iPhone & iPad Companion
FrontierStack
iPhone & iPad Companion
Watch your fleet, get push alerts, control services and reach device web UIs from your pocket — paired securely to the Mac.
Table of Contents
Part I
Getting Connected
Pair your iPhone or iPad with the Mac, lock it down, and keep it reachable wherever you are.
Chapter 1
Welcome to FrontierStack Mobile
Your servers in your pocket — a secure remote control for the FrontierStack Mac app, so you can watch, get alerted, and act from anywhere.
FrontierStack for iPhone and iPad is a companion to the FrontierStack server-administration app that runs on your Mac. It is not a separate product you set up from scratch, and it does not run servers itself. It is a small, secure remote control for the Mac app — so the servers, agents and devices you manage from your desk are with you wherever you happen to be.
This short book is the manual for the mobile app only. The full desktop reference — everything the Mac app does, from the web stack to the AI Administrator — lives in the FrontierStack Manual. Here we cover just what you need to pair a phone or tablet, keep it safe, and use it day to day.
1.1What this app is
Think of the Mac app as the brain and this app as a trusted hand. The Mac is where FrontierStack watches health, runs the AI Administrator and holds shared credentials. Most live monitoring and control travels through that Mac over a signed, encrypted connection.
Two deliberately enrolled paths can work without it. The phone can make a bounded reachability check against saved server ports, and you can separately enable a phone-specific direct SSH key for a server. The Mac's keys, passwords and general tool authority are never copied to the phone. The phone keeps its pairing identity and, only when you enable direct SSH, a separate Keychain-backed SSH key that you can revoke.
1.2What you can do from your phone
The mobile app is a secure incident companion and remote for the desktop — the things you reach for when you are away from your desk, organised into five tabs:
- Fleet. Every pinned server, the local Mac included, each with a status dot. Open one for full status, performance history, a bounded check made directly from the phone, approved service controls, reboot, diagnostics, logs, Remote Tools, direct SSH and database emergency preparation. Your pinned LAN devices sit below in collapsible sections.
- Operations. The Mac's current health, restore-readiness evidence, likely upstream causes, unusual server behaviour and controllable local services. This operational view is independent of what is hidden in the Mac sidebar.
- Shell. A real command-line on the Mac or any server, logging in automatically with the Mac's stored credentials (never sent to the phone). Plus your saved and ready-made scripts.
- AI. A multi-turn conversation with the AI Administrator, showing the tools it runs; read-only unless you switch on "Allow changes".
- More. Push alerts, checks, queue health, Phone & Fleet Sites, scripts, Fleet Run, reviewed offline actions, ZeroTier approvals, temporary Shares, device web UIs, Settings, Help and the offline manual.
Some of these work from anywhere; others depend on your phone being able to reach the right network. We explain exactly which is which in Staying Connected.
1.3Why it needs the Mac
The companion still needs a Mac for enrolment, fresh fleet state, live controls, alerts, scripts, Remote Tools and the AI Administrator. When the Mac is unavailable, the phone clearly labels its last signed inventory as cached. You can still open reachable web UIs, run a bounded phone-to-server reachability check, use an already enrolled direct SSH session, and prepare named service actions for later review and delivery.
Because the Mac does most of the work, three things follow. It must be reachable for fresh Mac observations and Mac-routed commands. Push alerts need the Mac or its push relay online to send them. And the permissions that govern what your phone may do are set on the Mac, not the phone — you stay in control from one place.
1.4Install order
Getting set up takes three steps, in this order:
- Install FrontierStack on the Mac. Download and run the desktop app, and turn on its control server so it can accept connections from your devices. The Mac is required for initial enrolment and remains the source of central health and control.
- Install this app on your iPhone or iPad. Get FrontierStack Mobile from the App Store. On first launch it simply waits to be paired.
- Pair the two. On the Mac, generate a pairing QR code under the Paired Devices pane. In this app, scan it. From then on the two are linked, and your phone is enrolled with its own key.
The next chapter, Pairing Your Device, walks through that pairing in full.
1.5How this manual is organised
This little book has two parts. Getting Connected — the part you are reading — covers this welcome, then pairing your device, the security model that keeps the link safe, and staying connected from home, over Tailscale, and away. Using FrontierStack Mobile then walks through the app itself: the tabs — Fleet, Operations, Shell, AI and More — and finally settings and troubleshooting, including app lock and what to check when something will not connect.
1.6Platform requirements
FrontierStack Mobile is a universal app that runs on both iPhone and iPad, adapting its layout to each. It needs a reasonably current version of iOS or iPadOS; install it from the App Store, which will tell you if your device is supported. Initial pairing needs a Mac running FrontierStack. After enrolment, live Mac-backed features need that Mac reachable over your network, Tailscale, or an explicitly enabled Cloudflare tunnel; the bounded offline features described above do not.
That is the whole picture: a Mac doing the work, a phone or tablet as your secure remote, and a signed link between them. When you are ready, turn to Pairing Your Device to begin.
Chapter 2
Pairing Your Device
Scan one QR code from the Mac and your iPhone or iPad enrols its own key — then the Mac decides exactly what it may do.
