Features
What Hostwarden does, with example prompts. A feature that exists only in Claude Code says so; in other tools the same rules reach the agent as instructions.
Knowing your hosts
- Onboarding a host — detects the OS on first connection and builds the host's memory.
- Names and aliases — recognizes when several DNS names point at the same server.
- A host's network — the network profile, VPNs, and out-of-band access recorded for a host.
Supported systems
- Supported systems — the OS families, appliances, platforms, and roles Hostwarden tells apart.
- Appliances — special handling for Proxmox VE, OPNsense, Synology DSM, and other appliances.
- WSL and workstations — how a WSL instance or a workstation is treated differently from a server.
- Windows Server — read-only housekeeping and security reporting over OpenSSH.
- Local administration — runs commands directly on the machine Hostwarden runs on, without SSH.
Checking servers
- Housekeeping checks — routine health inspection: disk, updates, services, hardware, and more.
- Security audit — checks SSH hardening, firewall posture, accounts, and other settings.
- Server baseline — what every server is expected to have, and how to bring one up to it.
- Disks, ZFS and btrfs — tracks disks by serial and rates ZFS and btrfs settings.
- Fleet audit — compares key policies across every server Hostwarden knows about.
Changing servers
- Plan mode — plans a complex or unfamiliar change before touching anything.
- Configuration management — works alongside Ansible, Puppet, Chef, and similar tools.
- Services in containers — changes the file that recreates a container, not the running one.
- Accounts — creates and removes accounts, groups, and sudo rules the way each host manages them.
- Files Hostwarden deploys — keeps a master copy of every script and config file it writes.
- Renaming a host — finds everywhere the old name is used before renaming a host.
- Language runtimes and deploy users — installs language runtimes and sets up restricted CI/CD accounts.
- Email reports — sends ad-hoc text or files about a managed server by email.
Many servers
- One task on many hosts — runs one question, check, or change across several servers at once.
- What a reboot would hit — answers from memory what a reboot or restart would take down.
- Planning a maintenance window — plans a disruptive step ahead, with who to tell and by when.
- Fleet read — gives an operations host a key limited to read-only checks.
Guests and hypervisors
- Hypervisors and their guests — lists and reads inside the guests of every hypervisor it manages.
- Changing a guest — prefers a snapshot before a risky change, and asks before stop or delete.
- New guests — creates VMs and containers with the server baseline applied at first boot.
- Installing an operating system — replaces an OS, sets up dual-boot, and manages EFI boot entries.
SSH access
- Host keys — checks every server's SSH host key against the workspace's known_hosts file.
- SSH certificates and your CA — audits an existing SSH CA and uses it wherever it sets up SSH trust.
- Reaching a host — configures SSH options, jump hosts, and alternative ports for each server.
The safety rules behind all of this are in Safety at a glance. What Hostwarden remembers between sessions, and how, is in How Hostwarden remembers.