Markover docs
GitHub

Advanced setup example

Remote access with Tailscale Serve

Tailscale Serve can add a private HTTPS route from one authorized device in your tailnet to Markover's loopback-only remote gateway. This example keeps the route private, leaves existing handlers alone, and keeps Tailscale Funnel off.

This is an advanced example, not automatic onboarding. Markover does not configure Tailscale, choose a public name, edit your tailnet policy, or install and remove Serve handlers for you. Review every placeholder and your current Serve configuration before running a command.

Before you configure Serve

  1. Install Tailscale 1.92 or newer on the Mac running canonical Markover and on the remote client device. Sign both into the same tailnet. Run tailscale version on each device to check.
  2. Choose one unused tailnet HTTPS port for Markover. A dedicated port avoids replacing an existing root handler or another application's route.
  3. Use Markover's fixed product endpoint, http://127.0.0.1:39831. Keep that target on loopback; do not bind Markover directly to a LAN or Tailscale address.
  4. Ask your tailnet administrator to authorize only the intended remote device to reach that HTTPS port and forward lastobelus.com/cap/markover-remote-client. See Tailscale's Serve identity headers and grants reference.

First inspect the existing private and public configuration:

tailscale serve status --json
tailscale funnel status --json

Continue only when your chosen HTTPS port is unused. Preserve every existing handler.

Add the private handler

Set the placeholder locally to the dedicated tailnet HTTPS port you selected:

export DEDICATED_HTTPS_PORT='replace-with-an-unused-port'

Then add one background Serve handler:

tailscale serve --bg \
  --https="${DEDICATED_HTTPS_PORT}" \
  --accept-app-caps=lastobelus.com/cap/markover-remote-client \
  http://127.0.0.1:39831

Tailscale Serve is private to your tailnet. Funnel is the separate public-internet feature and is not part of this setup.

Verify the result

Read the configuration again:

tailscale serve status --json
tailscale funnel status --json

Confirm all of these facts before using the remote client:

Enable Allow the authorized remote Markover client in canonical Markover only when you want the gateway to accept requests. Disabling Markover closes its loopback gateway but deliberately leaves the Tailscale handler in place.

Keep application routes separate

Tailscale Serve configuration is shared by applications using the same Tailscale configuration on a Mac. Each application should inspect Serve status before changing it, refuse ports that already have a handler, and remove only a handler it created that still exactly matches its expected route.

An unavailable backend is still owned. Markover may be disabled, stopped, or restarting while its persistent Serve handler remains configured. A timeout, connection refusal, or gateway error is not permission to replace that handler.

Application shutdown should close the application's loopback server, not its persistent Serve handler. Avoid broad reset commands on a Mac where more than one application uses Serve.

Remove the handler explicitly

When you intentionally retire this Markover route, inspect Serve status one last time. Continue only if the selected port, root path, target, and forwarded capability still match the Markover handler you configured. Then disable that exact port:

tailscale serve --https="${DEDICATED_HTTPS_PORT}" off

Read Serve and Funnel status again to confirm that only the intended handler was removed and Funnel remains off.