← Back to build reports
XLeRobot · Remote access · Tailscale + Termius

Reach the robot from anywhere — Tailscale + Termius

A step-by-step for getting an SSH terminal on the robot's computer from both a phone and a PC. Two parts: (1) join the private Tailscale network so you can reach the machine at all, then (2) connect with Termius. Do part 1 once per device; part 2 is what you open every day.

TL;DR Install Tailscale + sign in with an invited account → machine appears in your device list → open Termius, add a host pointing at the machine's Tailscale address, username + key/password → connect. Same idea on phone and PC; only the apps' buttons differ.
Before you start The real host address and login password are not on this public page. Get them from the private xlerobot-ops Space (or ask Gina). Wherever this guide shows <robot-host> / <user> / <password>, substitute those real values. You also need to be invited to the tailnet first — ask the owner to send you an invite.

Part 1 · Join the Tailscale network

Tailscale is a VPN-like mesh: once your device and the robot are both signed into the same account (tailnet), they can talk directly and privately, as if on the same home Wi-Fi — no port forwarding, works across countries. Nothing is exposed to the public internet.

On a phone (iOS / Android)

  1. Install Tailscale from the App Store / Google Play.
  2. Open it → Sign in with the account that was invited to this tailnet (accept the emailed invite first if you got one).
  3. Flip the toggle to Connected. Grant the VPN permission when the OS asks.
  4. Tap the machine list — the robot should appear with a name and an IP starting 100.. That means you're on.

On a PC (Windows / macOS / Linux)

  1. Download from tailscale.com/download and install.
    Linux one-liner: curl -fsSL https://tailscale.com/install.sh | sh then sudo tailscale up.
  2. Sign in with the same invited account. A browser window handles the login.
  3. Confirm it's up: the tray icon shows Connected, or run tailscale status in a terminal — the robot should be listed.
Quick test From either device, ping the machine to prove the link works before touching Termius:
ping <robot-host>
Replies = you're good. No replies = the machine isn't online on Tailscale, or your account isn't on the tailnet yet.

Part 2 · Connect with Termius

Termius is a friendly SSH client on every platform, and it can sync your saved hosts between phone and PC if you sign into a Termius account (optional). A "host" = one saved connection.

FieldValue
Address / Hostname<robot-host> (the Tailscale IP 100.x.x.x, or its Tailscale name)
Port22
Username<user>
Password / Key<password> — or better, an SSH key (see below)

On a phone

  1. Open Termius → Hosts tab → the + button → New Host.
  2. Fill Alias (e.g. robot), Hostname = <robot-host>, Port = 22.
  3. Under Username/Password enter <user> and <password> (or attach a key — see below).
  4. Save, then tap the host to connect. Accept the host-key fingerprint the first time.

On a PC (Termius desktop)

  1. New Host (top-left +, or right-click the host list).
  2. Same four fields: Address <robot-host>, Port 22, Username <user>, credential.
  3. Double-click the host to open a terminal tab. Accept the fingerprint on first connect.

Recommended: use an SSH key instead of a password

A key is safer and means no password typing. In Termius:

  1. Keychain → New Key → Generate (Ed25519). Termius makes a keypair; if you signed into a Termius account it syncs to your other devices automatically.
  2. Copy the public key. Add it to the robot once — append it to ~/.ssh/authorized_keys on the machine (do this while logged in with the password, or ask Gina to add it).
  3. In the host's settings, set Auth to that key instead of Password. Done — future connects are one tap.

If it won't connect

SymptomLikely cause / fix
Termius hangs, then "timed out"Tailscale is off on your device, or the robot is offline on the tailnet. Re-check Part 1 — the ping test should reply.
"Connection refused"You reached the machine but SSH isn't accepting on that interface. The robot's firewall is per-interface; the Tailscale interface (tailscale0) may need sudo ufw allow in on tailscale0 to any port 22. Ask Gina.
"Permission denied"Wrong <user> / <password>, or the key isn't in authorized_keys yet. These aren't the robot-panel or VNC password — it's the Linux login.
Host key changed warningOnly expected if the machine was reinstalled. If unsure, confirm with Gina before accepting.
Note SSH gives you a terminal. It does not start the robot arms or teleop. The control panel, recording, and any arm-driving pages live behind their own addresses + password in xlerobot-ops — and still require being on this same Tailscale network.