Apple content caching, managed

Know your content caches are working before deployment day.

When 2,500 iPads update at once, a caching Mac that quietly stopped means every one of them pulls gigabytes across your WAN. Cachard watches every content cache at every site, shows what each one is serving, alerts you the moment a site isn't covered, and updates the caches themselves one at a time, never while another cache at the same site is down. It runs on your own server, with nothing to install on the Macs.

All features in the trial · No agent on the Macs · Up and running in about ten minutes

Drag to pan · Ctrl + scroll to zoom · Hover a cache for details
AgentlessNothing to install on the MacsAn SSH key and one narrow sudoers rule. Works alongside Jamf, Mosyle, Intune or any MDM.
Self-hostedYour data stays on your networkOne small Linux VM or a container. No vendor cloud; license keys are checked offline.
Monitoring-only optionStart read-onlyThe console can't change any Mac, and the Macs themselves allow only status commands. Widen it when you're ready.
Built in productionMade by a K-12 network adminBorn running a district fleet of caching Mac minis, then built out for any organization.
Interactive tour

Click through the console

These are real screens from Cachard's demo mode, with a fictional school district and simulated Macs. Choose a stop, then tap the green markers.

cachard.fairhaven-usd.example/

Prefer to click everything yourself? The demo ships with every download:./run.sh --demothen open localhost:8080 (password demo).
What's inside

Everything a caching fleet needs, in one place

Live fleet view

Online, caching, cache used, served to devices, serving now and bandwidth saved for every Mac, refreshed every 15 seconds.

Network map & TV mode

Traffic flows from Apple to parent caches, site caches and individual devices, as rings or on a street map of your area. Put it on the NOC wall.

Configure many Macs at once

Cache size, parents, peers, listen and public IP ranges. Preview every change, apply in parallel, and Cachard re-reads each Mac to verify it stuck.

Device update tracking

What's being downloaded, cache hit rates, iOS and macOS rollout per site, and devices stuck re-downloading the same update.

macOS updates for the caches

Scan, schedule and roll out updates a few Macs at a time, with a site safeguard that won't update a cache while another at the same site is down.

AI insights (optional)

With your own Claude API key, Claude reads the whole fleet and explains what's happening in plain English, with prioritised fixes and a place to ask questions.

Site checks

Are devices at each site actually finding their cache? Internet speed per site. Mac health, disk and power settings.

History & replay

Daily totals kept for 13 months, a weekly report by email, and a replay of any day's traffic on the map.

Alerts that respect your day

Email and Microsoft Teams alerts for offline caches, lost parents and low disk, with quiet hours and all-clear messages.

Standard settings & drift

Define how every cache, or every cache at one site, should be set up. Cachard flags drift and MDM profiles that override local settings.

Accounts, SSO, two-step

Viewer, technician, administrator and platform administrator roles, email invitations, Microsoft Entra ID or Google sign-in, and required two-step sign-in.

Remote terminal (optional)

A shell on any Mac in the browser, or one command across many Macs. Off by default, platform administrators only, every session recorded, and it can be locked off at the server.

See the network

Your caches, on your streets

Set each site's address and Cachard builds a street map of your area from OpenStreetMap once, then keeps it on the server. Wall displays and locked-down networks never load map tiles.

  • Follow the bytes. Amber from Apple, blue between caches, green to devices, with the busiest links labeled.
  • Zoom into a site to see every iPad, iPhone, Mac and Apple TV it served, and what each one downloaded.
  • Problems show where they are. An offline cache pulses red; a parent that's set but unused is drawn dashed.
Street-map view of a fictional town with caches at each school and live traffic
TV mode: full-screen map with large totals and the live analysis
TV mode

Made for the wall in the NOC

Full-screen and hands-off. It tours each site, shows what's being served right now, and keeps the live analysis on screen. A read-only link works on any display without signing in.

Updating the caches themselves

Update the caches without taking a site offline

The caching Macs need macOS updates too. Cachard rolls them out the way an infrastructure admin would, so wherever a site has two or more caches, one of them is always serving.

