Website Β· Live demo Β· Quick start Β· AWS compatibility Β· Architecture Β· Discord
Try the live demo console β click through every service in your browser, no install needed (sample data, runs entirely client-side).
An open-source, self-hosted cloud platform. HomeCloud runs AWS-style services (compute, object storage, managed databases, serverless functions, queues, pub/sub, key-value tables, networking, identity, monitoring) on your own hardware, from one binary, managed through a web console, a CLI and a REST API.
Speaks AWS. The AWS CLI, the AWS SDKs and Terraform work against HomeCloud unchanged: point AWS_ENDPOINT_URL at it and use a HomeCloud access key. IAM policies, roles and temporary credentials are enforced exactly as in the console.
No third parties. No vendor lock-in. No surprise billing.
π‘ Built with privacy, transparency, and sovereignty at its core.
A web console modeled on the one you know, with a page for every service. It is built into the binary: run homecloud serve and open http://127.0.0.1:8080.
| Service | AWS equivalent | What you get |
|---|---|---|
| Compute | EC2, EBS, AMIs | Instances with CPU/memory limits from t3.nano to r5.large, 10 base images (Ubuntu, Debian, Amazon Linux, Rocky, Fedora, Alpine, β¦), user data, key pairs, start/stop/reboot/resize, volumes and snapshots, capture an instance as a new image, run-command, a shell in the browser, and an instance metadata service (IMDSv1/v2) that hands role credentials to SDKs inside instances |
| Auto Scaling | EC2 Auto Scaling | Groups that keep a desired number of instances across subnets, replace unhealthy ones, register them with load balancers and scale on CPU or memory targets |
| Shared files | EFS | File systems that any number of instances mount at the same time |
| Containers | ECS (Fargate), ECR | Versioned task definitions with secrets injected from Secrets Manager, services that keep N tasks running with rolling deployments and load-balancer registration, one-off tasks, and a private image registry you docker push to |
| Networking | VPC, ELB | VPCs and subnets with real private IP addressing, private DNS (ip-10-88-0-4.internal, mydb.rds.internal), security groups that filter traffic between resources (ingress and egress, by CIDR or by referenced group) and decide which ports are published; application load balancers with HTTP/HTTPS listeners, HTTPβHTTPS redirects, path/host routing rules, target groups and health checks |
| DNS | Route 53 | Public and private hosted zones (A, AAAA, CNAME, TXT, MX, SRV, CAA, NS, PTR), alias records that follow instances, tasks, databases and load balancers; a resolver at each VPC's .2 address and a LAN-facing DNS port |
| Certificates | ACM | A private certificate authority that issues TLS certificates for your domains and IPs, import of Let's Encrypt or other certificates, renewal, and HTTPS on load balancers |
| Object storage | S3 | Buckets, folders, uploads/downloads, versioning, public-read access, lifecycle expiry, presigned URLs, static website hosting, and a fully S3-compatible endpoint for AWS SDKs and aws CLI |
| Databases | RDS, ElastiCache, DocumentDB | PostgreSQL, MySQL, MariaDB, MongoDB, Redis, Valkey, Memcached with generated credentials in Secrets Manager, snapshots and restore, daily automated backups, resizing, password rotation and a query editor |
| Serverless | Lambda, API Gateway | Functions on AWS's official runtime images (Python, Node.js, Java, Ruby, .NET, Go/Rust custom runtimes, container images) with warm environments, execution roles, versions and aliases, layers, async invocation with retries and destinations, reserved concurrency; function URLs; HTTP APIs with JWT authorizers; SQS and DynamoDB stream triggers |
| Queues | SQS | Standard and FIFO queues, visibility timeouts, delays, long polling, dead-letter queues with redrive, batches |
| Pub/sub | SNS | Standard and FIFO topics fanning out to queues, functions and confirmed HTTP(S) endpoints, signed messages, raw delivery, full filter-policy syntax |
| Key-value | DynamoDB | Typed items with the full condition/update/projection expression language, GSIs and LSIs, batches, transactions, PartiQL, TTL and streams |
