ROUTINE / HIGH-VOLUME → MEDIOCRE TIER
Kimi K2 and Nemotron drive triage, health sweeps, updates, cleanup, notifications, and scheduled jobs. The watchdog runs every 2 hours, market alerts every 30 minutes.
THE DOSSIER — FULL FILE
One Lenovo ThinkCentre running Ubuntu. Twenty-one containers. Four AI agents that keep it all alive, and a family of five who just see “our cloud”.
Two gateways host the fleet: Hermes for routing and cron, OpenClaw for heavy agent work. Hermes learns the workflows and understands the system's personality, and each agent has exactly the permissions its job needs.
A tiered model policy keeps the fleet cheap to run: mediocre open-weight models handle scheduled and routine automation, while frontier models are reserved for engineering and market decisions. Failover is automatic, manual override is one command away.
Kimi K2 and Nemotron drive triage, health sweeps, updates, cleanup, notifications, and scheduled jobs. The watchdog runs every 2 hours, market alerts every 30 minutes.
Claude Opus and Sonnet take infrastructure changes, security work, secrets, and market analysis. The work that is expensive to get wrong.
The router has zero forwarded ports. Everything reaches the box through outbound-only tunnels or an encrypted mesh.
Cloudflare Tunnel: outbound-only, WAF + TLS. Any device, anywhere, no VPN.
Cloudflare Access (Google SSO, single-account allow-list) or Tailscale mesh VPN.
Zero forwarded router ports. fail2ban active. Secrets stored chmod 600.
The media pipeline is fully autonomous. A family member taps once, and about 30 seconds after download the result is on their screen, subtitled.
Request
Jellyseerr · family portal
Match + grab
Sonarr / Radarr
Search
Prowlarr · 6 indexers
Download
encrypted client
Subtitles
Bazarr
On screen
Jellyfin · ~30s refresh
4 agents with distinct roles and permission boundaries, coordinated across 2 gateways.
Mediocre open-weight models drive routine automation; frontier models are reserved for engineering and market decisions.
No inbound ports. Outbound-only tunnels, SSO on every admin panel, fail2ban underneath.
Uptime Kuma checks 31 endpoints every minute; an AI watchdog triages alerts so nothing pages a human at 3am.
Watchdog sweeps every 2h, market alerts every 30m, weekday pre-market snapshots. All of it runs as cron-driven agents.
Nightly restic snapshots with 7d/4w/6m retention, weekly integrity checks, secrets isolated.
Set in Newsreader, Schibsted Grotesk & IBM Plex Mono. Built with Astro. Served by Cloudflare. Watched by Buggy.