I installed Proxmox on a Hetzner dedicated server without touching the installer. No KVM console. No ISO mounting. No clicking through screens at 2 AM. An AI agent did it straight from the Hetzner Rescue system. Same scripts and checks you could run by hand. The difference is that it never gets bored and never skips a step. Here's the part that matters. The agent stops and waits for my approval before it erases a single disk. ⚠️ It verifies every step before moving on. And it leaves a written record of what passed, so I can audit the whole install afterwards. That's the standard I hold for client infrastructure at Webnestify. AI as an accelerator, not a replacement for judgment. The human still owns the dangerous decisions. Everything the agent ran is in the open-source repo, link in the comments. Read it before you trust it. Episode 2 of Self-Hosting 101 is live. 22 minutes, covering why Proxmox, which Hetzner box to order, the firewall setup most people get wrong, and the full install start to finish. 🔥 If you run infrastructure for an agency and want someone to own this layer for you, that's what I do. Reach out. Would you let an AI agent wipe a production disk, even with a manual approval gate? Links in the comments. #proxmox #hetzner #selfhosting #homelab #zfs #aiagents #baremetal #devops #webnestify
Webnestify s.r.o.
IT Services and IT Consulting
Bratislava-Rača, Bratislava 147 followers
Managed hosting, cloud, and cybersecurity for agencies. Founder's number included.
About us
Webnestify provides premium managed hosting, cloud infrastructure, and cybersecurity for agencies and growing businesses. If you are tired of juggling vendors and waiting hours for automated replies, we are here to reset the standard. We handle the entire technical side of your business so you can focus on yours. We operate on one strict rule: No support tickets. When you need something, you message the founder directly on Signal, WhatsApp, or email. We run your infrastructure, security, and automation as a single managed partnership. Stop fighting tech debt and reclaim your time.
- Website
-
https://webnestify.cloud
External link for Webnestify s.r.o.
- Industry
- IT Services and IT Consulting
- Company size
- 2-10 employees
- Headquarters
- Bratislava-Rača, Bratislava
- Type
- Privately Held
- Founded
- 2021
Locations
-
Primary
Get directions
Karpatské námestie 7770
10a
Bratislava-Rača, Bratislava 831 06, SK
Updates
-
If you can't restore it, you don't have a backup. This week a customer running xCloud on a Vultr VPS lost every site on their account. The host's disks died, backups were off, no snapshots existed. Support had nothing to give back. I have watched this exact story play out for years, and it is why I run three layers on every client server at Webnestify: 1. Provider snapshots, switched on from day one. Usually 15 to 25% of the instance price. Cheap insurance against a dead host. 2. Panel backups on a separate attached volume, so one broken site can be put back without rolling the whole server. 3. The client's own copy on a different provider. Provider backups die with the provider. Then the step almost nobody does. Once a month I restore one of them onto a fresh server and open the site. If that works, we have a backup. If it does not, we found out on a quiet Tuesday instead of during an outage. Layer one saved a client once. Their panel backup was corrupt and they had none of their own. I restored the server snapshot to a separate box, pulled that one site out, and lost roughly 20 hours of data instead of everything. Backups and tested restore paths are part of what I set up for agencies at Webnestify. If you are not sure yours would survive a dead disk, reach out. Full article and the podcast episode with Andre are linked below. How often does your team actually test a restore, not just check that the backup job ran? Links in the comments. #backups #disasterrecovery #managedhosting #cloudinfrastructure #agencyinfrastructure #cybersecurity #selfhosting #businesscontinuity #webnestify
-
Docker just removed the paywall from Hardened Images. That changes what I consider the baseline for client infrastructure. Until now, near-zero-CVE, distroless, non-root images with a signed SBOM were enterprise tooling. Today any team can pull them from dhi.io for free. Why it matters if you run an agency or a growing business: 🔐 Fewer CVEs in your containers means fewer emergency patch nights 🔐 No shell in the runtime image means a compromised app has far less to work with 🔐 Signed SBOM and provenance mean you can prove what runs in production At Webnestify I now treat hardened image plus rootless runtime as the default for every stack I manage. Not a premium add-on. The default. The new video walks through the switch and the three gotchas that catch people: distroless build steps, the non-root user, and low ports. If your containers still run stock images on a root Docker daemon, this is the kind of thing I fix for clients. Reach out if you want a second pair of eyes. What is stopping your team from moving to hardened base images today? Links in the comments. #docker #dockerhardenedimages #containersecurity #supplychainsecurity #distroless #rootlessdocker #managedhosting #cybersecurity #webnestify
