Introduction¶
In agent development, local debugging and real-time status monitoring are frequent operations. DSH’s Web UI provides an intuitive interface, but it usually needs to be opened on the local machine. When a shared network is unavailable or remote access is required, accessing the local interface directly often requires complex port forwarding or VPN configuration.
The dsh-remote-tailscale plugin uses the virtual network established by Tailscale to expose the local DSH Web UI to other devices in the same tailnet. It does not rely on a public network and uses only Tailscale’s secure channel for connections.
Plugin Overview¶
dsh-remote-tailscale is a DSH plugin maintained by hxt9805. It exposes the local DSH Web UI to other devices in the same Tailscale tailnet.
The core value of the plugin is that it does not require a shared LAN or Wi-Fi. As long as both devices are signed in to the same Tailscale account, the local DSH interface can be accessed over the HTTPS port.
Core Features¶
- Cross-device access: Open the local DSH Web UI from another device via Tailscale.
- Secure channel: Uses only the HTTPS port (default 8455); Funnel is not enabled, and no public internet exposure is used.
- Loopback proxy: Starts a local reverse proxy (default
127.0.0.1:3091). - Account authentication: Based on the Tailscale account, with no additional password required.
- Optional enablement: Provides a settings toggle, disabled by default, with an “auto-enable” option.
- Status monitoring: Provides a local status endpoint to make it easier for other tools to detect the plugin’s status.
Installation and Enablement¶
On a machine with DSH and Tailscale already installed, run the following command to install the plugin:
dsh plugin --profile web add github:hxt9805/dsh-remote-tailscale
After installation, restart the DSH process to load the plugin:
dsh web
Typical Usage¶
- Prepare the environment: Install DSH and Tailscale on the current machine and another target device, and sign in with the same Tailscale account on both. The two devices do not need to be on the same LAN.
- Enable remote access: In the local DSH Web UI, go to Settings -> Remote Access, and click the switch to enable the feature.
- Connect: On the other device, directly access the URL displayed on the page (formatted like
https://<machine>.<tailnet>.ts.net:8455/), or scan the QR code provided on the page.
Notes¶
- Port usage: The plugin uses port 8455 by default and does not occupy Tailscale’s default HTTPS port 443.
- Environment variable overrides:
- The loopback port can be overridden with the
DSH_TS_PORTenvironment variable. - The HTTPS service port can be overridden with the
DSH_TS_SERVE_PORTenvironment variable.
- The loopback port can be overridden with the
- WSL environment: When used under WSL, mirrored networking support is required so that the Tailscale process on Windows can connect to the DSH process inside WSL.
- Windows firewall: On Windows systems, ensure that the firewall allows inbound Tailscale connections; otherwise, other devices in the tailnet cannot connect.
- Access permissions: The plugin only allows devices signed in to the same Tailscale account to access it.
- License: This project is licensed under the MIT License.
Conclusion¶
dsh-remote-tailscale provides DSH users with a way to remotely access the local Web UI without configuring additional port forwarding. It establishes a secure channel through existing Tailscale connections, making it suitable for developers who need to seamlessly switch debugging environments across multiple devices.