← blog

A Mac's desktop in a browser tab, with no inbound ports open

October 11, 2026 · 7 min read

The agent plan sells a Mac you can open in a browser tab. No VNC client, no Tailscale install on your side, just a URL and a password. The machines sit in our own private facility in New Jersey. We were not willing to open an inbound port on its network for anything. Here is the architecture that squares those two facts.

The constraint

Forwarding a port to a Mac means exposing it to the whole internet, and port 5900 is a well-scanned target. We wanted the customer to reach the screen with nothing installed, and we wanted zero inbound ports on our network. Those pull in opposite directions until you stop thinking about inbound.

The pull model

Nothing in our facility accepts connections from the internet. Instead, the machines and the hub reach out. A small cloud-facing control plane holds a queue, and the hub polls it. When a customer asks to open their Mac, the request lands in that queue. The hub picks it up on its next poll and sets up the path. The direction of the first connection is always outward.

The pieces

Where the trust boundaries sit

The browser-to-gateway leg is HTTPS over the Funnel. The gateway-to-Mac leg runs inside the private tailnet, which the customer never joins. The customer authenticates with a screen password shown in their portal, and the token scopes them to one machine for one session. Our firewall, through all of this, has no open inbound port.

What we would reach for next

noVNC is enough for sign-in and light interaction. Its clipboard is a side panel rather than native paste, and latency is bound by our upload link. If a customer needed a heavier remote desktop, the upgrade path is a session broker on a small machine on the same tailnet. It would not change the no-inbound-ports rule. That rule is the part worth keeping. Everything else is a component you can swap.

Questions

How do you reach a Mac without opening inbound ports?
Nothing in our facility listens on the public internet. A cloud-facing hub polls for work and connects outward over a private mesh, and a Tailscale Funnel terminates TLS. Our firewall keeps every inbound port closed.
Is the VNC traffic encrypted?
Yes. The browser reaches the gateway over HTTPS via a Tailscale Funnel with a real certificate, and the leg from the gateway to the Mac runs inside the private tailnet.
How is access scoped to one session?
Each session mints a random token with a short expiry that maps to exactly one machine. When it expires it is removed, so an old link stops working.

Run your own numbers on the calculator or lease a runner.