  • Site safeguard

    Set the minimum number of caches each site must keep available. Cachard won't update Cache B while Cache A at the same school is down; it waits, then skips with a clear reason. Restarts ask first.

  • One site at a time, parents last

    A few Macs per batch, never two from the same site, with the parent caches that feed others updated last.

  • Pilot first, stop on failure

    Start with one Mac, stop the rollout if anything fails, and confirm each Mac came back with caching running before moving on.

  • Tonight, or every week

    Schedule a run for after school, or let Cachard install updates that have been out a few days in a weekly window. Alerts pause for Macs being updated.

Mac updates: which caching Macs are current, which updates each needs, and a rolling install plan
Mac updates. Every cache's macOS status and a rolling plan that keeps each site served.
Setup

From a fresh VM to a watched fleet in about ten minutes

# the one line from your trial email
$ curl -fsSL https://cachard.app/i/your-link | sudo bash
▸ Downloading Cachard 1.3.0 · checksum verified
▸ Checking this server
  ✓ Ubuntu 24.04 LTS · 4 GB memory · port 8080 is free
▸ Installing the service
  ✓ Service 'cachard' enabled (starts on boot)
▸ Starting
  ✓ Cachard is running

  Open:        http://10.10.0.15:8080/setup
  Setup code:  7F3A-91C2-0B6D
Get your install commandUbuntu 22.04/24.04, Debian 12 or macOS 12+ · or docker compose up -d
  1. Run one line

    Paste the command from your trial email on the server. It downloads Cachard, verifies the download, installs a hardened service and prints a one-time setup code. Offline bundles work on air-gapped networks.

  2. Follow the wizard

    Name your organization, start the trial or paste a license key, then scan your subnets. Cachard finds the Macs with Remote Login on.

  3. Prepare every Mac at once

    Enter a Mac admin password once. Cachard pins each host key, installs its key and a narrow sudoers rule, and confirms each Mac is ready. The password is never stored.

  4. Place your sites and turn on alerts

    Search an address for each site, build the street map, and point alerts at Teams or email.

Setup wizard preparing six Macs, each showing its name, model, macOS version and host key
Prepare. One password, every Mac identified and connected, with a clear reason when one isn't.
Setup wizard step for site locations with an address search
Sites & map. Address search or coordinates; the street map builds itself.
Who it's for

Anywhere hundreds of Apple devices share one Internet connection

K-12 school districts

iPad carts and Mac labs all pulling the same iPadOS update at 8:05 on a Monday.

  • One cache per school, a parent at the district office
  • Knows the school day: urgent during class, quiet overnight
  • Per-school reports for the technology director

Colleges & universities

Residence halls, labs and libraries across a campus, with student devices you don't manage.

  • Serve unmanaged devices on campus subnets
  • Listen and public IP ranges checked against reality
  • Roles for help-desk staff and network engineers

Businesses

Offices, stores or plants with Mac and iPhone fleets and expensive or thin WAN links.

  • Keep macOS and app downloads off the WAN
  • Works with any MDM, no agent to approve
  • SSO, audit log and on-premises data for compliance
The console rebranded as Northwind CacheView for Lakeview School District, with a purple accent and its own logo
Branded sign-in page with a custom background, logo and help message
White-label

Your name on the console, not ours

Managed service providers, resellers and central IT teams can present Cachard as their own product. Set it once under Settings → Branding, or ship a branding pack with the installer so the very first setup screen is already yours.

Product name & taglineLogo & dark-mode logoApp iconAccent colorSign-in page & backgroundSupport contactRenewal linkEmail sender & footerHide “Powered by”

Any accent color stays readable: text shades are adjusted automatically for contrast in light and dark mode. Weekly reports, alerts, two-step sign-in apps and the AI analyst all use your product name. Included with Enterprise and Partner licenses, and you can preview it during the trial.

Shown: “Northwind CacheView”, a fictional reseller brand.

