Birdcage – Secure remote access for personal AI
WireGuard mesh keeps your home AI claw off the public internet entirely.
JSON config for nginx is nice, but Caddy already does auto-SSL simpler.
Self-hosters, home lab enthusiasts, DevOps engineers
Cloudflare Tunnel · Caddy · Tailscale
What I've come up with is a simple configuration-based (json or yaml) templating system.
With nginx-quick-relay you can add back-ends to two groups: - `pass-through`: it forwards HTTP+HTTPS traffic as is with optional PROXY protocol, OR - `direct-serve`: it acquires and renews certificates, redirects HTTP to HTTPS, and forwards traffic to your HTTP/HTTPS endpoint
It also handles - client certificates (per domain) to only allow trusted peers to access your resources - optional exclusion of local network traffic from client certificate requirement (based on CIDR) - server certificates (per back-end server) - PROXY protocol to preserve info on the requesting client
WireGuard mesh keeps your home AI claw off the public internet entirely.
Rust edge engine handles SNI interception and dynamic SSL without DevOps overhead.
Reproducible builds across the entire stack—rare for consumer IoT security.
Reproducible builds across entire stack with E2E encryption, unlike Ring or Nest.
Useful article, but this is content not a product — standard leak tests exist everywhere.
Auto-generated tokens block the 175k exposed Ollama servers found online.