Skip to content

Latest commit

 

History

History
149 lines (100 loc) · 4.57 KB

File metadata and controls

149 lines (100 loc) · 4.57 KB

Remote Access Guide

Access your Portable RTX Compute Node from anywhere — hotel WiFi, coffee shop, or another city — using either Tailscale (easiest) or WireGuard (self-hosted).


Option A: Tailscale (Recommended)

Tailscale is a zero-config VPN built on WireGuard. It handles NAT traversal automatically and requires no port forwarding.

1. Install Tailscale on Both Machines

On both the host (Acer Predator) and client (Dell Precision):

  1. Download from tailscale.com/download and install.
  2. Sign in with the same Tailscale account on both machines.
  3. Both machines appear in your Tailscale admin console.

2. Find Your Tailscale IPs

In the Tailscale admin console, note the Tailscale IP of the host (e.g., 100.x.y.z). Alternatively:

# On the host
tailscale ip -4

3. Update Your Client Config

Replace Desktop.home with the Tailscale IP (or use MagicDNS hostname):

# In PowerShell on the client — test connectivity
Test-NetConnection -ComputerName 100.x.y.z -Port 22

# Set Ollama to use Tailscale IP
[System.Environment]::SetEnvironmentVariable("OLLAMA_HOST", "http://100.x.y.z:11434", "User")

Or use MagicDNS (enabled by default): the host becomes desktop-home.<tailnet>.ts.net — no IP needed.

4. Access Services Remotely

All services work identically over Tailscale:

Service Remote URL
Ollama http://100.x.y.z:11434
JupyterLab http://100.x.y.z:8888
SSH ssh <user>@100.x.y.z
Sunshine https://100.x.y.z:47990

⚠️ Security reminder: JupyterLab has no token by default. Add one before accessing remotely — see SETUP.md.

5. (Optional) Exit Node / Split Tunneling

If you only want to route traffic to the host through Tailscale, ensure split tunneling is on (the default). This keeps your regular internet traffic on the local ISP.


Option B: WireGuard (Self-hosted)

Use WireGuard if you want full control with no third-party service. This requires a static public IP or DDNS on the host side, and port forwarding on your router.

Prerequisites

  • Static IP or a DDNS service (e.g., DuckDNS, No-IP) pointing to your home router's WAN IP
  • Port forwarding: UDP 51820 → host LAN IP

1. Install WireGuard on the Host

Download from wireguard.com and install on Windows.

# Generate server key pair (run in PowerShell as Admin)
wg genkey | Tee-Object server_private.key | wg pubkey > server_public.key

2. Host WireGuard Config

Create C:\ProgramData\WireGuard\wg0.conf:

[Interface]
PrivateKey = <server_private_key>
Address = 10.8.0.1/24
ListenPort = 51820
DNS = 8.8.8.8

[Peer]
# Dell Precision (client)
PublicKey = <client_public_key>
AllowedIPs = 10.8.0.2/32

3. Client WireGuard Config

[Interface]
PrivateKey = <client_private_key>
Address = 10.8.0.2/24

[Peer]
# Acer Predator (GPU host)
PublicKey = <server_public_key>
Endpoint = <your-ddns-hostname-or-ip>:51820
AllowedIPs = 10.8.0.0/24
PersistentKeepalive = 25

4. Start WireGuard

On both machines, import the .conf file into the WireGuard GUI and click Activate.

Test:

# From client — ping the host over WireGuard tunnel
ping 10.8.0.1

5. Update Service Endpoints

Replace Desktop.home with 10.8.0.1 in your environment variables and SSH config.


Security Checklist for Remote Access

Before enabling remote access, review these items:

  • JupyterLab token set — jupyter lab --NotebookApp.token=<your_token>
  • SSH key-only auth — password auth disabled in sshd_config
  • Firewall rules — only Tailscale/WireGuard port open on host Windows Firewall
  • SMB not exposed — SMB (445) should never be internet-facing
  • Sunshine web UI — use a strong password; accessible on Tailscale IP only
  • No secrets in repo — confirm .gitignore covers .env, *.key, sunshine_state.json

Latency Expectations

Connection Typical Latency Usable For
LAN (same subnet) <1 ms Everything
Tailscale (same city) 5–20 ms SSH, Ollama, Jupyter
Tailscale (cross-country) 50–100 ms SSH, Ollama; streaming marginal
WireGuard (same ISP) 10–30 ms SSH, Ollama, Jupyter

Moonlight game streaming requires <30 ms for comfortable use. Over Tailscale at distance, latency may be too high for real-time streaming but SSH and LLM inference work fine.