FrontierStack overview
A native macOS app for running and administering your own servers, devices and services — locally and across a fleet.
A native macOS app for running and administering your own servers, devices and services — locally and across a fleet.
Create and edit Apache/Nginx virtual hosts, turn PHP on per site, issue Let's Encrypt certificates, and use the New Site (with DNS) wizard to create a vhost, a Cloudflare DNS record, a zone and a certificate in one flow.
Tight Cloudflare integration means you stop tab-hopping to their website. Create zones and DNS records, purge cache (everything, by URL or by prefix), flip Development Mode on and off, and keep an A record on your changing IP with built-in dynamic DNS — all from the app. Each pinned zone shows its SSL mode, certificate expiry, security level and today’s cache hit-rate, and the AI Administrator can create DNS records for you during a New Site flow.
MySQL, PostgreSQL, Redis and more, with per-instance credentials kept in a local vault. PHP, Node and Python runtimes are detected and managed.
FrontierStack watches MySQL and PostgreSQL on the host itself — a real liveness check (an SELECT 1 / pg_isready, not just a process or port), replication, and a corruption early-warning that scans the server's error log and flags an InnoDB assertion or a crashed table before it takes the database down. Because the watch runs on the server, it keeps monitoring — and keeps alerting — even when your Mac is asleep or offline, delivering straight to ntfy or a webhook. A scheduled mysqlcheck / pg_amcheck can back up and repair on its own, and the hard cases hand off to AI-assisted recovery: the assistant reads the log, diagnoses the fault and walks a guided rebuild behind the same approval card (and only on a high-end model — never a small local one). Best of all, an alert is never silent — if every messaging channel is off or failing, it still surfaces as a native macOS notification and push.
Link macOS, Linux, BSD and Windows servers over SSH and run a suite of diagnostics on any node or ad-hoc IP — ping, traceroute, netstat, port scan, SSL inspector, security audits — using a saved sudo password through the helper. Keep an old Xserve or Mac mini on macOS Server useful by managing it remotely, and link a Raspberry Pi (or a shelf of them) like any other Linux box.
Bring the devices around your servers into the same operational view. Monitor and control SwitchBot, Zigbee and HomeKit-exposed devices, cameras, sensors, smart plugs, UPS units and network gear; organise them by Places, automate responses, and power-cycle a machine when SSH cannot reach it.
Open ports, remote-access exposure, intrusion prevention (fail2ban/CrowdSec), a dedicated macOS Firewall pane (Application Firewall + pf), and a Malware Audit pane (Gatekeeper/SIP/FileVault/XProtect, persistence, ClamAV, YARA, VirusTotal) plus an EDR Fleet board.

An early warning before trouble becomes an outage — threshold checks on health, certificate expiry, open ports, capacity and connected cloud services, pushed to Telegram, LINE, Slack, Discord, ntfy, email, SMS, WhatsApp, Apprise (80+ destinations) and more. Enable several, list multiple recipients, and a per-send Delivery Errors check tells you if a channel is misconfigured.

Describe a problem in plain English — “why is the site throwing 502s?” — and the AI Administrator investigates and, with your approval, fixes it. It’s a full AI harness with ~70 tools and guard-rails: read-only diagnostics run on their own, every change is gated behind an approval card, and your secrets are injected at run time so they never reach the model. It supports all major cloud AI platforms — including OpenAI, Anthropic Claude, Google Gemini, xAI, DeepSeek and OpenRouter — plus local Ollama/LM Studio models and Apple’s on-device Foundation Models framework. It works on this Mac and on your remote servers over SSH, and loads multi-step skills — fleet security audits, malware analysis — on demand.
Beyond the assistant, create your own agents inside FrontierStack — goal-driven loops that run once or on a schedule, tailored to your use-case. Point one at a job (“watch this endpoint and restart it if it stalls”, “reconcile inventory every morning”) and it uses the same guarded tools to monitor things or do real work for you, streaming each step to a transcript you can stop at any time.
The free companion iPhone & iPad app is a full remote for your Mac. Pair with a QR code, then pick any server (the Mac included) and control its services, run a real shell that auto-logs into your boxes, chat with the AI Administrator, get trouble alerts as push notifications, switch network locations and browse device web UIs — from anywhere, over your LAN, Tailscale or a Cloudflare Tunnel. Every phone gets its own signed-request key with a scope you set (read-only to full) and can revoke from the Mac. See how mobile control works.
Save scripts to a palette and schedule them on real cron, then go further: FrontierStack ships native Apple Shortcuts actions (App Intents) — run a script, start a service, restart a container, flush DNS, send a notification or even ask the AI. They come with built-in Siri phrases, so you can just say “Check server health with FrontierStack” or “Ask FrontierStack…”, and they appear in Spotlight. A frontierstack:// URL scheme deep-links to any pane from AppleScript or a shell step.
Running an assistant, your own agents and outside harnesses means spend in several places. The AI Model Costs dashboard pulls it all into one view — flat subscriptions (ChatGPT, Claude Pro/Max, Cursor, Perplexity, T3 Chat…) and metered API token spend per provider and model — tracked against a monthly budget with a color-coded bar. A billing-trouble watcher even alerts you on out-of-credits, hard-limit or past-due before a key stops working.
FrontierStack also runs as its own MCP server, so an external AI harness — Claude Code, Claude Desktop, Cursor, Codex and other MCP clients — can drive the whole app. Their tool calls hit the same guarded executors as the built-in assistant, acting on live app state. The server binds to localhost behind a required token and stays read-only until you opt in to changes and scripts — so your coding agent can inspect and operate your servers through FrontierStack, with the same approval card in front of every change. And because that harness is your own subscription tool (Claude Code on a Claude plan, Cursor, …), the AI runs on the flat plan you already pay for — no metered API tokens.
Monitor agent runtimes — OpenClaw, Hermes, DeerFlow, LangGraph, CrewAI, AutoGen and more — from one dashboard, with status, models, tokens and sessions.
FrontierStack is one home for everything you run — install self-hosted services (web, data, CRM, e-commerce, education, AI, home, security) and connect your SaaS accounts with API credentials, then see them side by side in one sidebar. 500+ services in all; presets tailor the view to your use-case.
FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.
Download FrontierStack