Where AI agents operate your apps. Securely and reliably.
PaaSbox is a suite of tools and services for AI-assisted application deployment and operations on Hetzner, on servers you rent yourself. Today it is a set of open components, being prepared for publication, and one paid product, PaaSbox Clusters: software as a service that creates and maintains small, isolated k3s clusters in your own Hetzner project, for production and non-production. It ran end to end in a lab and is not bookable yet.
The product line, in order
- 1Open componentsFreeApache-2.0 · the node images published, the rest being preparedIn progress
- 2PaaSbox Clusters€29/monthincl. VAT · SaaS · single node · ran in a lab, not bookable yetIn progress
- 3ownpaaslab environment and control panel, laterPlanned
- 4Cloud Viewerthe app is finished; pairing with the portalIn progress
Built runs end to end in a lab. In progress is started, not finished. Planned is designed, not built.
What it is
What PaaSbox is
Every claim on this page carries its status. Built runs end to end in a lab on a real cluster, not released. In progress is started, not finished. Planned is designed, not built.
Open componentsIn progress
The building blocks for Kubernetes on Hetzner with Cluster API and k3s, the platform on top, the PaaS layer (App, ManagedPostgres, ManagedValkey), the catalog and the guardrails. Built and measured; Apache-2.0. The repositories are being prepared and go public in waves; the node images are already published.
PaaSbox ClustersIn progress
Software as a service for k3s clusters in your own Hetzner project, control plane included: the portal, the agent on the node, signed releases and the add-ons. You own the server, the cluster and its uptime. A planned €29 incl. VAT per cluster per month, single node. It ran end to end in a lab on 2026-10-10; not bookable yet.
pbx-agent on your nodeBuilt
A small program on the server, not an AI model. It listens on no port, calls the portal over outbound HTTPS and runs a fixed list of operations, never arbitrary commands. In a lab it ran every one of them on real Hetzner servers.
Upgrades with a way backBuilt
After a snapshot, at once or in your maintenance window. In a lab an upgrade replaced the node’s image in place in 83 seconds; the server rebooted, and the API was down for 34 seconds. Waiting for the window, and booting the previous image again when the node does not come back healthy, are In progress.
Snapshots to your bucketBuilt
Snapshots of the cluster’s state go from the node straight to your own S3 bucket, never through the portal. In a lab a restore in place took 160 seconds, with the data in the volumes intact. A restore onto a new server is Planned.
DNS names for your clustersBuilt
A free name under <team>.paasbox.app for your clusters, with the records Let’s Encrypt needs, after one sign-in. The API is built; the service opens with the components’ first release.
How it works
How PaaSbox Clusters works
Built In a lab, on real Hetzner servers, on 2026-10-10. The portal creates the cluster in your Hetzner project with your API token. The agent on the node opens every connection to the portal; the portal never connects to your server. Snapshots go from the node straight to your bucket.
You keep root on the server, the cluster and its uptime. It is fit for production and non-production; production here means one node, with three things accepted: there is no SLA, an upgrade reboots the node (34 seconds of API downtime in the lab), and a broken node is answered by a restore from a snapshot or a rebuild. If the portal is unreachable, the cluster keeps running and the scheduled snapshots continue. Every part and its status →
Security
What the portal holds
Built In a lab, as built for PaaSbox Clusters; the portal is not live yet.
Only what it needs
Your Hetzner token, the k3s tokens and the keys of your snapshot bucket, encrypted. Never admin kubeconfigs, the agent’s private keys, snapshot contents or your workloads’ data.
No command channel
The agent runs a fixed list of operations: snapshot, restore, upgrade, kubeconfigs, key rotation, and diagnostics with your consent for that one request. Nothing else can be sent to it.
Kubeconfigs only you can read
Temporary kubeconfigs, valid for 10 minutes to 24 hours, made on the node and encrypted to a key your browser makes. The portal passes them on and cannot read them.
Signed releases
The agent installs only versions named in a release manifest signed with a key kept offline, and goes back to the previous version if a new one does not reach the portal within 10 minutes. In a lab a tampered release was refused; the way back has not fired on a real server yet.
In a labBuilt
Agents already operate four apps
In a lab, an agent on a small model (Claude Haiku) operated four open-source apps, Vaultwarden, Listmonk, Umami and Forgejo, through each app’s operate skill. It acts through typed actions served as MCP tools: destructive ones are refused unless allowed, an approval is asked for where the catalog entry wants one, and every call lands in an audit log.
