iOS & iPadOS · on the App Store
Flotilla.
A native client for Unraid and Proxmox VE. Your whole homelab in one fleet view, with encrypted push alerts delivered through a relay that cannot read them.
- platforms
- Unraid · Proxmox VE
- devices
- iPhone · iPad
- price
- Free · $4.99 one-time
- server side
- MIT, open source
The problem
Homelab servers tell you nothing until you go looking. A disk starts throwing errors, a parity check finishes, an array goes offline — and you find out the next time you open a browser tab. The existing mobile options were single-platform, so running Unraid and Proxmox meant two apps, and the ones that offered alerts did it by handing your notifications to somebody else's server in plain text.
What it does
- One fleet view. Every server on one screen — storage under management, nodes online, containers and VMs running, live CPU.
- Containers and VMs. Start, stop, restart, pause and update. Follow logs live. Open a container's web UI from its port mappings.
- Unraid operations. Start, pause, resume and cancel parity checks with computed ETA and history; array start and stop; mover status; UPS battery, load and input voltage.
- Disk health. Per-disk temperature, errors and usage — and it never wakes a sleeping disk to tell you.
- Activity feed. Server notifications merged with state changes the app detects itself, grouped so a flapping service does not bury everything else.
- Widgets and Face ID. Home and lock screen widgets; optional biometric lock.
Push, without trusting the relay
Apple only accepts pushes signed with a developer's credential, so any iOS push feature for self-hosted software routes your alerts through a server the developer runs. That was the part worth engineering around.
Pairing happens on your LAN through a QR code carrying a symmetric key. Your server seals each event with ChaCha20-Poly1305 before anything leaves the network. The relay authenticates the sender, forwards ciphertext to Apple, and stores nothing it can decrypt. A Notification Service Extension decrypts on the phone and fills in the server's name from local storage, so the name never crosses the wire either. The relay's complete view of you is a pairing ID, an auth secret and an opaque blob.
Push is a paid feature and there are still no accounts. The app sends its StoreKit transaction receipt and the relay verifies that signature offline against a pinned Apple certificate chain — so it can prove an install is entitled without knowing who owns it. No user table exists.
Design decisions
- Pure client. The app talks to your servers and nothing else. No analytics, no crash reporting, no accounts. The one optional outbound request is fetching container icons, off by default.
- Trust on first use. Unraid ships a self-signed certificate, so the app pins the one it saw when you added the server and refuses quietly if it ever changes.
- Smart Connect. Add a Tailscale address as a second endpoint and reads fail over automatically when you leave the house. Mutations never fail over — retrying a stop command against a different endpoint risks running it twice.
- Never wake a disk. Temperatures are only rendered when the platform reports the disk as already spinning.
- Zero third-party dependencies. Foundation, SwiftUI, CryptoKit and Security. Nothing else ships in the binary.
Stack
All testable logic lives in a Swift package with no UI imports, which is why it carries a suite of several hundred tests that run in about three seconds. The app target is a thin SwiftUI layer over it. On the server side, the Unraid plugin is plain shell and PHP, the Proxmox companion is a small Go daemon, and the relay is a Cloudflare Worker — all MIT.
Install
The app is on the App Store, free for one server with nothing held back. Push, widgets and additional servers are a single $4.99 unlock with Family Sharing — no subscription.
Push also needs the agent on your server. Unraid users can install it from Community Applications (search for Flotilla); Proxmox users run a small daemon that receives PVE's native webhook locally and seals it before it leaves the node. Both are documented in the agent repository, along with the wire protocol.
Questions and feature requests go to GitHub Discussions, or support. There's a privacy policy too — it is short, because there is very little to say.