Your Markdown Notes on Your Phone, Over Tailscale

mdnest exists because its author wanted one thing a desktop notes app would not give him: the same folder of .md files, open on the laptop and on the phone, without handing those files to someone else's cloud. If you already run Tailscale, you are about ten minutes from that.

The idea is simple. mdnest runs on a machine you own and serves your notes to a browser. Tailscale puts that machine on a private network that only your own devices can join. Your phone opens a normal HTTPS address, and the address does not exist anywhere else on the internet.

What you get

1. Run mdnest on the always-on machine

Pick the machine that stays on: a home server, a mini PC, a NAS that runs Docker, or a small cloud VM. Then use the one-file install from the Quick Start:

mkdir mdnest && cd mdnest
curl -fsSLo docker-compose.yml https://raw.githubusercontent.com/mahsanamin/mdnest/main/deploy/compose/docker-compose.yml
echo "MDNEST_PASSWORD=$(openssl rand -base64 18)"  > .env
echo "MDNEST_JWT_SECRET=$(openssl rand -hex 32)"  >> .env
docker compose up -d

mdnest now listens on http://127.0.0.1:3236, on that machine only. That is the default and the point: nothing else can reach it yet. Your notes are plain .md files in ./notes.

Already keep your notes somewhere, such as an old Obsidian vault? Mount that folder instead. It stays a folder of Markdown files, and every other tool you use keeps working on it. The setup guide covers mounts.

2. Put it on your tailnet with HTTPS

On the same machine, with Tailscale installed and logged in:

tailscale serve --bg --https 3236 http://127.0.0.1:3236

tailscale serve proxies your tailnet's HTTPS traffic to mdnest on localhost, and keeps doing so in the background (--bg). Your notes are now at:

https://<machine-name>.<tailnet-name>.ts.net:3236

If this is the first time you have used tailscale serve, Tailscale may ask you to turn on HTTPS certificates for your tailnet in the admin console. It is one click, and it is what makes the certificate trusted.

3. Open it on your phone

Install the Tailscale app on the phone, sign in with the same account, and open the ts.net address in the browser. Sign in to mdnest with the password from .env.

To make it feel like an app, use the browser's Add to Home Screen. Next time, it is one tap from the home screen.

4. Optional: keep the LAN dark, allow only the tailnet

tailscale serve is enough on its own, because mdnest still only listens on localhost. If you would rather bind mdnest straight to the machine's Tailscale address, BIND_ADDRESS takes a comma-separated list:

BIND_ADDRESS=127.0.0.1,100.x.y.z

That binds localhost plus the Tailscale IP, and nothing on your home or office network. See the security model for how the layers fit together.

When not to use Tailscale

Tailscale is the best fit for one person, or a household, reaching their own server. For a team, where people should sign in with their company accounts, a public domain behind a TLS reverse proxy with SSO is the better shape. Everyone reaches the same notes without joining your tailnet.

FAQ

Is my data going through Tailscale's servers? Tailscale connects your devices directly over WireGuard wherever it can, and relays encrypted traffic when a direct path is not possible. Either way the traffic is end-to-end encrypted between your devices. Your notes live only on your machine.

Does it work offline? The phone needs to reach your server, so it needs a connection. What you get in return is a single copy of every note, with no sync conflicts to resolve.

Can I still use Obsidian or VS Code on the same notes? Yes. mdnest never takes ownership of the files. Point any editor at the same folder on the server, or at a git clone of it.