Skip to content
AIOctober 7, 20265 min read

🤖 I Run Claude 24/7 on a Small Home Machine and Use It from Telegram

I connected a second copy of my vault to Claude Code running 24/7 in Docker on a small home machine, and I use it from Telegram. The idea and the traps.

📝 Summary

For a while I only used my personal agent, Totty, on my PC. Now a second copy of the same vault (the folder of Markdown notes that works as its memory) lives on a small machine at home, in a Docker container, next to a Claude Code instance that runs 24/7. I reach it from my phone through two doors: Telegram and Remote Control.

In this post I explain what I built, how it works, and which traps I fell into. I'm not an expert in networking or Docker, it's a hobby for me. So this isn't a setup guide, it's the story of a concept that works.


🎯 Why Did I Want This?

When my PC was off, or I was out, and an idea hit me, I couldn't reach my agent. There was already a small machine at home that stays on all the time. The idea was simple: let a copy of Totty's vault live there, let me type from my phone, and let it do the work.

The goal wasn't "do everything remotely". It was smaller and more realistic: take a note, ask a question, draft a blog post, check on the state of my home setup.


🚪 Two Doors: Telegram and Remote Control

I get into the same machine in two different ways:

  • Telegram: Fast and light. I type a message, an answer comes back. While idle, the machine's resource usage is barely visible. The bot only listens to messages coming from my own chat.
  • Remote Control: Claude Code's own remote feature. For longer, deeper work. Permission prompts land straight on my phone and I approve or reject them.

Both look at the same vault, just for different moods. Short questions go to Telegram, long jobs go to Remote Control.


🔄 Two Machines, One Memory

This is the part I thought about the most: the vault now lives in two places. One on the PC, one on the home machine. What happens if both write to the same notes?

I solved it with git:

  • Both sides sync to the same main branch.
  • I don't commit after every reply. That turned the history into a mess. Instead, when things settle down, meaning nobody has touched the files for a while, a single commit is made. One working session, one commit.
  • If I'm in a hurry, I type /senkron in Telegram and it reports the result back to me.
  • If the same line changes in both places, the operation is rolled back and I get a warning. I prefer a visible conflict to something silently breaking.

One more thing: the Totty in the container can't do some jobs (image editing, my project repos). When I ask for something like that, it says "I can't do this, I added it to the PC queue" and leaves a note in a shared queue file. When I sit down at the PC, I pick it up from there.


🔐 An Agent That Sees No Secrets

Leaving an agent on 24/7 means taking seriously where secrets live. The setup I built follows this logic:

  • Claude sees no secrets at all. Secrets stay only with the most privileged user. The Telegram bridge and Claude run as separate users and can't read each other's environment.
  • Anything that needs a secret is a small wrapper. For example, Claude needs to upload an image to my server. There's a single-purpose script for that: it runs as the privileged user, validates its input, does the job, and masks sensitive information in the output. Claude only runs the script. It never sees the key.
  • A read-only look at the router. It can read the state of my home network device but can't change anything. The key it uses is locked to a fixed list of commands.

🧱 The Permission Wall and Not Working Around It

For requests coming from Telegram, Claude can't run any tool that isn't on the allow list. There's nobody to ask "do you approve?", so it's simply denied.

What really interested me was what it does when it's denied. Once it needed to write to a file and didn't have permission. It didn't try to sneak around through another route, it told me what was missing. I added the permission. The real value of a security wall isn't the wall itself, it's the agent stopping and asking when it sees one. I wrote that down as a rule too.


🛠️ What Can It Do for Now?

  • I ask for an image from Telegram, it generates one with Gemini and drops it into the chat.
  • It prepares the share card (og-card) for blog posts.
  • It opens the blog draft in my site's content management system. This post was prepared that way too.
  • It reads and summarizes the state of my home network.
  • It sees what happened on the PC and gives me a "here's what happened while you were away" summary.

🪤 The Traps I Fell Into

  1. "Refused" and "timed out" are not the same thing. If a connection is refused right away, there's a door on the other side but it won't let you in. If there's long silence, packets are getting lost somewhere. The problems behind the two turned out to be completely different. Reading the error message carefully is half of the diagnosis.
  2. Windows ignores file permissions. I tried it first on Windows, and the secrets file showed up in the container with permissions that let everyone read it. If I hadn't measured, I wouldn't have noticed. Lesson: don't trust something you haven't measured.
  3. An environment that looks ready may not be. When I rebuild the container, the remote control session can drop, and messages I write to the old session go nowhere. I made it a habit to open a new session after every rebuild.
  4. Automatic safety layers can stop you too. Claude's own safety check blocked a wrapper that was triggered from outside, once. The reason seemed reasonable, so I approved it manually and moved on.

🚀 Conclusion

On one side there's the Totty on my PC, on the other there's its copy, awake 24/7 on a small machine at home. Between them: git, a shared queue file, and a few narrow bridges. It's all hobby scale, but it really helps in daily life: I can type a blog idea from my phone while walking and find the draft ready when I get home.

More automation is next: scheduled tasks, voice messages, an email summary. I'll write about whichever one works out.

Share this article

If it helped, send it to someone who needs it.

All articles

Comments