Skip to content

Network and TLS ​

On the host computer ​

Docker publishes the proxy on 127.0.0.1:8317, reachable as http://localhost:8317. This avoids a public listener. The proxy still requires the client key for API requests and the separate management password for its management API.

Use URL=http://localhost:8317 on Make client and operations commands when you want to bypass portless. The containers use their own Docker network, so loopback does not depend on Tailscale being signed in.

On your local network ​

When portless is installed, make up starts its HTTPS proxy in LAN mode and registers https://hara.local. LOCAL_NAME changes the name:

bash
LOCAL_NAME=my-proxy make up
make ops models URL=https://my-proxy.local

Keep this name setting for later up, status, and down commands. Other devices must be on the same local network and able to use mDNS. Guest Wi-Fi and client isolation can block discovery or connections.

LAN mode applies to all portless apps

Starting portless in LAN mode makes every portless app on this computer reachable from the local network, not only Hara. make down removes the Hara alias but leaves the shared portless proxy running in LAN mode.

To return the shared proxy to local-only mode:

bash
portless proxy stop
PORTLESS_LAN=0 portless proxy start

Trust the local certificate ​

portless uses its own certificate authority. Node clients on the host need:

bash
export NODE_EXTRA_CA_CERTS="$HOME/.portless/ca.pem"

The Claude Make helper supplies this setting. Other devices need to trust the public ca.pem certificate in their own trust store. Transfer it through a trusted channel and verify its source. Do not transfer the CA private key, and do not disable TLS verification to work around trust problems.

On your tailnet ​

The Tailscale container serves HTTPS at https://cliproxy.<your-tailnet>.ts.net. Enable MagicDNS and HTTPS certificates in your own tailnet, then authorize the device using the login link from make status.

TS_HOSTNAME changes the device name. An optional TS_AUTHKEY can enroll it without the interactive login link; keep that key in your private environment and never in Compose or Git. Tailnet HTTPS certificates do not require the portless CA.

bash
make ops ws-smoke TS_URL=https://cliproxy.YOUR-TAILNET.ts.net

Replace the example hostname with the address from your own status output. Tailnet ACLs should allow only the devices and people who need this service. Management is reachable through these same addresses because the proxy template enables remote management; protect the management password and restrict network access.

.local mDNS names do not cross Tailscale. When away from your LAN, use the tailnet address. Avoid public port forwarding or Tailscale Funnel for this credential-bearing proxy.

Availability ​

The service runs only while the host and Docker are running. Upstream requests use the host's internet connection. Sleep, VPN changes, network isolation, expired logins, and provider outages can all interrupt requests. The public website being available does not indicate that your private proxy is healthy.

hara · built on CLIProxyAPI