH_TOKEN

Optional Tailscale identity headers are trusted on localhost Serve. Disable with --no-trust-tailscale-identity.


Dual path: LAN + cellular

Same process. LAN for Wi-Fi, Serve for phones off the LAN.

export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode public --via open --network lan \
  --host 0.0.0.0 --token "$OPENGATEWAY_AUTH_TOKEN" \
  --public-url "http://$(ipconfig getifaddr en0):8765"

tailscale serve --bg 8765
Card URL Phone
lan http://<lan-ip>:8765 Same Wi-Fi
tailnet-serve https://<host>.ts.net Cellular, Tailscale app on

Tap the card that matches the phone when generating the pair QR.


Docker

The container does not run the tailscale CLI. Serve must run on the Mac or Linux host that publishes 8765.

# .env
OPENGATEWAY_TAILSCALE_HOSTNAME=your-machine.tailnet-xxxx.ts.net

make docker-up on v0.1.6 runs tailscale serve --bg 8765 when the CLI is on the host. Confirm:

curl -fsS "https://$OPENGATEWAY_TAILSCALE_HOSTNAME/ping"

Send the bearer token if auth is on.


Funnel

World-reachable. Use a strong token.

opengateways serve --mode funnel --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale funnel --bg 8765

Checklist

  1. Hub is listening on the port you pass to tailscale serve.
  2. tailscale serve status shows a proxy, not "No serve config".
  3. Pair QR uses https://…ts.net, not http://100.x.
  4. Rotate the hub token if a machine leaves the tailnet.

Related: Gateways · Install · Production.

Canonical: docs/GATEWAYS.md · docs/PRODUCTION.md.

Clone this wiki locally