Pairing connects this app to FrontierStack running on your Mac. It takes one QR code and a few seconds. Behind that simplicity, the app enrols a private key that only ever lives on this device, so from then on the Mac can recognise — and trust — this exact phone or iPad. This chapter walks through pairing, approving a new device, and the permission levels that decide what it can do.
2.1How pairing works
Your Mac is the brain: it talks to your servers, agents and devices. This app is a secure remote control for it. Pairing is how the two recognise each other for good. When you scan the QR code, three things travel to the phone — the ways to reach your Mac (your home or office network, Tailscale, and a Cloudflare tunnel), a one-time token, and the Mac's certificate fingerprint so the connection can be pinned. The phone then generates its own key and enrols it with the Mac. After that first handshake the one-time token is spent; every later request is proven by the device's own key (see Security).
2.2Pairing step by step
- On your Mac, open FrontierStack → Paired Devices (in the Overview group).
- Click Pair a device. A QR code appears.
- In this app, tap Scan QR code and point the camera at the Mac's screen.
- The app reads the code, enrols its key, and connects. The new device appears in the list on the Mac.
Can't reach the Mac? Pair over Bluetooth. On a locked-down Wi-Fi network — guest networks, client isolation, a captive portal — the app may read the QR fine but fail to connect. If the Mac has Allow Bluetooth pairing turned on (in its Paired Devices pane) and you are within a few metres of it, tap Pair over Bluetooth and enrolment finishes over a short-range Bluetooth link instead. It uses the same one-time QR code and the same signed handshake — only the transport changes — so the result is identical to pairing over the network. The Mac only advertises over Bluetooth while its Pair dialog is open.
2.3What the QR code carries
The QR is not just a token — it is everything the app needs to reach your Mac safely:
- Reach paths — the addresses for your home/office network, Tailscale, and any Cloudflare tunnel, so the app can find the Mac whether you are home or away (Staying Connected).
- A one-time token — used only for the initial enrolment, then discarded.
- The certificate fingerprint — lets the app pin the Mac's HTTPS certificate, so the connection cannot be intercepted even though the certificate is self-signed.
Those saved paths are starting points, not a permanent copy of one LAN address. After pairing, the Mac advertises its pinned HTTPS control service over Bonjour. If its address changes, the phone can discover the new address but accepts it only when the full certificate fingerprint still matches this pairing.
2.4Approving the new device
A freshly paired device starts read-only — it can see status and alerts but cannot change anything until you say so. On the Mac, in the Paired Devices pane, each device is listed by name with a key fingerprint and a last-seen time. There you raise its permission level, rename it, or revoke it.
2.5Permission levels
The Mac decides how much each device may do. Set the level on the Mac in the Paired Devices pane (Overview group).
| Level | What this device can do |
|---|---|
| Read-only | See status, alerts, logs and device pages. No changes. |
| Restart | Read-only, plus start / stop / restart services. |
| Operate | Restart, plus fleet operations. |
| Full control | Everything, including tools, scripts and opening shares. |
If a button is disabled or an action is refused, this device's level does not allow it — raise it on the Mac, or use a device that already has the rights.
With the device paired and its level set, you are ready to use the app. Connectivity from home and away is covered next in Staying Connected, and the day-to-day tabs in Using the App.
Chapter 3
Security
Why it is safe to control your Mac from your pocket — even over the open internet. Signed requests, pinned encryption, an app lock, and instant revocation if a phone is lost.
This app can start and stop real services on a real Mac, sometimes from the other side of the world. That only makes sense if a stolen phone, a sniffed network or a guessed token can't be turned into control of your servers. FrontierStack is built so that none of those, on their own, is enough. This chapter explains the layers — and why they let you reach your Mac safely through a Cloudflare tunnel from anywhere.
3.1Every request is signed
The strongest protection is invisible. When this device was paired, it generated its own private key and stored it in the iOS Keychain — it never leaves the phone, and even this app cannot read it back out as plain text. Every request the app sends to your Mac is signed with that key. The Mac keeps an allow-list of the devices you approved, each by its public key, and checks the signature on every request against the device that claims to be sending it.
This is the FS1 per-device model: it uses Ed25519 signatures, and each signed request also carries a timestamp and a one-time nonce, so a captured request can't be replayed even seconds later. The practical consequence is the important part: a bearer token on its own — the kind of shared secret that older apps rely on — cannot control anything here. Without this device's private key, a copied token is inert.
3.2Encrypted, pinned connections
Signatures prove who is talking; encryption protects what they say. When your Mac advertises an HTTPS address, this app talks to it over TLS like any secure connection. But there is a twist: the Mac uses a self-signed certificate it generates itself, so there is no public authority to vouch for it.
Instead, the app uses certificate pinning. The pairing QR code carried the exact fingerprint of the Mac's certificate. From then on, the app accepts only a connection presenting that exact certificate — nothing else. An attacker who sits in the middle and offers their own certificate, even a "valid" one, is rejected, because its fingerprint won't match the one you pinned at pairing.
3.3Why this is safe from anywhere
Put the two together and you can see why reaching your Mac over a public path — a Cloudflare tunnel, for instance — is safe rather than reckless. The tunnel only carries traffic; it can't forge it.
- The connection is encrypted and pinned, so the tunnel (and anyone along the way) sees ciphertext to a certificate they can't impersonate.
- Every request is signed by this device's key, so even something that reached the Mac couldn't issue a command it would honour.
