Chapter 6
Settings, App Lock & Troubleshooting
Lock the app to your face or a passcode, unpair cleanly when a phone changes hands, and fix the handful of things that can go quiet between phone and Mac.
The Settings screen — under the More tab — protects this device, explains every route to the paired Mac, and performs a clean revocation when the phone moves on. This final chapter covers local or Mac-managed App Lock, push status, route diagnostics, unpairing, and the features that remain useful when the Mac connection goes quiet.
6.1A tour of Settings
Open More → Settings. It is a single scrolling form, grouped into sections:
- App Lock — either a local passcode and biometric unlock, or a lock managed by the paired Mac.
- Notifications — APNs permission, whether the Mac confirmed relay registration, the last background sync, and any setup error.
- Connection — the paired Mac, the active address, a result and latency for every saved or nearby route, Check all routes, this device's key, and Unpair this device.
- Help & Guide, Manual (offline) and About — concise help, the searchable manual stored in the app, and version information.
Most settings are local to this phone or tablet. Unpairing is the deliberate exception: it asks the Mac to revoke this device and clean up its server access before removing the local pairing.
6.2App Lock: a passcode for the app
FrontierStack Mobile is a remote control for real servers, so it is worth a lock of its own — separate from your device passcode. When the paired Mac does not require its own App Lock, turn on Require passcode to open. You are asked to set a passcode of at least six characters and confirm it. From then on a full-screen gate asks for the passcode before showing infrastructure data.
The app re-locks whenever you leave it — switch to another app, lock the phone, or send FrontierStack to the background — so a glance over your shoulder never exposes your fleet. To change the code later, tap Change passcode (you enter the current one first). To remove it, switch the toggle off and confirm with the current passcode.
6.9.1When App Lock is managed by the Mac
If the Mac required App Lock when you paired, Settings shows Managed by paired Mac: On. The phone asks for the same password, but neither the password nor the Mac's reusable verifier was copied to it; the phone holds a slow verifier bound only to this device's signing identity. Change or remove that lock on the Mac. Face ID or Touch ID remains a local switch on the phone.
6.3Fleet: unlock with a physical security key
A Fleet licence adds Physical security key in the same App Lock section. Enrol a Yubico YubiKey, Google Titan or FEITIAN ePass using Apple's system security-key sheet. The app stores only the public credential and supports up to three registered keys, so add a backup before relying on the policy.
When the policy is on, the app starts locked and re-locks whenever it leaves the foreground. Connect a compatible USB-C or Lightning key, or present an NFC-capable model when prompted, then touch it. If a passcode or mirrored Mac password is also configured, both steps are required; the key is not merely an alternative to the passcode. Without an enrolled key the app remains sealed and exposes no fleet controls.
6.4Face ID and Touch ID
Once a passcode is set, and if your device offers biometrics, an extra switch appears: Unlock with Face ID (or Unlock with Touch ID, matching your hardware). Turn it on and the lock screen offers biometric unlock the moment it appears — you rarely type the passcode at all. The passcode stays as the fallback for when a face or finger is not recognised.
Biometric unlock is a convenience layered on top of the passcode, not a replacement for it: you must set a passcode first, and removing the passcode turns biometrics off automatically. If your device has no Face ID or Touch ID, the switch simply does not appear and the passcode is the only gate.
6.5Unpairing this device
When you sell a phone, hand one to someone else, or want to start over, use Unpair this device. After confirmation, the app asks the Mac to revoke this phone, cancel its pending authority, remove its enrolled direct-SSH keys from servers, and deactivate its push access. Only after the Mac confirms cleanup does the phone remove its pinned certificate, addresses, protected cache and signing identity and return to the pairing screen.
If the Mac cannot confirm revocation, Settings shows the error with Retry Unpair and Forget Locally. Retry when possible. Forget Locally removes the pairing only from this phone; it is provided so you are not trapped by an unreachable Mac, but you must later revoke the device in Paired Devices on the Mac and finish any server-key cleanup listed there.
