Udon is under active development. Documentation not final.
udonudon

Network & remote access

Set the Mac's IP address and DNS, connect Tailscale, serve the dashboard with a trusted certificate, and reach your containers remotely by their own IPs.

Two Settings pages cover networking: System → Network for the Mac's own interfaces, and System → Tailscale for reaching Udon and your containers from anywhere without opening a port on your router.

The Mac's network

The Network settings, showing interfaces and IPv4The Network settings, showing interfaces and IPv4

The Overview card shows the default gateway, the DNS servers, and how many interfaces are up. The Interfaces table lists each interface with its IPv4 addresses and status, and tags the ones Tailscale and your containers use.

Each network service, such as Wi-Fi or Ethernet, gets a card with:

  • A switch in the card's header that turns the service on or off.
  • IPv4: Automatic (DHCP) or Manual, with IP address, subnet mask, and router fields.
  • DNS servers: add a server with the + button and remove one with its ×. Applying an empty list clears them, so the network's own DNS takes over.

IPv4 and DNS each have an Apply button, which turns on once you've made a valid change.

This page needs Admin Privileges. Without them it shows Admin Privileges required and an Open Health button instead. See Settings.

Tailscale

Tailscale gives this Mac a stable private address that your other devices can reach from anywhere. Settings → Tailscale needs an admin account but not Admin Privileges.

If Tailscale isn't installed, the page names the two ways to get it: the Mac app from tailscale.com, or the tailscale Homebrew package. Udon finds either one with no CLI setup. If it's installed but not running, the page says so and shows the daemon's message. Open the Tailscale app and finish signing in, and the page updates by itself.

Open Settings → Tailscale and click Sign in.

Under Finish signing in, click Open sign-in page (or copy the link) and approve this Mac.

The Status card reads Connected, with your tailnet's name and the Tailscale version.

Two icon buttons on the Status card end the session: Disconnect (a power symbol) and Log out (red). Hover one to see its name.

Remote access

Once connected, the Remote access card shows the address other tailnet devices use, under Reachable on your tailnet. Udon's certificate is self-signed, so browsers show a warning there.

Turn on Serve with a trusted certificate to publish the dashboard with a valid certificate, with no warning and no port in the address. The Trusted URL appears below the switch.

Don't forward Udon's port on your router. Use Tailscale or another private network instead; the install guide has the short version.

Reach containers by their own IPs

In the Container access card, turn on Advertise the container network to offer your containers' subnet (for example 192.168.64.0/24) as a Tailscale route. Approve the route once in the Tailscale admin console. After that, any device on your tailnet reaches a container at its own IP, with no port published on the Mac.

Preferences and devices

The Preferences card has switches for accepting subnet routes from other devices, MagicDNS, Tailscale SSH, blocking incoming connections, and running this Mac as an exit node. Its Exit node picker routes this Mac's own traffic through another node on your tailnet.

The Tailscale Preferences card with its switches and the Exit node pickerThe Tailscale Preferences card with its switches and the Exit node picker

The Devices table lists this Mac first, then its peers, with each one's OS, Tailscale IP, and online status. Click a column heading to sort; the order holds for the rest of the browser session.

Ask AI

Answers from Udon's documentation.

Ask how to install Udon, run containers, or share folders.