Remote access
Reach the appliance from outside your network with WireGuard, Cloudflare Tunnel, Tailscale or Dynamic DNS.
On this page
Settings › Remote access makes the appliance reachable from outside your local network. It is for administrators. Every method publishes the management interface only (sign-in, canvas and Settings). It never exposes anything inside a running environment; opening an application inside an environment is a separate, per-device action.
Methods by edition#
Choose a method from the Method list. A method that is on shows · on after its name. The page then shows only that method's card.
| Method | What it does | Editions |
|---|---|---|
| WireGuard VPN | Opens a VPN listener on the appliance. The appliance prepares peer configurations; you give each one to a device as a file or QR code | Community, Lite, Pro |
| Cloudflare Tunnel | Publishes the management interface at your Cloudflare hostname, using your Cloudflare account | Lite, Pro |
| Tailscale | Joins the appliance to your Tailscale network | Lite, Pro |
| Dynamic DNS | Keeps a public hostname pointed at your site's public address | Lite, Pro |
Cloudflare Tunnel, Tailscale and Dynamic DNS use your own accounts with those services. On Community the list offers WireGuard only.
Before you turn a method on#
Each method has an on/off switch at the top of its card. Each method changes who can reach the sign-in page. ONEP asks you to confirm, and says what will happen:
| Method | Who can reach the appliance |
|---|---|
| WireGuard VPN | A VPN listener opens on a UDP port. It becomes reachable once you forward that port on your router. Only devices with a peer configuration can connect. |
| Cloudflare Tunnel | The management interface is reachable over the public internet at your Cloudflare hostname. Anyone with the URL reaches the ONEP sign-in page. Environments stay isolated. |
| Tailscale | Every device on that tailnet can reach the management interface. Nothing becomes publicly reachable. |
| Dynamic DNS | A public DNS name points at your site's public address. The appliance is reachable only once you also forward a port on your router. |
With a public method, the sign-in page is on the internet. Use a strong password and turn on two-factor authentication in Settings › Account first.
Fields by method#
| Method | Fields |
|---|---|
| WireGuard VPN | Listen port and Server address (what peers connect to: a LAN address, public address or DNS name; leave it empty to detect the public address) |
| Cloudflare Tunnel | Tunnel token from your Cloudflare account, and Public hostname (optional) |
| Tailscale | Auth key from your Tailscale admin console, and Machine name (optional) |
| Dynamic DNS | Provider (Cloudflare DNS or DuckDNS), Zone (required for Cloudflare DNS, empty for DuckDNS), Hostname and API token |
Choose Save on the card to store the fields. A card with edits you have not saved shows Unsaved changes, and ONEP asks before you leave the tab with edits unsaved.
Set up WireGuard#
- Open Settings › Remote access and choose WireGuard VPN from the Method list.
- Set the Listen port and the Server address and choose Save.
- Turn it on with the switch on the card and confirm. The appliance opens its VPN listener on the UDP port shown. The switch reads Starting… until the service confirms.
- Forward the port on your router to the appliance, if you connect from outside your network.
- Hand out the peers. The Peers list shows each peer with a QR code. Scan the QR code in the WireGuard app on a phone, or choose Download .conf and import the file on a laptop. Show displays the configuration text.
Each peer configuration is for one device. Rotate keys replaces the keys for every peer: every configuration issued so far stops working, and new ones appear in the list. Rotating needs WireGuard to be on.
Secrets#
A tunnel token, Tailscale auth key or Dynamic DNS API token that you paste in is stored on the appliance and never shown again. The field then reads saved — paste to replace. To change one, paste a new value.
Turning a method off#
ONEP warns that remote access through that method stops, and that if you are connected through it now, your session will end. Make sure you can reach the appliance another way, for example from your LAN, before you turn off the method you are using.
If a method does not confirm within 90 seconds, the page says so and shows the state the service reports. The Exposure card on Status shows which methods are active.