devmachine

Concepts

Reaching your server

After setup, devmachine reaches your server at its public address, with a key only you have. That is enough to start. This page covers two ways to do more: a private network, so your server is reachable even when the public address is not, and private access to apps you do not want on the internet.

The public address

This is what setup gives you. Password logins are off, so only your key gets in. Add the firewall and fail2ban packages to close every port you do not use and to block addresses that keep guessing:

devmachine packages add firewall
devmachine packages add fail2ban
devmachine sync

A private network with Tailscale

Tailscale puts your computer and your server on a private network of your own, called a tailnet. Your server gets a private address that only your devices can reach. It keeps working when the public address has trouble, and on a network that blocks SSH.

  1. Add Tailscale to the server:

    devmachine packages add tailscale
    devmachine sync
  2. Sign the server in to your Tailscale account. This opens Tailscale’s own sign-in on the server; finish it in your browser:

    devmachine login tailscale
  3. Install Tailscale on your computer and sign in to the same account.

  4. Tell devmachine to try the private address first. In config.yml, add one line above the public address, with the server’s name in your tailnet (tailscale status on your computer lists it):

    machines:
      - name: main
        hosts:
          - tailscale:main
          - 203.0.113.10

devmachine tries the addresses in order and uses the first that answers. If Tailscale is off on your computer, it skips that line and uses the public address, so you are never locked out. See addresses and fallback.

To send your computer’s traffic through the server, set tailscale.exit_node: true on the machine and sync.

Any other private network

devmachine does not need Tailscale. With any VPN that gives your server an address your computer can reach — WireGuard, ZeroTier, a provider’s private network — add that address to hosts: the same way, first in the list.

Apps you do not want on the internet

A dev server, a database viewer, a mail catcher: these should be reachable by you, not by anyone who guesses a URL. Open a tunnel instead of publishing them:

devmachine tunnel alice 3000

The app answers at localhost:3000 on your computer until you press Ctrl-C. Nothing is published: no DNS record, no open port. See publishing for when to use expose instead.