Tailscale for remote server access
Tailscale creates a private mesh VPN (built on WireGuard) between your devices with almost no configuration — the easiest way to securely reach a home server from anywhere without opening ports on your router.
1Install Tailscale
curl -fsSL https://tailscale.com/install.sh | sh2Authenticate the device
This opens a link to log in with your Tailscale account (Google/Microsoft/GitHub/email) and add this machine to your private network.
sudo tailscale up3Install Tailscale on your other devices too
Repeat the same install+login on your phone, laptop, etc. -- once two devices are on the same Tailscale network (called a 'tailnet'), they can reach each other directly by a stable 100.x.x.x IP, from anywhere, with no port forwarding.
4(Optional) enable Magic DNS
Magic DNS lets you reach devices by a friendly name (e.g. home-server) instead of memorizing their Tailscale IP, configured from the Tailscale admin console.
The free tier covers up to 3 users and 100 devices, comfortably enough for personal/home use.