| Workflows | Step Functions | State machines in Amazon States Language: Task (Lambda, SQS, SNS), Choice, Wait, Parallel, Map, Pass, Succeed, Fail, with Retry/Catch, JSONPath input/output processing, intrinsic functions and a full execution history |
| Events | EventBridge, Scheduler | Event buses with the full pattern syntax, input transformers, retries and DLQs; schedules with at()/rate()/cron() and time zones |
| Identity | IAM, STS | Users, groups, roles with trust policies, AWS-managed and custom policies (with versions, conditions and permissions boundaries), instance profiles, access keys, temporary credentials, console passwords, a policy simulator |
| App identity | Cognito | User pools with sign-up, sign-in, refresh tokens, forced password changes, groups and global sign-out; RS256 JWTs with a JWKS endpoint; API Gateway routes can require them |
| Secrets & keys | Secrets Manager, KMS, SSM Parameter Store | Versioned secrets with staging labels and Lambda rotation; symmetric, RSA, ECC and HMAC keys with policies, grants and rotation; hierarchical parameters with SecureString values, versions and labels |
| Monitoring | CloudWatch | Per-resource metrics, custom metrics with metric math, alarms that notify SNS topics or webhooks, log groups with filter patterns, Logs Insights queries and subscription filters |
| Infrastructure as code | CloudFormation | YAML/JSON stack templates for 30 resource types across every service, with parameters, outputs, !Ref/!GetAtt/!Sub/!Join, dependency ordering, readiness waits, rollback, updates and ordered deletion |
| Audit | CloudTrail | A record of every change and every denied request, with who, what, when and from where |
Everything runs as containers on Docker, labelled so HomeCloud never touches containers it didn't create. See docs/architecture.md for how each service is built, docs/aws-compat.md for the AWS APIs it speaks and docs/api.md for the native API reference.
You need Docker (Docker Engine on Linux, or Docker Desktop / OrbStack on macOS and Windows).
Linux / macOS
curl -fsSL https://homecloud.pages.dev/scripts/install.sh | shWindows (PowerShell)
irm https://homecloud.pages.dev/scripts/install.ps1 | iexRunning it on a VPS or home server? See Install on a server (system service, TLS, firewall, backups).
Or build from source with Go 1.25+ and Node.js 22+: make (the binary lands in bin/homecloud).
homecloud serveOn first start HomeCloud creates your account, prints the root console password once, and writes CLI credentials to ~/.homecloud/credentials. Open http://127.0.0.1:8080 and sign in as root.
To reach it from other machines, bind to your LAN or Tailscale address (add --tls-self-signed, or --tls-cert/--tls-key, to serve HTTPS):
homecloud serve --addr 0.0.0.0:8080 --public-host homelab.tailnet.ts.net --tls-self-signed# Compute: a web server whose port 80 is published
homecloud vpc create-sg web && homecloud vpc allow sg-xxxx 80
homecloud ec2 run --name web --image ami-nginx --sg sg-xxxx
homecloud ec2 ssh i-xxxx
# Storage
homecloud s3 mb s3://photos
homecloud s3 cp ./beach.jpg s3://photos/2025/
homecloud s3 presign s3://photos/2025/beach.jpg
# A PostgreSQL database; the password lives in Secrets Manager
homecloud rds create orders-db --engine postgres --public
homecloud rds query orders-db "select version()"
homecloud rds password orders-db
# Serverless: a function behind an HTTP API, fed by a queue
homecloud lambda create resize --runtime python3.12 --code ./resize
homecloud lambda url resize
homecloud sqs create jobs --dlq jobs-dlq
homecloud lambda trigger resize jobs
# Schedules and events
homecloud events schedule nightly 'cron(0 3 ? * * *)' --target arn:aws:lambda:us-east-1:<account>:function:resize
# Containers behind a load balancer
docker tag myapi localhost:5500/myapi:1 && docker push localhost:5500/myapi:1
homecloud elb create-target-group api-tg --port 8000
homecloud elb create web --listen 80=api-tg
homecloud ecs register api --image localhost:5500/myapi:1 --port 8000 --secret DB_PASS=prod/db:password
homecloud ecs create-service api api --count 3 --target-group api-tg
# Infrastructure as code (see docs/examples/pipeline.yaml)
homecloud cfn create pipeline docs/examples/pipeline.yaml -p Env=dev
homecloud cfn delete pipeline
# Anything else
homecloud api GET /api/v1/cloudwatch/alarmsRun homecloud --help or homecloud <service> --help for every command.
