23 ms·
CLI agents make self-hosting on a home server easier and fun
- deleted 9mo ago[deleted]
- simonw 9mo agoThis posts lists inexpensive home servers, Tailscale and Claude Code as the big unlocks. I actually think Tailscale may be an even bigger deal here than sysadmin help from Claude Code at al. The biggest reason I had not to run a home server was security: I'm worried that I might fall behind on updates and end up compromised. Tailscale dramatically reduces this risk, because I can so easily configure it so my own devices can talk to my home server from anywhere in the world without the risk of exposing any ports on it directly to the internet. Being able to hit my home server directly from my iPhone via a tailnet no matter where in the world my iPhone might be is really cool.
- philips 9mo agoI agree! Before Tailscale I was completely skeptical of self hosting. Now I have tailscale on an old Kindle downloading epubs from a server running Copyparty. Its great!
- ryandrake 9mo agoMaybe I'm dumb, but I still don't quite understand the value-add of Tailscale over what Wireguard or some other VPN already provides. HN has tried to explain it to me but it just seems like sugar on top of a plain old VPN. Kind of like how "pi-hole" is just sugar on top of dnsmasq, and Plex is just sugar on top of file sharing.
- Skunkleton 9mo agoYes, that is really all it is.
- mfcl 9mo agoIt's plug and play.
- Forgeties79 9mo agoAnd some people may not value that but a lot of people do. It’s part of why Plex has become so popular and fewer people know about Jellyfin. One is turnkey, the other isn’t. I could send a one page bullet point list of instructions to people with very modest computer literacy and they would be up and running in under an hour on all of their devices with Plex in and outside of their network. From that point forward it’s basically like having your own Netflix.
- Jtsummers 9mo agoI think you answered the question. Sugar. It's easier than managing your own Wireguard connections. Adding a device just means logging into the Tailscale client, no need to distribute information to or from other devices. Get a new phone while traveling because yours was stolen? You can set up Tailscale and be back on your private network in a couple minutes. Why did people use Dropbox instead of setting up their own FTP servers? Because it was easier.
- johnisgood 9mo agoYeah, but "people" here are alleged software engieners. It is quite disheartening.
- wiether 9mo agoFirst and foremost they are humans, with a limited time on Earth. Being a software engineer doesn't mean you want to spend you free time tinkering about your self-hosting setup and doing support for your users. With Tailscale, not only you don't have to care about most things since _it just works_, but also on-boarding of casual users is straightforward. Same goes for Plex. I want to watch movies/shows, I don't want to spend time tinkering with my setup. And Plex provides exactly that. Ditto for my family/friends that can access my library with the same simple experience as Netflix or whatever. Meanwhile, I have a coworker who want to own/manage everything. So they don't want to use Tailscale and they dropped Plex when they forced to use the third-party login system. Now they watch less than a third than they used to be, and they share their setup with nobody since it's too complicated to do. To each their own, but my goal is to enjoy my setup and share it with others. Tailscale and Plex give me that.
- johnisgood 9mo agoThere is a difference between "I choose not to" and "I cannot". The thread is full of people saying Tailscale "unlocked" self-hosting, implying capability, not time savings or time preference. Choosing convenience is fine. But if basic port forwarding or WireGuard is beyond someone's skill set, "software engineer" is doing a lot of heavy lifting. I am not saying they are, but if it really is the case, then yeah. As for file sharing... I remember when non-SWEs knew how to torrent movies, used DC++ and so on. These days even SWEs have no idea how to do it. It is mind-boggling.
- atmosx 9mo agoYou don’t have to run the control plane and you don’t have to manage DNS & SSL keys for the DNS entries. Additionally the RBAC is pretty easy. All these are manageable through other tools, but it’s more complicated stack to keep up.
- Frotag 9mo agoI always assumed it was because a lot of ISPs use CGNAT and using tailscale servers for hole punching is (slightly) easier than renting and configuring a VPS.
- Cyph0n 9mo agoIt’s a bit more than sugar. 1. 1-command (or step) to have a new device join your network. Wireguard configs and interfaces managed on your behalf. 2. ACLs that allow you to have fine grained control over connectivity. For example, server A should never be able to talk to server B. 3. NAT is handled completely transparently. 4. SSO and other niceties. For me, (1) and (2) in particular make it a huge value add over managing Wireguard setup, configs, and firewall rules manually.
- drnick1 9mo ago> Kind of like how "pi-hole" is just sugar on top of dnsmasq, and Plex is just sugar on top of file sharing. Speaking of that, I have always preferred a plain Unbound instance and a Samba server over fancier alternatives. I guess I like my setups extremely barebone.
- ryandrake 9mo agoYea, my philosophy for self-hosting is "use the smallest amount of software you can in order to do what you really need." So for me, sugar X on top of fundamental functionality Y is always rejected in favor of just configuring Y."
- simonw 9mo agoIf you're confident that you know how to securely configure and use Wireguard across multiple devices then great, you probably don't need Tailscale for a home lab. Tailscale gives me an app I can install on my iPhone and my Mac and a service I can install on pretty much any Linux device imaginable. I sign into each of those apps once and I'm done. The first time I set it up that took less than five minutes from idea to now-my-devices-are-securely-networked.
- zeroxfe 9mo ago> Plex is just sugar on top of file sharing. right, like browsers are just sugar on top of curl
- edoceo 9mo agocurl is just sugar on sockets ;)
- epistasis 9mo agoSSH is just sugar on top of telnet and running your own encryption algorithms by hand on paper and typing in the results.
- InfinityByTen 9mo agoAt least postman is :P
- SchemaLoad 9mo agoTailscale is Wireguard but it automatically sets everything up for you, handles DDNS, can punch through NAT and CGNAT, etc. It's also running a Wireguard server on every device so rather than having a hub server in the LAN, it directly connects to every device. Particularly helpful if it's not just one LAN you are trying to connect to, but you have lots of devices in different areas.
- lelandbatey 9mo agoIf Plex is "just file sharing" then I guarantee you'd find Tailscale "just WireGuard". I enjoy that relative "normies" can depend on it/integrate it without me having to go through annoying bits. I like that it "just works" without requiring loads of annoying networking. For example, my aging mother just got a replacement computer and I am able to make it easy to access and remotely administer by just putting Tailscale on it, and have that work seamlessly with my other devices and connections. If one day I want to fully self-host, then I can run Headscale.
- navigate8310 9mo agoTailscale is able to punch holes in CGNAT which a vanilla wireguard cannot
- BatteryMountain 9mo agoSetting up wireguard manually can be a pain in the butt sometimes. Tailscale makes it super easy but then your info flows through their nodes.
- tech_ken 9mo agoManaging the wg.conf is a colossal PITA, especially if I'm trying to like provision a new client and don't have access to my main laptop. It's crying out for a CRUD app on top of it, and I think tailscale is basically that plus a little. The value add seems obvious. Also plex is way more than sugar on top of file sharing; it's like filesharing, media management, and a CDN rolled into one product. Soulseek isn't going to handle transcoding for you.
- epistasis 9mo agoI use Tailscale for exactly those reasons, plus the easy SSL certificates and clients for Android and iOS. From this thread, I've learned about Pangolin: https://github.com/fosrl/pangolin https://github.com/fosrl/pangolin Which seems very compelling to me too. If it has apps that allow various devices connect to the VPN it might be worth it to me to trial using it instead of Tailscale...
- dangoodmanUT 9mo agodefinitely, but to be fair, beyond that it's just linux. Most people would need claude code to get what ever they want to use linux for running reliably (systemd service, etc.)
- dangoodmanUT 9mo agoi'm still waiting for ECC minipcs, then i'll go all in on local DBs too
- aaronax 9mo agoSupermicro has some low power options such as https://www.supermicro.com/en/products/system/Mini-ITX/SYS-E300-9A-4CN8.php https://www.supermicro.com/en/products/system/Mini-ITX/SYS-E...
- drnick1 9mo agoI'd rather expose a Wireguard port and control my keys than introduce a third party like Tailscale. I am not sure why people are so afraid of exposing ports. I have dozens of ports open on my server including SMTP, IMAP(S), HTTP(S), various game servers and don't see a problem with that. I can't rule out a vulnerability somewhere but services are containerized and/or run as separate UNIX users. It's the way the Internet is meant to work.
- CSSer 9mo agoThe answer is people who don't truly understand the way it works being in charge of others who also don't in different ways. In the best case, there's an under resourced and over leveraged security team issuing overzealous edicts with the desperate hope of avoiding some disaster. When the sample size is one, it's easy to look at it and come to your conclusion. In every case where a third party is involved, someone is either providing a service, plugging a knowledge gap, or both.
- sauercrowd 9mo agoPeople are not full time maintainers of their infra though, that's very different to companies. In many cases they want something that works, not something that requires a complex setup that needs to be well researched and understood.
- buildfocus 9mo agoWireguard is _really_ simple in that sense though. If you're not doing anything complicated it's very easy to set up & maintain, and basically just works. You can also buy quite a few routers now that have it built in, so you literally just tick a checkbox, then scan a QR code/copy a file to each client device, done.
- vladvasiliu 9mo agoThis may come with its own limitations, though. My ISP-provided router (Free, in France) has WG built-in. But other than performance being abysmal, its main pain point is not supporting subnet routing. So if all you want is to connect your phone / laptop while away to the local home network, it's fine. If you want to run a tunnel between two locations with multiple IPs on the remote side, you're SoL.
- comrade1234 9mo agoI just have a vpn server on my fiber modem/router (edgerouter-4) and use vpn clients on my devices. I actually have two vpn networks - one that can see the rest of my home network (and server) and the other that is completely isolated and can't see anything else and only does routing. No need to use a third-party and I have more flexibility
- PaulKeeble 9mo agoIts especially important in the CGNAT world that has been created and the enormous slog that IPv6 rollout has ultimately become.
- shadowgovt 9mo agoBesides the company that operates it, what is the big difference between Tailscale and Cloudflare tunnels? I've seen Tailscale mentioned frequently but I'm not quite sure what it gets for me. If it's more like a VPN, is it possible to use on an arbitrary device like a library kiosk?
- ssl-3 9mo agoI don't use Cloudflare tunnels for anything. But Tailscale is just a VPN (and by VPN, I mean: Something more like "Connect to the office networ" than I do "NordVPN"). It provides a private network on top of the public network, so that member devices of that VPN can interact together privately. Which is pretty great: It's a simple and free/cheap way for me to use my pocket supercomputer to access my stuff at home from anywhere, with reasonable security. But because it happens at the network level, you (generally) need to own the machines that it is configured on. That tends to exclude using it in meaningful ways with things like library kiosks.
