Homelab AI Dev Platform: OpenCode + GitOps for Safer Container Updates

One homelab operator built an AI development platform around OpenCode's webserver mode, gating AI-generated code behind PR reviews and deploying via GitOps. The goal: reduce the manual overhead of maintaining a dozen Docker Compose stacks while keeping unreviewed code off production.
Setup
The platform runs on a simple VM on TrueNAS with basic dev tooling. OpenCode is installed as a systemd unit, exposing a web UI with a built-in terminal, file browser, Git diffs, and Git worktree support for parallel coding sessions. The server gets its own user on the Git server with dedicated SSH keys — it can clone projects and push branches, but cannot push directly to the deploy branch.
The VM has internet access and Git server connectivity, but no network access to the actual services. This minimizes blast radius, allowing the author to grant root access to OpenCode when it needs to install build tools or test dependencies.
Workflow
- Plan the feature or improvement in OpenCode: spec, implementation plan, self-reviews.
- Test or verify changes when possible.
- Iterate with OpenCode on things that need adjustment.
- OpenCode pushes changes to a feature branch.
- Owner opens and merges a PR after review.
- GitOps takes over: Arcane for Docker service changes, GitOps plugin for Home Assistant config, Cloudflare Pages workers for blog updates.
Concrete Wins
The most impactful use case so far: container updates. Previously, the author spent hours per update cycle reading release notes for each service, checking for breaking changes, running updates, and manually verifying services. Now OpenCode produces a summary of release notes in minutes, making version upgrades faster and safer. The AI has also added healthchecks to most containers, speeding up issue detection.
Missing Piece: CI Feedback
The setup lacks CI integration. On GitHub, the author would point a coding agent at Actions logs to diagnose failing tests, linter errors, stack traces, and IaC plan changes. Forgejo (the self-hosted Git server) does not expose job logs through the public API, though undocumented APIs exist. The author considers this the main gap.
Bottom Line
This is a pragmatic, security-conscious homelab AI platform. It lets the owner make infrastructure changes from any device (including phone) without giving AI direct access to production services. The friction of PR review and the sandboxed VM make it safe enough for personal use while highlighting the gap in CI feedback for self-hosted Git servers.
📖 Read the full source: HN AI Agents
👀 See Also

OpenClaw Agent Implements Contextual Reminders with Relationship Nudges
An OpenClaw user built a personal agent system with contextual reminders that trigger based on calendar load, current tasks, and time of day rather than fixed schedules. The system includes an escalation ladder for reminders and uses memory tracking to suggest contacting people based on relationship history.

Graduate Student Uses Claude to Build AI Image Detection Experiment
A graduate student at The New School collaborated with Claude to build a website called InPixelsWeTrust.org that tests whether users can distinguish real photos from AI-generated images in 6 rounds with 10-second decisions.

Developer Builds AI Bookkeeping App with Claude Code
A developer built AICountant, an AI bookkeeping app for freelancers and small businesses, using Claude Code across the stack including Next.js App Router, Prisma with PostgreSQL, and Vercel Blob storage. The app extracts receipt data, converts foreign currencies using historical exchange rates, and organizes everything into a searchable ledger.

Using Claude to Audit Email Systems for Missing User Scenarios
A developer used Claude to analyze their database schema and email triggers, identifying four critical gaps: no follow-up for unverified signups, no acknowledgment for downgrades, no notification for accepted team invitations, and no warnings for approaching plan limits.