One control plane for every machine you run — cloud VPS, bare metal, office PCs, GPU rentals. Capture the whole box into an encrypted .hsi, restore or relocate with IP rewrite, deploy apps through HostPack → Docker → Traefik, and turn capacity into a usable OpenAI-compatible API. Files, DB, Workers, Storage — and Inference on the path to fleet proof. Your data, your bucket, your exit.
Same control plane. Same agent. Same portability and AI path — whether we host the box or you bring cloud, colo, office machines, or GPU rentals.
Buy capacity from us and the whole stack is baked in: deploy, managed databases, backup, clone, one-click relocate. Portability is the product — not an upsell.
Install the agent on Hostinger, Hetzner, DigitalOcean, Vultr, AWS, bare metal, office PCs, or a rented GPU. Fleet-aware, provider-agnostic — one dashboard for every machine you refuse to lose.
The market is sliced into panels, snapshot products, GPU marketplaces, and foundation APIs. Nobody owns the full loop: onboard any machine → protect it → move it → provision cloud when you need it → expose inference to your apps without binding to a vendor. That loop is HostSSH.
A managed HostPack → Docker → Traefik path takes your repo to a live, TLS-terminated URL — no Nix, no Dockerfile required, no hand-wired reverse proxy.
HostPack inspects your repo, picks the runtime and produces a lean, reproducible OCI image — Node, Python, Go, Rust, static and more. No Dockerfile to maintain, no Nix to learn.
The image runs as a supervised Docker container with health checks, sealed-secret injection, resource caps, persistent volumes and health-gated deploys so a bad build never silently goes live.
Traefikbinds your domain, issues and renews Let's Encrypt TLS (HTTP-01 today; DNS-01 for wildcards and pre-cutover certs as nodes upgrade), and load-balances traffic. Routes are declarative, so a relocated box re-binds automatically.
The relocate engine is the moat — but every node also runs a full day-to-day platform. These five primitives ship with the agent; you don't bolt them on later.
Named volumes survive redeploys. The .hsi captures volume data — uploads, media, SQLite, WordPress, MinIO blobs — binary-safe, not SQL dumps only.
One-click Postgres (pgvector), MariaDB, and Redis— generated creds, internal networking, included in full-server capture & restore.
Background workers and queue consumers deploy like web apps — --command, Slot caps, sealed secrets — without a public route. Spin on-demand workers from MCP too.
OpenAI-compatible gateway routes model names to CPU fleet, office GPUs, or rentals — apps never see upstream hosts. Today: Copilot + MCP. Gateway + templates in product; live fleet completion proof on the path.
BYO R2/S3/B2 for encrypted .hsi backups (zero-egress restores). Need app object storage? One-click MinIO beside your apps.
From the first deploy to a 3am disaster recovery — capture, restore, relocate, provision and prove it, all from one control plane or one Go binary.
HostPack builds it, Docker runs it, Traefik routes it. Push to ship, with health checks, secrets and versioned images you can roll back to.
Provision Postgres, MariaDB or Redis in a click — connection strings, internal networking, and inclusion in full-server capture & restore.
Named volumes survive redeploys. The .hsi captures the bytes inside — uploads, media, SQLite, WordPress — not empty mount names.
Same HostPack → Docker path as web apps, with a command override and no public route — queue consumers and cron-style processes with Slot caps.
The whole box — platform brain & master key, every database, Docker volume data, system config & sidecars — not just a SQL dump.
Integrity drills verify your backup repository is readable and restorable. Full sandbox row-verify is on the roadmap — a backup you haven't tested is still a rumour.
A deterministic pass flips every public reference; internal services ride a stable WireGuard overlay — so a moved box just works.
Hostinger + bring-your-own machine today; the same queue expands across Hetzner, DigitalOcean, Vultr and AWS as drivers land.
Images sealed before they leave the host. R2, S3, MinIO, B2, Wasabi, SFTP or local — you own the storage, zero-egress restores.
ed25519 license tokens unlock features per tier; the control plane keeps every agent and server in one fleet view — even across providers.
One Go binary drives everything; MCP + Copilot let AI agents diagnose and operate the fleet through the same RBAC-gated actions you use.
Issue sealed keys, map models to fleet upstreams, and call an OpenAI-compatible base URL — swap office GPU for cloud rental without changing app code.
Same agent join path whether the box is a Hostinger VPS, a desk PC behind NAT, or a Vast GPU — no public IP required when you tunnel.
Pack apps onto a box with hard CPU/memory/PID caps in four sizes — a real isolation unit you can meter, place, and move between machines.
Default-deny firewall baseline today; full Security Score, granular profiles and armed auto-revert rolling out behind the security spine.
Auto uptime monitors on every routed domain, plus disk, backup and cert watches — that page you on Slack, PagerDuty, webhook or email, not just draw a red dot.
Keyless, audited root access from the browser through an mTLS relay — private beta; session recording and pentest before general availability.
A real capture → restore round-trip across a live fleet: a whole data box cloned onto a fresh server, every database verified to the row — engine proof we dogfood before we sell. Scheduled integrity drills keep the backup repo honest; full sandbox row-verify is next.
Built by Sevak Girard at Girard Media and dogfooded on our own production fleet — the deploy, backup, and relocate paths run our real servers before they run yours.
You pay for the software; storage stays on your own R2/S3/B2. No surprise egress, no data hostage — emergency restores work even on an expired license.
One command installs the agent, prompts for your license key, and unlocks Files, DB, Workers, Storage, the deploy pipeline, backup, clone, relocate & Web-SSH — on any provider.
$ curl -fsSL https://get.hostssh.com | shHostSSH is in private build, dogfooded on a real production fleet. Early access includes the proven relocate engine plus the day-to-day platform — Files, DB, Workers, Storage, Copilot, slots, and git-push deploys as they land.