Skip to content

Open source · MIT · pre-release

Build yourselfa cloud.

A control plane for the machines you own. It builds and deploys your apps, gives them a database and a login when they ask for one, and watches all of it. Every change it makes is a commit to the machine's NixOS configuration.

The network at work

Three requests, and the path each one really takes.

An AI query

  1. A query reaches the gateway on the box.
  2. It is routed to the model server on the gaming PC. The agent there reads that provider and reports it up its pinned link; daedalus keeps the gateway's routes in step.
  3. The tokens stream back the way the request came.

A Claude session

  1. An admin turns remote control on for a machine in Settings. The box sends that policy down the machine's pinned link.
  2. The agent runs Claude Code's remote control there, as a job of the OS. You steer the session from wherever you use Claude, and the box lists it on its Claude page.

A push to main

  1. The GitHub App tells the box. The webhook is verified before anything is believed.
  2. The box builds the image itself with Railpack and runs the repo's own checks inside the build.
  3. The image goes to the box's own registry, and the app restarts on it. The outcome goes back to GitHub as a check run.

What is in it

Everything it touches.

What it runs, and what it connects to.

Logos are trademarks of their owners, shown only to say which service is meant.

Get it

Two pieces.

The engine runs the box. The agent joins your other machines to it.

The engine

For NixOS.

View on GitHub
nix flake init -t github:santiagotoscanini/daedalus#config

The agent

For Windows, macOS and Linux.

Releases on GitHub
Set-ExecutionPolicy -Scope Process Bypass -Force; irm https://daedalus.toscanini.me/install.ps1 | iex

Questions

Before you clone it.

What does it cost?

Nothing. It is MIT-licensed, and there is no account, plan or hosted tier. You bring the machine and a domain.

What does it need?

A machine running NixOS, a domain on Cloudflare for DNS and the public tunnel, and a GitHub App for builds, which the control plane creates for you. The docs list every account and key that lives outside the repository.

Is it finished?

No. There is no tagged release yet, so a clone follows main. Everything a box needs to log in to its control plane is in the catalog of modules; many of the stacks it was built beside are still being moved in.

What can the control plane do to the machine?

Very little on its own. It runs as an unprivileged container with no sudo, no container socket and no SSH key. Its one door is a socket to the agent on the box, which can start a fixed list of systemd units that the NixOS configuration wrote down.

What if the machine dies?

The repository is the system. Every input is pinned and every secret is encrypted in it, so a fresh checkout and one decryption key rebuild the same machine. App data is not in the repository; it comes back from the replicated snapshots, wherever you keep them.

Does it reach my other machines?

Only the ones you install the agent on. Each one opens a single TLS connection to the box, both sides pinning each other's key, and waits until you approve it before the box tells it anything.

Follow the thread.

The NixOS modules a host imports, the control plane they run, the template a new host starts from, and this site. One repository.

git clone https://github.com/santiagotoscanini/daedalus