Inspiration

Rackline started as a tool I built for myself.

I manage Hetzner infrastructure and wanted a native way to securely monitor and manage servers from my iPhone and iPad without depending on a browser or exposing infrastructure credentials to another backend.

I have been developing and using versions of Rackline for roughly two years. After using it personally for about a year and a half, I decided to turn it into a polished App Store product that other Hetzner users could use as well.

Security was the most important design requirement from the beginning. Infrastructure management on a mobile device should never make destructive actions easier at the expense of safety.

What it does

Rackline is a native iPhone and iPad command center for Hetzner infrastructure.

It provides:

  • Hetzner Cloud project monitoring
  • Server and infrastructure inventory
  • Live server metrics including CPU, disk IOPS and throughput
  • Networks, IPs, volumes, images, ISOs and SSH keys
  • Firewalls, load balancers, DNS and certificates
  • Infrastructure search and Smart Views
  • Cost and pricing visibility
  • Live operations and activity
  • Demo Mode with synthetic infrastructure data
  • 350+ offline Help & FAQ answers
  • English, German, Spanish and French
  • Native iPhone and iPad experiences

Rackline is designed around a read-only-first security model.

Users can connect a Hetzner project with only a Read token for monitoring. Administration access is separate and optional.

Credentials are stored in Apple Keychain and requests go directly from the device to Hetzner. Rackline does not proxy Hetzner credentials through a WORK Digital Media server.

Administration sessions automatically relock, and actions are classified by risk:

  • Read
  • Safe write
  • Sensitive write
  • Billable
  • Destructive

Destructive actions require additional safeguards such as device authentication, impact review and typed resource confirmation.

RevenueCat

RevenueCat powers Rackline Pro subscription entitlement management.

Rackline uses RevenueCat to:

  • Determine whether Rackline Pro is active
  • Manage Monthly and Annual subscription entitlements
  • Restore purchases
  • Handle existing App Store subscribers
  • Maintain entitlement state across launches
  • Support subscription lifecycle management
  • Provide subscription-related analytics

Rackline keeps its own custom native SwiftUI paywall while RevenueCat acts as the subscription source of truth through the rackline_pro entitlement.

The Annual subscription includes a 3-day introductory trial for eligible App Store accounts.

I also designed the app so RevenueCat configuration fails safely. If subscription configuration is unavailable, Rackline never displays fabricated prices or trial information.

Demo Mode

Users do not need to provide a Hetzner API token just to evaluate Rackline.

The app includes a complete Demo Environment with synthetic infrastructure, allowing users to explore the interface, monitoring tools and workflows safely before connecting real infrastructure.

Users can experience the app before committing, and eligible users can also test Rackline Pro with the 3-day Annual trial.

How I built it

Rackline is built natively for Apple platforms using:

  • Swift
  • SwiftUI
  • RevenueCat
  • StoreKit
  • Apple Keychain
  • LocalAuthentication / Face ID
  • Swift Charts
  • Hetzner Cloud API
  • Hetzner Robot API
  • native iOS/iPadOS localization and accessibility APIs

The architecture deliberately separates:

  • Demo and Live environments
  • Read and Administration credentials
  • Subscription state and Hetzner credentials
  • Read operations and infrastructure mutations

The app contains extensive automated unit and UI coverage across security, subscriptions, localization, infrastructure workflows and iPhone/iPad layouts.

Challenges

The biggest challenge was balancing powerful infrastructure controls with mobile convenience without weakening security.

I did not want possession of a write-capable API token to automatically mean unrestricted access inside the app.

That led to Rackline's separate Administration Unlock system, automatic relocking, risk classification and additional authentication for destructive actions.

Subscription migration was another important challenge. Rackline needed to support existing App Store subscribers while moving entitlement management to RevenueCat without asking users to purchase again or create a new Rackline account.

Localization was also substantial. Rackline now supports English, German, Spanish and French across thousands of interface strings while keeping technical Hetzner terminology consistent.

What I learned

Building Rackline reinforced how important failure states are in infrastructure software.

A successful API call is only one part of the experience. The app also needs to behave safely when:

  • credentials are invalid
  • connectivity disappears
  • APIs are rate limited
  • subscription information is temporarily unavailable
  • users cancel authentication
  • infrastructure data is incomplete
  • a destructive action is interrupted

The safest behavior is often more important than the fastest behavior.

What's next

I am continuing to expand Rackline while keeping the same security-first philosophy.

Current areas of development include:

  • richer monitoring and operational intelligence
  • additional automation workflows
  • expanded cost visibility
  • deeper dedicated-server support
  • additional native platform integrations
  • a fully native Android version

Rackline is now available on the App Store.

Built With

Share this project:

Updates

Submission history