Put the Larktun Network Inside an App Without VPN Permission
On mobile devices, private device networking almost always raises the same question: do we need system VPN permission?
Whether you use Larktun or Tailscale, if you want every app on the phone to access a private network, the usual answer is yes. A system-level VPN tunnel gives the client full capability: traffic can be routed through the private network, DNS and routes can be handled centrally, and apps can access internal services without being aware of the tunnel. But this also creates practical friction. Users must understand and approve a VPN profile, apps may need extra platform capabilities, and the tunnel can conflict with a company VPN, campus VPN, or other proxy tools that already occupy the system network entry point.
So is there another path: can we use private device networking without requesting system VPN permission?
Yes. The key is tsnet.