- vachina 9mo agoYou can self host a tailscale network entirely on your own, without making a single call to Tailscale Inc. Your cloudflare tunnel availability depends on Cloudflare’s mood of the day.
- SchemaLoad 9mo agoYeah same story for me. I did not trust my sensitive data on random self hosting apps with no real security team. But now I can put the entire server on the local network only and split tunnel VPN from my devices and it just works. LLMs are also a huge upgrade here since they are actually quite competent at helping you set up servers.
- Melatonic 9mo agoWhy not cloudflare tunnels ?
- mobilio 9mo agoCF tunnels are game changers for me!
- driton 9mo agoEven behind a tunnel, if you happen to be running an older version of a service (like Immich) with a known exploit, you are still vulnerable to attacks. Tailscale sidesteps this by keeping the service completely "invisible" to the outside world, so the two don't quite compare in my view.
- JamesSwift 9mo agoJust use subpath routing and fail2ban and Im very comfortable with exposing my home setup to the world. The only thing served on / is a hello world nginx page. Everything else you need to know the randomly generated subpath route.
- MattSayar 9mo agoJust be sure to run it with --accept-dns=false otherwise you won't have any outbound Internet on your server if you ever get logged out. That was annoying to find out (but easy to debug with Claude!)
- BatteryMountain 9mo agoTailscale is a good first step, but its best to configure wireguard directly on your router. You can try headscale but it seems to be more of a hobby project - so native wireguard is the only viable path. Most router OS's supports wireguard these days too. You can ask claude to sanity check your configuration.
- johnisgood 9mo agoTailscale does not solve the "falling behind on updates" problem, it just moves the perimeter. Your services are still vulnerable if unpatched: the attacker now needs tailnet access first (compromised device, account, or Tailscale itself). You have also added attack surface: Tailscale client, coordination plane, DERP relays. If your threat model includes "OpenSSH might have an RCE" then "Tailscale might have an RCE" belongs there too. WireGuard gives you the same "no exposed ports except VPN" model without the third-party dependency. The tradeoff is convenience, not security. BTW, why are people acting like accessing a server from a phone is a 2025 innovation? SSH clients on Android/iOS have existed for 15 years. Termux, Prompt, Blink, JuiceSSH, pick one. Port N, key auth, done. You can run Mosh if you want session persistence across network changes. The "unlock" here is NAT traversal with a nice UI, not a new capability.
- Galanwe 9mo ago> BTW, why are people acting like accessing a server from a phone is a 2025 innovation? > SSH clients on Android/iOS have existed for 15 years That is not the point, Tailscale is not just about having a network connection, it's everything that goes with. I used to have OpenVPN, and there's a world of difference. - The tailscale client is much nicer and convenient to use on Android than anything I have seen. - The auth plane is simpler, especially for non tech users (parents, wife) whom I wish to access my photo album. They are basically independent with tailscale. - The simplicity also allows me to recommend it to friends and we can link between our tailnet, e.g. to cross backup our NAS. - Tailscale can terminate SSH publicly, so I can selectively expose services on the internet (e.g. VaultWarden) without exposing my server and hosting a reverse proxy. - ACLs are simple and user friendly.
- johnisgood 9mo agoYou are listing conveniences, which is fair. I said the tradeoff is convenience, not security. > "Tailscale can terminate SSH publicly" You are now exposing services via Tailscale's infrastructure instead of your own reverse proxy. The attack surface moved, it did not shrink.
- twelvedogs 9mo ago
- PeterStuer 9mo agoThese are two very separate issues. Tailscale or other reverse proxies will give you access from the WAN. Claude Code or other assistants will give you conversational management. I already do the former (using Pangolin). I'm building towards the latter but first need to be 100% sure I can have perfect rollback and containement across the full stack CC could influence.
- lee_ars 9mo agoI've started experimenting with Claude Code, and I've decided that it never touches anything that isn't under version control. The way I've put this into practice is that instead of letting claude loose on production files and services, i keep a local repo containing copies of all my service config files with a CLAUDE.md file explaining what each is for, the actual host each file/service lives on, and other important details. If I want to experiment with something ("Let's finally get around to planning out and setting up kea-dhcp6!"), Claude makes its suggestions and changes in my local repo, and then I manually copy the config files to the right places, restart services, and watch to see if anything explodes. Not sure I'd ever be at the point of trusting agentic AI to directly modify in-place config files on prod systems (even for homelab values of "prod").
- mtoner23 9mo agoPeople are way too worried about security imo. Statistically, no one is targeting you to be hacked. By the time you are important and valuable enough for your home equipment to be a target you would have hired someone else to manage this for you
- fetzu 9mo agoI think this is very dangerous perspective. A lot of attacks on infra are automated, just try to expose a Windows XP machine to the internet for a day and see with how much malware you end up with. If you leave your security unchecked, you will end up attacked; not by someone targeting you specifically, but having all your data encrypted for ransom might still create a problem for you (even if the attacker doesn’t care about YOUR data specifically).
- subscribed 9mo agoOh, sure, no one is targeting me specifically. Its only swarms of bots and scripts going through the entire internet, including me. iptables and fail2ban should be installed pretty early, and then - just watch the logs.
- johnfn 9mo agoOnce, when I was young and inexperienced, I left a server exposed to the Internet by accident (I accidentally exposed a user with username postgres, password postgres). In hours the machine had been hacked to run a botnet. Was I stupid? Yes. But I absolutely wasn't a high-profile enough person to "be a target" - clearly someone was just scanning IP addresses.
- cirelli94 9mo agoCrying inside myself after a crypto miner took my VM this past week.
- ErikBjare 9mo agoAnd mine last year
- hexfish 9mo agoIs Tailscale still recording metadata about all your connections? https://github.com/tailscale/tailscale/issues/16165 https://github.com/tailscale/tailscale/issues/16165
- znpy 9mo ago> The biggest reason I had not to run a home server was security: I'm worried that I might fall behind on updates and end up compromised. In my experience this is much less of an issue depending on your configuration and what you actually expose to the public internet. Os-side, as long as you pick a good server os (for me that’s rocky linux) you can safely update once every six months. Applications-wise, i try and expose as little as possible to the public internet and everything exposed is running in an unprivileged podman container. Random test stuff is only exposed within the vpn. Also tailscale is not even a hard requirement: i rub openvpn and that works as well, on my iphone too. The truly differentiating factor is methodological, not technological.
- miki123211 9mo agoNow I wish there was some kind of global, single-network version of Tailscale... TS is cool if you have a well-defined security boundary. This is you / your company / your family, they should have access. That is the rest of the world, they should not. My use case is different. I do occasionally want to share access to otherwise personal machines around. Tailscale machine sharing sort of does what I want, but it's really inconvenient to use. I wish there was something like a Google Docs flow, where any Tailscale user could attempt to dial into my machine, but they were only allowed to do so after my approval.
- fartfeatures 9mo agoTake a look at Zrok it might be what you want: https://zrok.io https://zrok.io
- PLG88 9mo agoYou have more or less described OpenZiti. Just mint a new identity/JWT for the user, create a service, and viola, only that user has access to your machine. Fully open source and self-hostable.
- josecodea 9mo agoTailscale Funnel, no? For the permissions, just add basic auth in the reverse proxy and choose whom to share the passwd with. Now if you want OAuth or something like that... well tough luck, you need to set up OIDC or whatever and that's going to be taking you some time, but it still works how you want.
- throwup238 9mo agoThere’s also Cloudflare tunnels for stuff that you want to be available to the internet but dont want to open ports and deal with that. You can add an auth policy that only works with your email and Github/whatever SSO.
- josecodea 9mo agoGreat! I have looked into this and I have a few questions though... Basically, I feel that tailscale does not make it very easy to set up services this way, and the only method I have figured out has a bit too many steps for my liking, basically: - to expose some port to the tailnet, there needs to be a `tailscale serve` command to expose its ports - in order for this command to run on startup and such, it needs to be made into a script that is run as a SystemD service - if you want to do this with N services, then you need to repeat these steps N times Is this how you do it? is there a better way?
- cmiles8 9mo agoAnyone seriously about tech should have a homelab. It’s a small capital investment that lasts for years and with proxmox or similar having your own personal “private cloud” on demand is simple.
- e2e4 9mo agoMy stack. Claude code working via CLIs: Coolify on hetzner
- pablonaj 9mo agoCan you comment a bit on your setup? Sounds interesting.
- Humorist2290 9mo agoFun. I don't agree that Claude Code is the real unlock, but mostly because I'm comfortable with doing this myself. That said, the spirit of the article is spot on. The accessibility to run _good_ web services has never been better. If you have a modest budget and an interest, that's enough -- the skill gap is closing. That's good news I think. But Tailscale is the real unlock in my opinion. Having a slot machine cosplaying as sysadmin is cool, but being able to access services securely from anywhere makes them legitimately usable for daily life. It means your services can be used by friends/family if they can get past an app install and login. I also take minor issue with running Vaultwarden in this setup. Password managers are maximally sensitive and hosting that data is not as banal as hosting Plex. Personally, I would want Vaultwarden on something properly isolated and locked down.
- heavyset_go 9mo agoI believe Vaultwarden keeps data encrypted at rest with your master key, so some of the problems inherent to hosting such data can be mitigated.
- Humorist2290 9mo agoI can believe this, and it's a good point. I believe Bitwarden does the same. I'm not against Vaultwarden in particular but against colocation of highly sensitive (especially orthogonally sensitive) data in general. It's part of a self-hoster's journey I think: backups, isolation, security, redundancy, energy optimization, etc. are all topics which can easily occupy your free time. When your partner asks whether your photos are more secure in Immich than Google, it can lead to an interesting discussion of nuances. That said, I'm not sure if Bitwarden is the answer either. There is certainly some value in obscurity, but I think they have a better infosec budget than I do.
- Gualdrapo 9mo agoOne day when I have some extra bucks I'd try to get a home server running, but the idea of having something eating grid electricity 24/7 doesn't seem to play along well with this 3rd world budget. Are there some foolproof and not so costly off-grid/solar setups to look at (like a Raspberry-based thingy or similar)?
- noname120 9mo agoMac Mini (M1 and later) under Asahi Linux just uses 5 W for a normal workload. If you push it to 100% of CPU it reaches 20 W. That’s very little.
- SchemaLoad 9mo agoOnly thing is you can't run Proxmox which makes self hosting much better, and you'll be limited to ARM builds, which on server is at least a lot easier than trying to run desktop apps. Modern micro desktops are also fairly power efficient, perhaps not quite as low as the mac, but much lower than a regular gaming desktop idling. Avoid stacking in too many hard drives since each one uses almost as much power as the desktop does at idle.
