docsget pocketty

Get Started

Connect with Tailscale

Give each host a Tailscale name that works from anywhere, and sign in with your tailnet identity.

pocketty speaks plain SSH. To reach a host from a café or a train, the phone needs an address for it that does not change. Tailscale gives each host a name in your tailnet, the private network of your Tailscale account, such as studio.tail1234.ts.net. No ports open to the internet. This works for a computer at home and for a cloud VM.

For a cloud VM, Tailscale has two more advantages. The name stays the same when the provider moves the VM to a new address. And the connection does not go through the provider’s SSH proxy. Some proxies, such as boxd’s, cannot carry the connection that pocketty uses for herdr.

1. Set Up Tailscale

  1. Install Tailscale on your iPhone or iPad, and sign in.
  2. Put the host on your tailnet, with the same Tailscale account:
    • A Mac or a desktop computer: install the Tailscale app, and sign in.

    • A Linux server or a cloud VM: in a shell on it, run:

      curl -fsSL https://tailscale.com/install.sh | sh
      sudo tailscale up --ssh --hostname=shed

      Change shed to the name you want, and open the link that tailscale up shows. --ssh turns on Tailscale SSH.

  3. Turn on MagicDNS in the Tailscale admin console. Each machine then gets a name like studio.tail1234.ts.net. The console shows it under Machines.

2. Add the Host

Tap + on the host list. Type the host’s Tailscale name as the Address, and your user on the host as the User. Then choose how pocketty signs in:

Sign In with Tailscale SSH

With Tailscale SSH, pocketty signs in with your tailnet identity, so you do not put a key on the host. Set Sign in with to Tailscale SSH, and tap Save.

Tailscale SSH runs on Linux hosts and cloud VMs. The Tailscale app for Mac cannot be a Tailscale SSH host, so for a Mac, use a code or a setup command.

Your tailnet policy may ask you to confirm a login in the browser. pocketty then shows Approve this login on the host screen. Tap Approve, confirm in the page that opens, and pocketty goes on by itself.

Tailscale SSH shows the host’s own SSH host key. If a cloud provider makes new host keys, for example when boat.dev resumes a sandbox, pocketty shows Trust new key. See When a Host Key Changes.

How Nearby Uses It

When the phone and the computer share a Wi-Fi network, the computer shows up under Nearby. A Mac shows up when Remote Login is on. A Linux host shows up when it runs the daemon and avahi. That list comes from Bonjour on the local network. When you tap a computer that runs the daemon, pocketty saves its MagicDNS name, so the host works from anywhere. For a Mac without the daemon, pocketty saves its address on the local network.

Remote Login on a Mac

pocketty connects to the Mac’s own SSH server. Turn it on in System Settings → General → Sharing → Remote Login.

Without Tailscale

Any address the phone can reach works: a LAN address at home, a VPN, or a public server. A code needs Tailscale, so connect with a setup command instead.

    Type to search keys, notifications, the CLI, and more.