Run open-source software on hardware you own: a Raspberry Pi, a Linux machine, or an Apple-silicon Mac that's already running at your place. We take care of the tunnel, SSL, and domain.
You manage everything from the browser through your Obacht account, while your data stays on your own hardware rather than in our cloud. No port forwarding, and no Docker knowledge needed.
obacht is currently in closed beta. Sign up to get early access.
You want to run your own website, a password manager, or a tool for your team on hardware that's yours. But somewhere between SSH, Docker, certificates and dynamic DNS, the project stalls.
Obacht is the missing operating layer for a single small device. You install signed templates from the dashboard, point a domain at a service, and HTTPS comes automatically. The device runs on your network; the control plane lives in your browser.
the homelab way
with obacht
tunnel, SSL & domain — handled
Pick a template, get it running on your device, keep an eye on it, and optionally make it reachable under your own domain.
Signed templates for real apps
vaultwarden
runningA growing catalogue of 40+ templates: WordPress and other CMSs, Vaultwarden, Uptime Kuma, n8n, Gitea and more. All signed, running in containers, with a versioned manifest.
Access and visibility when you need them
pi-01
onlineBrowser terminal, file browser, host metrics (CPU, RAM, disk, temperature), service actions and an audit log of what happened on the device. No VPN setup, no port forwarding.
Your domain, automatic HTTPS
blog.example.org
liveConnect a domain you own, bind it to a service running on your device, and Obacht handles routing and Let's Encrypt certificates. Nothing is public until you say so. No router config, no static IP.
Start with an inexpensive Raspberry Pi, repurpose an existing Linux machine, or let the Apple-silicon Mac that's already running at your place pitch in. Same control plane in the browser, same templates, same domain.
Raspberry Pi
Drag the bundle onto an SD card, plug it in, in the dashboard within minutes. Plenty for a small site, a CMS, or a password manager.
Linux machine
An old laptop, a mini PC, or any retired machine. Install Ubuntu once, run a single install command — after that you never have to touch the machine again.
Apple-silicon Mac
Your iMac or Mac mini is running anyway. Obacht uses the spare capacity in the background, alongside your normal work. Containers run isolated in their own Linux VM — separate from your files and your home network.
The Mac needs Apple silicon (M1 or newer) and macOS 14 or newer. Meant for devices that stay on anyway — iMac and Mac mini, not the mobile MacBook.
New devices boot in restricted mode: signed templates only, no arbitrary commands, audit log on every change. When you want full control, you unlock power-mode explicitly, and you can lock it back down whenever you like.
The default. Install signed templates and configure them through the UI, with monitoring and alerts included. The device stays on a tight leash.
Unlock to get a full browser terminal, run arbitrary commands, edit files, manage services. Every change is recorded in the audit log.
Templates run on your device. Files live on your SD card, USB drive, or your Mac. Traffic to your domain is routed, not stored. Obacht is the operating layer. Your project stays yours.
Read the security architectureYour domain
yoursobacht — operating layer
replaceableYour data
on your deviceYour hardware
yoursHow it works
Pi: drop the install bundle onto the SD card and power on. Mac: install the app and click "Use this Mac". The device registers itself within minutes and shows up in the dashboard. No command line required.
Browse the template catalogue and pick something: a CMS, a password manager, a survey tool. One click installs and configures it on your device.
Enter your domain. SSL is issued automatically and traffic is routed to your device, reachable from anywhere without touching your router.
obacht is currently in closed beta. Sign up to get early access.
Sign up for the closed beta