Skip to main content
Version: 2026.8.1

Tailscale only

Tailscale is the recommended way to run Cobblr with real HTTPS and nothing exposed to the internet. It puts your devices on a private mesh, hands each one an auto-renewed ts.net certificate, and the same URL works at home or away. There are two ways to ride it. Choose own hostname unless the box is already a tailnet node you want to serve from directly.

The full walkthrough lives in Install. This page is the map of the two ways, so you can pick before you open that guide.

Own hostname (tsnet)​

The bundled proxy joins your tailnet as its own node and serves the address you choose. In .env:

COBBLR_SITE_ADDRESS=cobblr.your-tailnet.ts.net
COMPOSE_PROFILES=caddy
COBBLR_TLS_MODE=tsnet
  • The box needs no Tailscale install. Only the devices you browse from do. cobblr.your-tailnet.ts.net shows up as the node cobblr.
  • Approve it once. On first start the proxy prints a one-time sign-in link in its logs (docker compose logs caddy | grep -iE 'to authenticate|login.tailscale'). Open it, approve the new node, and you're done. There is no key to mint.
  • For an unattended join, add a reusable auth key as TS_AUTHKEY=tskey-auth-... and it skips the approval step.
  • The setup builder produces this when you pick Tailscale, then Own hostname.
  • The address must be the node's own full name, tailnet included. Tailscale issues a certificate for nothing else, and a mismatch leaves the node Connected while the browser fails. See SSL_ERROR_INTERNAL_ERROR_ALERT.
  • It needs MagicDNS and HTTPS certificates enabled on your tailnet, both one-time steps covered in Install.

The server's own name (tailscale serve)​

If the box is already on your tailnet, skip the bundled proxy and let the machine serve Cobblr under its own name:

COBBLR_SITE_ADDRESS=myserver.your-tailnet.ts.net
COMPOSE_PROFILES=
  1. Bring the stack up. It runs without Caddy, and the web container stays on loopback.
  2. Run sudo tailscale serve --bg 8088 on the box. tailscale serve on the host publishes it with a real certificate.

This is the Server's name option in the builder. The steps, including reaching it from outside the tailnet with tailscale funnel, are in Install.

Which to pick​

  • Own hostname is the easier path and gives the tidier URL. It keeps Tailscale off the host and gives you a clean per-service URL.
  • The serve variant fits when the machine is already on the tailnet and you would rather not run a second proxy.
Why Tailscale is the recommendation

The ts.net certificate is what the phone camera needs, and the private network doubles as secure remote access.