netclode: The Mainframe in Your Pocket
How a native iOS client uses hardware-isolated microVMs and an S3-backed filesystem to make self-hosted AI coding agents feel local.

There are some cloud coding agents available, but they were a bit underwhelming when I tried them… so I built my own! It solves my problem + it’s very fun to do.
- Netclode shifts the computational burden of AI agents from the client to a self-hosted k3s cluster, enabling complex coding tasks from an iPhone.
- Kata Containers and JuiceFS combination achieves "stateless persistence," allowing microVMs to be spun up instantly while retaining full workspace state.
- A dedicated secret proxy pattern ensures LLM agents never have direct access to API keys, mitigating security risks in "Full YOLO" execution modes.
- The SwiftUI client employs sophisticated state machines and partial streaming to mask network latency and maintain a responsive UI.
The Mobile Coding Paradox
Coding from a mobile device has historically been an exercise in frustration. The constrained environment lacks the necessary compute, storage, and tooling required for modern development. Netclode addresses this by completely decoupling the interface from the execution environment. The iOS app is merely a thin, highly optimized window into a robust, self-hosted backend infrastructure.
The Illusion of State
To make a remote session feel instantaneous, Netclode relies on a "Warm Pool" of idle microVMs managed by k3s. These aren't standard Docker containers; they use Kata Containers and Cloud Hypervisor for hardware-level isolation. This allows for what the project calls "Full YOLO mode"—granting the AI agent root access and the ability to run nested Docker containers without compromising the host system.
The magic trick underlying this architecture is JuiceFS. Instead of relying on local persistent volumes, JuiceFS mounts S3 buckets as a POSIX filesystem within the microVMs. When a user closes the app, the active VM can be aggressively terminated to save resources. Upon reopening, an idle VM from the pool is instantly assigned and the JuiceFS volume is remounted, restoring the exact workspace state—including massive directories like node_modules—in seconds.
Treating the AI as a Hostile Actor
Granting an autonomous AI agent root access inside a sandbox presents significant security challenges. Injecting sensitive environment variables, such as an Anthropic API key, directly into the sandbox is inherently risky. A hallucinating or compromised agent could easily exfiltrate or log these credentials.
Netclode mitigates this risk through a dedicated secret-proxy service written in Go. This service acts as a strict perimeter, intercepting all outbound requests from the agent to external LLM APIs. The proxy injects the necessary credentials on the fly, ensuring that the agent itself never has direct access to the keys it utilizes.
Masking the Network
A powerful backend is useless if the mobile client feels sluggish or unresponsive. The Netclode SwiftUI client (clients/ios/) employs sophisticated techniques to mask network latency and provide a native feel. The AppStateCoordinator uses a state machine to manage reconnections, implementing an exponential backoff strategy with jitter to quickly re-establish communication when the app returns to the foreground.
Furthermore, the MessageRouter implements partial streaming to handle real-time LLM generation. Instead of waiting for complete responses, the UI updates incrementally as chunks of text arrive. To prevent the main thread from freezing during rapid streaming, the ChatStore utilizes a debounced persistence pattern, delaying disk writes by 500ms.
The Vendor-Agnostic Baseline
Unlike proprietary solutions such as Claude Code, which lock users into a specific ecosystem and pricing model, Netclode functions as a vendor-agnostic harness. It allows developers to plug in various models, whether cloud-based APIs like Anthropic or local models running via Ollama. This philosophy of independence, combined with its unique architectural approach, distinguishes it within the crowded AI coding agent landscape.
| Tool | Architecture | Primary Interface | Isolation Level | Model Lock-in |
|---|---|---|---|---|
| Netclode | k3s + MicroVMs | Native iOS/macOS | Hardware (Kata) | Vendor-Agnostic (Ollama/API) |
| OpenCode | Client/Server Docker | VS Code / Desktop | OS-Level (Docker) | Vendor-Agnostic |
| Claude Code | Local CLI | Terminal / IDE Plugin | None (Runs locally) | Locked to Anthropic |