Hybrid on-premises

Work in Hodman. Run projects inside your network

Your team uses the Hodman web workspace. An execution agent on your server runs project code and reaches the internal systems you authorize, without giving those systems a public endpoint.

Where each part runs

Hybrid on-premises architecture. Hodman hosts the web UI and API. The execution agent inside the customer network initiates WSS over port 443 to the API; tasks and results travel over that connection. The agent runs project containers that access local files, databases and internal services. Selected context and model responses may pass between Hodman and the AI provider. Local storage does not prevent requested outputs from leaving the network.
The agent initiates the management connection from inside your network. Internal systems do not need an internet-facing endpoint. Requested outputs and AI context can still leave the network.

Hodman.ai

The web workspace and Hodman API stay hosted: sign-in, administration, tasks, conversations and coordination with your execution agent.

Your server

Your execution agent manages Docker project containers, local files and databases. Project code reaches approved internal APIs and services from inside your network.

Your AI source

AI work uses your supported subscription, API key or optional Credits. The selected provider may receive task context and tool outputs; on-prem execution does not make model inference local.

Build an internal dashboard without exposing the source database

Give a project read access to a database on your private network. Its code queries the database locally and serves a dashboard through your internal ingress or VPN. Your team can ask Hodman to change the dashboard, inspect the preview and review the result. Decide which query results and logs the agent may return to the hosted workspace and AI provider.

Keep internal services off the public internet

The execution agent connects to Hodman. It does not need an inbound management port. Preview, application access and webhooks need their own network setup. External providers and registries may also require outbound access.

Choose what the agent can read and return

Use scoped credentials, read-only connections where possible and output filtering in each connector. Data Protection Policy can guide masking implementation, but it is not an automatic network-wide filter. Test which data reaches the workspace and model before connecting sensitive systems.

Know what crosses the network boundary

Code or command results requested for a task can be sent to Hodman and your AI provider. Restored values may be cached by Hodman. This is not an offline installation or a guarantee that no company data leaves your network.

Connect your infrastructure to the workspace

Public Docker Hub distribution is being prepared. The setup guide describes the planned public-image installation; use a release tag confirmed by your administrator.

  1. 01

    Give your coding agent the installation guide.

  2. 02

    Install the execution package on a dedicated server or VM.

  3. 03

    Authorize the runtime in your Hodman workspace.

  4. 04

    Verify a test project and its access path before connecting production data.

The execution agent controls the Docker daemon. Use a dedicated host, review its privileges and back up local data. A publicly downloadable image does not by itself mean the software is open source.

Included with Ultra

Ultra workspace plan

On-premises execution is available with Ultra. Your server, AI provider and infrastructure costs are paid separately.