User manual / Remote access

Remote access

Reach the appliance from outside your network with WireGuard, Cloudflare Tunnel, Tailscale or Dynamic DNS.

On this page
  1. Methods by edition
  2. Before you turn a method on
  3. Fields by method
  4. Set up WireGuard
  5. Secrets
  6. Turning a method off

Settings › Remote access makes the appliance reachable from outside your local network. It is for administrators. Every method publishes the management interface only (sign-in, canvas and Settings). It never exposes anything inside a running environment; opening an application inside an environment is a separate, per-device action.

Methods by edition#

Choose a method from the Method list. A method that is on shows · on after its name. The page then shows only that method's card.

MethodWhat it doesEditions
WireGuard VPNOpens a VPN listener on the appliance. The appliance prepares peer configurations; you give each one to a device as a file or QR codeCommunity, Lite, Pro
Cloudflare TunnelPublishes the management interface at your Cloudflare hostname, using your Cloudflare accountLite, Pro
TailscaleJoins the appliance to your Tailscale networkLite, Pro
Dynamic DNSKeeps a public hostname pointed at your site's public addressLite, Pro

Cloudflare Tunnel, Tailscale and Dynamic DNS use your own accounts with those services. On Community the list offers WireGuard only.

Before you turn a method on#

Each method has an on/off switch at the top of its card. Each method changes who can reach the sign-in page. ONEP asks you to confirm, and says what will happen:

MethodWho can reach the appliance
WireGuard VPNA VPN listener opens on a UDP port. It becomes reachable once you forward that port on your router. Only devices with a peer configuration can connect.
Cloudflare TunnelThe management interface is reachable over the public internet at your Cloudflare hostname. Anyone with the URL reaches the ONEP sign-in page. Environments stay isolated.
TailscaleEvery device on that tailnet can reach the management interface. Nothing becomes publicly reachable.
Dynamic DNSA public DNS name points at your site's public address. The appliance is reachable only once you also forward a port on your router.
Protect the sign-in page

With a public method, the sign-in page is on the internet. Use a strong password and turn on two-factor authentication in Settings › Account first.

Fields by method#

MethodFields
WireGuard VPNListen port and Server address (what peers connect to: a LAN address, public address or DNS name; leave it empty to detect the public address)
Cloudflare TunnelTunnel token from your Cloudflare account, and Public hostname (optional)
TailscaleAuth key from your Tailscale admin console, and Machine name (optional)
Dynamic DNSProvider (Cloudflare DNS or DuckDNS), Zone (required for Cloudflare DNS, empty for DuckDNS), Hostname and API token

Choose Save on the card to store the fields. A card with edits you have not saved shows Unsaved changes, and ONEP asks before you leave the tab with edits unsaved.

Set up WireGuard#

  1. Open Settings › Remote access and choose WireGuard VPN from the Method list.
  2. Set the Listen port and the Server address and choose Save.
  3. Turn it on with the switch on the card and confirm. The appliance opens its VPN listener on the UDP port shown. The switch reads Starting… until the service confirms.
  4. Forward the port on your router to the appliance, if you connect from outside your network.
  5. Hand out the peers. The Peers list shows each peer with a QR code. Scan the QR code in the WireGuard app on a phone, or choose Download .conf and import the file on a laptop. Show displays the configuration text.

Each peer configuration is for one device. Rotate keys replaces the keys for every peer: every configuration issued so far stops working, and new ones appear in the list. Rotating needs WireGuard to be on.

Secrets#

A tunnel token, Tailscale auth key or Dynamic DNS API token that you paste in is stored on the appliance and never shown again. The field then reads saved — paste to replace. To change one, paste a new value.

Turning a method off#

ONEP warns that remote access through that method stops, and that if you are connected through it now, your session will end. Make sure you can reach the appliance another way, for example from your LAN, before you turn off the method you are using.

If a method does not confirm within 90 seconds, the page says so and shows the state the service reports. The Exposure card on Status shows which methods are active.

Something wrong or missing on this page? Write to hello@onep.io.