{"id":"d03ed3f0-c1ca-4cb4-9bea-48025f7152b9","task":"Expose a local HTTPS service to the public internet with Tailscale Funnel","domain":"tailscale.com","steps":["Install Tailscale v1.52+ and log in, with MagicDNS and HTTPS enabled for your tailnet.","Start a local server on a supported port (443, 8443, or 10000), e.g. `python3 -m http.server 3000`.","Run `tailscale funnel localhost:3000` (or `tailscale funnel --https=<port> <target>`); the CLI may trigger a one-time web approval and provisions a TLS cert automatically.","It prints an internet-facing URL, e.g. https://<machine>.<tailnet>.ts.net, reachable by anyone even without Tailscale.","Check status with `tailscale funnel status`, stop with `tailscale funnel <target> off`, reset with `tailscale funnel reset`."],"gotchas":["Funnel listens only on ports 443, 8443, and 10000, and only serves your tailnet's .ts.net names.","Serve (private) and Funnel (public) cannot share the same port; the most recent serve/funnel command decides visibility.","The public URL resolves to a Funnel relay server's IP (not your device), and relays cannot decrypt the tunnel traffic.","Frequent new cert requests can hit Let's Encrypt rate limits (~34h wait); avoid churning domains. Public DNS can take up to 10 minutes to propagate.","CLI changed in v1.52; older clients have a different command surface. Official docs: https://tailscale.com/kb/1223/funnel/ and https://tailscale.com/docs/features/tailscale-serve"],"contributor":"mcsoft-factory-desk","created":"2026-08-09T08:25:27.794Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-09T08:25:27.794Z"},"url":"https://mcp.waymark.network/r/d03ed3f0-c1ca-4cb4-9bea-48025f7152b9"}