Skip to content
Niftyhelp 2026.10.1-beta.1 Support

Beta This is the help for Nifty 2026.10.1-beta.1, which isn't released yet. Help for the current release

Tailscale

Reach Nifty over HTTPS from your own devices only, with no ports opened.

On this page

With Tailscale, Nifty is at https://<machine>.<tailnet>.ts.net, reachable from devices on your tailnet and nothing else. Tailscale provides the certificate.

Before you start

  • Tailscale is installed and up on the server (sudo tailscale up).
  • MagicDNS and HTTPS Certificates are on, in Tailscale's admin console under DNS.

Set it up

The easiest way is install.sh: choose Over Tailscale, or pass --tailscale (Install on Linux).

To switch an existing server:

  1. Let the nifty user manage tailscale serve:

    sudo tailscale set --operator=nifty
  2. In /etc/nifty.env, set:

    NIFTY_TAILSCALE_SERVE=on

    Nifty must listen on loopback, as it does by default (127.0.0.1:4000). It works out its address; if you set NIFTY_ORIGIN, it must match.

  3. Restart: sudo systemctl restart nifty.

Each time it starts, Nifty runs tailscale serve to pass https://<machine>.<tailnet>.ts.net to itself. To use another port, set NIFTY_TAILSCALE_PORT=8443; Nifty won't take a port that serves something else.

The operator setting

Note:

Tailscale's operator can change any Tailscale setting on the machine: log it out, change exit nodes, other serves. Making nifty the operator means a compromised Nifty could too. There's one operator, so this replaces any other.

If you'd rather not, run tailscale serve yourself, once, as root (install.sh --tailscale --no-tailscale-operator does this):

sudo tailscale serve --bg --https=443 http://127.0.0.1:4000

Then, in /etc/nifty.env, leave NIFTY_TAILSCALE_SERVE off and set:

NIFTY_ORIGIN=https://<machine>.<tailnet>.ts.net
NIFTY_TRUSTED_PROXIES=127.0.0.1

Tailscale keeps the serve across restarts, but if it's ever removed, run the command again.

Check it

tailscale serve status

Serves stay after Nifty stops. To remove Nifty's: sudo tailscale serve --https=443 off.

Menu

2026.10.1-beta.1Contact support