The first three build logs covered the orchestration framework, the SDLC harness, and the agents running the dev lifecycle. This one is about where all of it runs: a single Mac Mini at home, wearing two faces.
One Machine, Two Identities
The Mini has a public face and a private face, and they never touch.
| Face | Network | Who can reach it | |---|---|---| | Public | Cloudflare Tunnel → learn-agentic-ai.com | Anyone with the URL | | Private | Tailscale (MagicDNS) | My personal devices only |
The important property: zero open inbound ports on either face. Nothing is exposed to the public internet directly.
The Public Face
learn-agentic-ai.com — this site — is served by the Mini. A Cloudflare Tunnel terminates TLS at Cloudflare's edge and forwards to localhost, so there are no firewall holes to punch. A small DDNS client keeps the DNS record current if my home IP rotates, with the daemon driven by the OS scheduler rather than the client's own loop.
That's the whole public surface: a tunnel out, no ports in.
The Private Face
Everything else — the orchestration API, the Celery worker, Redis, Postgres with pgvector, and a personal knowledge feed — lives on the private face, reachable only over Tailscale with MagicDNS. To my laptop, the Mini behaves like it's on the same LAN, even though it's a tunnel away. To the public internet, it doesn't exist.
The Tradeoff I Had to Make
The Mini has to survive a reboot or a power cut with nobody there to type a password. That turned out to be harder than expected on macOS, which has no true before-login networking, and FileVault gates all networking behind the pre-boot unlock screen.
So unattended access required a real tradeoff: FileVault off, auto-login on, Tailscale connecting on login. I made that choice deliberately and wrote down the rationale. The threat model for a home-only box is network exposure, not physical theft — and network exposure is already handled by Tailscale plus zero open ports. The encryption-preserving alternatives (a scheduled-reboot unlock command, or an IP-KVM for unplanned crashes) were noted and deferred, not ignored. That's the honest version: not "FileVault is bad," but "here is exactly what I traded and why."
Why Self-Host At All
Cost is part of it — this is real infrastructure for the price of electricity. But the real reason is the privacy argument. If you believe AI systems should be able to run on hardware you own, against data that never leaves your network, then the most credible thing you can do is build that way yourself. The private face is that belief, made physical.
I'm documenting all of this in English and Portuguese at learn-agentic-ai.com. If you want infrastructure that you actually control, reach out at [email protected].