- atahanacar 9mo agoI doubt anyone who is too tight on cash that they have to think about the electricity cost of a home server can afford a Mac.
- imiric 9mo agoYour fridge and other home appliances likely use much more power than whatever a small server would. The mini PC in the article is very power efficient. You likely won't notice it in your power bill, regardless of your budget. You could go with a solar-powered setup if you prefer, but IMO for this type of use case it would be overengineering.
- efilife 9mo agohow many times will I get clickbaited by some cool title only to see AI praise in the article and nothing more? It's tiring and happens way too often related "webdev is fun again": claude. https://ma.ttias.be/web-development-is-fun-again/ https://ma.ttias.be/web-development-is-fun-again/ Also the "Why it matters" in the article. I thought it's a jab at AI-generated articles but it starts too look like the article was AI written as well
- keybored 9mo agoEverything is now not-niche but on the cusp of hitting the mainstream. Like Formal Methods.[1] But they were nice enough to put it in the title. Then tptacek replied that he “called it a little bit” because of: Did Semgrep Just Get A Lot More Interesting?[2] (Why? What could the reason be?) [1] https://martin.kleppmann.com/2025/12/08/ai-formal-verification.html https://martin.kleppmann.com/2025/12/08/ai-formal-verificati... [2]: https://fly.io/blog/semgrep-but-for-real-now/ https://fly.io/blog/semgrep-but-for-real-now/
- jacobthesnakob 9mo agoMaybe because I don’t do SWE for my job, but I have fun writing docker-compose files, troubleshooting them, and adding containers to my server. Then I understand how/why stuff works if it breaks, why would I want to hand that over to an AI? Waiting for the follow-on article “Claude Code reformatted my NAS and I lost my entire media collection.”
- chasing0entropy 9mo agoROFL. There have been at least two posts of Claude without confirmation deleting a repository and one where it wiped an entire partition
- efilife 9mo agopsa: The title has been changed since
- sprainedankles 9mo agoImpeccable timing, I finally got around to putting some old hardware to use and getting a home assistant instance (and jellyfin, and immich, and nextcloud, ...) set up over winter break. Claude (and tailscale) saved hours of my time and enabled me to build enough momentum to get things configured. It's now feasible for me to spend 15-20 minutes knocking down homeserver tasks that I otherwise would've ignored. Quite fun!
- hinkley 9mo agoWhat I’d really like is to run the admin interface for an app on a self hosted system behind firewalls, and push read replicas out into the cloud. But I haven’t seen a database where the master pushes data to the replicas instead of the replicas contacting the master. Which creates some pretty substantial tunneling problems that I don’t really want on my home network. Is there a replica implementation that works in the direction I want?
- chasing0entropy 9mo agoUse NAT hole punching if you're advanced, or you could fall back to IP/port filtering
- hinkley 9mo agoWhy do I have to use a tunnel and empower a machine I don’t control to mess with a machine I do? Why has this been made so difficult? Why wouldn’t a master be aware of all of its replicas? Raft does.
- bakies 9mo agoTailscale will take care of the networking if you install it in both locations.
- reachableceo 9mo agoCloudron makes this even easier. Well worth 1.00 a day! Handles the entire stack (backups , monitoring , dns , ssl , updates ).
- sciences44 9mo agoInteresting subject, thank you! I have a cluster of 2 Orange Pis (16 GB RAM each) plus a Raspberry Pi. I think it's high time to get them back on my desk. I never had time to get very far with the setup due to a lack of time. It took so long to write the Ansible scripts/playbooks, but with Claude Code, it's worth a try now. So thanks for the article; it makes me want to dust it off!
- atmosx 9mo agoJust make sure you have a local and remote backup server. From to time, test the restore process.
- yencabulator 9mo agoClaude with root access will ensure there's "motivation" to run the restore process regularly.
- __MatrixMan__ 9mo agoI haven't tried it yet, but the evil twin to this practice is to nuke everything periodically to ensure that your agent isn't relying on any filesystem state that it hasn't specified builds for (i.e. https://grahamc.com/blog/erase-your-darlings/ https://grahamc.com/blog/erase-your-darlings/). They tend to slip out of declarative mode and start making untracked changes to the system from time to time.
- cafebeen 9mo agoThis is great and echoes my experience. Although I would add a caveat that this mostly applies to solo work. Once you need to collaborate or operate on a team, many of limits of self-hosting return.
- holyknight 9mo agonot with these hardware prices...
- SchemaLoad 9mo agoSecond hand micro desktops are still cheap, at least for now.
- drnick1 9mo agoHardware that is considered e-waste (like a Core 2 Duo) makes a wonderful home server.
- SchemaLoad 9mo agoYou can go much newer than that and get semi modern intel chips second hand. For something that runs 24/7, the power cost will exceed the savings from using long obsolete chips.
- minihoster 9mo agoMight as well ask here in case author or anyone else with a similar setup is reading. Has anyone run into stability issues running a bunch of self-hosting stuff on a mac mini M1 (8GB)? My setup is pretty basic - docker running Jellyfin, Immich, *arr software, qbittorrent. Stuff is stored on a NAS over SMB. Usually within a few hours of rebooting, the OS or at least userspace totally freezes. SSH connections are instantly closed, screen share doesn't work. It responds to ping for a while but that also goes down eventually. Pretty stumped...
- jackschultz 9mo agoI literally did this yesterday and had the same thought. Older computer (8 gigs ram) with crappy windows I never used and I thought huh, I wonder how good these models can take me through installing linux with goal of docker deploys of relatively basic things like cron tasks, personal postgres, and minio that I can used for self shared data. Took a couple hours with some things I ran across, but the model had me go through the setup for debian, how to go through the setup gui, what to check to make it server only, then it took me through commands to run so it wouldn't stop when I closed the laptop, helped with tailscale, getting the ssh keys all setup. Heck it even suggested doing daily dumps of the database and saving to minio and then removing after that. Also knows about the limitations of 8 gigs of ram and how to make sure docker settings for the difference self services I want to build don't cause issues. Give me a month and true strong intention and ability to google and read posts and find the answer on my own and I still don't think I would have gotten to this point with the amount of trust I have in the setup. I very much agree with this topic about self hosting coming alive because these models can walk you through everything. Self building and self hosting can really come alive. And in the future when open models are that much better and hardware costs come down (maybe, just guessing of course) we'll be able to also host our own agents on these machines we have setup already. All being able to do it ourselves.
- notesinthefield 9mo agoI find myself a bit overwhelmed with hardware options during recent explorations. Seemingly everything can handle what I want a local copy of my Bandcamp archive to stream via jellyfin. Good times we’re in but even having good sysadmin skills, I wish someone would just tell me exactly what to buy.
- devonhk 9mo ago> I wish someone would just tell me exactly what to buy. I’ll bite. You can save a lot of money by buying used hardware. I recommend looking for old Dell OptiPlex towers on Facebook Marketplace or from local used computer stores. Lenovo ThinkCentres (e.g., m700 tiny) are also a great option if you prefer something with a smaller form factor. I’d recommend disregarding advice from non-technical folks recommending brand new, expensive hardware, because it’s usually overkill.
- SchemaLoad 9mo agoI spent so long trying to make Raspberry Pis work but they just kind of suck and everything is harder on them. I only just discovered that there are an infinite supply of these micro desktops second hand from offices/government. I was able to pick up a 9th gen intel with 16gb ram for less than the cost of a Pi 5, and it's massively more powerful.
- jacobthesnakob 9mo agoPi’s are incredible little basic home servers but they can’t handle transcoding. Great option for places with very expensive electricity too.
- SchemaLoad 9mo agoI just found their proprietary hardware and being ARM too limiting. I wanted to set up full disk encryption to set up nextcloud on, and found that on the pi this is an incredibly complex process. While on an x86 PC it's just a checkbox on install. And then you can only use distros which have a raspberry pi specific build. Generic ARM ones won't work.
- bicepjai 9mo agoI feel the same way. I now have around 7 projects hosted on a home server with Coolify + Cloudflare. Always worry about security and I have seen many posts related to self hosting on HN trending recently
- SchemaLoad 9mo agoFor security just don't expose the server to the internet. Either set up wireguard or tailscale. You can set it up in a split tunnel config so your phone only uses the VPN for LAN requests.
- bicepjai 9mo agoI am expecting Cloudflare Tunnel to take care of security. In fact, that is the only reason I am okay hosting from home. Are you talking about something more on top of Cloudflare Tunnel or extra security features or a replacement?
- SchemaLoad 9mo agoCloudflare Tunnel is a very similar solution. Just a different product for the same task.
- easterncalculus 9mo agoNice. This is a great start. The next steps are backups and regular security updates. The former is probably pretty easy with Claude and a provider like Backblaze, for updates I wonder if "check for security issues with my software and update anything in need" will work well (and most importantly, how consistently). Alternatively, getting the AI to threat model and perform any docker hardening measures. Then someday we self-host the AI itself, and it all comes together.
- zrail 9mo agoMy security update system is straightforward but it took quite a lot of thought to get here. My self hosted things all run as docker containers inside Alpine VMs running on top of Proxmox. Services are defined with Docker Compose. One of those things is a Forgejo git server along with a runner in a separate VM. I have a single command that will deploy everything along with a Forgejo action that invokes that command on a push to main. I then have Renovate running periodically set to auto-merge patch-level updates and tag updates. Thus, Renovate keeps me up to date and git keeps everyone honest.
- StrLght 9mo ago> Your home server's new sysadmin: Claude Code (In)famous last words?
- comrade1234 9mo agoPrices are going to have an effect here. I have a 76TB backup drive of 8 drives. A few months ago one of my 10TB drives failed and I replaced it with a 12 TB WD gold for 269CHF. I was thinking of building a new backup drive (for fun) and so I priced the same drive and now it's 409CHF. It's not tariffs (I'm in Switzerland). It's 100% the buildout of data centers for AI.
- benzguo 9mo agoGreat post! Totally agree – agents like Claude Code make self-hosting a lot more realistic and low maintenance for the average dev. We've gone a step further, and made this even easier with https://zo.computer https://zo.computer You get a server, and a lot of useful built-in functionality (like the ability to text with your server)
- danpalmer 9mo agoThere's something ironic about using Claud Code – a closed source service, that you can't self-host the hardware for, and that you can't get access to the data for – to self-host so that you can reduce your dependencies on things.
- SchemaLoad 9mo agoBefore you had to rely on blog posts and reddit for information, something you also couldn't self host. And if you are just asking it questions and taking actions yourself, you are learning how it works to do it yourself next time.
