Safe way home, no open ports
From taking inventory of your tailnet, installing the app, and joining the tailnet, all the way to private remote access, least privilege, Serve, subnet router basics, troubleshooting and maintenance. 12 chapters, 10 minutes each. The Sales Handbook, Prompt Library and Skill Handbook are in the Resource Hub.
Basics: understanding secure remote access
Before you start
Start by deciding who may reach your Home Assistant, which devices join the tailnet, and what this guide deliberately leaves out.
02Install the app
Find Tailscale on the Home Assistant Apps page, install it and start it; do not guess at settings, and do not rush to make the service public.
03Join the tailnet
Use the Tailscale app's Web UI to make this Home Assistant a member of your tailnet, then confirm that it appears in the admin console.
04Status and logs
Before you change any network option, learn to read the app's status and logs; that is the shortest path when troubleshooting.
Daily use: private remote access
Open HA remotely
Let only phones and computers that have joined the tailnet open HA, and set up a verifiable, private remote-access workflow first.
06Manage devices
Treat Home Assistant, your phone and your laptop as Machines you manage: name them, audit them, deauthorize the devices you no longer use, and check key expiry.
07Least privilege
Tailscale is not a reason to assume "install it and everything can reach everything". Check the policy in the admin console first, then write the access scope to be exactly what is needed.
08Serve
When you need a clean HTTPS entry point, first understand the security difference between Serve and Funnel; this guide covers tailnet-only Serve and nothing else.
Advanced: subnet router basics
Subnet router
Let this HA host advertise one subnet of your home LAN only when you are sure you need it; this chapter covers only basic one-way access to a single subnet.
10Approve routes
An advertised route is not a usable route yet: approve it in Machines, then verify from another tailnet device.
Maintenance: stable use and troubleshooting
Daily use
Turn remote use into a repeatable habit: confirm Tailscale first, then open HA, and know where to check when the connection drops.
12Troubleshooting and maintenance
Work through one outside-in checklist to handle connection failures, routes you cannot see, expired logins and problems that appear after a settings change.