Checking the host…
This console can run PowerShell as administrator on every machine in the fleet and reboot them. It is never served without a password.
Remote Desktop downloads a .rdp file; open it and Windows App (macOS) or Remote Desktop Connection (Windows) takes over. RustDesk needs its client installed and the address pasted into the ID box with Direct IP access on.
The in-browser viewer. The portal is on the tailnet, so it carries the pixels for you — this works from a borrowed laptop that has no Tailscale of its own, over Funnel. It needs the viewer service installed once per machine.
Installing downloads TightVNC 2.8.85 from tightvnc.com, checks it against a pinned SHA-256, registers it as a service, generates an 8-character password that only the portal keeps, and opens TCP 5900 to 100.64.0.0/10 and nothing else.
A virtual display is what lets a machine be captured with the lid shut or no monitor attached. Without one, Windows powers down the panel and RustDesk streams a black rectangle.
Live PowerShell on this machine. Output streams as it arrives. Shift+Enter for a new line.
If the portal is connected but this page is stale or blank, reload the interface. The host keeps running either way.
Public puts this console on the internet behind only its password. Use it when you must reach the fleet from a machine that cannot run Tailscale, and turn it off afterwards.
Admin console → Settings → Keys → API access tokens, not Auth keys. The value begins tskey-api-. An auth key enrols devices and cannot manage them.
Scan this with your authenticator, then enter a code to confirm. If you would rather not scan, paste the URI or type the secret by hand — all three carry the same value.
Save these recovery codes now — they are shown once and each works a single time. They are the only way in if you lose the authenticator.
This is the hard stop for public exposure: Funnel traffic carries no Tailscale identity, so turning it on blocks Funnel outright even if Reachability is set to public.