- Replay is blocked by the per-request timestamp and nonce, so re-sending a captured request fails.
The Mac decides whether the public path even exists, and you can close it. Nothing here depends on the network being private — the protections travel with each request.
3.4App lock
Network security can't help if someone simply picks up your unlocked phone. The app lock closes that gap. In Settings, turn on a passcode; from then on the app is locked until you enter it, and you can add Face ID or Touch ID for one-tap unlock. The app re-locks whenever you leave it — switch apps or lock the phone, and it asks again on your return.
The passcode itself is never stored. A locally chosen passcode is protected by a unique salt and a deliberately slow PBKDF2-HMAC-SHA256 verifier in the device Keychain, with progressive delays after failed attempts. Biometric unlock is handled by iOS, which only tells the app yes or no.
Mirroring the Mac's lock. If the Mac itself has an App Lock password, this app adopts it at pairing and requires the same password. Neither the password nor the Mac's reusable verifier travels. The phone receives a slow verifier cryptographically bound to this device's pairing identity. While mirrored, you cannot change or remove the lock from the phone; change it on the Mac. Face ID or Touch ID remains a local convenience.
Whenever the app leaves the foreground, it covers the app-switcher snapshot with a data-free privacy screen, even when App Lock is not enabled. Any live direct-SSH session is closed on backgrounding or lock and never reconnects automatically; return, unlock and connect again deliberately.
3.5What this device is allowed to do
Authentication answers "is this really my phone?"; permission scopes answer "and how much may it do?". That decision lives on the Mac, not here. Each paired device is assigned one of four levels — Read-only, Restart, Operate or Full control — and the Mac enforces it on every signed request. A phone you carry everywhere can stay safely at a low level even though it is fully paired.
If a button is disabled or an action is refused, this device's level doesn't permit it — raise it on the Mac, or use a device that already has the rights. The four levels and what each unlocks are set out in Pairing.
Two grants sit alongside the level, both set on the Mac. Allow AI Administrator (on by default) decides whether this phone may use the AI tab at all — a way to let one device chat while blocking another. Allow remote shell is offered only at Full control and is off by default; it is what lets this device open the Shell tab and reach your servers directly. Neither is a bypass: even with AI allowed, any change still needs Full control's "Allow changes" and the app unlocked.
3.6Authority while the Mac is unavailable
Offline does not turn the phone into an unrestricted controller. The last signed inventory is labelled with its age. A direct reachability check can connect only to the saved SSH endpoint and a small set of standard ports implied by services FrontierStack already observed; it does not scan a range or download a probe. Direct SSH uses a second, phone-specific Ed25519 key and refuses a missing or changed saved server identity.
Service start, stop, restart and reload requests may be prepared while the Mac is offline. They remain signed on this phone for at most four hours and do nothing until you open More → Queued Actions, review the exact target and explicitly send them after the Mac returns. The Mac verifies the signature, expiry, permission and App Lock again, and executes an accepted request once. Scripts, shell commands, reboots, fleet runs, device power and access changes are never accepted by this queue.
3.7If you lose a device
Because each phone has its own key, you never have to change anything else to cut one off. On the Mac, open Paired Devices (in the Overview group), find the device by name, and revoke it. Its key is removed from the allow-list at once: the moment it tries to talk to the Mac again, its signature is rejected. Your other devices are untouched and keep working.
Revoking on the Mac is the authoritative step — it stops the device even if you can't reach the phone itself. Unpair this device on a phone you still hold first asks the Mac to revoke the phone, remove its enrolled direct-SSH keys and stop its push access. Only if the Mac cannot confirm that cleanup does the app offer Forget Locally; after using that fallback, finish revocation from Paired Devices on the Mac.
For a phone that is genuinely gone, the Mac offers a stronger one-click action: Secure lost phone. Beyond revoking the key, it immediately cancels the device's older queued actions, closes its open sessions, removes any SSH keys it installed on your servers for direct access, and deactivates its push notifications. Servers that are offline at that moment stay listed so you can finish removing the keys when they come back.
Chapter 4
Staying Connected
How the app finds your Mac wherever you are — same Wi-Fi, Tailscale, or a Cloudflare tunnel — and what the little coloured dot is telling you.
After you pair, the phone never asks you to type an address. It knows the routes captured when you scanned the QR code and can rediscover that same Mac nearby if its LAN address changes. It quietly tries the available paths until one answers. This chapter explains that process, why away-from-home access sometimes needs a little help, and how to read the connection status at a glance.
The Mac-backed connection is anchored to its control server. If that server is switched off, or the Mac is asleep or off the network, there is no live Mac endpoint for the app to reach; the bounded offline features are covered in Using the App. For pairing itself, see Chapter 2; for the desktop side of the control server, see the desktop manual.
4.1The three paths home
When you paired, the QR code carried more than a token: it carried a small list of addresses at which your Mac can be found — its address on your home or office network, its Tailscale address, and the address of any Cloudflare tunnel the Mac has enabled. The app keeps that list and, every time it needs to talk to the Mac, walks it in a fixed order:
- Your home or office network first. If the phone and the Mac are on the same Wi-Fi (or wired LAN), the app connects directly — the fastest, lowest-latency path, with nothing in between.