- 12 recorded runs for $0.058 in model spend
- The lab round of 2026-10-09: Vaultwarden, Listmonk and Umami passed every lab row they have; Forgejo passed 12 of 13, because its alert row needs the platform’s metrics
- Backups with a tested restore and an upgrade with a rollback for each of the four, with the data checked
“In a lab” means virtual machines on a Mac running a real Kubernetes cluster, not production. A read proxy that redacts what agents read is In progress; an operations agent that may do only what a person on call may do is Planned. I build PaaSbox with agents too; I decide, and I am the only one who touches a live system.
In progress For PaaSbox Clusters, a REST API and MCP tools are being built now. With them an agent can read your clusters, their health, snapshots and operations, take a snapshot, schedule an upgrade, switch add-ons on and off, and get a kubeconfig sealed to its own key. A destructive operation needs an explicit confirmation, and every call is audited. What agents do today →
apiVersion: catalog.paasbox.com/v1alpha1kind: Suitemetadata: { name: team }spec: apps: umami: {} listmonk: {} forgejo: {} vaultwarden: {} bindings: umami.db: { provider: cnpg-shared } forgejo.db: { provider: cnpg-shared } forgejo.cache: { provider: valkey } vaultwarden.db: provider: cnpg-dedicated params: { size: 1Gi }The approach
Small, isolated clusters
How I work with agents on DevOps, and what PaaSbox Clusters is built for: an agent’s change is tested in a cluster of its own before it reaches anything that matters, and every stage and every app gets a small cluster instead of a share of a big one.
Test in isolated clusters
Build a cluster for the test, run extensive tests in it, delete it. A test that breaks something breaks only that cluster. In a lab a PaaSbox cluster was created in 2 minutes 46 seconds and deleted in 14.
One cluster per stage and per app
Several small single-node clusters, one per stage and per app, instead of one large highly available cluster that stages and apps share. A failed upgrade or a runaway test then reaches one stage of one app.
Self-contained environments
Kubernetes stands up an app with its database, certificates and configuration the same way every time, so an environment can be created, tested and thrown away, by you or by an agent.
Local labsPlanned
The same approach on your own machine: ownpaas is to bring self-contained Kubernetes labs to your computer, so a test can run before a Hetzner server is involved.
Offers
What it costs
The open components are free. PaaSbox Clusters is the one paid product, software as a service at a planned price, and cannot be booked yet.
Open componentsIn progress
Free
The building blocks, the catalog and the guardrails, to run yourself.
- Clusters on Hetzner with Cluster API and k3s
- The platform and the PaaS layer
- The catalog format, the lab rows and four golden entries
- The Gardener extensions for Hetzner, for a landscape you run yourself
- Apache-2.0; the pool manager BSL-1.1
Being prepared for publication; the node images are already published.
PaaSbox ClustersIn progress
€29per cluster per month, incl. VAT
Outside the EU: $29 plus applicable sales tax
single node · planned price
Not bookable yet
Software as a service for one k3s cluster on one server in your own Hetzner project, kept current by the portal.
- For production and non-production, on one node
- Created in your project with your Hetzner API token
- k3s and the node's operating system upgraded in your maintenance window, after a snapshot
- Snapshots to your own S3 bucket, and restore
- Temporary kubeconfigs and a short list of curated add-ons
- Detach at any time; the cluster keeps running
Paddle, the merchant of record, issues the invoice. Hetzner bills you directly for the server. Clusters with three servers come later, with their own price.
The price of PaaSbox Clusters includes VAT where it applies; outside the EU it is $29 plus applicable sales tax. Paddle, the merchant of record, issues the invoice. A setup or consulting is on request. Pricing has the details.
Outlook
What comes next
In progress or designed, not released. No dates are promised.
Three servers per clusterPlanned
PaaSbox Clusters opens with one server per cluster. Clusters with three servers come later, with their own price.
Cloud Viewer with your clustersIn progress
Cloud Viewer, my app for costs, logs, metrics, uptime checks and alerts on Hetzner, is finished. Paired with the portal, it is to show your clusters’ state, read-only, and push an alert when a snapshot or an upgrade fails or a node stops reporting. Both sides are built; the pairing has not run end to end.
ownpaasPlanned
ownpaas will be sold later as a lab environment and control panel.
Agents that operate your appsPlanned
An operations agent that may do only what a person on call may do: it reads through a redacting proxy, acts through typed actions and waits for a person’s approval where it counts. It runs PaaSbox’s own clusters first; a managed service follows.
Open and closed
The mechanism is open
Whoever lets an agent touch their systems wants to read the guardrails and rerun the proofs, so those are open: the building blocks, the catalog format, the action runner, the read proxy, the harness and the measured results. What costs work every month is sold: PaaSbox Clusters as software as a service, and later the curated catalog at breadth and operations. Every component and its licence →