4. Remote access
- Private network
- Tailscale
- Terminal
- Remote Login (SSH)
- Desktop
- Screen Sharing
The goal: from your laptop or phone, anywhere, you can open a terminal on the Mac mini or see its screen — and nobody else on the internet can even see that it exists.
Tailscale: a private network for your devices
Section titled “Tailscale: a private network for your devices”Tailscale connects your devices into a private network (a tailnet) using WireGuard. Each device gets a stable private address and name, and traffic goes directly between devices when possible.
- On the Mac mini, download the Standalone macOS app from tailscale.com/download (Tailscale recommends it over the Mac App Store version). Don’t install both.
- Open it, approve the system extension and VPN configuration when macOS asks, and sign in.
- In the Tailscale menu, open Settings and turn on the option to launch Tailscale at login (or add it
to Login Items, see step 5). While you’re there, install the
CLI integration so the
tailscalecommand works in Terminal. - Install Tailscale on your laptop and phone and sign in to the same account.
- In the Tailscale admin console, find the Mac mini, open its menu and choose Disable key expiry. Otherwise the server drops off your tailnet when its key expires (every 180 days by default) and you’d have to be there to re-authenticate.
- Rename the machine to
your-mac-miniif it isn’t already, and make sure MagicDNS is on (DNS tab), so you can use the name instead of an address.
Check it from the Mac:
tailscale statustailscale ip -4 # the Mac's tailnet address (100.x.y.z)If Terminal says command not found, the CLI integration isn’t installed (or you have the Mac App Store
version). The same command is inside the app:
/Applications/Tailscale.app/Contents/MacOS/Tailscale status. health-check.sh falls back to it
automatically.
Remote Login (SSH)
Section titled “Remote Login (SSH)”- System Settings → General → Sharing → Remote Login → On.
- Click ⓘ next to it and set Allow access for to Only these users, with just your account.
From your laptop (on the tailnet):
ssh you@your-mac-miniUse keys instead of passwords
Section titled “Use keys instead of passwords”On your laptop, create a key if you don’t have one, and copy it to the server:
ssh-keygen -t ed25519 -C "laptop" # accept the default path; set a passphrasessh-copy-id you@your-mac-minissh you@your-mac-mini # should log in without the account passwordThen, on the Mac mini, turn off password logins. macOS’s sshd_config includes every file in
/etc/ssh/sshd_config.d/, so add one:
sudo tee /etc/ssh/sshd_config.d/100-keys-only.conf >/dev/null <<'EOF'PasswordAuthentication noKbdInteractiveAuthentication noEOFsudo launchctl kickstart -k system/com.openssh.sshdKeep your current SSH session open and test a new connection before logging out.
A handy entry in your laptop’s ~/.ssh/config:
Host mini HostName your-mac-mini User youNow ssh mini just works.
Screen Sharing
Section titled “Screen Sharing”- System Settings → General → Sharing → Screen Sharing → On.
- Click ⓘ and allow access for Only these users.
Connect from another Mac with the Screen Sharing app (in /System/Library/CoreServices/Applications/,
or search Spotlight), entering your-mac-mini. From Finder you can also use Go → Connect to Server…
and vnc://your-mac-mini.
- Between two Apple silicon Macs on macOS 14 or later, choose High Performance in the Screen Sharing app for a much smoother, higher-resolution session.
- From Windows, Linux, an iPad or a phone, use any VNC client over Tailscale. Some clients need VNC viewers may control screen with password turned on under Screen Sharing’s ⓘ options; set a strong password if you do.
- Screen Sharing works when the Mac is at the login window or the screen is locked — you’ll just see the lock screen first.
Test from outside your home
Section titled “Test from outside your home”Turn off Wi-Fi on your phone (so it’s on mobile data), open the Tailscale app, and:
- SSH in with an SSH app (or from a laptop tethered to the phone), and
- open a VNC or Screen Sharing session.
If both work, you can reach the server from anywhere.