Advanced setup example
Remote access with Tailscale Serve
Tailscale Serve can add a private HTTPS route from one authorized device in your tailnet to Markover's loopback-only remote gateway. This example keeps the route private, leaves existing handlers alone, and keeps Tailscale Funnel off.
Before you configure Serve
- Install Tailscale 1.92 or newer on the Mac running canonical Markover and on the remote client device. Sign both into the same tailnet. Run
tailscale versionon each device to check. - Choose one unused tailnet HTTPS port for Markover. A dedicated port avoids replacing an existing root handler or another application's route.
- Use Markover's fixed product endpoint,
http://127.0.0.1:39831. Keep that target on loopback; do not bind Markover directly to a LAN or Tailscale address. - Ask your tailnet administrator to authorize only the intended remote device to reach that HTTPS port and forward
lastobelus.com/cap/markover-remote-client. See Tailscale's Serve identity headers and grants reference.
First inspect the existing private and public configuration:
tailscale serve status --json
tailscale funnel status --json
Continue only when your chosen HTTPS port is unused. Preserve every existing handler.
Add the private handler
Set the placeholder locally to the dedicated tailnet HTTPS port you selected:
export DEDICATED_HTTPS_PORT='replace-with-an-unused-port'
Then add one background Serve handler:
tailscale serve --bg \
--https="${DEDICATED_HTTPS_PORT}" \
--accept-app-caps=lastobelus.com/cap/markover-remote-client \
http://127.0.0.1:39831
Tailscale Serve is private to your tailnet. Funnel is the separate public-internet feature and is not part of this setup.
Verify the result
Read the configuration again:
tailscale serve status --json
tailscale funnel status --json
Confirm all of these facts before using the remote client:
- Your chosen HTTPS port has one root-path handler.
- Its target is the expected
http://127.0.0.1:…Markover gateway. - It forwards only
lastobelus.com/cap/markover-remote-client. - Every pre-existing Serve handler is unchanged.
- Funnel has no grant for the Markover port.
Enable Allow the authorized remote Markover client in canonical Markover only when you want the gateway to accept requests. Disabling Markover closes its loopback gateway but deliberately leaves the Tailscale handler in place.
Keep application routes separate
Tailscale Serve configuration is shared by applications using the same Tailscale configuration on a Mac. Each application should inspect Serve status before changing it, refuse ports that already have a handler, and remove only a handler it created that still exactly matches its expected route.
Application shutdown should close the application's loopback server, not its persistent Serve handler. Avoid broad reset commands on a Mac where more than one application uses Serve.
Remove the handler explicitly
When you intentionally retire this Markover route, inspect Serve status one last time. Continue only if the selected port, root path, target, and forwarded capability still match the Markover handler you configured. Then disable that exact port:
tailscale serve --https="${DEDICATED_HTTPS_PORT}" off
Read Serve and Funnel status again to confirm that only the intended handler was removed and Funnel remains off.