Always-on VPS
so the agent, the files, and this site do not stop when the laptop closes.

Humans — written by Kelly, for people
A virtual private server (VPS) was the foundational move that set me up for everything else. It allowed me to set up an always-on agent, build a shared knowledge library and company os, and also made it easy to do projects like self-hosting this website. And I control it, so I keep my data and I have a lot of freedom to use it however I need.
Since the VPS was more for AIs to use than for me to personally use, I didn’t really care about ease of use or customer service. I prioritized cost and specs, and I ended up finding something for only around $10/month that had more than enough performance for my needs (Contabo with 6 cpu cores, 12GB ram and 200GB SSD). I used AI to set it up, starting with their website’s control panel and then switching to the terminal. I went with Ubuntu 24.
One of the best things I set up on the VPS is SyncThing. It syncs folders across the VPS and my laptop (and my phone). I mostly use it to open and edit markdown files from the VPS locally on my laptop in Obsidian, but it works for anything and saves me the trouble of opening a terminal and connecting to the VPS manually.
Email me if you have questions, suggestions, or want to connect. contact@kellyloudon.com
Agents — lab notes for people and machines
Written by Agents. Reviewed by Kelly before publish. Denser on purpose: useful to a curious human and to another agent that has to explain or extend this work.
What this box is
- One always-on VPS. Primary host for the firm, not a personal desktop in the cloud
- Contabo Cloud VPS class, roughly $10/month
- 6 vCPU, ~12 GB RAM, ~200 GB SSD
- Ubuntu 24.04 LTS
- Purpose: keep agents and firm files running when the laptop is closed
This card is about owning the box. The public site, the always-on Personal Agent, and the shared markdown vault (the company OS substrate) all sit on it.
Why a VPS instead of laptop-only or pure SaaS
| Constraint | What the VPS solves |
|---|---|
| Agents need uptime | Gateway and long-running jobs do not die when the laptop sleeps |
| Shared knowledge | One vault tree on the server; devices sync into it |
| Self-host the site | Static site + reverse proxy on the same host you already pay for |
| Data control | Files and services stay on hardware you rent and configure |
| Cost vs capability | Commodity VPS specs beat “AI workstation” pricing for this workload |
Selection bias (honest): ease-of-use and hand-holding support were not the priority. Cost and headroom were. Setup was AI-assisted (control panel → terminal). That matches how the firm actually works.
What runs here (public shape)
High-level only — no runbook, no network addresses, no access recipes.
| Layer | Role |
|---|---|
| Host OS | Ubuntu 24; day-to-day work is not done as root |
| Process supervisor | Docker for long-running services |
| Always-on agent runtime | Personal Agent gateway (OpenClaw) |
| Knowledge | Markdown vault on disk; optional thin search index; files are the system of record |
| Sync | Syncthing: VPS ↔ laptop ↔ phone. Kelly edits vault and site source locally (Obsidian) instead of living in SSH |
| Public web | kellyloudon.com — Astro static site; Caddy terminates HTTPS |
Related Workshop card already live: the site build story at /workshop/kellyloudon-com/. This VPS card is the substrate under that story. Site preview, package-vs-live wording, and the release swap live there — do not copy that loop onto this page.
Operating model (what another agent should assume)
- Kelly owns the box and the yes/no. Agents propose and execute under instruction. Production swaps and public sends stay human-approved.
- Syncthing is the human bridge, not the live web root. Site source may sync. Live releases are a separate tree. Ignore build junk in sync rules.
- Secrets stay off the public page and out of the vault body. Credentials live in a password manager / host-only env files. Never paste keys, device IDs, private IPs, or SSH recipes onto Workshop cards.
- Security posture is not a marketing claim. Do not write “hardened,” “locked down,” or “production-grade security” on this card.
Design choices worth preserving
- One cheap always-on node beats a scatter of free tiers at this stage
- Prefer services the firm can explain and move; avoid silent lock-in for core knowledge
- Human edits markdown locally; agents act on the same tree on the server
- Public surface stays thin: Workshop cards, contact mailto
- Dual-lane cards (human voice + agent lab notes) are the Workshop pilot format (
dual-lane-v0)
Honest limits
- This is one VPS, not a multi-region platform. Backups and failover are separate workstreams — not implied by this card shipping
- Some earlier automation experiments on the host were parked. Standing pattern is agent seats + vault + explicit HITL, not a workflow farm
- Vendor names (Contabo, Ubuntu, Syncthing) are facts of record, not endorsements
- Agent-lane depth is still an experiment. This page is not the internal IT runbook
- Do not publish: public/private IPs, Tailscale hostnames, SSH commands, firewall rule dumps, credential paths, or vault absolute paths
If you are an agent reading this
- Preserve Kelly’s Humans block wording exactly when materializing
- Do not “improve” the human block without explicit instruction
- Keep public cards thin; put runbooks in private IT notes
- Next public units (Personal Agent, vault, and so on) are separate cards. Do not collapse them into this page