-
-
Garry Tan's YC keynote nailed the big idea. AI is a new operating regime. Skill files behave like employees. The brain you build is the asset you own, while the model is just rented. From where I sit, running infrastructure for agencies, I see the other half of that story. Most people rushing into AI are not technical. They follow a tutorial that shows every feature and none of the security. Broad access to the inbox. API keys in plain sight. No scoped permissions. One malicious email or one leaked key is enough. I have watched real businesses do this damage to themselves. And when an agency's client gets burned, the client blames the agency and leaves. Here is the opportunity I keep pointing agencies toward. Stop selling only web design. Start building and managing AI workflows for your clients. A website is a one-off invoice. A managed second brain is recurring, and much harder to churn out of. At Webnestify I run my own second-brain system in production, and I help agencies stand up the same for their customers, with the security boundary the tutorials skip. If your agency wants to make that shift, I am happy to talk. 🔐 If you run an agency, what is stopping you from selling AI workflows instead of just websites? Links in the comments 👇 #AI #AIworkflows #digitalagency #managedservices #cybersecurity #automation #webnestify
-
-
Renting a VPS and adding a SaaS control panel on top is not managed hosting. The panel manages your websites. The server stays your problem. OS updates, firewall, backups, incident response. All yours. Most people find out the hard way. The site goes down, they open a ticket, and the vendor's honest answer is "that's outside our scope, it's your server." ⚠️ And it gets worse. That panel installed an agent with root access on your box, connected to the vendor's cloud around the clock. You carry all the liability. They hold standing access. If the vendor gets breached, your server is one hop away. I wrote a full breakdown on Webnestify Insights: - The responsibility gap nobody reads in the contract - Why the always-on root agent is their access and your risk - Why "AI will manage it for me" is the same illusion with a new coat of paint - Coolify and Dokploy, the open-source way to own the serverless workflow on your own hardware - And honestly, when the cloud is the right call 🔐 Someone has to actually own server management. Either you learn it, and everything I do is public, no gatekeeping. Or you delegate it to someone accountable to you. That is exactly what I do at Webnestify for agencies around the world. When a panel-managed server goes down at 2am, who do you think is responsible: you or the vendor? 👉 Links in the comments. #DedicatedHosting #ManagedHosting #SelfHosting #CyberSecurity #CloudInfrastructure #OpenSource #WebHosting #AgencyGrowth #webnestify
-
-
The docker group is the most common quiet root backdoor I find on client servers. Nobody puts it there maliciously. Someone got tired of typing sudo, added themselves to the group, and moved on. From that moment, anyone in that group can mount the host filesystem into a container and own the machine. No password, no exploit, no trace in the auth log. At Webnestify I switched every box I manage to rootless Docker. The daemon runs as an unprivileged user, containers run as that user, and a container escape lands as a nobody instead of root. The reason most people skip it: the manual setup has six fiddly steps, and missing one leaves a daemon that silently refuses to start. So I automated it. One command provisions a dedicated user, writes the subordinate UID maps, enables lingering, installs a pinned SHA256-verified Docker, and proves it works with a hello-world check. It refuses system accounts and docker-group members, and it fails closed on hosts that block rootless. The script is open source. This is the standard I hold for client infrastructure. If your servers have never had that once-over, that is exactly the kind of work I take on. Is rootless Docker part of your hardening baseline yet, or still on the someday list? Links in the comments. #docker #rootlessdocker #linux #cybersecurity #serversecurity #devops #opensource #managedhosting
-
-