- Tailscale next. If a direct connection doesn't answer, the app tries the Mac's Tailscale address. This works wherever you are, as long as your phone and Mac are members of the same tailnet.
- A Cloudflare tunnel last. If neither of those works, the app falls back to a Cloudflare tunnel — but only if the Mac has one enabled. This reaches your Mac from anywhere without any network of your own.
The app remembers which path last worked and tries that one first next time, so reconnecting on a familiar network is near-instant. You never choose the path by hand; you simply open the app and it lands on whichever route is live.
If the saved LAN address no longer answers, the phone also browses for FrontierStack over Bonjour. A discovered address is only a hint: the phone accepts it only after the Mac presents the exact certificate fingerprint saved during pairing, then remembers the fresh address. Two FrontierStack Macs on the same LAN cannot be confused because each phone matches the full fingerprint, not the Mac's display name.
4.2When you're on the same Wi-Fi
At home or in the office — phone and Mac on the same network — the app takes the direct path. This is the best case: everything is reachable and fast. Service status, start and stop, alerts, the AI, device web UIs and LAN shares all behave as if the phone were sitting next to the Mac, because in network terms it is.
The Mac advertises its pinned HTTPS control service over Bonjour. If DHCP, a Wi-Fi move or a network change gives it a new address, the phone can find it again without re-pairing. The app verifies the Mac's identity using the certificate fingerprint it captured at pairing, so even a self-signed certificate can't be impersonated on your own network.
Several phones can use the same Mac on one LAN at the same time. Each phone has its own signing key, permission level and request session, so one does not replace another. Several FrontierStack Macs can also advertise at once: the phone filters Bonjour results by the full fingerprint from its own pairing and verifies the pinned certificate again before sending a signed request.
4.3When you're away from home
The moment you leave your network, the direct path stops answering and the app moves on to the other two. Away access comes down to a simple question: can your phone reach your Mac at all right now?
- Tailscale answers yes whenever your phone and Mac share a tailnet. It is the most reliable away path: it works on cellular, on hotel and café Wi-Fi, behind almost any router, with no ports to open.
- A Cloudflare tunnel answers yes whenever the Mac has one running. It needs nothing on the phone and reaches from anywhere, but it depends entirely on the Mac keeping that tunnel up.
If neither is available — no shared tailnet, no tunnel — the app simply can't see your Mac from outside, and the status dot goes to offline. That is expected behaviour, not a fault: a Mac on a private home network is, by design, not reachable from the open internet.
4.4Device web UIs and LAN shares
Reaching your Mac is only half the story. The Web UIs page (under More) opens the web interfaces of other things on your network — routers, NAS boxes, printers, dashboards — and Shared (under More) can open LAN shares your Mac has temporarily exposed. These live on the network itself, not on your Mac, so the app reaching your Mac does not guarantee it can reach them.
A device web UI or a LAN share is reachable only when your phone can actually get onto that network:
- On the same Wi-Fi — everything on the LAN is directly reachable.
- Over Tailscale — reachable if your tailnet routes to that network, for example through a subnet router advertising the LAN's range. Without that, Tailscale gets you to the Mac but not to the printer beside it.
This is the practical reason the TIP above recommends a subnet router or a Tailscale-connected router: it turns "I can reach my Mac" into "I can reach my whole network," which is what makes the Web UIs and Shared screens useful from the road.
4.5Connection status
The coloured dot at the top of Operations is the app's honest summary of whether it can talk to your Mac right now. Fleet shows a separate offline banner whenever it is displaying the last signed inventory. The connection has three states:
| State | What it means |
|---|---|
| Connected | The app reached your Mac on one of the three paths and is showing live data. Service controls work to the extent your device's access level allows. |
| Connecting | The app is trying the paths in order. This is normal for a moment after launch, after a network change, or after a pull-to-refresh. |
| Offline | No path answered. The Mac is asleep, off, or unreachable from where you are — or its control server is off. The app shows the last data it had, clearly marked stale. |
To force a fresh attempt, pull down to refresh on Fleet or Operations. The state returns to connecting while the app re-walks the path list, then settles on connected or offline. For route-by-route evidence, open More → Settings → Connection and tap Check all routes; it shows LAN, Tailscale and other saved routes, their result and latency. The compact Phone & Fleet row on Fleet opens the site view without consuming the rest of the screen.
4.6What has to be true
None of the three paths can conjure a connection that isn't there. For the app to reach your Mac, all of the following must hold:
- The Mac's control server is enabled. This is the service the phone talks to. If it's switched off on the Mac, every path fails and the dot stays offline.
- The Mac is online and reachable. It must be awake, on a network, and reachable from where your phone is — same Wi-Fi, shared tailnet, or via its Cloudflare tunnel. A sleeping Mac answers nothing; consider keeping it from sleeping if you rely on remote access.
- You have a working away path, if you're away. Off your home network, that means Tailscale on both ends, or a tunnel the Mac keeps running.
