TLS for Home Agent to VPS
The full setup path puts Caddy in front of the VPS Agent so pairing and relay management happen over HTTPS with automatic certificates.
Caddy443/tcp
Tater Tunnel
The Home Agent owns device approval, relay tokens, route targets, and revocation. The VPS should hold only enough state to relay traffic and manage WireGuard peers.
The full setup path puts Caddy in front of the VPS Agent so pairing and relay management happen over HTTPS with automatic certificates.
Phones and laptops use WireGuard to reach the VPS tunnel address. This gives the mobile VPN behavior users expect.
After claim, sensitive VPS endpoints require the relay management token from the Home Agent.
Revoking a device removes the WireGuard peer and the Home Agent device record.
curl -fsS https://tunnel.example.com/api/health
sudo wg show tater0
sudo ufw status verbose