- danpalmer 9mo agoOr you could read man pages, ask people for help, read books... all of which are more closely aligned with self-hosting than outsourcing the whole process. I agree you could use LLMs to learn how it works, but given that they explain and do the actions, I suspect the vast majority aren't learning anything. I've helped students who are learning to code, and very often they just copy/paste back and forth and ignore the actual content.
- SchemaLoad 9mo agoSure, you could. But this isn't my job, it isn't my career. I just want Nextcloud running on a machine at home. I know linux and docker well enough to validate the ideas coming out of Gemini, and it helps me find stuff much faster than if I had to read man pages or read books. And I find the stuff that the average self hoster needs is so surface level that LLMs flawlessly provide solutions.
- danpalmer 9mo agoMy push back isn't really on the possibility, it's on the irony. Self hosting is for many an ideological act that's about reducing dependencies on big tech, removing surveillance, etc. LLMs are essentially the antithesis of this. If you're self hosting for other reasons then that's fine. I self host media for various reasons, but I also give all my email/calendar/docs/photos over to a big tech company because I'm not motivated by that aspect.
- chaz6 9mo agoI would really like some kind of agnostic backup protocol, so I can simply configure my backup endpoint using an environment variable (e.g. `-e BACKUP_ENDPOINT=https://backup.example.com/backup https://backup.example.com/backup -e BACKUP_IDENTIFIER=xxxxx`), then the application can push a backup on a regular schedule. If I need to restore a backup, I log onto the backup app, select a backup file and generate a one time code which I can enter into the application to retrieve the data. To set up a new application for backups, you would enter a friendly name into the backup application and it would generate a key for use in the application.
- dangus 9mo agoI use Pika Backup which runs on the BorgBackup protocol for backing up my system’s home directory. I’m not really sure if this is exactly what you’re talking about, though. It just sends backups to network shares.
- cryostasis 9mo agoI'm actively in the process of setting this up for my devices. What have you done for off-site backups? I know there are Borg specific cloud providers (rsync.net, borgbase, etc.). Or have you done something like rclone to an S3 provider?
- dangus 9mo agoNo off-site backup for me, these items aren’t important enough, it’s more for “oops I broke my computer” or “set my new computer up faster” convenience. Anything I really don’t want to lose is in a paid cloud service with a local backup sync over SMB to my TrueNAS box for some of the most important ones. An exception is GitHub, I’m not paying for GitHub, but git kinda sorta backs itself up well enough for my purposes just by pulling/pushing code. If I get banned from GitHub or something I have all the local repos.
- cryostasis 9mo agoGood to know! I have shifted more to self hosting, e.g., Gitea rather than Github, and need to establish proper redundancy. Hopefully Borg Backup, with it's deduplication will be good, at least for on-site backups.
- wswin 9mo agoHome NAS servers are already shipped with user friendly GUI. Personally I haven't used them, but I certainly would prefer it, or recommend it to tech-illitarate people instead of allowing LLM to manage the server.
- elemdos 9mo agoI’ve also found AI to be super helpful for self-hosting but in a different way. I set up a Pocketbase instance with a Lovable-like app on top (repo here: https://github.com/tinykit-studio/tinykit https://github.com/tinykit-studio/tinykit) so I can just pull out my phone, vibecode something, and then instantly host it on the one server with a bunch of other apps. I’ve built a bunch of stuff for myself (journal, CRM, guitar tuner) but my favorite thing has been a period tracker for a close friend who didn’t want that data tracked + sold.
- 1shooner 9mo agoOthers here mention Coolify for a homeserver. If you're looking for turnkey docker-compose based apps rather than just framework/runtime environments, I will recommend the runtipi project. I have found it to be simple and flexible. It offers an 'app store' like interface, and supports hosting your own app store. It manages certs and reverse proxy via traefik as well. https://runtipi.io/ https://runtipi.io/
- indigodaddy 9mo agoCosmos Cloud is great too. I use it on a free tier OCI Ampere 24G VM https://cosmos-cloud.io/ https://cosmos-cloud.io/
- austin-cheney 9mo agoI have found that storage is up in price more than 60% from last year. I am writing a personal application to simplify home server administration if anybody is interested: https://github.com/prettydiff/aphorio https://github.com/prettydiff/aphorio
- tezza 9mo agoWait… tailscale connection to your own network, and unsupervised sysadmin from an oracle that hallucinates and bases its decisions on blog post aggregates? p0wnland. this will have script kiddies rubbing their hands
- amelius 9mo ago> The reason is simple: CLI agents like Claude Code make self-hosting on a cheapo home server dramatically easier and actually fun. But I want to host an LLM.
- shamiln 9mo agoTailscsle was never the unlock for me, but I guess I never was the typical use case here. I have a 1U (or more), sitting in a rack in a local datacenter. I have an IP block to myself. Those servers are now publicly exposed and only a few ports are exposed for mail, HTTP traffic and SSH (for Git). I guess my use case also changes in that I don’t use things just for me to consume, select others can consume services I host. My definition here of self-hosting isn’t that I and I only can access my services; that’s be me having a server at home which has some non critical things on it.
- zrail 9mo agoCurious how long you've been sitting on the IP block. I've been nosing around getting an ASN to mess around with the lower level internet bones but a /24 is just way too expensive these days. Even justifying an ASN is hard, since the minimum cost is $275/year through ARIN.
- bakies 9mo agoIs that the minimum for an ASN? /24 is a lot of public IP space! I'd expect just to get a static IP from and ISP if I were to coloc like this
- zrail 9mo agoThe minimum publicly routable IPv4 subnet is /24 and IPv6 is /48. IPv6 is effectively free, there are places that will lease a /48 for $8/year, whereas as far as I can tell it's multiple thousands of USD per year to acquire or lease a /24 of IPv4.
- zebnyc 9mo agoBasic question: If I wanted a simple self hosting solution for a bot with a database, what is the simplest solution / provider I can go with. This bot is just for me doesn't need to be accessible to the general public. Thanks
- chasing0entropy 9mo agoAsk chatGPT bro
- cryptica 9mo agoI started self-hosting after noticing that my AWS bill increased from like $300 per month to $600 per month within a couple of years. When looking at my bill, 3/4 of the cost was 'AWS Other'; mostly bandwidth. I couldn't understand why I was paying so much for bandwidth given that all my database instances ran on the same host as the app servers and I didn't have any regular communication between instances. I suspect it may have been related to the Network File System (NFS)? Like whenever I read a file on the host machine, it goes across the data-center network and charges me? Is this correct? Anyway, I just decided to take control of those costs. Took me 2 weeks of part-time work to migrate all my stuff to a self-hosted machine. I put everything behind Cloudflare with a load balancer. Was a bit tricky to configure as I'm hosting multiple domains from the same machine. It's a small form factor PC tower with 20 CPU cores; easily runs all my stuff though. In 2 months, I already recouped the full cost of the machine through savings in my AWS bill. Now I pay like $10 a month to Cloudflare and even that's basically an optional cost. I strongly recommend. Anyway it's impressive how AWS costs had been creeping slowly and imperceptibly over time. With my own machine, I now have way more compute than I need. I did a calculation and figured out that to get the same CPU capacity (no throttling, no bandwidth limitations) on AWS, I would have to pay like $1400 per month... But amortized over 4 years my machine's cost is like $20 per month plus $5 per month to get a static IP address. I didn't need to change my internet plan other than that. So AWS EC2 represented a 56x cost factor. It's mind-boggling. I think it's one of these costs that I kind of brushed under the carpet as "It's an investment." But eventually, this cost became a topic of conversation with my wife and she started making jokes about our contribution to Jeff Bezos' wife's diamond ring. Then it came to our attention that his megayacht is so large that it comes with a second yacht beside it. Then I understood where he got it all from. Though to be fair to him, he is a truly great businessman; he didn't get it from institutional money or complex hidden political scheme; he got it fair and square through a very clever business plan. Over 5 years or so that I've been using AWS, the costs had been flat. Meanwhile the costs of the underlying hardware had dropped to like 1/56th... and I didn't even notice. Is anything more profitable than apathy and neglect?
- jdsully 9mo agoThe most likely culprit was talking to other nodes via their public IP instead of their local ones. That gets billed as interent traffic (most expensive). The second culprit is your database or other nodes are in different AZs and you get a x-zone bandwidth charge. Bandwidth inside the same zone is free.
- dwd 9mo agoBeen self-hosting for last 20 years and I would have to say LLMs were good for generating suggestions when debugging an issue I hadn't seen before, or for one I had seen before but was looking for a quicker fix. I've used it to generate bash scripts, firewall regex. On self-hosting: be aware that it is a warzone out there. Your IP address will be probed constantly for vulnerabilities, and even those will need to dealt with as most automated probes don't throttle and can impact your server. That's probably my biggest issue along with email deliverability.
- MrDarcy 9mo agoThe best solution I’ve found for probes is to put all eggs into the basket listening on 443. Haproxy with SNI routing was simple and worked well for many years for me. Istio installed on a single node Talos VM currently works very well for me. Both have sophisticated circuit breaking and ddos protection. For users I put admin interfaces behind wireguard and block TCP by source ip at the 443 listener. I expose one or two things to the public behind an oauth2-proxy for authnz. Edit: This has been set and forget since the start of the pandemic on a fiber IPv4 address.
- aaronax 9mo agoAnd use a wildcard cert so that all your services don't get proved due to cert transparency logs.
- SchemaLoad 9mo agoThese days I just wouldn't put my homeserver exposed to the internet only. LAN only with a VPN. Does mean you can't share links and such with other people, but your server is now very secure and most of the stuff you do on it doesn't need public access anyway.
- FaradayRotation 9mo ago~10 years ago I remember how shocked I was the first time I saw how many people were trying to probe my IP on my home router, from random places all over the globe. Years later I still had the same router. Somewhere a long the line, I fired the right neurons and asked myself, "When was the last time $MANUFACTURER published an update for this? It's been awhile..." In the context of just starting to learn about the fundamentals of security principles and owning your own data (ty hackernews friends!), that was a major catalyst for me. It kicked me into a self-hosting trajectory. LLMs have saved me a lot of extra bumps and bruises and barked shins in this area. They helped me go in the right direction fast enough. Point is, parent comment is right. Be safe out there. Don't let your server be absorbed into the zombie army.
