GuidesFiles, photos and homeHome Assistant on a server

Run Home Assistant with rootless Podman

Home Assistant on Debian 13 in rootless Podman under a user of its own behind Caddy, reachable from anywhere with its app, with electricity prices from Nord Pool, bans after failed logins, and your home's devices reached over a VPN.

Tested on Home Assistant 2026.9.3 on Debian 13 (trixie) on a Melonslab server Updated September 26, 2026

Recommended server for this guide

VC-S Micro · 2 vCPU · 8 GB Memory · 250 GB Storage

Month to month, no lock-in 7-day money-back guarantee

€7.99/mo

Deploy now
On this page

What you will set up

Home Assistant runs your smart home: it shows your devices in one place, and automations make them act on their own, such as charging the car when electricity is cheapest. On a server, Home Assistant is always on and reachable from anywhere, with no port opened at home.

Here it runs as a container under a user of its own called homeassistant, behind Caddy from the Podman guide.

A server is not in your home, so Home Assistant cannot find your devices by itself there. What works on a server:

  • integrations that talk to services on the internet, such as Nord Pool's electricity prices, weather, and many cloud-connected devices;
  • Home Assistant's app on your phone, from anywhere;
  • devices at home reached over a VPN, such as WireGuard or Headscale, or that send their data to it themselves.

Every step below was run on a Melonslab server with Debian 13:

  • Home Assistant 2026.9.3 was set up over an SSH tunnel, and then worked through Caddy once it trusted it.
  • Nord Pool showed the electricity prices for SE3 in SEK per kWh.
  • Five wrong passwords through Caddy banned the visitor's real address.
  • Everything came back by itself after a reboot.

Home Assistant used about 250 MB of memory.

Before you start

You need:

  • a server set up as in the Podman guide, with Caddy running;
  • an A record and an AAAA record for home.example.com pointing at your server;
  • SSH access to the server from your computer, which step 4 uses.

The examples use home.example.com for Home Assistant and 203.0.113.10 for your server's IPv4 address, which ip -brief address show eth0 shows. Replace them throughout.

1. Create the user

As root:

useradd -m -s /bin/bash homeassistant
loginctl enable-linger homeassistant
machinectl shell homeassistant@

2. Describe the container

mkdir -p ~/.config/containers/systemd ~/homeassistant

Create ~/.config/containers/systemd/homeassistant.container:

[Unit]
Description=Home Assistant

[Container]
ContainerName=homeassistant
Image=ghcr.io/home-assistant/home-assistant:stable
Volume=%h/homeassistant:/config
Environment=TZ=Europe/Stockholm
# Only Caddy, on this server, can reach Home Assistant: the port is not open to the internet.
PublishPort=127.0.0.1:8099:8123
AutoUpdate=registry

[Service]
Restart=always

[Install]
WantedBy=default.target

Home Assistant keeps everything in ~/homeassistant: its settings, its history and its database. Start it:

systemctl --user daemon-reload
systemctl --user start homeassistant
systemctl --user enable --now podman-auto-update.timer

3. Put Caddy in front

Go back to root with exit, switch to machinectl shell caddy@, and add this block at the end of ~/Caddyfile:

home.example.com {
    reverse_proxy 127.0.0.1:8099
}

Restart Caddy with systemctl --user restart caddy. Until step 5 is done, https://home.example.com answers 400: Bad Request: Home Assistant refuses requests from a proxy it has not been told to trust.

4. Set it up over an SSH tunnel

On your own computer, open a tunnel to Home Assistant's port on the server, and keep it open:

ssh -L 8123:127.0.0.1:8099 root@203.0.113.10

Then open http://localhost:8123 in your browser. That goes straight to Home Assistant, not through Caddy. Choose Create my smart home:

  • Create your account, with Name, Username, Password and Confirm password, and choose Create account.
  • Set your Home location: search for your address. Home Assistant stores it, and uses it for sunrise, weather and similar.
  • Choose your Country, then what, if anything, to share with Home Assistant's developers, and Finish.

