Why you'd want one

Right now, the things that run your work are probably scattered across three or four companies' accounts. Your website with one, your email list with another, your tools somewhere else. Any one of them can lock you out, raise the rent, or shut down and take your work with it.

Your own box puts all of it in one place that answers to you. Your website, on its own steady address, instead of a slice of someone else's hosting account. Your database or your app's backend, on the same box, instead of a pile of separate rented services. One small monthly bill. One key. And the key is yours.

website your list tools their keys → website · data · tools all on one box one key, and it's yours
Scattered across accounts other people hold the keys to, or gathered on one box whose only key is yours.

You're still renting, to be straight about it. Think of a storage unit: you don't own the building and you never will, you pay the facility every month. But for as long as you do, that unit is yours. You hold the only key, nobody goes through your things, and the day you decide to leave you take every last box with you. That is what your own box is, and it's the opposite of renting space where the company keeps a copy of your key.

See the whole picture at shannondobbs.com/vps →

Now · the part that's yours to do

Set up your box safely

Standing up your own box means, at one point, holding a couple of keys. This is a slow walk through that part, because it's the part that scares people, and it's the one part the AI can't do for you.

Not because it's hard. Because it's yours. Making the account, holding the password, deciding what to trust, those are decisions only you can make, and that's a good thing. It's what keeps this yours and not somebody else's. Once these few steps are done, you hand the rest to Claude Code and it does the technical wiring for you.

Read the whole thing once before you touch anything. It's shorter than it looks, and you only do it one time.

The one rule, above all others

Your account login and your passwords never go to anyone. Not to us, not to a website, and not to the AI. If anything ever asks you to paste a password or a private key into a chat box, that is the one thing you never do. Everything below is built so you never have to. (The AI helping you has been told the same thing, in writing, at the top of this page.)

Here's the whole shape before the steps. You're renting a small computer, and giving one AI assistant a scoped key to work on it for you. Three things stay yours the whole time:

What stays yours

Everything else can be handed over, rebuilt, or shut off. These three, you keep.

1

Make your hosting account

You're renting a small computer from a hosting company, the same way you'd rent a storage unit. You make the account yourself, with your own email and card. The AI can't do this for you and shouldn't, it's your account with your name on it.

When you're done, keep that login where you keep your other important logins. It's how you'd ever move or close the box later. Nobody else needs it, ever.

What do I even pick? (specs, in plain words)

You want a small Ubuntu server, roughly 4 to 6 processors, 8 to 11 GB of memory, no graphics card. Small on purpose, it's a router, not a brain. When it asks for an operating system, choose Ubuntu 24.04. It runs about six to twelve dollars a month.

Not sure which host? Paste Claude Code a couple you found and ask it to compare them for what you need. You own the box, so you can move to a different host later without losing anything.

2

Meet your master password

When the box is created, the host hands you a root password. Think of it as the master key to the whole building. It's powerful, so it gets treated with care:

Save it somewhere safe, a password manager, or wherever you keep things that matter. And back to the one rule: never paste it into a chat, an email, or the AI. You may use it yourself, in your own window, exactly once in the next step, and maybe not even then.

3

Make a key for the AI

This is the heart of it, and it's the step worth understanding, because understanding it is what makes the fear go away.

A key is not a password. It comes in two halves.

Private half stays with you → your box Public half bolt it on, safe to share
The public half is a padlock you bolt onto your box; anyone can see it. The private half is the only thing that opens it, and it never leaves your side.

So instead of ever giving the AI your master password, you do this: ask Claude Code to make you a key. It creates both halves right there on your computer, keeps the private half safe on your machine, and shows you the public half, a block of text that starts with ssh-ed25519. That half is the padlock. It is safe to share.

Then you put that padlock on your box, one of two easy ways:

  • The easy way (no terminal): most hosts have a box labeled "SSH Keys" in their web control panel. Paste the public half into it. Done. It's just a web form, like any other.
  • The other way: if your host doesn't have that box, Claude Code gives you one line to run in a terminal that installs the padlock using your master password once. That's the only time your hands ever touch the password.
Wait, what's a terminal, and how do I open one?

