← Back to all guides

Your address with Tailscale

MarkdownOpen in ClaudeOpen in ChatGPT

You already have a temporary address; this makes it permanent.

At the end, the runner has an address like https://loopgate-runner.your-tailnet.ts.net that only your team's own laptops can open: Tailscale builds a private network between your devices, called a tailnet, and nothing outside it can reach the runner.

Set this up with your agent

Copy this to a coding agent on your laptop. It runs the commands and checks each step with you; what you sign in to, press or paste stays yours.

This is for a coding agent that can run commands on my laptop (Claude Code, Codex, Cursor), not a chat website.
Walk me through Loopgate's guide "Your address with Tailscale": https://loopgate.dev/runner/guides/address-tailscale.md. The guides it links to are beside it, each ending in .md.
Run its commands yourself, on my laptop or on my box over SSH as the guide says, one step at a time, and check each "You should see" line before the next step.
These are mine: tell me when it is my turn, wait for me, and never ask me to type them into this chat. Signing in to anything (the portal, a cloud console, Slack, GitHub), pressing Add a runner, every token and password, my AI subscription's device code, and making the Slack app.
If I paste you the portal's install line, run it on the box: its token works once, for an hour.

At a glance

Time: 15 minutes, plus a few minutes on each teammate's laptop.

What you need:

  • The runner, started in Any Linux computer with Docker
  • A Tailscale account (check Tailscale's pricing for the size of your team)
  • Tailscale on the laptop of each person who opens the runner

Steps:

  1. Put Tailscale on the box
  2. Turn on HTTPS once
  3. Serve the runner
  4. Let your team in

Steps

  1. On the box, install Tailscale with its own script.

    curl -fsSL https://tailscale.com/install.sh | sh

    You should see: Installation complete! and a hint to run tailscale up.

  2. Join the box to your tailnet.

    sudo tailscale up

    You should see: To authenticate, visit: and a web address. Open it on your laptop, sign in to Tailscale and approve the box; the command on the box then finishes.

  3. On your laptop, open the admin console at https://login.tailscale.com/admin/dns and check that MagicDNS is enabled.

    MagicDNS gives each device a name; it is on for most new tailnets.

  4. Scroll to HTTPS Certificates, press Enable HTTPS and confirm.

    You should see: HTTPS Certificates marked as enabled.

    It is off until an admin turns it on. This was the step we missed ourselves.

  5. On the box, send the tailnet's HTTPS traffic to the runner.

    sudo tailscale serve --bg 4311

    You should see: Available within your tailnet: followed by an address ending .ts.net/. That is the runner's address; copy it.

  6. Give the runner that address, with no slash at the end, and restart it.

    cd ~/loopgate && echo "LOOPGATE_RUNNER_URL=https://loopgate-runner.your-tailnet.ts.net" >> runner.env
    docker compose up -d runner

    You should see: the portal's Devices row shows the new address, no longer marked temporary.

  7. In the admin console, open Users and invite each teammate.

  8. Each teammate installs Tailscale from https://tailscale.com/download and signs in to your tailnet.

    You should see: the box loopgate-runner in their Tailscale device list.

  9. Each teammate opens the Loopgate portal, opens Devices and presses Open on the runner's row.

    You should see: the workbench. The very first visit may take a few seconds while Tailscale makes the certificate.

    Their browser then stays signed in for thirty days from its last use, while Tailscale is on.

Check

The runner names its .ts.net address, and Settings → General no longer says temporary:

cd ~/loopgate && docker compose logs runner

You should see: Runner ready at https://…ts.net.

Next

Connect Slack, if you have not yet. Links it posts from now on survive a restart.

If something is off

  • The address does not open. Check that Tailscale is on and signed in to your tailnet on that laptop.
  • tailscale serve says HTTPS is not enabled. Turn on HTTPS Certificates (step 4), then run step 5 again.
  • "This link expired. Open the runner from the portal again." Press Open in Devices again.

Doing it by hand

By hand has every line of runner.env and tunnel.env.