Skip to main content

Blog Post

Build Log: Self-Hosting on a Mac Mini — Two Faces, Zero Open Ports

•3 min read•By Brandon

Build LogSelf-HostingInfrastructurePrivacy

The first three build logs covered the orchestration framework, the SDLC harness, and the agents running the dev lifecycle. This one is about where all of it runs: a single Mac Mini at home, wearing two faces.

One Machine, Two Identities

The Mini has a public face and a private face, and they never touch.

| Face | Network | Who can reach it | |---|---|---| | Public | Cloudflare Tunnel → learn-agentic-ai.com | Anyone with the URL | | Private | Tailscale (MagicDNS) | My personal devices only |

The important property: zero open inbound ports on either face. Nothing is exposed to the public internet directly.

The Public Face

learn-agentic-ai.com — this site — is served by the Mini. A Cloudflare Tunnel terminates TLS at Cloudflare's edge and forwards to localhost, so there are no firewall holes to punch. A small DDNS client keeps the DNS record current if my home IP rotates, with the daemon driven by the OS scheduler rather than the client's own loop.

That's the whole public surface: a tunnel out, no ports in.

The Private Face

Everything else — the orchestration API, the Celery worker, Redis, Postgres with pgvector, and a personal knowledge feed — lives on the private face, reachable only over Tailscale with MagicDNS. To my laptop, the Mini behaves like it's on the same LAN, even though it's a tunnel away. To the public internet, it doesn't exist.

The Tradeoff I Had to Make

The Mini has to survive a reboot or a power cut with nobody there to type a password. That turned out to be harder than expected on macOS, which has no true before-login networking, and FileVault gates all networking behind the pre-boot unlock screen.

So unattended access required a real tradeoff: FileVault off, auto-login on, Tailscale connecting on login. I made that choice deliberately and wrote down the rationale. The threat model for a home-only box is network exposure, not physical theft — and network exposure is already handled by Tailscale plus zero open ports. The encryption-preserving alternatives (a scheduled-reboot unlock command, or an IP-KVM for unplanned crashes) were noted and deferred, not ignored. That's the honest version: not "FileVault is bad," but "here is exactly what I traded and why."

Why Self-Host At All

Cost is part of it — this is real infrastructure for the price of electricity. But the real reason is the privacy argument. If you believe AI systems should be able to run on hardware you own, against data that never leaves your network, then the most credible thing you can do is build that way yourself. The private face is that belief, made physical.

I'm documenting all of this in English and Portuguese at learn-agentic-ai.com. If you want infrastructure that you actually control, reach out at [email protected].

I taught before I built, and it still shapes how I explain this work. I build production agentic AI systems and write about what I learn doing it.

Not sure if this is for you?

Take the readiness check on the practice site — see if it's a fit before you book anything.

two minutes

Check if it's a fit