A terminal is just a plain window where you type a line and press enter, no buttons, no menus. It looks bare, but that's all it is. Most of the time Claude Code does the typing for you; you rarely open one yourself. But if a step says "run this," here's how to get one:

On a Mac: press Cmd + Space, type Terminal, press enter. A small window opens. That's it.

On Windows: click Start, type Terminal (or PowerShell), press enter.

On a Chromebook or phone: you probably won't need one, do the web-form way above. If you truly need a terminal, tell Claude Code what device you're on and it'll point you to the easiest option.

When a step says "your own window," it means this. Not the AI chat, an actual terminal on your computer, where you are the one typing.

If you see this, do this (the little snags)

If it asks "Are you sure you want to continue connecting?" → type yes and press enter. That's your box introducing itself the first time. Normal.

If it says "permission denied (publickey)" → the padlock didn't go on. Ask Claude Code to walk the install line again, or paste the public half into the host's SSH-Keys box instead.

If you never get asked for a password → good, that usually means the key is already working. Let Claude Code confirm it's in.

If anything asks you to paste your password or private key into a chat → stop. That's the one thing you never do. It is never required.

Why this is safe, in one breath: the AI can walk in and do the work, but it never holds the master key to the building. And if you ever want it gone, you delete that one padlock and it's locked out instantly. No argument, no phone call. You can always take the key back.
4

Hand over the address, and point the AI at the right files

Now you give Claude Code the two things that are safe to share: your box's address, and the private key it already made (which only works on your box and which you can revoke any time).

Here's the part that keeps the AI on the rails: don't just say "go set up my box." That's how you get an AI confidently doing random things. Instead, point it at the repo's own step-by-step, in order, and tell it to follow those and not improvise:

Where these files live: the public repo this page itself is part of, github.com/Techniq42/fls-membrane. (That is a different address from your box's. Don't mix the two up.)

  • README.md — what this is, and the round-trip demo.
  • SETUP.md — the exact from-zero setup steps.
  • membrane.sh — the one command that builds the whole capability layer.
  • add-caged-seat.sh — later, only when you want to open one scoped door to someone else.

A good thing to actually say: "Read README.md and SETUP.md in this repo, explain the plan to me first, then walk me through it step by step. Don't run anything that isn't in those files, and stop if anything's unclear."

The rules your AI is held to

At the very top of this page, in a part only the AI reads, it is given a short list of hard rules. So you can see the fence it stands behind, here those rules are in plain words. Your AI has been told:

  • Never ask you for a password or a private key, and never let you paste one into the chat. If you offer, stop the person and send them back to the safe way, where they put the public half on the box themselves.
  • Explain each step to the person, in plain words, before doing it, and stop if they are unsure.
  • Do only what the files listed above call for. Never go off on your own and change things nobody asked for.
  • When there is a choice, pick the safest, most easily-undone option, and ask the person when you are not sure.

If your AI ever pushes against these rules, that is your cue to slow down and ask it why.

5

Why this stays yours

You hold the account. You hold the password. You hold the key. You can revoke the AI's access whenever you want, and you can move the whole box to another host or wipe it entirely, because it's genuinely yours. Nobody is holding your work hostage, and nobody can. That's the difference between a storage unit where the manager keeps a copy of your key, and one where you hold the only key there is.

Stuck on any step? Every line here is something you can paste to Claude Code with "explain this to me like I've never done it." Take it slow. This is the only part that's yours to do by hand, and it's a few minutes, once. After that, you drive and it wires.

Still stuck, or you'd rather not do it yourself? That's a real option, and no judgment. We can set the whole thing up for you, or just talk it through and point you the right way. Come find us at shannondobbs.com/vps →

Field notes

Get the field notes when they land.

The whole build is in the repo and it's yours right now, no email needed. This is just the occasional note as it grows, and word when there's a seat at the fire. Nothing else.

Fellowship of Living Systems · yours to run, fork, and change · a link back keeps the lineage