Push notifications follow the same logic from the other direction: the Mac (or its push relay) must be online to send an alert. If alerts go quiet, the cause is usually the same as a missing connection — the Mac is asleep, off, or unreachable. The summary below ties the three locations together.
| Where you are | How it connects | What's reachable |
|---|---|---|
| Same Wi-Fi / LAN as the Mac | Direct, over your network | Everything: Mac, services, AI, device web UIs, LAN shares |
| Away, shared tailnet | Tailscale | The Mac and the AI; devices and LAN shares too if a subnet router routes to that network |
| Away, Cloudflare tunnel only | Cloudflare tunnel (Mac-enabled) | The Mac and the AI; device UIs only if otherwise reachable |
| Away, no Tailscale and no tunnel | — (no Mac path) | Cached signed inventory, reachable web UIs, bounded direct server checks, enrolled direct SSH, and preparation of reviewed service actions; no fresh Mac-backed state, AI or live control |
Part II
Using FrontierStack Mobile
The five tabs you live in day to day — Fleet, Operations, Shell, the AI Administrator, and everything else under More.
Chapter 5
Using the App: Fleet, Operations, Shell & AI
Once your phone is paired, the app is a secure incident companion and remote for the desktop. This chapter walks through the five tabs — what each shows, what still works offline, and what it lets you do.
FrontierStack for iPhone and iPad is a secure incident companion and remote for FrontierStack on your Mac. Its main screen has five tabs — Fleet, Operations, Shell, AI and More. Most fresh observations and controls come from the Mac over the signed connection created at pairing, while a small, clearly labelled set of phone-originated health and recovery features remains useful when that connection is unavailable. This chapter covers all five; Settings and the lock screen are in the next chapter, and pairing itself is in Pairing your device.
Two ideas run through every tab. First, observation sources stay distinct: cached Mac data shows its age, and a check made now by the phone does not masquerade as full service health. Second, what you are allowed to do depends on this device's permission level, which you set on the Mac — and the most powerful things (a raw shell, direct SSH, or letting the AI make changes) need extra grants, described where they come up.
5.1Fleet — your servers and devices
The Fleet tab is home. At the top, Phone & Fleet keeps two independent facts apart: the route this phone is using to reach the Mac, and the Fleet site the Mac currently uses to scope monitoring and devices. Below it are two groups: your servers and your pinned devices.
The Servers section lists every pinned server — the local Mac is just the first row, so you drive it exactly like any other. Each row carries a status dot:
| Dot | Meaning |
|---|---|
| Green | Up — reachable and healthy. |
| Amber triangle | Degraded — reachable but something needs attention. |
| Red | Down — the Mac can't reach it right now. |
| Hollow | Unknown — not yet probed. |
Tap a server to open it. Its detail screen gives you the same host-level controls as the desktop:
- Check server reachability — contact the saved SSH port and up to eight standard ports implied by services FrontierStack already detected, straight from this phone. A connection proves reachability, not complete service health.
- Services — start, stop, restart or reload each detected service.
- Reboot a remote Unix or Windows server, Run Diagnostics (a plain-language "what's wrong right now") and View Logs. Reboot reports success only after the server or its enrolled monitor accepts it.
- Open Web UI in the built-in browser, and Open Shell (jumps to a shell bound to this server).
- Remote Tools — ping, traceroute, listening ports, a web check and a log tail, run on the server itself.
- Terminal Sessions — list tmux, GNU screen and Zellij sessions without reading their contents; attach over Direct SSH, or end one session after confirmation.
- Fleet Run — read-only checks for pending reboot, disk usage, or uptime/load across every server (see More, below).
- Full status details — OS, uptime, CPU, memory, every reported address, service state and SSH identity evidence in one diagnostic view.
- Performance & history — current CPU, memory, disk, load and uptime followed by six hours to one week of helper-recorded history, learned-baseline assessment, reboot markers and watchdog events.
- Database Emergency & Power Prep — graduated database actions that use the database protocol when SSH is unavailable, including clean shutdown before a reboot or hard power cut.
5.5.1Performance & history
The phone combines current performance and Behaviour & History because they answer one question on call: is this machine behaving normally? Choose a six-hour, one-day, three-day or one-week window. FrontierStack shows whether it is still learning the baseline, behaving normally for this server, or reporting a specific unusual change. Reboots and watchdog incidents appear on the same timeline so a spike has context.
5.5.2Database Emergency & Power Prep
When a database connection pool is exhausted, SSH can fail at the same time. Emergency actions therefore ask the Mac to reach the database over its own client protocol and port. The steps progress from killing stuck connections, through stopping writes and flushing, to a clean database shutdown. A clean shutdown prepares the server for a safer reboot or power cut; stopping the database always requires confirmation.
Below the servers, your pinned devices appear in collapsible sections by kind — routers, switches, printers, NAS, smart-home and so on — each with an online/offline dot and a menu to open its web UI, check its status, or power-cycle it (where a plug or KVM is linked on the Mac).
5.2Operations — the Mac's health and recovery evidence
The Operations tab begins with the live connection state and a refresh button, then gathers the Mac's operational summary rather than merely listing services. Overview shows server count, App Lock state, MCP state, open issues and whether remote changes are currently authorised. Restore readiness shows the latest bounded restore checks, encrypted recovery-copy evidence and representative-workload rehearsal without exposing backup paths, contents, accounts or credentials.
When FrontierStack has evidence for them, Likely upstream causes points to a confirmed dependency worth investigating first, and Server behaviour reports privacy-reduced anomalies learned from local history. These are diagnostic hints, not proof of causation. The final Services section shows the Mac's controllable local services and offers Start or Stop with authority checks and confirmation where appropriate.
