Closed beta

Your own server. Reachable from anywhere.

Run open-source software on hardware you own: a Raspberry Pi, a Linux machine, or an Apple-silicon Mac that's already running at your place. We take care of the tunnel, SSL, and domain.

You manage everything from the browser through your Obacht account, while your data stays on your own hardware rather than in our cloud. No port forwarding, and no Docker knowledge needed.

obacht is currently in closed beta. Sign up to get early access.

Self-hosting shouldn't require a homelab degree.

You want to run your own website, a password manager, or a tool for your team on hardware that's yours. But somewhere between SSH, Docker, certificates and dynamic DNS, the project stalls.

Obacht is the missing operating layer for a single small device. You install signed templates from the dashboard, point a domain at a service, and HTTPS comes automatically. The device runs on your network; the control plane lives in your browser.

the homelab way

  • forward port 443
  • set up dynamic DNS
  • renew TLS certificates
  • debug docker networking
  • edit YAML at midnight

with obacht

  1. 01connect a device
  2. 02pick a template
  3. 03attach your domain

tunnel, SSL & domain — handled

Install. Operate. Publish.

Pick a template, get it running on your device, keep an eye on it, and optionally make it reachable under your own domain.

Install

Signed templates for real apps

vaultwarden

running
Signature verifiedregistry key
Image pulledpinned digest
Service started184 MB RAM
Installed from the dashboard, no terminal
signed

A growing catalogue of 40+ templates: WordPress and other CMSs, Vaultwarden, Uptime Kuma, n8n, Gitea and more. All signed, running in containers, with a versioned manifest.

  • From a blog to a password manager, installed from the dashboard
  • Signed manifests, so you know which template you're actually running

Operate

Access and visibility when you need them

pi-01

online
CPU12%
Disk86%
Temp48°C
Disk almost full — email sentAll checks passing — nothing to do
alerts on

Browser terminal, file browser, host metrics (CPU, RAM, disk, temperature), service actions and an audit log of what happened on the device. No VPN setup, no port forwarding.

  • Browser-based terminal and file browser, no SSH client required
  • Live host metrics and last-seen status
  • Email alerts when something needs attention
  • Restart services and ship updates straight from the web app

Publish

Your domain, automatic HTTPS

blog.example.org

live
DNS verifiedCNAME ok
Certificate issuedLet's Encrypt
Routed to devicepi-01
TLS terminates on your device
https

Connect a domain you own, bind it to a service running on your device, and Obacht handles routing and Let's Encrypt certificates. Nothing is public until you say so. No router config, no static IP.

  • Custom domains with automatic HTTPS via the Obacht proxy
  • Bind any local port on the device to a public hostname
  • Your service stays on your device; only traffic is routed

Three device classes, the same idea.

Start with an inexpensive Raspberry Pi, repurpose an existing Linux machine, or let the Apple-silicon Mac that's already running at your place pitch in. Same control plane in the browser, same templates, same domain.

Raspberry Pi

Small, frugal, dedicated

Drag the bundle onto an SD card, plug it in, in the dashboard within minutes. Plenty for a small site, a CMS, or a password manager.

  • Drag-and-drop setup onto the SD card, no shell
  • Low power draw, runs unattended
  • An affordable way into self-hosting

Linux machine

Put old hardware back to work

An old laptop, a mini PC, or any retired machine. Install Ubuntu once, run a single install command — after that you never have to touch the machine again.

  • Old laptops, mini PCs, retired computers
  • Install Ubuntu once, run one command, done
  • From then on everything runs through the dashboard: monitor and keyboard can go
  • Arm or x86, the agent runs on both

Apple-silicon Mac

More power, on a device you already have

Your iMac or Mac mini is running anyway. Obacht uses the spare capacity in the background, alongside your normal work. Containers run isolated in their own Linux VM — separate from your files and your home network.

  • Full Apple-silicon performance; AI models run natively with Metal
  • Sandboxed in a VM, no access to your files or your LAN

The Mac needs Apple silicon (M1 or newer) and macOS 14 or newer. Meant for devices that stay on anyway — iMac and Mac mini, not the mobile MacBook.

Restricted by default. More power when you ask for it.

New devices boot in restricted mode: signed templates only, no arbitrary commands, audit log on every change. When you want full control, you unlock power-mode explicitly, and you can lock it back down whenever you like.

Restricted mode

The default. Install signed templates and configure them through the UI, with monitoring and alerts included. The device stays on a tight leash.

Power mode

Unlock to get a full browser terminal, run arbitrary commands, edit files, manage services. Every change is recorded in the audit log.

Your hardware. Your data. Your domain.

Templates run on your device. Files live on your SD card, USB drive, or your Mac. Traffic to your domain is routed, not stored. Obacht is the operating layer. Your project stays yours.

Read the security architecture

Your domain

yours

obacht — operating layer

replaceable

Your data

on your device

Your hardware

yours

How it works

01

Connect your device

Pi: drop the install bundle onto the SD card and power on. Mac: install the app and click "Use this Mac". The device registers itself within minutes and shows up in the dashboard. No command line required.

02

Install open-source software

Browse the template catalogue and pick something: a CMS, a password manager, a survey tool. One click installs and configures it on your device.

03

Connect your domain

Enter your domain. SSL is issued automatically and traffic is routed to your device, reachable from anywhere without touching your router.

Closed beta

obacht is currently in closed beta. Sign up to get early access.

Sign up for the closed beta
obacht — self-hosting made simple