One email. That is all it took to rob a business owner who did everything a tutorial told him to do. I investigated the breach. He had connected an AI agent to his inbox and handed it access to his other tools, exactly the way the videos showed. Overnight, an email in his spam folder addressed "To Hermes agent" told the agent to run a command. It did. His API keys and session cookies were gone before he woke up. He was not careless. He was carrying the cognitive load that every business owner carries right now. The tools change constantly. Every channel adds more hype and more "you have to try this." Separating the safe path from the dangerous one has become a second job on top of the one you already have. That gap is exactly where I work. At Webnestify, before a client connects a single AI tool, I scope the permissions, keep the part that reads untrusted content away from the part that can act, and put a human in front of anything irreversible. The agent stays useful. It just stops being a liability. AI agents can take real work off your plate. They should not hand your business to a stranger to do it. If your team is wiring AI into your operations, who is checking what a confused agent can actually reach? Links in the comments 👇 #AISecurity #PromptInjection #CyberSecurity #ManagedInfrastructure #AIagents #InfoSec #BusinessAutomation #Webnestify #HermesAgent #Hermes #OpenClaw
-
-
Search "Contabo" or "OVHcloud" and you'll drown in angry threads. CPU steal. Slow support tickets. A datacenter fire that took 30,000 servers with it. The reviews read like a warning label. Here's the thing: most of those complaints are real. And almost all of them are predictable. Cheap hosting runs on three trades. Dense nodes, so you get a noisy neighbour. Unmanaged support, so your 3am incident is your problem. And you own your backups, because the safety net was never included. But here's the detail that actually changed how I use them. Try to pin down Contabo's uptime guarantee. Their current terms promise 99.9%, but only for network connectivity, with no service credit if they miss it. Meanwhile their own help center still cites an older 95% figure, pointing right back at those same terms. When a host can't give you one straight answer on its own uptime, that's not what I'd bet a client's production on. 🔐 So here's exactly how I use both. Contabo and OVHcloud live on my dev boxes, my staging, and anything I'm just kicking the tyres on. Throwaway environments where a slow ticket or a busy node costs me nothing. For real production, mine or a client's, I reach for something else. That's the whole thing in one line: great value for non-critical work, wrong place to bet a business. The trick isn't avoiding budget hosts. It's matching the provider to the workload, reading the SLA before you sign, and keeping your backups with a different company in a different place. If your infrastructure has outgrown the cheapest line on a pricing page, that's the kind of problem I untangle at Webnestify. When did you last actually read your host's uptime guarantee? Links in the comments 👇 #CloudHosting #Contabo #OVHcloud #VPS #DevOps #SelfHosting #SLA #Backups #Infrastructure
-
-
Data ownership isn't a feature you bolt on later. It's a decision you make at the start. We run AI agents in our workflow, and one question kept coming up: where does the memory live? Most tools answer that with "our servers." We don't love that answer. So we started using cavemem, a memory tool for AI agents that runs fully local. Context stays on our own infrastructure. No third-party account, no external API holding our working notes, nothing leaving the machine. For an agency handling client work, that's not a nice-to-have. It's how you keep your promises on privacy and compliance. You can't lose control of data you never handed over. It's also open source, which means we can audit exactly what it does instead of trusting a marketing page. That's the standard we apply to the tools we build on. Credit to the developers for making something this useful and giving it away for free. The self-hosted ecosystem gets stronger every time someone does. How much of your business data sits on tools you don't actually control? Links in the comments. #DataOwnership #SelfHosted #OpenSource #AIagents #DataPrivacy #Compliance #GDPR #LocalFirst #ManagedHosting
-
One of a kind out there on internet!
Most self-hosting tools ask for root. Mine refuses to run as root. On purpose. For the past 200+ hours I've been building something I genuinely love: a terminal app that makes self-hosting Docker apps simple, safe, and completely sudo-free. It's called wdm — a TUI and CLI for installing, updating, and checking a curated set of Docker Compose self-hosting templates. Safe defaults. Minimal operational friction. Written in the latest Go. The part I'm most proud of: It runs entirely on rootless Docker. No sudo. No root-owned socket. On any fresh Linux server, even one with no Docker installed. It bootstraps a dedicated non-privileged user and sets up your secured Docker apps out of the box. Almost no one touches this. Vaultwarden, Nextcloud, Jellyfin, n8n, Authentik and many more. Running securely, in minutes. This is the work I care about most: educating people and building secure solutions everyone can actually use in daily life. If that resonates, I'd really appreciate a ⭐ — it genuinely helps more people find the project. And if there's an app you'd love to see supported, open an issue with a request. I'm listening. P.S. You can also run this app on any cloud provider like RunCloud xCloud and others. #SelfHosting #Docker #Golang #OpenSource #DevOps #Cybersecurity #Homelab #Linux #admin #foss #pangolin Links in comment.
-