Automatic updates

Stays current without a maintenance weekend

Cachard checks for new versions every few hours. Install with one click, or let it update itself overnight in your maintenance window.

  • Signed and verified

    Every release is signed and checked on your server before anything is installed.

  • Your schedule

    Notify only, install patches automatically, or install everything, on the days and hours you choose. Never while the caches are updating macOS.

  • Backed up, with automatic rollback

    Data is backed up first. If the new version doesn't start, the previous version and data come back on their own.

  • Air-gapped too

    Offline update files for networks without Internet access, and cachard update on the command line.

  • Built-in support

    Help & support in the console, and a one-click support bundle with passwords, keys and secrets removed.

Settings, Updates: up to date, with install policy, channel and notification options
Settings → Updates. Release notes, history and policy in one place, shown here on a white-labeled console.
Help and support page showing the support contact, documentation and a support bundle button
Help & support. Your support contact, the guides and a diagnostics bundle.
Security & privacy

Read exactly what it can do, before you install anything

Cachard can manage infrastructure Macs, so it's built to be inspected. Your cache telemetry never leaves your network, and everything below is spelled out in the Security & Architecture Guide for your security review.

Monitoring-only mode

Install with --monitor-only and the console can't change any Mac, for any account, while the Macs themselves allow only read-only status commands. Only root on the server can switch modes.

Remote terminal off by default

The browser terminal is off until a platform administrator turns it on, every session is recorded, and --no-terminal locks it off for good.

Least privilege on the Macs

A dedicated SSH key and a visudo-checked sudoers file that the Mac enforces. It's published in full below.

Four roles

Viewer, Technician, Administrator and Platform administrator, with Microsoft or Google single sign-on and two-step sign-in.

Stays on your network

Self-hosted on Linux or Docker. No vendor cloud and no usage analytics. Update checks send only the version and license ID, and can be turned off.

What it collects

Cache status and settings, macOS versions, and from the caching logs each device's IP address, type, OS build and what it downloaded. No user names, Apple Accounts or content. Kept 30 days, on your server.

Audited

Changes, actions, Mac updates, account and security changes and terminal sessions are recorded with who, when and the exact commands.

Signed updates

Releases are signed, verified on your server by a root-owned updater, backed up first and rolled back automatically if they fail.

The sudoers file Cachard installs

The only commands Cachard's account may run as root on a Mac without a password, in full mode. /etc/sudoers.d/zz-cachard:

# Installed by Cachard. Lets the console's SSH account run only these commands as root.
Cmnd_Alias CACHARD_UTIL   = /usr/bin/AssetCacheManagerUtil
Cmnd_Alias CACHARD_PREFS  = /usr/bin/defaults write /Library/Preferences/com.apple.AssetCache.plist *, /usr/bin/defaults delete /Library/Preferences/com.apple.AssetCache.plist *
Cmnd_Alias CACHARD_REBOOT = /sbin/shutdown -r now
Cmnd_Alias CACHARD_SWU    = /usr/sbin/softwareupdate
Cmnd_Alias CACHARD_SWPREF = /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate *
cacheadmin ALL=(root) NOPASSWD: CACHARD_UTIL, CACHARD_PREFS, CACHARD_REBOOT, CACHARD_SWU, CACHARD_SWPREF

In monitoring-only mode

Read-only status commands, nothing else:

# Installed by Cachard (monitoring-only). Lets the console's SSH account run only these read-only commands as root.
Cmnd_Alias CACHARD_READ = /usr/bin/AssetCacheManagerUtil -j status, /usr/bin/AssetCacheManagerUtil -j settings, /usr/bin/AssetCacheManagerUtil status, /usr/bin/AssetCacheManagerUtil settings, /usr/bin/AssetCacheManagerUtil canActivate
cacheadmin ALL=(root) NOPASSWD: CACHARD_READ
Pricing

Priced per caching Mac, not per device

Every plan includes every feature, automatic updates and email support. Start with a 30-day trial; no card needed.

