Docs / Home server & tunnel

Home server & tunnel

Use a computer at home or in the office as a server, with no VPS to rent and no public IP. Sites and web apps can be reached from the internet at a free <name>-app.hack.id address.

What it is good for

Less suited to busy shops or services that must always be up: home power and internet can drop. Use a VPS for those.

Choose your device

DeviceHowStatus
Mini PC or old laptopInstall Ubuntu Server 24.04, then the Saka agentRecommended, most stable
Raspberry Pi 4/5Install Ubuntu Server 24.04 64-bit (Raspberry Pi OS is not supported yet)Supported (arm64)
Windows 10/11 PCUbuntu inside Windows via WSL2Beta
MacUbuntu in a Multipass virtual machineBeta

Requirements are the same as any server: at least 1 GB RAM for the agent, 2 GB for OpenClaw (1 GB for Hermes). The Saka agent runs on Linux only, so Windows and Mac run Ubuntu inside.

Path A: mini PC or laptop with Ubuntu

  1. Install Ubuntu Server 24.04 (or Ubuntu Desktop if you want a screen).
  2. In the BIOS, turn on power on after power loss (the name varies by brand) so the computer starts again after a power cut.
  3. For a laptop, keep it awake when the lid is closed:
Terminal
sudo sed -i 's/^#\?HandleLidSwitch=.*/HandleLidSwitch=ignore/' /etc/systemd/logind.conf
sudo systemctl restart systemd-logind
  1. In the Saka panel, open Servers then Add server, copy the command, and run it on that computer. Details in Getting started.

Path B: Windows via WSL2 (beta)

  1. Open PowerShell as Administrator, run the command below, and restart if asked. Then create an Ubuntu username and password.
PowerShell (Administrator)
wsl --install -d Ubuntu-24.04
  1. In the Ubuntu terminal, check that systemd is on with systemctl is-system-running. If you get an error, add this to /etc/wsl.conf, run wsl --shutdown in PowerShell, and open Ubuntu again:
/etc/wsl.conf
[boot]
systemd=true
  1. Run the Add server command from the Saka panel in the Ubuntu terminal. Docker is installed automatically inside Ubuntu; Docker Desktop is not needed. If Docker Desktop is already installed, turn off WSL integration for Ubuntu-24.04 to avoid conflicts.
  2. WSL stops when all its windows are closed. To keep it running, create a Task Scheduler task: trigger At log on, action runs the command below. Also set Windows to never sleep when plugged in.
Task Scheduler: action
wsl.exe -d Ubuntu-24.04 --exec sleep infinity

Path C: Mac via Multipass (beta)

  1. Install Homebrew if you do not have it, then create an Ubuntu virtual machine and open a shell in it:
Mac terminal
brew install --cask multipass
multipass launch 24.04 --name saka --cpus 2 --memory 4G --disk 30G
multipass shell saka
  1. Run the Add server command from the Saka panel inside that virtual machine. Apple Silicon (M1 and later) and Intel Macs are both supported.
  2. In System Settings, under Energy or Battery, stop the Mac from sleeping automatically when plugged in. After the Mac restarts, start it again with multipass start saka.

Already installed OpenClaw directly on your PC?

An OpenClaw you installed yourself on Windows or Mac is not managed by Saka. Saka only manages OpenClaw installed from the panel (inside Docker). Recommended: install OpenClaw through Saka in Ubuntu (WSL or Multipass), then stop the old OpenClaw. Do not run both with the same Telegram bot token, because they will compete for messages.

ImportantDo not expose the OpenClaw dashboard or gateway to the internet through a tunnel. It is the way into an assistant that holds your API keys. From outside your home, use the Open dashboard button in the Saka panel, which is protected by your login.

Open a site to the internet: tunnel

Home servers usually sit behind a router without a public IP. A tunnel makes an outbound connection from the server to Cloudflare's network, so you do not open any router port and your home IP stays hidden. HTTPS is automatic.

  1. Open the Tunnel menu in the panel.
  2. Enter an address name (e.g. cakeshop becomes cakeshop-app.hack.id), pick the server, then choose what it opens: a Saka site or another web app by port number (e.g. 3000 or 8080).
  3. For a site, keep Make this the site's main address checked if the site's current domain cannot be opened from the internet. WordPress switches all its links to this address. Deleting the tunnel restores the previous domain.
  4. Press Create address.

Until phone verification is available, new addresses are reviewed by the Saka team first and you are notified on Telegram. The limit is 3 addresses per account. Names that are easy to misuse for scams (bank, login, verify, big brands) cannot be used.

Good to know

Through the API or AI

Your AI agent can create tunnels over MCP (tunnel_buat, tunnel_daftar, tunnel_hapus) or the API:

curl
curl -s -X POST https://app.saka.work/api/v1/tunnel \
  -H "Authorization: Bearer $SAKA_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"nama": "tokokue", "server_id": "<id-server>", "situs_id": "<id-situs>", "utama": true}'

For a web app, replace situs_id with "port": 8080. To delete: DELETE /api/v1/tunnel/<id> with {"konfirmasi": "<name>"}.