- syndacks 9mo agoCan the same thing be said for using docker compose etc on a VPS to host a web app? Ie you can get the ergonomic / ease of using Fly, Renderer? Historically, managed platforms like Fly.io, Render, and DigitalOcean App Platform existed to solve three pain points: 1. Fear of misconfiguring Linux 2. Fear of Docker / Compose complexity 3. Fear of “what if it breaks at 2am?” CLI agents (Claude Code, etc.) dramatically reduce (1) and (2), and partially reduce (3). So the tradeoff has changed from: “Pay $50–150/month to avoid yak-shaving” → “Pay $5–12/month and let an agent do the yak-shaving”
- recvonline 9mo agoI started the same project end of last year and it’s true - having an LLM guide you through the setup and writing docs is a real game changer! I just wish this post wasn’t written by an LLM! I miss the days where you can feel the nerdy joy through words across the internet.
- chasd00 9mo agoWhat I do at home is ubuntu on a cheap small computer I found on ebay. ufw blocks everything except 80, 443, and 22. Setup ssh to not use passwords and ensure nginx+letsencrypt doesn’t run as root. Then, forward 80 and 443 from my home router to the server so it’s reachable from the internet. That’s about it, now I have an internet accessible reverse proxy to surface anything running on that server. The computers on the same LAN (just my laptop basically) have host file entries for the server. My registrar handles DNS for the external side (routers public ip). Ssh’ing to the server requires a lan IP but that’s no big deal I’m at home whenever I’m working on it anyway.
- dizhn 9mo agoPut wireguard on that thing and don't expose anything on your public IP. Better yet don't have a public IP. Just port forward the wireguard IP from your router. That's it. No firewall no nothing. Not even accidental exposure.
- drnick1 9mo ago> Put wireguard on that thing and don't expose anything on your public IP. Better yet don't have a public IP. This is nonsense. You can't self-host services meant to interact with the public (such as email, websites, Matrix servers, etc.) without a public IP, preferably one that is fixed.
- nick2k3 9mo agoAll fine and great with Tailscale until you company places an iOS restriction on external VPNs and your work phone is also your primary phone :(
- jacobthesnakob 9mo agoMy work WiFi blocked traffic to port 51820, the default WireGuard port. I was wondering why my VPN started failing to handshake one day. I changed my ports to 51821 that night and back in business. I checked our technology policy and there’s no “thou shalt not use a VPN” clause so no clue why someone one day decided to drop WireGuard traffic on the network.
- teiferer 9mo agoRestrict use of private devices? Though just blocking particular ports for this purpose is very 90s and obviously ineffective, as you demonstrated. Anybody proficient in installing wireguard also knows how to change ports.
- ivanjermakov 9mo agoUsually you can ask for a separate phone for work. I can't stand when personal devices are poisoned with Intune and other company crap.
- teiferer 9mo ago> your work phone is also your primary phone :( That's the flaw right there. Don't mix company assets with pricate use. Phone, laptop, car. Your life is already very dependent on your employer (through income), don't get yourself locked in even more by depending on them for personal tech. Plus it's a security risk to your company. Unless you have a low paying job, which rarely anybody on HN does, you can afford your own phone and laptop. And IT won't find your messages to girlfriend or pictures you don't want others to see or browsing history.
- CuriouslyC 9mo agoTailscale is pretty sweet. Cloudflare WARP is also pretty sweet, a little clunkier but you get argo routing for free and I trust Cloudflare for security.
- JodieBenitez 9mo agoSo it's self hosting but with a paid and closed saas dependency ? I'll pass.
- HarHarVeryFunny 9mo agoDoesn't have to be that way though. As discussed here recently, a basic local agent like Claude Code is only a couple hundred lines of code, and could easily be written by something like Claude Code if you didn't want to do it yourself. If you have your own agent, then it can talk to whatever you want - could be OpenRouter configured to some free model, or could be to a local model too. If the local model wasn't knowledgeable enough for sysadmin you could perhaps use installable skills (scripts/programs) for sysadmin tasks, with those having been written by a more powerful model/agent.
- deleted 9mo ago[deleted]
- RicoElectrico 9mo agoI just use Proxmox on Optiplex 3060 micro. On it, a Wireguard tunnel for remote admin. The ease of creating and tearing down dedicated containers makes it easy to experiment.
- esbeeb 9mo agoI too have that same Dell Optiplex 3060 micro. I love it for experimenting also. Also use wireguard for remote access. I use incus for my Linux containers, preferring it to proxmox.
- fhennig 9mo agoI think it's great that people are getting into self-hosting, but I don't think it's _the_ solution to get us off of big tech. Having others run a service for you is a good thing! I'd love to pay a subscription for a service, but ran as a cooperative, where I'm not actually just paying a subscription fee, instead I'm a member and I get to decide what gets done as well. This model works so well for housing, where the renters are also the owners of the building. Incentives are aligned perfectly, rents are kept low, the building is kept intact, no unnecessary expensive stuff added. And most importantly, no worries of the building ever getting sold and things going south. That's what I would like for my cloud storage, e-mail etc.
- sroerick 9mo agoHey, I was thinking about this same idea lately. What exactly would you want hosted by somebody? I was thinking about what if your "cloud" was more like a tilde.club, with self hosted web services plus a Linux login. What services would you want? Email and cloud make sense. I think a VPN and Ad Blocker would too. Maybe Immich and music hosting? Calendar? I don't know what people use for self hosting
- fhennig 9mo agoI don't actually need much, I think basically just encrypted cloud storage would be great. If there was something like proton mail, but ran as a co-op, I'd also use that (it has great calendar support too). I'd really focus on it being usable for non-techies, I don't think I'd want a linux login for anything. IMO, the focus should be on the basic infrastructure of digital life for the everyday person. tilde.club sounds interesting though! Hadn't heard of it before.
- tech_ken 9mo agoMy (admittedly a bit tinfoil) take on the recent self-hosting boom is that it's highly compatible with individualist suburban capitalism; and that while there are elements of it that offer an alternative path to techno-feudalism, by itself it doesn't really challenge the underlying ideology. It's become highly consumerist, and seems more like a way of expressing taste/aesthetics than something that's genuinely revolutionary. Cooperative services (as you describe) seem like they offer a way more legitimate challenge, but I feel like that's a big reason why they don't see as much fete-ing in the mainstream tech media and industry channels. I say all this as someone who's been self-hosting services in one form or another for almost a decade at this point. The market incorporation/consumerfication of the hobby has been so noticeable in the last five years. Even this AI thing seems like another step in that direction; now even non-experts can drop $350+ on consumer hardware and maybe $100 on some network gear so that they can control their $50/bulb Hue lights and manage their expansive personal media collection.
- nojs 9mo agoThis post is spot on, the combo of tailscale + Claude Code is a game changer. This is particularly true for companies as well. CC lets you hack together internal tools quickly, and tailscale means you can safely deploy them without worrying about hardening the app and server from the outside world. And tailscale ACLs lets you fully control who can access what services. It also means you can literally host the tools on a server in your office, if you really want to. Putting CC on the server makes this set up even better. It’s extremely good at system admin.
- fassssst 9mo agoUmm, what happened to zero trust? Network security is not sufficient.
- thrownawaysz 9mo agoI went down the self host route some years ago but once critical problems hit I realized that beyond a simple NAS it can be a very demanding hobby. I was in another country when there was a power outage at home. My internet went down, the server restart but couldn't reconnect anymore because the optical network router also had some problems after the power outage. I could ask my folks to restart, and turn on off things but nothing more than that. So I couldn't reach my Nextcloud instance and other stuff. Maybe an uninterruptible power supply could have helped but the more I was thinking about it after just didn't really worth the hassle anymore. Add a UPS okay. But why not add a dual WAN failover router for extra security if the internet goes down again? etc. It's a bottomless pit (like most hobbies tbh) Also (and that's a me problem maybe) I was using Tailscale but I'm more "paranoid" about it nowadays. Single point of failure service, US-only SSO login (MS, Github, Apple, Google), what if my Apple account gets locked if I redeem a gift card and I can't use Tailscale anymore? I still believe in self hosting but probably I want something even more "self" to the extremes.
- cyberax 9mo agoLong time ago, it was popular for ISPs offer a small amount of space for personal websites. We might see a resurgence of this, but with cheap VPS. Eventually.
- SchemaLoad 9mo agoFree static site hosting and cheap VPSs already exist. Self hosting is less about putting sites on the internet now and more about replicating cloud services locally.
- Imustaskforhelp 9mo agoVPS's are really so dirt cheap that some of them only work because people dont use the servers 100% that they are allocated at or when people dont use the resources they have for most part because of economies of scale but vps's are definitely subsidized. Cheap vps servers 1 gb ram and everything can cost around 10-11$ per year and using something like hetzner's cheap as well for around 30$ ish an year or 3$ per month most likely while having some great resilient numbers and everything If anything, people self host because they own servers so upgrading becomes easier (but there are vps's which target a niche which people should look at like storage vps, high perf vps, high mem vps etc. which can sometimes provide servers for dirt cheap for your specific use case) The other reason I feel like are the ownership aspect of things. I own this server, I can upgrade this server without costing a bank or like I can stack up my investment in a way and one other reason is that with your complete ownership, you don't have to enforce t&c's so much. Want to provide your friends or family vps servers or people on internet themselves? Set up a proxmox or incus server and do it. Most vps servers sometimes either outright ban reselling or if they allow, they might sometimes ban your whole account for something that someone else might have done so somethings are at jeopardy if you do this simply because they have to find automated ways of dealing with abuse at scale and some cloud providers are more lenient than others in banning matters. (OVH is relaxed in this area whereas hetzner, for better or for worse, is strict on its enforcement)
- didntknowyou 9mo agoidk exposing your home network to the world and trusting AI will produce secure code is not a risk I want to take
- Dbtabachnik 9mo agoHow is readcheck any different than using raindrop.io?
- journal 9mo agonone of you have what it takes to self host your perfect self hosting fantasy because most of you won't cooperate with others. keep waiting for that unicorn you wouldn't see standing right in front of you.
- wantlotsofcurry 9mo agoWas this article written entirely by Claude for the most part? It definitely reads like it was.
- jordanf 9mo agoNo
- _jplc 9mo agoSelf hosting post. Tailscale. Its comedic at this point.
- teiferer 9mo agoCan just "self host" documents, email and chat on google workspace.
- jaime-ez 9mo agohas any one experience using cloudflare tunnels in a (small scale - 5000 user/day) self hosted web service? I just got 2 dynabook XJ-40 (32 gb ram, 512 gb ssd) for 200 usd each and I'm going to replace my DO droplets with them (usd150+ per month). I plan to use cloudflare tunnel to make the service available to the internet without exposing my home network. Any downsides ? (besides that cloudflare will be MITM for the service but it is not a privacy focused business)
- dpe82 9mo agoI've recently begun moving the systems I administer to Claude-written NixOS configs. Nix is great but can be a real pain to write yourself; Claude removes the pain.