HomeCloud speaks the AWS protocols on its API port, so the AWS CLI, SDKs (boto3, JS, Go, Java) and Terraform work unchanged with HomeCloud credentials and IAM:
eval "$(homecloud aws-env)" # AWS_ENDPOINT_URL, keys and region
aws s3 ls
aws lambda invoke --function-name hello out.jsonSee docs/aws-compat.md for the supported services and operations.
homecloud service install # launchd (macOS) or systemd (Linux)
homecloud backup -o backup.tar.gz # state, keys and every Docker volume
homecloud restore backup.tar.gz # with the server stopped
homecloud upgrade # verified update from GitHub releases- β Phase 1: Core cloud stack: compute, storage, networking, web console, CLI and API
- β Phase 2: Serverless and event-driven services: Lambda, API Gateway, SQS, SNS, EventBridge, DynamoDB
- β Phase 3 (first cut): Observability and governance: CloudWatch metrics/logs/alarms, CloudTrail, IAM, Secrets Manager
- β Containers: ECS services and tasks, ECR registry, load balancers, shared file systems
- β Workflows: Step Functions
- β Infrastructure as code: CloudFormation-style stacks
- β AWS compatibility: the AWS CLI, SDKs and Terraform work against HomeCloud for IAM/STS, EC2/VPC, S3, Lambda, DynamoDB, SQS, SNS, Secrets Manager, SSM, KMS, CloudWatch, EventBridge, Step Functions, Elastic Load Balancing, Auto Scaling, ECS and ECR
- π Next: AWS APIs for RDS, API Gateway, Route 53, ACM, EFS, ElastiCache and CloudFormation; stricter security groups and resource policies; VM-backed instances (QEMU/KVM); multi-node clusters
- π Phase 4: Edge compute and hardware integrations
Designs for the two largest open items: multi-node clusters (#55) and edge compute and hardware integrations (#56).
π See the open issues for everything planned, with a checklist per item.
cli/ Go server + CLI (single binary)
cmd/ CLI commands
internal/server wires services into one HTTP API
internal/svc/<name> one package per service (ec2, s3, rds, lambda, ...)
internal/httpx native API routing, IAM checks, errors
internal/awsapi AWS protocols: SigV4, awsJson, awsQuery, REST
internal/system backup and restore
internal/runtime Docker engine wrapper
internal/store persistent state
console/ Next.js web console (static export, embedded into the binary)
docs/ architecture and API reference
make test # Go tests (AWS CLI/boto3 tests run when installed)
cd cli && go run . serve # API on :8080
cd console && NEXT_PUBLIC_API_URL=http://127.0.0.1:8080 npm run dev # console on :3000
make release # cross-compiled archives for 6 platforms in dist/Releases are built by GitHub Actions when a v* tag is pushed.
HomeCloud is a community project, currently unfunded and maintained by volunteers.
- Sponsor development via GitHub Sponsors / Open Collective (Coming Soon)
- Contribute infrastructure, bugfixes, or UX improvements
- Share HomeCloud with your communities!
Weβre building HomeCloud for the community, and weβd love for you to join us:
π¬ Join the Discord Community: connect, discuss, and collaborate. π οΈ Contribute Code: check out Issues and Pull Requests to get started. π£ Share Feedback: help shape what HomeCloud becomes.
πΉ By contributing, you agree to our Contributor License Agreement (CLA).
HomeCloud is released under GNU AGPL-3.0: open, transparent, and libre. If you deploy or modify it publicly, share your changes too.







