Skip to content

4. Remote access

Private network
Tailscale
Terminal
Remote Login (SSH)
Desktop
Screen Sharing

The goal: from your laptop or phone, anywhere, you can open a terminal on the Mac mini or see its screen — and nobody else on the internet can even see that it exists.

Tailscale: a private network for your devices

Section titled “Tailscale: a private network for your devices”

Tailscale connects your devices into a private network (a tailnet) using WireGuard. Each device gets a stable private address and name, and traffic goes directly between devices when possible.

  1. On the Mac mini, download the Standalone macOS app from tailscale.com/download (Tailscale recommends it over the Mac App Store version). Don’t install both.
  2. Open it, approve the system extension and VPN configuration when macOS asks, and sign in.
  3. In the Tailscale menu, open Settings and turn on the option to launch Tailscale at login (or add it to Login Items, see step 5). While you’re there, install the CLI integration so the tailscale command works in Terminal.
  4. Install Tailscale on your laptop and phone and sign in to the same account.
  5. In the Tailscale admin console, find the Mac mini, open its menu and choose Disable key expiry. Otherwise the server drops off your tailnet when its key expires (every 180 days by default) and you’d have to be there to re-authenticate.
  6. Rename the machine to your-mac-mini if it isn’t already, and make sure MagicDNS is on (DNS tab), so you can use the name instead of an address.

Check it from the Mac:

Terminal window
tailscale status
tailscale ip -4 # the Mac's tailnet address (100.x.y.z)

If Terminal says command not found, the CLI integration isn’t installed (or you have the Mac App Store version). The same command is inside the app: /Applications/Tailscale.app/Contents/MacOS/Tailscale status. health-check.sh falls back to it automatically.

  1. System Settings → General → Sharing → Remote Login → On.
  2. Click ⓘ next to it and set Allow access for to Only these users, with just your account.

From your laptop (on the tailnet):

Terminal window
ssh you@your-mac-mini

On your laptop, create a key if you don’t have one, and copy it to the server:

Terminal window
ssh-keygen -t ed25519 -C "laptop" # accept the default path; set a passphrase
ssh-copy-id you@your-mac-mini
ssh you@your-mac-mini # should log in without the account password

Then, on the Mac mini, turn off password logins. macOS’s sshd_config includes every file in /etc/ssh/sshd_config.d/, so add one:

Terminal window
sudo tee /etc/ssh/sshd_config.d/100-keys-only.conf >/dev/null <<'EOF'
PasswordAuthentication no
KbdInteractiveAuthentication no
EOF
sudo launchctl kickstart -k system/com.openssh.sshd

Keep your current SSH session open and test a new connection before logging out.

A handy entry in your laptop’s ~/.ssh/config:

Host mini
HostName your-mac-mini
User you

Now ssh mini just works.

  1. System Settings → General → Sharing → Screen Sharing → On.
  2. Click ⓘ and allow access for Only these users.

Connect from another Mac with the Screen Sharing app (in /System/Library/CoreServices/Applications/, or search Spotlight), entering your-mac-mini. From Finder you can also use Go → Connect to Server… and vnc://your-mac-mini.

  • Between two Apple silicon Macs on macOS 14 or later, choose High Performance in the Screen Sharing app for a much smoother, higher-resolution session.
  • From Windows, Linux, an iPad or a phone, use any VNC client over Tailscale. Some clients need VNC viewers may control screen with password turned on under Screen Sharing’s ⓘ options; set a strong password if you do.
  • Screen Sharing works when the Mac is at the login window or the screen is locked — you’ll just see the lock screen first.

Turn off Wi-Fi on your phone (so it’s on mobile data), open the Tailscale app, and:

  • SSH in with an SSH app (or from a laptop tethered to the phone), and
  • open a VNC or Screen Sharing session.

If both work, you can reach the server from anywhere.