Secure Remote Access: Connecting to Home Assistant on RPi5 via Tailscale

In my previous post, I shared how to install Home Assistant OS (HAOS) inside a KVM on a Raspberry Pi 5. While having a powerful local server is great, it brings up a major question: How do you access it securely from the outside?
For this setup, I wanted to achieve two specific goals:
- Enable a free and secure VPN for my mobile device (so I can surf safely on public Wi-Fi).
- Gain seamless remote access to Home Assistant without exposing any ports to the internet.
The answer to both is Tailscale.
Why Tailscale?
Tailscale is a zero-config VPN built on the WireGuard protocol. It creates a private “mesh” network where all your devices can talk to each other as if they were in the same room.
- No Port Forwarding: It works even if your ISP uses CGNAT.
- Private VPN (Exit Node): You can route your phone’s traffic through your home RPi5, encrypting your data on public networks.
- Simple Security: It uses your existing SSO (Google, GitHub) with 2FA for access.
1. Setting Up the Host (Raspberry Pi 5)
First, we prepare the RPi5 host to act as our primary gateway.
- Installation:
curl -fsSL [https://tailscale.com/install.sh](https://tailscale.com/install.sh) | sh - Enable IP Forwarding: This allows the RPi5 to route traffic for your mobile device.
echo 'net.ipv4.ip_forward = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf echo 'net.ipv6.conf.all.forwarding = 1' | sudo tee -a /etc/sysctl.d/99-tailscale.conf sudo sysctl -p /etc/sysctl.d/99-tailscale.conf - Start as Exit Node:
sudo tailscale up --advertise-exit-node - Admin Approval: In the Tailscale Admin Console, find your
rpi5, click the three dots (…) -> Edit route settings, and check Exit Node.
2. Setting Up the Mobile VPN
Once the host is ready, it’s time to secure your phone.
- Install the Tailscale app on your Android or iOS device.
- Log in and activate the VPN.
- Use Exit Node: In the app, select your
rpi5as the Exit Node. - Verify: Check your IP on your phone; it should now match your home IP address.
3. Remote Access to Home Assistant (HAOS)
To access your HAOS instance directly, we install Tailscale as an add-on inside the virtual machine.
- In Home Assistant, go to Settings -> Add-ons -> Add-on Store.
- Install the Tailscale add-on.

- Start it and use the Web UI to authenticate.
- Important: In the Tailscale Admin Console, click the dots next to both
rpi5andhaand select Disable Key Expiry so you don’t get locked out after 180 days.
4. How to Access Your Dashboard
With the VPN active on your phone, you have two ways to reach your dashboard:
- Tailscale IP: Use the unique IP assigned to your Home Assistant node (starts with
100.x.x.x). - The URL: Open the Home Assistant Companion app and set your External URL to
http://<your-ha-tailscale-ip>:8123.
Conclusion
By using Tailscale on the Raspberry Pi 5, I’ve managed to secure my mobile browsing and my home automation at the same time. No open ports, no monthly fees for a VPN provider—just a fast, private tunnel back to my own hardware.