Concepts
Reaching your server
After setup, devmachine reaches your server at its public address, with a
key only you have. That is enough to start. This page covers two ways to do
more: a private network, so your server is reachable even when the public
address is not, and private access to apps you do not want on the internet.
The public address
This is what setup gives you. Password logins are off, so only your key gets
in. Add the firewall and fail2ban packages to close every port you do not
use and to block addresses that keep guessing:
devmachine packages add firewall
devmachine packages add fail2ban
devmachine sync
A private network with Tailscale
Tailscale puts your computer and your server on a private network of your own, called a tailnet. Your server gets a private address that only your devices can reach. It keeps working when the public address has trouble, and on a network that blocks SSH.
-
Add Tailscale to the server:
devmachine packages add tailscale devmachine sync -
Sign the server in to your Tailscale account. This opens Tailscale’s own sign-in on the server; finish it in your browser:
devmachine login tailscale -
Install Tailscale on your computer and sign in to the same account.
-
Tell devmachine to try the private address first. In
config.yml, add one line above the public address, with the server’s name in your tailnet (tailscale statuson your computer lists it):machines: - name: main hosts: - tailscale:main - 203.0.113.10
devmachine tries the addresses in order and uses the first that answers. If Tailscale is off on your computer, it skips that line and uses the public address, so you are never locked out. See addresses and fallback.
To send your computer’s traffic through the server, set
tailscale.exit_node: true on the machine and sync.
Any other private network
devmachine does not need Tailscale. With any VPN that gives your server an
address your computer can reach — WireGuard, ZeroTier, a provider’s private
network — add that address to hosts: the same way, first in the list.
Apps you do not want on the internet
A dev server, a database viewer, a mail catcher: these should be reachable by you, not by anyone who guesses a URL. Open a tunnel instead of publishing them:
devmachine tunnel alice 3000
The app answers at localhost:3000 on your computer until you press
Ctrl-C. Nothing is published: no DNS record, no open port. See
publishing for when to use expose instead.