This app is independent of the Mac's sidebar. Whatever you have hidden there to keep the desktop tidy remains reachable on the phone. Nothing on the phone changes the Mac's visual sidebar, and a cosmetic desktop preference cannot hide an operational item during an incident.
5.3Shell — a real command line
The Shell tab opens a command-line on the Mac or any linked server. Pick the target from the bar at the top — This Mac or any server — then type commands and read their output. Servers log in automatically using the key and credentials already stored on your Mac; a sudo command uses the server's saved sudo password. None of those credentials ever travel to your phone — the Mac runs the command and streams the output back.
Under More → Scripts you'll find your saved scripts and the built-in maintenance presets, synced from the Mac; tap one to run it and watch the output stream in.
Direct SSH — when the Mac is offline. The shell above is routed through the Mac. On a server's page you can also tap Enable direct SSH (while the Mac is online) to install this device's own SSH key on that server; after that, SSH (direct) opens a real terminal straight from the phone to the server — even when the Mac is offline or on another network — as long as you can reach the server's network (same Wi-Fi or over Tailscale). The phone's SSH key is generated on and never leaves the phone, and the Mac's own key and passwords are never copied to it. Revoking or unpairing the device removes its key from your servers.
cd sticks). It runs ordinary commands and scripts; full-screen terminal programs like top or vim aren't supported.5.4AI — chat with the Administrator
The AI tab is a multi-turn conversation with the same AI Administrator that runs on your Mac. Ask about your servers, services or devices in plain language; as it works it shows the tools it runs and their results inline, so you can see how it reached an answer.
The current AI conversation is Mac-backed. If the Mac cannot be reached, cached health and direct checks remain available elsewhere in the app, but the phone does not send your infrastructure snapshot or credentials to a separate AI service and does not pretend that an offline answer is live.
By default the assistant is read-only — it can look but not change. Switch on "Allow changes" (top-right) to let it act: restart a service, flush DNS, and so on. The conversation history — including any tool results, which can contain secrets — stays on the Mac; your phone only sees the rendered replies. Everything the AI does here still runs on the Mac and obeys the same guards as on the desktop; a chat from the phone can be turned off entirely per device with the Mac's Allow AI Administrator switch, and it always requires the app unlocked and this device signed. Conversations you have from the phone are saved into the Mac's AI Administrator history, so you can pick them back up there.
A green shield to the left of each reply means the answer was protected: before anything left your Mac for the AI model, FrontierStack scrubbed secrets (keys, tokens, passwords) from the tool results — tap the shield to read what that means. You can select and copy both your questions and the replies (press and hold, or use the Copy action) to paste an answer elsewhere. And when you have a server selected, the assistant answers about that machine — the query still runs on your Mac, but "how long has it been up?" or "what's listening?" is scoped to the device you picked, not the Mac.
5.5More — alerts, locations and the rest
The More tab gathers everything that doesn't need its own tab.
5.5.3Agent Activity
Agent Activity is the phone's status-only view of work known to the paired Mac. It groups running coding-agent processes, FrontierStack sessions and jobs, configured runtimes, and detected worker boxes into Needs You, Running, Recently Finished, and Ready. Tap an item with a host to inspect that host's durable terminal sessions.
5.5.4Queue Operations
Queue Operations mirrors the Mac's read-only queue dashboard. Pull to refresh health for RabbitMQ, Kafka, NATS/JetStream, Redpanda, AWS SQS, Azure Service Bus, Google Pub/Sub, Celery, Redis Streams, Pulsar and RocketMQ. It shows backlog, consumers, lag and dead-letter totals without downloading message bodies. Configure credentials and thresholds on the Mac; the phone receives only the signed, sanitised health summary.
5.5.5Queued Actions
When the Mac is offline, eligible service menus say Queue Start, Queue Stop, Queue Restart or Queue Reload. The request stays on this phone and does not run automatically. Open More → Queued Actions to inspect the exact target and expiry, swipe to cancel anything you no longer want, then explicitly send the remaining actions after the Mac returns. Each request expires after four hours and the Mac rechecks its signature, permission and App Lock before executing it once.
5.5.6Alerts
Alerts is the inbox of server alerts — a service down, a disk filling, a certificate expiring — raised by the Mac and its agents. Tap Enable push notifications so they reach you even when the app is closed. Push needs the Mac (or its relay) online to send.
5.5.7Checks — watchdogs and a maintenance pause
Checks is the manager for the Mac's Service Guardian: every service being guarded, whether each is healthy, and which have Keep Alive or Auto Recover switched on. It is the phone-side view of the pane described in Chapter 11 of the desktop manual.
Its useful trick is the pause. Before working on a machine, pause all checks — or just one service — for anything from 15 minutes to a day. While paused, the Mac stops health-checking and stops restarting that service, so your maintenance doesn't fight the watchdog or set off alerts.
Disk repair is protected automatically: while Disk Utility First Aid or a filesystem repair tool is running, automatic recovery pauses without changing its settings. Maintenance-timeout counters are cleared, and recovery waits 60 seconds after repair finishes before starting fresh. The Checks screen shows this safety hold.