- HarHarVeryFunny 9mo agoInteresting use case for Claude Code, or any similar local executor talking to a remote AI (Gemini suggests that "Hybrid-Local AI Agent" is a generic name for these, although I've never heard it called that before). I wonder if a local model might be enough for sysadmin skills, especially if were trained specifically for this ? I wonder if iOS has enough hooks available that one could make a very small/simple agentic Siri replacement like this that was able to manage the iPhone at least better than Siri (start and stop apps, control them, install them, configure iPhone, etc) ?
- Finbarr 9mo agoI used Codex to set up a raspberry pi as a VPN with WireGuard. I had no similar experience before and it was super easy. I used Claude Code to audit and clean up a 10+ year old AWS account- patching security, shutting down redundant services, simplifying the structure. I want Claude Code to replace every bad UI out there. I know what outcome I want and don’t need to learn all the details to get there.
- tamimio 9mo agoNope, never trust AI to do such things, it’s imminent to cause issues. Maybe as an assistant only but never installed on the same server and worse, the privilege to access/execute commands.
- tkgally 9mo agoI used Claude Code just yesterday in a similar way: to solve a computer problem that I previously would have tried googling. I had a 30-year-old file on my Mac that I wanted to read the content of. I had created it in some kind of word processing software, but I couldn’t remember which (Nexus? Word? MacWrite? ClarisWorks? EGWORD?) and the file didn’t have an extension. I couldn’t read its content in any of the applications I have on my Mac now. So I pointed CC at it and asked what it could tell me about the file. It looked inside the file data, identified the file type and the multiple character encodings in it, and went through a couple of conversion steps before outputting as clean plain text what I had written in 1996. Maybe I could have found a utility on the web to do the same thing, but CC felt much quicker and easier.
- krupan 9mo agoOh my gosh, everything you want to host comes with a docker compose file that requires you to tweak maybe two settings. Caddy as your web proxy has the absolute simplest setup possible. You don't need AI to help you with this. You got this. You want to make sure you understand the basics so you (or your LLM doesn't do anything brain dead stupid). It's not that hard, you can do it!
- jawns 9mo agoRemember: In all likelihood, your residential ISP does not permit you to operate a server. Granted, that's rarely enforced, but if you're a stickler for that sort of thing, check your ISP's Acceptable Use Policy.
- megous 9mo agoMy idea of fun is deeply tied to understanding how things work—learning them, then applying that knowledge in my own way, as simply as possible. That process gives me a sense of ownership and control, which is not something I get from an approach where AI does things for me that I do not understand.
- walterraj 9mo agoI have a hard time reading things like “The last one is the real unlock.” or “That alone justified the box.” without immediately thinking of an AI trying to explain something. Not to say this was written with one, but the frequency with which I see phrasing like this nowadays is skyrocketing...
- drnick1 9mo agoReminder: If you are using Tailscale or a VPS you aren't really self-hosting.
- teiferer 9mo agoOr a non-local LLM to keep it all maintained.
- legojoey17 9mo agoI just got around to a fresh NixOS install and I couldn't be happier as I've been able to do practically everything via Codex while keeping things concise and documented (given it's nix, not a bunch of commands of the past). I recently had a bunch of breakages and needed to port a setup - I had a complicated k3s container in proxmox setup but needed it in a VM to fix various disk mounts (I hacked on ZFS mounts, and was swapping it all for longhorn) As is expected, life happens and I stopped having time for anything so the homelab was out of commission. I probably would still be sitting on my broken lab given a lack of time.
- ibizaman 9mo agoYou might be interested in checking out my project SelfHostBlocks which allows you to declaratively setup quite a few services with declarative LDAP and SSO integration with LLDAP and Authelia. Even if you don’t end up using it, it might inspire you. Also, all integrations are tested with NixOS VM tests using playwright to ensure no breakage. https://github.com/ibizaman/selfhostblocks https://github.com/ibizaman/selfhostblocks
- legojoey17 9mo agoCool, I'll definitely take a look! I do have a preference for container-oriented setups and do have an elaborate set of plumbing on kuberenetes at the moment. That being said, I procrastinated on getting postgres backups working and ended up causing self-inflicted corruption, so it is nice to see you've got that setup and have thought of pretty much everything!
- visageunknown 9mo agoI find LLMs remove all the fun for me. When I build my homelab, I want the satisfaction of knowing that I did it. And the learning gains that only come from doing it manually. I don't mind using an LLM to shortcut areas that are just pure pain with no reward, but I abstain from using it as much as possible. It gives you the illusion that you've accomplished something.
- lurking_swe 9mo ago> It gives you the illusion that you've accomplished something. What’s the goal? If the act of _building_ a homelab is the fun then i agree 100%. If _having_ a reliable homelab that the family can enjoy is the goal, then this doesn’t matter. For me personally, my focus is on “shipping” something reliable with little fuss. Most of my homelab skills don’t translate to my day job anyway. My homelab has a few docker compose stacks, whereas at work we have an internal platform team that lets me easily deploy a service on K8s. The only overlap here is docker lol. Manually tinkering with ports and firewall rules, using sqlite, backups with rsync, etc…all irrelevant if you’re working with AWS from 9-5. I guess I’m just pointing out that some people want to build it and move on.
- visageunknown 9mo agoIf your sole goal is to have a homelab that self-hosts services, I completely agree. I'm speaking for those who are interested in developing their skills and knowledge, and believe that building something with AI somehow does that. I'll agree to disagree on it not being applicable. Having fundamental knowledge on topics like networking thru homelabbing have helped me develop my understanding from the ground up. It helps in ways that are not always obvious. But if your goal is purely to be better at your job at work, it is not the most efficient path.
- Gigachad 9mo agoI don’t give them direct access to my computer. I just use them as an alternative to scrolling reddit for answers. Then I take the actions myself.
- cyberrock 9mo ago
- valcron1000 9mo ago> When something breaks, I SSH in, ask the agent what is wrong, and fix it. > I am spending time using software, learning What are you actually learning? PSA: OP is a CEO of an AI company
- enos_feedler 9mo agoyou are learning what it takes to keep a machine up and running. You still witness the breakage. You can still watch the fix. You can review what happened. What you are implying from your question is that compared to doing things without AI, you are learning less (or perhaps you believe nothing). You definitely are learning less about mucking around in linux. But, if the alternative was not ever running a linux machine at all because you didn't want to deal with running it, you are learning infinitely more.
- croes 9mo agoHow can you review if you don‘t know in the first place? You can watch your doctor, your plumber, your car mechanic and still wouldn’t know if they di something wrong if you don’t know the subject as such.
- doctoboggan 9mo agoYou can learn a lot from watching your doctor, plumber or mechanic work, and you could learn even more if you could ask them questions for hours without making them mad.
- defrost 9mo agoYou learn less from watching a faux-doctor, faux-plumber, faux-mechanic and learn even less by engaging in their hallucinations without a level horizon for reference. Bob the Builder doesn't convey much about drainage needs for foundations and few children think to ask. Who knows how AI-Bob might respond.
- rkomorn 9mo ago
- le_meer 9mo agoJust got a home-server. Immich is awesome! How's Caddy working out though? I need a way to expose immich to public internet (not just a VPN). Something like photos.domain.com For now I'm just using Cloudflare tunnels, but ideally I also want to do that myself (without getting DDoS)
- digiown 9mo agoLook up mutual TLS / client authentication. Caddy and Immich supports it. Then you can expose it to the internet reasonably securely.
- kilobaud 9mo agoI am curious what you mean by doing it yourself, i.e., do you mean (as perhaps an oversimplification) having a DNS record pointing at your home IP address? What are you wanting to see as the alternative to a Cloudflare tunnel?
- le_meer 9mo agoI mean, how do I expose my home server to the internet, without relying on externally hosted platforms like Cloudflare or Tailscale? While still minimising the risk of DoS
- windex 9mo agoI had problems with tailscale being flaky about a year ago and it would stop responding taking down networking with it. I've since ripped it out and went with a VPS based wireguard for all PCs and mobiles. Stable since then.
- mintflow 9mo agoThis is the reason why I am creating a Debian VM on my macOS to let Claude code in yolo mode to do some experiment:)
- deleted 9mo ago[deleted]
- catlifeonmars 9mo ago> I have flirted with self-hosting at home for years. I always bounced off it - too much time spent configuring instead of using. It just wasn't fun. No judgement, but wanting to tinker/spend time on configuration is a major reason why many people do self-host.
- jordanf 9mo agoyeah, for sure! i realize that and respect it. i wrote a little bit about it here actually: https://fulghum.io/fun2 https://fulghum.io/fun2
- teiferer 9mo agoOpens with "self-hosting" and then brings claude code into the mix. You realize it's not actually running locally right? Privcy-wise that's a nightmare. A non-deterministic blackbox running in somebody's AI cloud is controlling your server. Congrats.
- Havoc 9mo agoI’d suggest rather asking it to write you bash scripts And ideally doing it via lxc or vm. Extra complication but gives you something repeatable that you can stick on git
- csomar 9mo agoVibe-setting up a home network server with VaultWarden is beyond reckless. LLMs have tendency to overlook security in order to get things working. You are, thereby, exposing your passwords (and potentially your 2FA as bitwarden supports that) to the whole world. This is beyond stupid. Even before LLMs my main concern with setting up BitWarden on my own server was two folds: security and availability. LLMs doesn't fix the second point but they make the first point much worse.
- teiferer 9mo agoVibe-maintaining is even worse than vibe-setting up. And ironically all in the name of "self hosting". Claude code defies both words in that.
- Fokamul 9mo ago>Your home server's new sysadmin: Claude Code Lol, no thank you. Btw do your knees hurt?
- timwis 9mo agoGreat article! I think a paragraph on your backup strategy would make it even more complete and compelling, particularly given you put your passwords and photos in there.
- jordanf 9mo agothanks. I fleshed that out a bit more. appreciate the feedback.
- pmihaylov 9mo agoI also built a "devops" agent on top of claude code like that - I deployed it on my server and let it debug all the gnarly infra issues for me. I route it through a familiar interface like slack tho as I don't like to ssh from phone or w/e using a tool I built - https://www.claudecontrol.com/ https://www.claudecontrol.com/
- apexalpha 9mo agoI am in the process of doing the same. I have a Netbird mesh (Tailscale but open source) with 3 k3s nodes. They are geographically separated for HA. Claude and Gemini have been instrumental in helping me understand the core concepts of kubernetes, how to tune all these enterprise applications for high latency, think about architecture etc... My biggest "wow, wtf?" moment was ben I was discussing the cluster architecture with Claude. It asked: want me to start the files? I thought it meant update the notes, so replied 'yes'. It spit out 2 sh files and 5 YAMLs that completely bootstrapped my cluster with a full GitOps setup using ArgoCD. Learning while having a 24/7 senior tutor next to me has been insane value.