Education

Schools & colleges

$49 per caching Mac / year
  • K-12, higher education and nonprofits
  • All features, unlimited devices
  • Automatic updates and email support
  • Purchase orders welcome
Start free trialRequest a quote or PO
Business

Companies

$75 per caching Mac / year
  • All features, unlimited devices
  • Microsoft and Google single sign-on
  • Automatic updates and email support
  • Annual invoicing
Start free trialRequest a quote
Enterprise

Large fleets

Let's talk 50+ caching Macs
  • White-label branding included
  • Volume pricing and multi-year terms
  • Guided onboarding and priority support
  • Security questionnaire help
Contact sales
Partner

MSPs & resellers

Wholesale for every customer you manage
  • Full white-label: your name, logo and support
  • Branding packs for branded installs
  • Wholesale per-cache pricing
  • Partner support line
Become a partner
12 MacsEducation $588/yrBusiness $900/yr
Questions

Asked by network admins

Do I need to install anything on the Macs?

No agent. The setup wizard installs an SSH key and a sudoers rule that allows only the content-caching and software-update commands. Remote Login must be on. Macs where password sign-in over SSH is disabled can be prepared with a script or your MDM.

What exactly can Cachard do on our Macs?

It signs in over SSH with its own key and runs a fixed list of commands. As root, only the commands in the sudoers file above. With the remote terminal off (the default), the console can't run anything else. The Security & Architecture Guide covers the full detail, including how the key is stored and what the account can do without root.

Can we start with monitoring only?

Yes. Install with sudo ./install.sh --monitor-only (or CACHARD_MODE=monitor with Docker). Cachard shows everything but can't change any Mac, and the Macs get a read-only sudoers rule. Switch to full management later with sudo cachard mode full.

Does it replace our MDM?

No, it works next to Jamf, Mosyle, Kandji, Intune or any other MDM. When an MDM profile manages a caching setting, Cachard shows it and warns before you change it locally.

Which macOS versions are supported?

Any Mac that runs Apple's content caching and the AssetCacheManagerUtil tool, on Apple silicon or Intel. The console reads each Mac's version and adapts.

What does the server need?

Ubuntu 22.04 or 24.04, or Debian 12, on a small VM (1 vCPU, 1 GB RAM, 2 GB disk); a Mac with macOS 12 or newer, such as a spare Mac mini or one of your caching Macs; or Docker. It needs to reach the Macs on port 22. Internet access is only needed to install, to build the street map once, and for automatic updates, optional AI insights and Teams alerts. Air-gapped servers can update from offline files.

What happens when the trial or license ends?

Cachard keeps monitoring, mapping and alerting. It stops making changes to the Macs until a license key is entered, so your caches are never left unwatched.

Is AI insights required, and what does it send?

It's optional and off by default. With your own Claude API key, Cachard sends an aggregate snapshot (Mac names, sites, states, settings, traffic totals and findings) and shows you exactly what's sent. Device IP addresses and identities, passwords and keys are never sent.

Can we put our own name and logo on it?

Yes. Enterprise and Partner licenses include white-label branding: product name, logos, icon, accent color, sign-in page, support contact, renewal link and email sender, with the option to hide “Powered by Cachard”. Every plan can show your organization's name and logo next to the product name.

How do updates work?

Cachard checks a signed release feed once a day. You choose to be notified, to install patches automatically, or to install everything, within a maintenance window. Each update backs up your data first and rolls back on its own if the new version doesn't start. Updates are included while your license's support term is active.

Can we try it without touching our network?

Yes. ./run.sh --demo runs a fictional district with 14 simulated Macs on any machine with Python.

30-day trial

Try Cachard on your own caches

Tell us a little about your network and we'll email you a one-line install command for your server right away. Need a quote or want to resell Cachard? Choose that below and we'll reply within one business day. Prefer email? Write to sales@cachard.app.

We use your details only to send what you asked for and to follow up about Cachard. Security · Privacy