6.6Troubleshooting
Most trouble is connectivity: the phone and the Mac can't find each other, or a control is greyed out because of where things stand on the Mac. Work down the table, then read the notes below it.
| Symptom | Likely cause | Fix |
|---|---|---|
| FrontierStack connection unavailable — Fleet shows cached inventory even though This Mac is reachable | A direct port check succeeded, but no saved or nearby route completed the signed, certificate-pinned FrontierStack control handshake | Check FrontierStack is open with its control server enabled; pull to refresh, then use Settings → Check all routes for the exact route, certificate or handshake failure. Re-pairing is not the first remedy. |
| Controls are greyed out — buttons show but do nothing | The Mac is locked, or this device is read-only | Unlock the Mac, or raise this device's level under the Paired Devices pane. |
| Check again leaves the phone read-only | The button reads the Mac's current decision; it does not grant authority | In Paired Devices on the Mac, set this phone to Restart services or higher, and make sure FrontierStack is unlocked. Re-pair only if the phone is no longer listed there. |
| A saved LAN address no longer works | DHCP or a network change gave the Mac a new address | Keep both devices on the same LAN and refresh. Bonjour finds the paired Mac's current address and accepts it only after the saved certificate fingerprint matches. If Paired Devices on the Mac says automatic LAN discovery needs access, enable FrontierStack under System Settings → Privacy & Security → Local Network. Saved LAN and Tailscale routes remain available while Bonjour is blocked. |
| A service action says Queue instead of running | The Mac is offline | Review it under More → Queued Actions. It runs only after the Mac returns and you explicitly send it; it expires after four hours. |
| Direct SSH is blocked | The phone key was not enrolled, the server identity is missing or changed, or the server network is unreachable | While the Mac is online, enable direct SSH from the server page and capture its identity. Compare the fingerprint out of band where possible; then use the same LAN or Tailscale to reach the server. |
| No push notifications arrive | Notifications aren't enabled, or the sender is offline | Enable them in Alerts (under the More tab) and allow notifications when iOS asks; make sure the Mac (or its push relay) is online to send. |
| A device web page won't load | The network is unreachable, or the certificate is unapproved or changed | Use the same Wi-Fi or Tailscale. For a local self-signed site, compare and approve its SHA-256 fingerprint; a changed fingerprint stays blocked. Public sites need normally trusted HTTPS. |
6.7When you can't reach the Mac
The app probes saved LAN, Tailscale and other enrolled routes without waiting for a dead address to consume the whole connection attempt. On the same LAN, Bonjour also looks for this exact paired Mac if its address changed; the full saved certificate fingerprint must match before a discovered address is accepted. Several phones may connect to one Mac independently, and several Macs may advertise on the LAN without colliding because display names are never used as trust.
If none answers, Operations shows offline and Fleet keeps the last signed inventory with its age. Check that FrontierStack is open with its control server enabled, then verify the same Wi-Fi or Tailscale on both ends. Pull to refresh forces a retry after a network change. In Settings, Reached via identifies the active address and Check all routes shows why each alternative connected, stood by, was unreachable or was blocked. Bringing Tailscale up triggers another connection refresh automatically.
You can still open a cached server and choose Check server reachability. That bounded check goes from the phone to the saved SSH and service addresses without the Mac. It distinguishes "the Mac is unavailable" from "the server is also unreachable," but an open port alone does not prove the service or operating system is healthy. Enabled direct SSH and reachable web UIs also remain available. Mac-backed AI, fresh central telemetry, reboots and live controls resume only when the Mac returns.
6.8Greyed-out controls and missing alerts
If you can see status but the Start/Stop buttons do nothing, the app isn't broken — it is telling you the action isn't permitted right now. Either the Mac is locked at its login window, in which case it won't act on a remote command until someone unlocks it, or this device's permission level is too low. Raise the level on the Mac under the Paired Devices pane, or pick up a device that already has the rights.
The authority banner appears only after a live response from the Mac; when the Mac cannot be reached, Fleet reports that as a connection problem instead. Its Check again button only asks the Mac for the current permission decision. It cannot raise its own permission — that would defeat the per-device guardrail. If the phone still appears in Paired Devices and can read current status, its pairing and signing key are working; changing its permission on the Mac is enough. Pair again only after the Mac no longer lists the phone, the device was revoked, or the app explicitly reports an invalid pairing identity.
For alerts, remember the chain has two ends. The phone has to have notifications enabled — Enable notifications in Settings, and allow them when iOS prompts — and the Mac (or its push relay) has to be online to send them. If alerts simply stop arriving, the most common reason is that the Mac went to sleep or offline; wake it and confirm it is reachable from the Fleet tab.
6.9Where to go from here
That is the whole companion app: pair once from the Mac, watch your fleet from anywhere, act when your permission level allows, and keep the phone itself locked. You have a faithful, secure window onto everything FrontierStack runs — in your pocket.
For more, use the concise in-app Help & Guide or Manual (offline) under Settings. The manual is stored in the app, remains available before pairing and during an outage, and supports on-device search. The desktop manual covers every Mac pane and service in depth — start at the FrontierStack manual. For news, downloads or support, visit frontierstack.app.
FrontierStack User Manual · Version 1.0.0 · Chapter 6