- geooot 9mo agoI also liked using AI agents to do sysadmin stuff, especially with Nix OS. On top of Nix being great, the configuration of a system being files gives the agent good context on the current state the system is. Then when it does make changes, its great to be able to review its work via diffs.
- elitan 9mo agoBeen using Claude Code to build a small deployment tool (Frost) for exactly this use case. The meta experience is interesting - using an AI agent to build tooling that makes self-hosting easier. What I've found: Claude Code is great at the "figure out this docker/nginx/systemd incantation" part but the orchestration layer (health checks, rollbacks, zero-downtime deploys) still benefits from purpose-built tooling. The AI handles the tedious config generation while you focus on the actual workflow. github.com/elitan/frost if curious
- MORPHOICES 9mo ago[flagged]
- sgt 9mo agoTry Claude and LVM, Linux software RAID and partitions though, it's hilariously bad at it.
- everlier 9mo agoI use coding agents for similar kind of problem very frequently. It makes wonders debugging obscure system issues related to components that I have no faintest idea about. Also building a homelab very soon. I think you may find this project useful: https://github.com/av/harbor https://github.com/av/harbor
- bilekas 9mo agoI recently got a zimaboard2 and have been blown away how powerful it is, x86 and 16GB I think it was around 250$. I have it running proxmox. Dedicated GPU for transcoding, all working out of the box with the ZimaOS.. And no AI needed.
- zmmmmm 9mo agoit's kind of fascinating, LLMs suddenly are making the Linux Desktop waaay more accessible, of all things. All those fancy GUIs in Mac and Windows designed to be user friendly (but which most users hate and are baffled by anyway) are very hostile for models to access. But text configuration files? it's like a knife through butter for the LLMs to read and modify them. All of a sudden, Linux is MORE user friendly because you can just ask an LLM to fix things. Or even script them - "make it so my theme changes to dark at night and then back to light each morning" becomes something utterly trivial compared to the coding LLMs are being built to handle. But hey, if your OS really doesn't support something? the LLM can probably code up a whole app for you and integrate it in. I think it's going to be fascinating to see if the power of text based interfaces and their natural compatibility with LLMs transfers over into an upswing in open source operating systems.
- duttish 9mo agoI've been building a home library system mainly for personal use, I want to run it cheaply so a $4 black Friday sale OVH vps is perfect. But I wanted decent deployments. Hosting a image repository cost 3-4x of the server. Sending over the container image took over an hour due to large image processing python dependencies. Solution? Had a think and a chat with Claude code, now I have blue-green deployments where I just upload the code which takes 5 seconds, everything is then run by systemd. I looked at the various PaaSes but they ran up to $40/month with compute+database etc. I would probably never have built this myself. I'd have gotten bored 1/3 through. Now it's working like a charm. Is it enterprise grade? Gods no. Is it good enough? Yes.
- Draiken 9mo agoThis summarizes what LLMs are best at: hobby projects that you care mostly about the outcome and won't have to actively maintain forever. When using them with production code they are a liability more than a resource.
- fergie 9mo agoI see why this is easy and fun, but is it really "self-hosting" if you are dependent on a $1200 a year AI-service to build and maintain it?
- compounding_it 9mo agoI don't really understand this post completely. >I am spending time using software, learning, and having fun - instead of maintaining it and stressing out about it. Using software, learning and having fun with with what? everything is being done by Claude here. The part of fun and learning is to learn to use and maintain it in the first place. How will you learn anything if Claude is doing everything for you ? You are not understand how things work and where everything goes. This post could be written or at least modified by an LLM, but more importantly I think this person is completely missing the point of self hosting and learning.
- dannersy 9mo agoThey get to feel like hackerman without understanding any of it. Also, this feels like a security nightmare. I wouldn't self host anything without understanding what you're opening yourself up to.
- Draiken 9mo agoLLMs give you that dopamine hit without the effort. I did it! Except you didn't and you don't know anything about what it did or learned anything along the way. Success?
- jordanf 9mo agohi, OP here. people have different reasons/motivations for doing stuff, right? i wrote about it here: https://fulghum.io/fun2 https://fulghum.io/fun2
- HeartofCPU 9mo agoGreat until Claude decides to delete your storage and all your containers are gone
- hmontazeri 9mo agoLove this. I run also all my stuff by myself and I’m not an infra expert by all means just know enough to self host my app and services. I also built an remote monitoring agent using Go and rails I call it https://bareagent.io https://bareagent.io which monitors servers, docker containers and sends notifications when in any of those containers an error occurres as it is attached to the container logs
- pixelbyindex 9mo agoI also started started experimenting with self-hosting in the last few years. Started with a simple Plex server, then gradually evolved my little setup into a handful of open-source apps that now cover most of what I use during my day to day. There are a few important things to consider, like unstable IPs, home internet limits, and the occasional power issue. Cloud providers felt overpriced for what I needed, especially once storage was factored in. In the end, I put together a small business where people can run their own Mac mini with a static IP: https://www.minimahost.com/ https://www.minimahost.com/ I’m continuing to work on it while keeping my regular software job. So far, the demand is not very high, or perhaps I am not great at marketing XD
- maximgeorge 9mo ago[dead]
- micw 9mo agoFor me the most important benefit is that the agent can keep the docs up to date. When I do a change, I let it document what is changed, how and why.
- InfinityByTen 9mo agoI was just thinking I should write something about this, because the words needs spreading. I cannot say how happy I am configuring my own immich server on a decade old machine. I just feel empowered. Because despite my 9 years of software development, I haven't gotten into the nitty gritties of networking, VPN and I always see something non-standard while installing an open source package and without all of this custom guidance, I always would give up after a couple of hours of pulling my hair apart. I really want to go deeper and it finally feels this could be a hobby. PS: The rush was so great I was excitedly talking to my wife how I could port our emails away from google, considering all of the automatic opt in for AI processing and what not. The foolhardy me thought of even sabbatical breaks to work on long pending to-do's in my head.
- Maledictus 9mo agoEmail is endgame, I suggest you get more experience self hosting in other areas first.
- InfinityByTen 9mo agoI concur. I did mention there was a rush and foolhardiness. That's my mid 30s excitement. Let me revel a bit :P I do want to be able to take control; with photos and Google not giving me a folder view to manage them was the last straw that pushed me deep into the self hosted world. I just want to de-google as much as reasonable.
- lee_ars 9mo ago> PS: The rush was so great I was excitedly talking to my wife how I could port our emails away from google, considering all of the automatic opt in for AI processing and what not. The foolhardy me thought of even sabbatical breaks to work on long pending to-do's in my head. I've been email self-hosting for a decade, and unfortunately, self-hosting your email will not help with this point nearly as much as it seems on first glance. The reason is that as soon as you exchange emails with anyone using one of the major email services like gmail or o365, you're once again participating in the data collection/AI training machine. They'll get you coming or they'll get you going, but you will be got.
- chromehearts 9mo agoMe personally; I have a similar mini pc with kubuntu installed, coolify to deploy my projects & cloudflare tunnels to expose them to the internet. the mini pc is still usable for daily use so that's great too
- bambax 9mo agoI self-host many things on a NAS (Asustor) using Portainer (a Docker UI/facilitator). It all works perfectly and has a marginal cost of about zero, since I need the NAS in any case. But I wouldn't give the keys of the house to Claude or any LLM for that matter. When needed, I ask them questions and type commands myself. It's not that hard.
- oulipo2 9mo agoI would also suggest the great Karakeep for read-it-later :)
- hendry 9mo agoTimely! I just re-setup my Pi5 with the help of Claude. https://github.com/kaihendry/ai-pi https://github.com/kaihendry/ai-pi Tbh I did the mistake of throwing away Ansible, so testing my setup was a pain! Since with AI, the focus should be on testing, perhaps it's sensible to drop Ansible for something like https://github.com/goss-org/goss https://github.com/goss-org/goss Things are happening so fast, I was impressed to see a Linux distro embrace using a SKILL.md! https://github.com/basecamp/omarchy/blob/master/default/omarchy-skill/SKILL.md https://github.com/basecamp/omarchy/blob/master/default/omar...
- mzhaase 9mo agoInstead of the vibe-admin approach, why not have the LLM write an Ansible playbook? At least its repeatable and auditable that way.
- imadierich 9mo ago[dead]
- tomashubelbauer 9mo agoI have a love-hate relationship with Home Assistant. I love its mission and I love it in spirit, but whenever I need to add or change something in it, I don't love the process. Without disparaging the work already done on improving it in recent years, I still find the UI and UX to be lacking. Claude Code has been shifting my perception much closer to the love end of the axis, because it allows me to side-step the boring parts of managing my Home Assistant instance and it is able to carry out the changes I want very reliably. I still struggle with letting go of writing code and becoming only a full-time reviewer when it comes to AI agents doing programming, but I don't struggle in the slightest with assuming the position of a reviewer of the changes CC does to my HA instance, delegating all the work to it. The progress I made on making my house smart and setting up my dashboards has skyrocketed compared to before I started using CC to manage HA via its REST and WS APIs.
- khalic 9mo agoTo the tailscale promotion team: can you guys please dial it back? The half hidden ads are seriously annoying
- nickdothutton 9mo agoOn the one hand, self-hosting, even at home, is more accessible than it has ever been. Hardware, software, and agents to help with setup and maintenance. While at the same time ISPs, the big email providers, and even (in the UK) government legislation makes it more difficult or risky than it has ever been. We have gained much but also lost much since the mid 1990s.
- alexdns 9mo ago"another few hundred USD for 8TB in NVMe SSD" lol
- mr-karan 9mo agoI've landed on a similar philosophy but with a slightly different approach to orchestration. Instead of managing everything interactively, I built a lightweight bash-based deployment system that uses rsync + docker compose across multiple machines. The structure is dead simple: `machines/<hostname>/stacks/<service>/` with a `config.sh` per machine defining SSH settings and optional pre/post deploy hooks. One command syncs files and runs `docker compose up -d`. I could see Claude Code being useful for debugging compose files or generating new stack configs, but having the deployment itself be a single `./deploy.sh homeserver media` keeps the feedback loop tight and auditable.
- neoromantique 9mo agoI have very similar setup, but I use komo.do with netbird. Which basically accomplishes same thing, but gives a bit more UI for debugging when needed.