5. Let it trust Caddy

Still over the tunnel, open Settings, System, Network. Under HTTP server:

  • Open Reverse proxy, turn on Trust X-Forwarded-For, choose Add Trusted proxies, and enter 203.0.113.10/32, your server's own IPv4 address, which Caddy's connections come from.
  • Open IP banning. Enable IP banning is on already: set Login attempts before ban to 5.
  • Choose Save.

Home Assistant restarts. Reload the page: it shows Confirm new HTTP server configuration, with the changed settings. Choose Confirm. If you do not confirm within five minutes, Home Assistant puts the old settings back, a safety net in case new settings made it unreachable.

Now close the tunnel, and use https://home.example.com. Older guides put these settings in configuration.yaml under http:. Since 2026, Home Assistant reads them from there only once, at the first start, and ignores them afterwards.

6. Secure your account

With IP banning, an address that gets the password wrong five times in a row is banned until you lift the ban. Also turn on a second factor: open your profile, at the bottom left, then Security, and under Multi-factor authentication modules, choose Enable next to Authenticator app.

7. Add integrations

Open Settings, Devices & services, and choose Add integration. Some that work well on a server:

  • Nord Pool, the electricity prices where you live: pick your area, such as Sweden 3, and SEK. You get the current and next price, and the day's lowest and highest, to use in automations.
  • A weather forecast for your home location, such as from the Norwegian Meteorological Institute.
  • The integrations for your electricity company, car, heat pump or other devices that are connected to the internet.

8. Use the app

Install Home Assistant's app on your phone. It finds no server by itself, so choose to enter the address, https://home.example.com, and log in. The app shows your dashboards, sends notifications from your automations, and can report your phone's location, so that Home Assistant knows when you are home.

9. Reach your devices at home

Devices that only work on your home network need a way to reach the server:

  • Connect your home router, or a small computer at home, to the server with WireGuard or Headscale. Home Assistant then reaches the devices at their addresses at home.
  • Or have devices send their data to Home Assistant themselves, for example over MQTT, which Home Assistant's documentation covers.

Home Assistant cannot discover devices by itself on a server, and its log says Cannot watch for dhcp packets: that is expected in a container, and harmless.

10. Keep it up to date

The timer from step 2 updates Home Assistant every day. The stable tag gets each release, and a new version comes out every month, with release notes that list what changed. Back up first if you want to be able to go back.

11. Back up

As homeassistant:

mkdir -p ~/backup
systemctl --user stop homeassistant
tar -czf ~/backup/homeassistant.tar.gz -C ~ homeassistant
systemctl --user start homeassistant

That saves your settings, automations, history and accounts. Copy ~/backup to another machine, and keep it private. Home Assistant also has its own backups, under Settings, System, Backups.

Troubleshooting

https://home.example.com answers 400: Bad Request. Home Assistant does not trust Caddy, and its log, podman logs homeassistant, says A request from a reverse proxy was received from 203.0.113.10, but your HTTP integration is not set-up for reverse proxies. Do step 5 over the tunnel from step 4.

The settings from step 5 went back after a few minutes. The log says Pending HTTP config was not confirmed within 0:05:00. Do step 5 again, and choose Confirm after the restart.

Home Assistant answers 403: Forbidden. Your address has been banned. As homeassistant, delete ~/homeassistant/ip_bans.yaml, or just your address in it, and run systemctl --user restart homeassistant.

Run it on your own server

VC-S Micro

€7.99/mo

vCPU
2
Memory
8 GB
Storage
250 GB
Transfer
10 TB
Standard
HDD · RAID 10
  • Full root access
  • Native /64 IPv6
  • RAID-protected storage
  • Malmö, Sweden
  • Month to month, no lock-in
  • 7-day money-back guarantee
All guides