Operations
Remote Access
Choose between a private VPN, an HTTPS reverse proxy, and direct exposure.
Recommended Choice
| Scenario | Solution | Public Exposure |
|---|---|---|
| Personal use or small team | Tailscale / Private VPN | None |
| Managed public domain | HTTPS reverse proxy + NasDash authentication | Port 443 only |
Port 2504 directly on the Internet | Not recommended | Public application port |
For Tailscale, install the client on the NasDash host and the authorized devices, apply ACLs, and then open http://IP_TAILSCALE:2504. The Tailscale widget is independent of this access method: see the three Tailscale use cases.
For a domain, place NasDash behind a reverse proxy, enable HTTPS, maintain strong passwords, and restrict administration to trusted users.
Public does not mean unprotected
Public reader mode exposes authorized resources to anyone who can reach the instance. Verify categories, IPs, ports, calendars, and Docker hosts before enabling it.