Operations

Remote Access

Choose between a private VPN, an HTTPS reverse proxy, and direct exposure.

ScenarioSolutionPublic Exposure
Personal use or small teamTailscale / Private VPNNone
Managed public domainHTTPS reverse proxy + NasDash authenticationPort 443 only
Port 2504 directly on the InternetNot recommendedPublic application port

For Tailscale, install the client on the NasDash host and the authorized devices, apply ACLs, and then open http://IP_TAILSCALE:2504. The Tailscale widget is independent of this access method: see the three Tailscale use cases.

For a domain, place NasDash behind a reverse proxy, enable HTTPS, maintain strong passwords, and restrict administration to trusted users.

Public does not mean unprotected

Public reader mode exposes authorized resources to anyone who can reach the instance. Verify categories, IPs, ports, calendars, and Docker hosts before enabling it.