What you will set up
Home Assistant runs your smart home: it shows your devices in one place, and automations make them act on their own, such as charging the car when electricity is cheapest. On a server, Home Assistant is always on and reachable from anywhere, with no port opened at home.
Here it runs as a container under a user of its own called homeassistant, behind Caddy from the Podman guide.
A server is not in your home, so Home Assistant cannot find your devices by itself there. What works on a server:
- integrations that talk to services on the internet, such as Nord Pool's electricity prices, weather, and many cloud-connected devices;
- Home Assistant's app on your phone, from anywhere;
- devices at home reached over a VPN, such as WireGuard or Headscale, or that send their data to it themselves.
Every step below was run on a Melonslab server with Debian 13:
- Home Assistant 2026.9.3 was set up over an SSH tunnel, and then worked through Caddy once it trusted it.
- Nord Pool showed the electricity prices for SE3 in SEK per kWh.
- Five wrong passwords through Caddy banned the visitor's real address.
- Everything came back by itself after a reboot.
Home Assistant used about 250 MB of memory.
Before you start
You need:
- a server set up as in the Podman guide, with Caddy running;
- an A record and an AAAA record for
home.example.compointing at your server; - SSH access to the server from your computer, which step 4 uses.
The examples use home.example.com for Home Assistant and 203.0.113.10 for your server's IPv4 address, which ip -brief address show eth0 shows. Replace them throughout.
1. Create the user
As root:
useradd -m -s /bin/bash homeassistant
loginctl enable-linger homeassistant
machinectl shell homeassistant@
2. Describe the container
mkdir -p ~/.config/containers/systemd ~/homeassistant
Create ~/.config/containers/systemd/homeassistant.container:
[Unit]
Description=Home Assistant
[Container]
ContainerName=homeassistant
Image=ghcr.io/home-assistant/home-assistant:stable
Volume=%h/homeassistant:/config
Environment=TZ=Europe/Stockholm
# Only Caddy, on this server, can reach Home Assistant: the port is not open to the internet.
PublishPort=127.0.0.1:8099:8123
AutoUpdate=registry
[Service]
Restart=always
[Install]
WantedBy=default.target
Home Assistant keeps everything in ~/homeassistant: its settings, its history and its database. Start it:
systemctl --user daemon-reload
systemctl --user start homeassistant
systemctl --user enable --now podman-auto-update.timer
3. Put Caddy in front
Go back to root with exit, switch to machinectl shell caddy@, and add this block at the end of ~/Caddyfile:
home.example.com {
reverse_proxy 127.0.0.1:8099
}
Restart Caddy with systemctl --user restart caddy. Until step 5 is done, https://home.example.com answers 400: Bad Request: Home Assistant refuses requests from a proxy it has not been told to trust.
4. Set it up over an SSH tunnel
On your own computer, open a tunnel to Home Assistant's port on the server, and keep it open:
ssh -L 8123:127.0.0.1:8099 root@203.0.113.10
Then open http://localhost:8123 in your browser. That goes straight to Home Assistant, not through Caddy. Choose Create my smart home:
- Create your account, with Name, Username, Password and Confirm password, and choose Create account.
- Set your Home location: search for your address. Home Assistant stores it, and uses it for sunrise, weather and similar.
- Choose your Country, then what, if anything, to share with Home Assistant's developers, and Finish.
5. Let it trust Caddy
Still over the tunnel, open Settings, System, Network. Under HTTP server:
- Open Reverse proxy, turn on Trust X-Forwarded-For, choose Add Trusted proxies, and enter
203.0.113.10/32, your server's own IPv4 address, which Caddy's connections come from. - Open IP banning. Enable IP banning is on already: set Login attempts before ban to
5. - Choose Save.
Home Assistant restarts. Reload the page: it shows Confirm new HTTP server configuration, with the changed settings. Choose Confirm. If you do not confirm within five minutes, Home Assistant puts the old settings back, a safety net in case new settings made it unreachable.
Now close the tunnel, and use https://home.example.com. Older guides put these settings in configuration.yaml under http:. Since 2026, Home Assistant reads them from there only once, at the first start, and ignores them afterwards.
6. Secure your account
With IP banning, an address that gets the password wrong five times in a row is banned until you lift the ban. Also turn on a second factor: open your profile, at the bottom left, then Security, and under Multi-factor authentication modules, choose Enable next to Authenticator app.
7. Add integrations
Open Settings, Devices & services, and choose Add integration. Some that work well on a server:
- Nord Pool, the electricity prices where you live: pick your area, such as
Sweden 3, andSEK. You get the current and next price, and the day's lowest and highest, to use in automations. - A weather forecast for your home location, such as from the Norwegian Meteorological Institute.
- The integrations for your electricity company, car, heat pump or other devices that are connected to the internet.
8. Use the app
Install Home Assistant's app on your phone. It finds no server by itself, so choose to enter the address, https://home.example.com, and log in. The app shows your dashboards, sends notifications from your automations, and can report your phone's location, so that Home Assistant knows when you are home.
9. Reach your devices at home
Devices that only work on your home network need a way to reach the server:
- Connect your home router, or a small computer at home, to the server with WireGuard or Headscale. Home Assistant then reaches the devices at their addresses at home.
- Or have devices send their data to Home Assistant themselves, for example over MQTT, which Home Assistant's documentation covers.
Home Assistant cannot discover devices by itself on a server, and its log says Cannot watch for dhcp packets: that is expected in a container, and harmless.
10. Keep it up to date
The timer from step 2 updates Home Assistant every day. The stable tag gets each release, and a new version comes out every month, with release notes that list what changed. Back up first if you want to be able to go back.
11. Back up
As homeassistant:
mkdir -p ~/backup
systemctl --user stop homeassistant
tar -czf ~/backup/homeassistant.tar.gz -C ~ homeassistant
systemctl --user start homeassistant
That saves your settings, automations, history and accounts. Copy ~/backup to another machine, and keep it private. Home Assistant also has its own backups, under Settings, System, Backups.
Troubleshooting
https://home.example.com answers 400: Bad Request. Home Assistant does not trust Caddy, and its log, podman logs homeassistant, says A request from a reverse proxy was received from 203.0.113.10, but your HTTP integration is not set-up for reverse proxies. Do step 5 over the tunnel from step 4.
The settings from step 5 went back after a few minutes. The log says Pending HTTP config was not confirmed within 0:05:00. Do step 5 again, and choose Confirm after the restart.
Home Assistant answers 403: Forbidden. Your address has been banned. As homeassistant, delete ~/homeassistant/ip_bans.yaml, or just your address in it, and run systemctl --user restart homeassistant.