5.5.8Phone connection & Fleet sites
The Fleet tab keeps this compact: one Phone & Fleet row shows the active Fleet site and opens the detailed Phone & Fleet Sites screen. That screen separates three things that the old “Location” label could make look like one: how this iPhone reaches the Mac, the site the Mac matches from its own network, and the Fleet site currently used to scope monitoring and devices. The phone's physical position and network do not select the Fleet site.
Choose Follow Mac's detected site to let the Fleet context follow the Mac. Pin another Fleet site when you deliberately want to view or operate that site's context. Pinning does not change the phone's route to the Mac and does not make a remote private network reachable; opening devices at that site still needs an existing route such as Tailscale or a VPN.
5.5.9Fleet Run, Shared & web UIs
Fleet Run offers reviewed, fleet-wide read-only checks for pending reboots, disk usage, and uptime/load, then shows per-host results. Package updates, Git pulls, service restarts, installs and custom commands remain in the Mac's staged operator-review flow. Shared lists the temporary Debug Shares the Mac has opened, which you can open or stop; opening a new one needs Full control and the Mac's external-change policy. Web UIs & Bookmarks opens the admin pages of routers, NAS and cameras, plus addresses bookmarked on the phone. Local self-signed sites require explicit fingerprint trust; public sites require normally trusted HTTPS.
5.5.10The manual on the phone
More → Manual opens this book from the app bundle. It works without the Mac or a network connection, and its search runs on the phone. The manual is also available from the pairing screen, which is useful when the connection itself is what you need to troubleshoot.
Finally, More holds Settings and Help — covered next.
Chapter 6
Settings, App Lock & Troubleshooting
Lock the app to your face or a passcode, unpair cleanly when a phone changes hands, and fix the handful of things that can go quiet between phone and Mac.
The Settings screen — under the More tab — protects this device, explains every route to the paired Mac, and performs a clean revocation when the phone moves on. This final chapter covers local or Mac-managed App Lock, push status, route diagnostics, unpairing, and the features that remain useful when the Mac connection goes quiet.
6.1A tour of Settings
Open More → Settings. It is a single scrolling form, grouped into sections:
- App Lock — either a local passcode and biometric unlock, or a lock managed by the paired Mac.
- Notifications — APNs permission, whether the Mac confirmed relay registration, the last background sync, and any setup error.
- Connection — the paired Mac, the active address, a result and latency for every saved or nearby route, Check all routes, this device's key, and Unpair this device.
- Help & Guide, Manual (offline) and About — concise help, the searchable manual stored in the app, and version information.
Most settings are local to this phone or tablet. Unpairing is the deliberate exception: it asks the Mac to revoke this device and clean up its server access before removing the local pairing.
6.2App Lock: a passcode for the app
FrontierStack Mobile is a remote control for real servers, so it is worth a lock of its own — separate from your device passcode. When the paired Mac does not require its own App Lock, turn on Require passcode to open. You are asked to set a passcode of at least six characters and confirm it. From then on a full-screen gate asks for the passcode before showing infrastructure data.
The app re-locks whenever you leave it — switch to another app, lock the phone, or send FrontierStack to the background — so a glance over your shoulder never exposes your fleet. To change the code later, tap Change passcode (you enter the current one first). To remove it, switch the toggle off and confirm with the current passcode.
6.9.1When App Lock is managed by the Mac
If the Mac required App Lock when you paired, Settings shows Managed by paired Mac: On. The phone asks for the same password, but neither the password nor the Mac's reusable verifier was copied to it; the phone holds a slow verifier bound only to this device's signing identity. Change or remove that lock on the Mac. Face ID or Touch ID remains a local switch on the phone.
6.3Fleet: unlock with a physical security key
A Fleet licence adds Physical security key in the same App Lock section. Enrol a Yubico YubiKey, Google Titan or FEITIAN ePass using Apple's system security-key sheet. The app stores only the public credential and supports up to three registered keys, so add a backup before relying on the policy.
When the policy is on, the app starts locked and re-locks whenever it leaves the foreground. Connect a compatible USB-C or Lightning key, or present an NFC-capable model when prompted, then touch it. If a passcode or mirrored Mac password is also configured, both steps are required; the key is not merely an alternative to the passcode. Without an enrolled key the app remains sealed and exposes no fleet controls.
6.4Face ID and Touch ID
Once a passcode is set, and if your device offers biometrics, an extra switch appears: Unlock with Face ID (or Unlock with Touch ID, matching your hardware). Turn it on and the lock screen offers biometric unlock the moment it appears — you rarely type the passcode at all. The passcode stays as the fallback for when a face or finger is not recognised.
Biometric unlock is a convenience layered on top of the passcode, not a replacement for it: you must set a passcode first, and removing the passcode turns biometrics off automatically. If your device has no Face ID or Touch ID, the switch simply does not appear and the passcode is the only gate.
6.5Unpairing this device
When you sell a phone, hand one to someone else, or want to start over, use Unpair this device. After confirmation, the app asks the Mac to revoke this phone, cancel its pending authority, remove its enrolled direct-SSH keys from servers, and deactivate its push access. Only after the Mac confirms cleanup does the phone remove its pinned certificate, addresses, protected cache and signing identity and return to the pairing screen.
If the Mac cannot confirm revocation, Settings shows the error with Retry Unpair and Forget Locally. Retry when possible. Forget Locally removes the pairing only from this phone; it is provided so you are not trapped by an unreachable Mac, but you must later revoke the device in Paired Devices on the Mac and finish any server-key cleanup listed there.
