<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara" -->

---
title: I ditched my reverse proxy nightmare and let Tailscale...
description: A self-hoster describes replacing a struggling Nginx/Caddy reverse proxy setup with Tailscale&#x27;s built-in HTTPS serving (Magic DNS and `tailscale serve`) to get...
canonical: https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: I ditched my reverse proxy nightmare and let Tailscale handle Vaultwarden&#x27;s HTTPS instead | daily.dev
og:description: A self-hoster describes replacing a struggling Nginx/Caddy reverse proxy setup with Tailscale&#x27;s built-in HTTPS serving (Magic DNS and `tailscale serve`) to get...
og:url: https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara
og:image: https://api.daily.dev/og/posts/QYO3N9ara.png
og:image:alt: I ditched my reverse proxy nightmare and let Tailscale handle Vaultwarden&#x27;s HTTPS instead
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# I ditched my reverse proxy nightmare and let Tailscale handle Vaultwarden's HTTPS instead

**[XDA Developers](https://daily.dev/sources/xda-developers)** · 4 min read · 0 upvotes · 0 comments

## Summary

A self-hoster describes replacing a struggling Nginx/Caddy reverse proxy setup with Tailscale's built-in HTTPS serving (Magic DNS and `tailscale serve`) to get Vaultwarden working securely on a Raspberry Pi Zero 2 W. Running `tailscale serve --bg --https 443 http://localhost:8081` fixed both the web portal certificate errors and the mobile app's connection failures, letting the author avoid reverse proxy complexity entirely while running Vaultwarden alongside BentoPDF and OmniTools in Docker.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.xda-developers.com/tailscale-and-magicdns-eliminate-vaultwarden-reverse-proxy-need>

## Questions this post answers

### How do I get HTTPS working for Vaultwarden without setting up a reverse proxy like Nginx or Caddy?

Use Tailscale's built-in serve feature instead of a reverse proxy. Running `tailscale serve --bg --https 443 http://localhost:8081` exposes Vaultwarden over HTTPS using Tailscale's Magic DNS and automatic certificates, fixing both the web portal's insecure-connection error and the mobile app's certificate error, without touching Nginx or Caddy.

_daily.dev surfaces self-hosting fixes like this Tailscale HTTPS trick for developers wrangling Vaultwarden setups._

### Why does the Vaultwarden mobile app fail to connect with a certificate error even though the web portal works over HTTPS?

The mobile app is stricter about certificate validity than a browser, so a self-signed or improperly configured HTTPS certificate that lets the web portal load can still cause the app to reject the connection as insecure. Switching HTTPS handling to Tailscale serve, which issues valid certificates, resolved the app's certificate error and allowed sign-in on the first attempt after adding the phone to the same tailnet.

_developers debugging mobile app cert errors on self-hosted tools can track fixes like this via daily.dev._

## Similar posts on daily.dev

- [Tailscale replaced my dynamic DNS setup, and I stopped worrying about IP addresses entirely](https://daily.dev/posts/tailscale-replaced-my-dynamic-dns-setup-and-i-stopped-worrying-about-ip-addresses-entirely-ds2sgbbru) · XDA Developers · 0 upvotes · 0 comments
- [Tailscale’d Into Homelabbing](https://daily.dev/posts/tailscale-d-into-homelabbing-vyztndhi7) · Lobsters · 6 upvotes · 0 comments

---

Tags: [#self-hosting](https://daily.dev/tags/self-hosting), [#raspberry-pi](https://daily.dev/tags/raspberry-pi), [#tailscale](https://daily.dev/tags/tailscale)

[View this post on daily.dev](https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"I ditched my reverse proxy nightmare and let Tailscale handle Vaultwarden's HTTPS instead","url":"https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara"},"datePublished":"2026-08-30T17:03:32.454Z","dateModified":"2026-08-30T17:03:59.674Z","description":"A self-hoster describes replacing a struggling Nginx/Caddy reverse proxy setup with Tailscale's built-in HTTPS serving (Magic DNS and `tailscale serve`) to get...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bc76ca25411aaf453e38d0a838e99538?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bc76ca25411aaf453e38d0a838e99538?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"XDA Developers","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"XDA Developers","logo":"https://media.daily.dev/image/upload/s--kCg6yyAP--/f_auto,q_auto/v1774964407/logos/xda-developers?_a=BAMAMiWQ0","url":"https://daily.dev/sources/xda-developers"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"self-hosting,raspberry-pi,tailscale","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"XDA Developers","item":"https://daily.dev/sources/xda-developers"},{"@type":"ListItem","position":3,"name":"I ditched my reverse proxy nightmare and let Tailscale handle Vaultwarden's HTTPS instead"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/i-ditched-my-reverse-proxy-nightmare-and-let-tailscale-handle-vaultwarden-s-https-instead-qyo3n9ara#faq","mainEntity":[{"@type":"Question","name":"How do I get HTTPS working for Vaultwarden without setting up a reverse proxy like Nginx or Caddy?","acceptedAnswer":{"@type":"Answer","text":"Use Tailscale's built-in serve feature instead of a reverse proxy. Running `tailscale serve --bg --https 443 http://localhost:8081` exposes Vaultwarden over HTTPS using Tailscale's Magic DNS and automatic certificates, fixing both the web portal's insecure-connection error and the mobile app's certificate error, without touching Nginx or Caddy. daily.dev surfaces self-hosting fixes like this Tailscale HTTPS trick for developers wrangling Vaultwarden setups."}},{"@type":"Question","name":"Why does the Vaultwarden mobile app fail to connect with a certificate error even though the web portal works over HTTPS?","acceptedAnswer":{"@type":"Answer","text":"The mobile app is stricter about certificate validity than a browser, so a self-signed or improperly configured HTTPS certificate that lets the web portal load can still cause the app to reject the connection as insecure. Switching HTTPS handling to Tailscale serve, which issues valid certificates, resolved the app's certificate error and allowed sign-in on the first attempt after adding the phone to the same tailnet. developers debugging mobile app cert errors on self-hosted tools can track fixes like this via daily.dev."}}]}
```

