CLANKER LABS

Self-host your home.
Let the agent run it.

One stack that puts your notes, mail, media, passwords and photos back on hardware you own — and puts an agent in front of it, so keeping twenty-one apps alive is not your evening.

Get started See what's in it
clanker-labs

What we're trying to achieve

You should not rent your own life back

Your notes, photos, mail, media and passwords live on someone else's disk, priced per seat, and mined to train models. Self-hosting is the obvious answer and almost nobody does it — because keeping twenty apps alive is a second job. So the second job is the thing we automated.

Yours, actually

Runs on your metal — a NUC, an old laptop, a VPS you already pay for. Every app binds loopback and is reachable only over your tailnet. No accounts, no seats, no telemetry.

Two commands, not two weekends

setup provisions the box. chezmoi brings up the fleet. Both idempotent, both safe to re-run, and they refuse in the right order if you run them in the wrong one.

Operated by an agent

LeClanker watches the box, fixes what it can and reports what it can't. It reaches every app through one MCP server, so a sentence in a chat can become a row in a database.

It tells you where it will cut you

The docs name the traps: which compose file collides on port 5432, which app starts locked after every reboot, which drive will read as an empty library instead of a broken one. A tool that admits its edges is easier to trust.

Demos

Two things that are hard to believe without seeing

Both of these are recordings of real output from a running box, not mockups. The only edits are redactions — a tailnet hostname is not something to publish on a page anyone can read.

make checks

Eleven questions, asked end to end every morning. Not "is the process running" — the agent is asked something and has to answer, the gateway has to return a real tool call, the mountpoint is resolved rather than trusted.

Anything still red at 07:15 gets handed to an agent with a shell, and the checks are re-run to decide whether it actually worked.

Three failures left in on purpose. A demo where everything passes is a demo nobody believes.

A sentence becomes a row

An idea mentioned in a chat, captured without anybody opening an app. The agent picks the tool, files it, and the suite starts researching it on its own.

One MCP server fronts the whole suite — ideas, tasks, notes, journal, lists. It can capture and read, and deliberately cannot delete or edit: an agent that misreads "clear my list" should be unable to act on it.

Real exchange. That idea is still in the database.

The stack

Twenty-one apps, three layers

Separate repos, one product. The order matters — the foundation brings up the machine, the intelligence layer serves models and runs the agent, and the apps are the things you stop renting. Most repos are private for now; those are marked rather than linked, so nothing here sends you to a 404.

Foundation

bare machine → running fleet
setup

Provisioning for dev machines and VPSes — packages, users, SSH hardening, firewall, container runtime, dotfiles.

Clanker-Labs/setup
chezmoi

Clones, configures, brings up and monitors every app in the ecosystem, and carries the dotfiles as a chezmoi source. One canonical secrets file fans out to every app.

private

Intelligence

the agent layer
LeClanker

The agent that governs the house. LangGraph, MCP-native, spawnable subagents, and a model you choose — frontier or entirely local.

private
LeHarness

Detects the hardware, picks a serving engine, and exposes one OpenAI-compatible URL no matter what is underneath it.

private
localflow

A Kanban board for the agent sessions already running on your machines, with burn rate and cost per provider.

private

Apps

the things you stop renting
selfkey

Every credential in one encrypted vault, with an audit trail and an API so apps fetch secrets with no human in the loop. A copy of the database is useless without the master passphrase, which is never written to disk.

private
selfmail

A small Rust mail relay for your private network. Outbound mail from a residential IP is silently discarded — no bounce, no error — which is why this relays instead.

Clanker-Labs/selfmail
selflix

Point it at a folder and get a streaming UI, indexed and searchable, on any device on the network.

private
jinsen

A self-hosted life dashboard. The home screen behaves like a phone — a launcher of icons, widgets and a dock — and each icon opens a real app: ideas, lists, notes, journal, health, planning, finances.

private
ai212

Reads a brokerage account and writes you a daily report — what moved, what it cost, and which position was responsible.

private
tradesights

Talk is cheap and options cost money. This ranks the stocks where those two stop agreeing — price against what the options market was paid to believe — and puts the biggest disagreement at the top of one list. It reads and it reports; there is no path from it to a broker.

Clanker-Labs/tradesights
selftrade

A backtester built to be able to say no. It ships with a strategy transcribed from a trading video, and reports that the strategy lost 0.245R per trade over 64 trades. Paper by default; live takes two deliberate switches.

private
clankergram

Instagram, but the users are agents. They post about their work — refactors, training runs, overnight crawls.

private
LaRecherche

Maps papers and authors into a navigable citation graph, so a literature search is something you steer rather than scroll.

private
moude

Reads your listening history and tells you the mood of your day, week, month or year — with the receipts.

private
guessflix

GeoGuessr for films. You get a heavily cropped frame, a second of silent clip, or one line of dialogue, and you guess.

private
safepill.ai

Photograph a pill and see what laboratories found in the published records whose photographs match it.

private
theroundtable

Collaborative storytelling — anyone in the world plays their part in writing a single long-running story.

private
TheWorld

Everyone in the world submits rough sketches, and they become pages in one long-running series.

private

Get started

Two steps, in order

Provisioning and deployment are deliberately separate. The first installs a toolchain on a machine; the second brings up apps on a machine that already has one. Run them the wrong way round and the preflight will tell you exactly what is missing.

  1. Provision the machine. Installs the container runtime, language toolchains, dev tooling and your dotfiles. Run once, then open a new shell.
  2. Bring up the stack. Clones every app, generates their config from one canonical secrets file, starts them behind your tailnet, and prints a health table.
# 1 — provision (once), then open a new shell
curl -fsSL https://raw.githubusercontent.com/Clanker-Labs/setup/main/install.sh | bash

# 2 — bring up the fleet
git clone https://github.com/Clanker-Labs/chezmoi && cd chezmoi
make bootstrap

# 3 — ask whether it actually works
$ make checks
  ✓ agent-answers          replied in 4s: pong
  ✓ containers-healthy     no container reports unhealthy
  ✓ datastores-private     every database and cache binds loopback only

Every project also installs standalone — each repo's README has a one-liner if you only want one piece.