6.6Troubleshooting
Most trouble is connectivity: the phone and the Mac can't find each other, or a control is greyed out because of where things stand on the Mac. Work down the table, then read the notes below it.
| Symptom | Likely cause | Fix |
|---|---|---|
| FrontierStack connection unavailable — Fleet shows cached inventory even though This Mac is reachable | A direct port check succeeded, but no saved or nearby route completed the signed, certificate-pinned FrontierStack control handshake | Check FrontierStack is open with its control server enabled; pull to refresh, then use Settings → Check all routes for the exact route, certificate or handshake failure. Re-pairing is not the first remedy. |
| Controls are greyed out — buttons show but do nothing | The Mac is locked, or this device is read-only | Unlock the Mac, or raise this device's level under the Paired Devices pane. |
| Check again leaves the phone read-only | The button reads the Mac's current decision; it does not grant authority | In Paired Devices on the Mac, set this phone to Restart services or higher, and make sure FrontierStack is unlocked. Re-pair only if the phone is no longer listed there. |
| A saved LAN address no longer works | DHCP or a network change gave the Mac a new address | Keep both devices on the same LAN and refresh. Bonjour finds the paired Mac's current address and accepts it only after the saved certificate fingerprint matches. If Paired Devices on the Mac says automatic LAN discovery needs access, enable FrontierStack under System Settings → Privacy & Security → Local Network. Saved LAN and Tailscale routes remain available while Bonjour is blocked. |
| A service action says Queue instead of running | The Mac is offline | Review it under More → Queued Actions. It runs only after the Mac returns and you explicitly send it; it expires after four hours. |
| Direct SSH is blocked | The phone key was not enrolled, the server identity is missing or changed, or the server network is unreachable | While the Mac is online, enable direct SSH from the server page and capture its identity. Compare the fingerprint out of band where possible; then use the same LAN or Tailscale to reach the server. |
| No push notifications arrive | Notifications aren't enabled, or the sender is offline | Enable them in Alerts (under the More tab) and allow notifications when iOS asks; make sure the Mac (or its push relay) is online to send. |
| A device web page won't load | The network is unreachable, or the certificate is unapproved or changed | Use the same Wi-Fi or Tailscale. For a local self-signed site, compare and approve its SHA-256 fingerprint; a changed fingerprint stays blocked. Public sites need normally trusted HTTPS. |
6.7When you can't reach the Mac
The app probes saved LAN, Tailscale and other enrolled routes without waiting for a dead address to consume the whole connection attempt. On the same LAN, Bonjour also looks for this exact paired Mac if its address changed; the full saved certificate fingerprint must match before a discovered address is accepted. Several phones may connect to one Mac independently, and several Macs may advertise on the LAN without colliding because display names are never used as trust.
If none answers, Operations shows offline and Fleet keeps the last signed inventory with its age. Check that FrontierStack is open with its control server enabled, then verify the same Wi-Fi or Tailscale on both ends. Pull to refresh forces a retry after a network change. In Settings, Reached via identifies the active address and Check all routes shows why each alternative connected, stood by, was unreachable or was blocked. Bringing Tailscale up triggers another connection refresh automatically.
You can still open a cached server and choose Check server reachability. That bounded check goes from the phone to the saved SSH and service addresses without the Mac. It distinguishes "the Mac is unavailable" from "the server is also unreachable," but an open port alone does not prove the service or operating system is healthy. Enabled direct SSH and reachable web UIs also remain available. Mac-backed AI, fresh central telemetry, reboots and live controls resume only when the Mac returns.
6.8Greyed-out controls and missing alerts
If you can see status but the Start/Stop buttons do nothing, the app isn't broken — it is telling you the action isn't permitted right now. Either the Mac is locked at its login window, in which case it won't act on a remote command until someone unlocks it, or this device's permission level is too low. Raise the level on the Mac under the Paired Devices pane, or pick up a device that already has the rights.
The authority banner appears only after a live response from the Mac; when the Mac cannot be reached, Fleet reports that as a connection problem instead. Its Check again button only asks the Mac for the current permission decision. It cannot raise its own permission — that would defeat the per-device guardrail. If the phone still appears in Paired Devices and can read current status, its pairing and signing key are working; changing its permission on the Mac is enough. Pair again only after the Mac no longer lists the phone, the device was revoked, or the app explicitly reports an invalid pairing identity.
For alerts, remember the chain has two ends. The phone has to have notifications enabled — Enable notifications in Settings, and allow them when iOS prompts — and the Mac (or its push relay) has to be online to send them. If alerts simply stop arriving, the most common reason is that the Mac went to sleep or offline; wake it and confirm it is reachable from the Fleet tab.
6.9Where to go from here
That is the whole companion app: pair once from the Mac, watch your fleet from anywhere, act when your permission level allows, and keep the phone itself locked. You have a faithful, secure window onto everything FrontierStack runs — in your pocket.
For more, use the concise in-app Help & Guide or Manual (offline) under Settings. The manual is stored in the app, remains available before pairing and during an outage, and supports on-device search. The desktop manual covers every Mac pane and service in depth — start at the FrontierStack manual. For news, downloads or support, visit frontierstack.app.