- Draiken 9mo agoI use Ansible. It's simple enough and I had some prior experience with it, so I merely have some variables, roles that render a docker-compose.yml.j2 template and boom. It all works, I have easy access to secrets, shared variables among stacks and run it with a simple `ansible-playbook` call. If I forget/don't know the Ansible modules, Claude or their docs are really easy to use. Every time I went down a bash script route I felt like I was re-inventing something like Ansible.
- river_otter 9mo agoNext level up is self hosting your LLM! I put LM Studio on a mac mini at home and have been extremely happy with it. Then you can use a tool like opencode to connect to that LLM and boom, Claude Code dependency is removed and you just got even more self-hosted. For what you're using Claude Code for, a smaller open-weight model would probably work fine
- NicoJuicy 9mo agoWell, to a limit. I have an RTX 3090 24gb that enables a lot of use-cases. But for what i'm using Agents right now, claude code is the tool to go.
- river_otter 9mo agomakes sense. You could look at something like https://github.com/musistudio/claude-code-router https://github.com/musistudio/claude-code-router if at some point you're interested in going down that path. I've been using gpt-oss-20b which would fit on your GPU and I've found useful for basic tasks like recipe creation and agentic tool usage (I use it with Notion MCP tools)
- NicoJuicy 9mo agoIt's a really good model for its size, but context length is a serious issue to avoid hallucination
- cowboy7q 9mo ago[dead]
- fnwbr 9mo agowhy does a post from january 2026 recommend ubuntu version 22.04?
- deleted 9mo ago[deleted]
- piqufoh 9mo agoI'm working on something very similar, but I've found that if I'm not doing the work - I forget what has been set up and how its running a lot faster. For example - I have ZFS running with a 5-bay HDD enclosure, and I honestly can't remember any of the rules about import-ing / export-ing to stop / start / add / remove pools etc. I have to write many clear notes, and store them in a place where future me will find them - otherwise the system gets very flaky through my inability to remember what's active and what isn't. Running the service and having total control is fun, but it's a responsibility too
- Maledictus 9mo agoWhich enclosure do you use, and can you recommend it?
- Draiken 9mo agoWrite scripts for everything. If you need to run the command once, you can now run it again in the future. It's very tempting to just paste some commands (or ask AI to do it) but writing simple scripts like this is an amazing solution to these kinds of problems. Even if the scripts get outdated and no longer work (maybe it's a new version of X) it'll give you a snapshot of what was done before.
- mvanbaak 9mo agoThis is the reason one should always ask the LLM to create scripts to complete the task. Asking it to do things is fine, but as you stated you will forget. If you ask the LLM to do something, but always using a script first, and if you ask: 'Create a well documented shell script to <your question here>', you will have auto documentation. One could go one step further and ask it to create a documented terraform/ansible/whatever tooling setup you prefer.
- ibizaman 9mo agoThis is the reason I adore NixOS. The documentation is the code. Seriously.
- sambuccid 9mo agoAnd if you prefer to learn well how to do it without AI, you can always try to do it manually the old way but then use AI at the end to review your config and spot any security issues
- drchaim 9mo agoMy workflow is a bit different in the sense I open my claude session in my laptop, at the directory of my ansible homelab code, and I also give Claude access to ssh to my homelab. But at the end it's almost the same, great tool.
- jeena 9mo agoI self host a lot of stuff myself: https://uptime.jeena.net/status/everything https://uptime.jeena.net/status/everything And until now without AI, but I'm kind of curious but afraid that it will bring my servers down and then I can't roll back :D But perhaps if I would move over to NixOS, then it would be easy to roll back.
- larodi 9mo agoSystem Concierge, not sysadmin.
- timwalz 9mo ago[flagged]
- tietjens 9mo agoThis is very cool and I'm doing something similar but without the Claude interface as the contact point for manipulating the server. What happens if one day Claude is down, or it becomes too expensive, or it is purchased by another company, etc. In this case you will be completely unable to navigate the infrastructure of your homeserver that your life will have become dependent on. But a homeserver is always about your levels of risk, single points of failure. I'm personally willing to accept Tailscale but I'm not willing to give the manipulation of all services directly over to Claude.
- donatj 9mo agoI have been self hosting since the late 90s, but I've always just installed everything on Bare metal. I hear more and more about these elaborate Docker setups. What does a setup like this actually look like? Is it just a single docker-compose.yml with everything you want to run and 'docker compose up'?
- abc123abc123 9mo agoAnd why would I bother with a home setup? Sure, for industrial IT go for it, VM:s and/or containers, but for my own personal stuff, baremetal, packages, and good old fashioned way is more than enough.
- jordanf 9mo agoyeah basically.
- reactordev 9mo agoI just recently wrote my own agent that can gdb, objdump, nasm, cc, make, and more. Agents are powerful. Even more so with skills and command line tools they can call to do things. You can even write custom tools (like I did) for them to use that allows for things like live debugging. The tailscale piece to this setup is key.
- tbyehl 9mo agoMy favorite genre of post in r/homelab and r/selfhosted this past year has been "I used AI to set all this stuff up and something broke so I asked AI to fix it and now all my data is gone." There are so many NAS + Curated App Catalog distros out there that make self-hosting trivial without needing to Vibe SysAdmin.
- jordanf 9mo agoI keep hearing this, and asking for examples, and there aren't really any.
- iLoveOncall 9mo agoI've broken my internet many times by asking ChatGPt for help setting up PiHole as a DHCP server. I'll post conversation excerpts later if I remember. It was just giving commands to run that were plain wrong and extremely destructive, and unless you already knew what they were doing you were screwed. Here: https://chatgpt.com/share/696539b6-65f0-8010-9324-5e35da42eefd https://chatgpt.com/share/696539b6-65f0-8010-9324-5e35da42ee... I have 4-5 more conversations like this. It's honestly almost a piece of art, the LLM keeps spouting out shit like "Ah got it, your issue is clear now", and digging deeper into the wrong direction.
- mlrtime 9mo agoI'm a sysadmin / infra engineer by trade. DNS is something I stopped hosting myself because it's always DNS and when it goes down everything else does to. Email/DNS I outsource, everything else I homelab.
- iLoveOncall 9mo agoWell my PiHole uses the DNS servers from CloudFlare so I don't actually self-host DNS, but having PiHole as DHCP server was the only way for me to have all my devices going through the PiHole. In the end I literally had to give up, it's just too problematic.
- WiSaGaN 9mo agoI have a similar experience when I found out that claude code can use ssh to conect to remote server and diagnose any sysadmin issue there. It just feels really empowered.
- deleted 9mo ago[deleted]
- stuaxo 9mo agoIs everyone just running claude code not even in a container, letting it go wild and change stuff?
- raxxorraxor 9mo agoI use Cursor and quickly let it run pretty wild. Claude doesn't seem to mind to extract auth info from everywhere. Cursor usually blacklists some files for AI access depending on language and environment, but Claude just queries environment variables without even simulating a bad conscience. Probably info that gets extracted by the next programmer using it. Well, whoops...
- legoxx 9mo agoI am building a homelab with the help of various AI services. I started with ChatGPT, then moved to Claude, and I am now working with Cursor and Gemini. In my experience, this approach works extremely well—I would not have been able to accomplish this much on my own. However, there is an important caveat: you must understand what you are doing. AI systems sometimes propose solutions that do not work, and in some cases they can be genuinely dangerous to your data integrity or your privacy. AI is therefore a powerful accelerator, not a replacement for expertise. You still need to critically evaluate its suggestions and veto roughly 10% of them.
- yyaakkqq 9mo ago"piping everything to sudo bash makes a home server easier and fun"
- FatherOfCurses 9mo agoTelling us you did all this without sharing how is just bragging.
- kissgyorgy 9mo agoMy non-technical friend, never learned coding, doesn't know Linux, zero sysadmi experience does this and he can do anything and doesn't even know what Clause is doing. He learned some concepts recently like Docker, SSH, but that's basically it.
- loufe 9mo agoThreads like this one make me feel at home. Last night I spent an hour trying to figure out a way to adjust tailscale to allow me access to containers on a MacVLAN on my NAS when I connect in away from home. Claude's an excellent tool to help me make informed decisions. I find the knowledge needs to be double checked more than some domains (I'm a big fan of requesting Claude search online for information before using its discourse as a basis for any decisions) but I still feel like I'm learning the WHY and HOW because I can still ask. I share a lot of the same hesitations as others in the thread - using a giant US-based tech giant's tool for research as well as another US giant's tool to manage access, but it's really a game change and I'd be unable to find the time to do everything I want if I didn't have access to these otherwise. I'm not even a software guy by engineering, my network is already complicated enough that learning and correctly securing things otherwise would simply just not be feasible with the time and energy I'd like to dedicate to it.
- cyber_kinetist 9mo agoNo, 2026 is definitely not the year of home servers, because hardware has become too expensive. Maybe viable if you have a bunch of spare parts laying around. But probably not when RAM and storage prices are off the charts!
- tech_ken 9mo agoI think this is a good idea so long as you ensure you've got a good backup going or don't put anything super critical on there. I think it's seriously outside odds that Claude `rm -rf /`s your server, but definitely not 0%.
- kzahel 9mo agoAs an added bonus you could add on a mobile-first claude code UI on top of claude. I've been working on this and use it on my pi5 at home. https://yepanywhere.com/ https://yepanywhere.com/ (and no, this product is not against TOS as it is using the official claude code SDK unlike opencode https://yepanywhere.com/tos-compliance.html https://yepanywhere.com/tos-compliance.html)
- noncoml 9mo agoAny opinions on Readeck vs Karakeep?
- tawman 9mo agoI do the same thing on my Hostinger VPS with Claude even though I have been using Linux 30 years. Just removes the friction and time. I version control the DevOps with git, and even had Claude setup automated backups to my Google Drive via cron. workdir/ ├── README.md ├── CLAUDE.md # Claude Code instructions ├── BACKUP.md # Backup documentation ├── .gitignore ├── traefik/ │ ├── docker-compose.yml │ └── config/ │ └── traefik.yml ├── authentik/ │ ├── docker-compose.yml │ └── .env.example ├── umami/ │ ├── docker-compose.yml │ └── .env.example ├── n8n/ │ ├── docker-compose.yml │ └── .env.example └── backup/ ├── backup.sh # Automated backup script ├── restore.sh # Restore from backup ├── verify.sh # Verify backup integrity ├── list-backups.sh # List available backups └── .env.example
- larodi 9mo agoAuthor fails to recognize the fact that CLI agents make all kind of hoisting easier and fun. Like publishing to CloudFlare Pages which costs close to nothing and now takes seconds, while previously could taker days.