Your metal.
Our brains.
Run the open-source Ruust agent on any Linux box you own. It pulls from your Ruust panel and turns your hardware into a proper platform: builds, HTTPS, ingress and private networking, all managed. You keep the compute, the network and the data.
Pull-based agent · never opens your box to us · Apache-2.0
Your box reaches out. We never reach in.
The control plane stores desired state. Your host polls it and converges on its own schedule. No callback, no listener, no port waiting to be knocked on.
From bare box to production.
Run the agent
One line on any Linux box. It installs the open-source agent and enrols the host to your account with a scoped token.
curl -fsSL ruust.run/enrol | shIt pulls, never listens
The agent polls your panel for desired state and converges. Ruust never opens a connection to your box: no inbound ports, no SSH from us, nothing to expose.
Lay Eggs on your metal
Push a repo and the agent clones it, builds it into an image and runs it, all on your host. Your source is built on your own machine and never leaves it: nothing is uploaded to us, nothing is pushed to a registry. TLS, ingress and private networking are wired up the same as fully hosted.
The platform, on hardware you control.
Your hardware, your rules
A spare VPS, a homelab, a bare-metal rack, or a regulated cloud account you already pay for. Your workloads run on machines you own.
Unmetered egress, literally
It is your pipe. Bandwidth was never our cost, and now it is not even on our network. Serve, stream and sync with no bill for it, ever.
No compute markup
You pay for the panel, not a margin on someone else's servers. Bring a small box and run real things on it, at a flat, tiny fee per Egg.
Audit the agent
The agent, the on-host ingress and the firewall are open source. Read every line that runs on your host before you decide to trust it.
Your code built on your metal
The build runs on your host, not ours. Your repo is cloned and turned into an image on your own machine, then run there. The source and the built image never leave your box and never touch our servers or a shared registry. Sovereignty all the way down to the build.
One panel, mixed fleet
BYOH Eggs and fully hosted Eggs share a Coop. Connect them privately, burst to our regions when you need to, and pull back when you do not.
Owning your data is not nostalgia.
It is leverage.
The last decade taught everyone the same lesson the hard way: rented infrastructure can change its terms, its prices, or its mind overnight. A region closes. A bill triples. An account is frozen by an automated system with no one to appeal to. When your data and your compute sit on someone else’s balance sheet, so does your business.
Sovereignty is not a server in a cupboard. It is the power to walk away without asking permission, and to know exactly where your data sleeps at night.
Your data, where the law says it belongs
Keep workloads on hardware in a jurisdiction you choose, in a building you can name. Meet GDPR, data residency and public-sector rules without decoding a shared-responsibility matrix first.
A platform you are free to leave
The agent is Apache-2.0 and the wire contract is open. Your images are standard OCI and your data is on your own disks. Portability is the default here, not a migration project you keep putting off.
Nobody pulls the plug but you
Because we never open a connection to your box, there is no remote switch for us to flip, and none for anyone to lean on us to flip. Your host answers to you, on its own schedule.
Make the hardware you own earn its keep
That rack, that homelab, that reserved cloud account: turn it into a real platform instead of paying a second landlord for the same compute. Ownership that finally pays you back.
Our part is to make ownership feel effortless. You keep the compute, the network and the data; we bring the builds, the TLS, the ingress and the brains, and we stay on the far side of a connection you control. Self-hosting without the sysadmin tax. The nest egg stays yours.
Open where it touches your box. Managed where it is the value.
- The agent, the Caddy ingress and the host firewall
- Clones and builds your repo into an image, on your box
- Holds one scoped host token, nothing more
- Pulls desired state; receives env secrets encrypted in transit
- Apache-2.0, versioned wire contract, yours to fork
- The dashboard, builds, placement and the reconciliation brain
- Desired-state store, private networking and Coops
- Certificates, custom domains and metrics
- Billing and support
- Open a connection to your host
- Run an inbound command or SSH in
- Upload, store or build your source code off your box
- Hold your decrypted secrets at rest
- Meter or cap your egress
You bring the compute, so we only charge for the panel.
Flat, per Egg, per month, whatever the size. On our metal an Egg starts at £3. On yours it is a small management fee, and egress is free because it never leaves your network.
Kick the tyres on your own box.
- 1 host
- Up to 3 Eggs
- Everything managed: builds, TLS, ingress
- Community support
Any size Egg. Capped at £20 per host.
- Unlimited hosts and Eggs
- Teams, private networking, Coops
- Custom domains and automatic TLS
- Unmetered egress, on your pipe
For regulated fleets and air-gaps.
- SSO and SAML, roles and audit logs
- Priority support with an SLA
- The control plane on your metal too, air-gapped
- Onboarding and migration help
Your compute stays yours. We never mark it up, meter your bandwidth, or bill for a region you did not use. The nest egg stays yours.
The questions everyone asks first.
Which machines work?
Any modern Linux host with Docker and cgroups v2: a cloud VPS, a homelab box, bare metal, or a locked-down cloud account you already pay for.
Does the agent phone home with my data?
It pulls desired state and reports health. It never ships your app data anywhere, and it never opens an inbound port. You can read the source before you run it.
Where does my code get built?
On your own host. When you push a repo, the agent clones it and builds the image locally with your host's Docker (auto-detecting the stack, no Dockerfile required), then runs it. Your source and the built image never leave your machine and are never pushed to a registry, so a BYOH host only ever holds images it built itself. On our fully hosted regions we build it for you instead.
Can I mix BYOH and hosted Eggs?
Yes. Put both in one Coop, connect them privately, and move workloads between your metal and our regions as your needs change.
What about DNS and certificates?
Point your own domain at your host. Ruust issues and renews TLS automatically, the same as it does on our regions.
Is it really self-hosted if the panel is yours?
The infra is: your compute, your network, your data. The control plane stays managed. If you need the panel on your own metal too, air-gapped, that is the Enterprise tier.
What exactly is open source?
The agent, the on-host ingress and firewall, the CLI, and the wire contract the agent speaks. The panel, the brains, stays ours.
Bring a box. We will do the rest.
Point Ruust at a box you own. Builds, TLS, ingress and private networking, all handled, all on your metal. Your code never leaves it, and neither does your data.