best apps to self-host for 2026
See 25 apps wey worth to run for your VPS for 2026. We list wetin dem dey replace, di real RAM/disk needs, and di wahala wey you fit face for each one.
Wetin you dey build
No be just one app — na shortlist. Dis na di hub for everything else for dis site: twenty-five applications wey really worth to run for your own VPS for 2026, wey dem group by di work dem dey do. For each one, you go get di service wey e dey replace, an honest RAM-and-disk figure, and di single thing wey go cause wahala if you skip am. Di links dey point to di full step-by-step guide if e dey exist.
I don run VPS host for fifteen years, and I dey run most of dem for my own boxes. So di resource numbers wey dey below na wetin di app dey actually use under small real workload, no be di "minimum" wey marketing page dey talk. Read dem as budget, den add headroom.
Prerequisites and di honest reality
Every app for here dey run for fresh Ubuntu 24.04 KVM VPS with root or sudo. Almost all of dem dey come as Docker containers, so install Docker once and you ready for di whole list:
curl -fsSL https://get.docker.com | sudo sh
sudo usermod -aG docker "$USER"
newgrp docker
docker run --rm hello-worldIf docker commands fail with permission denied while trying to connect to the Docker daemon socket, you skip di group step or you no open new shell — log out and log back in. If docker compose return docker: 'compose' is not a docker command, you get di ancient standalone binary; di script wey dey above dey install di modern Compose plugin, wey you go call as docker compose (space, no be hyphen).
Three realities dey set di shape for everything wey dey below. First, RAM na di constraint, no be disk or CPU. 1 GB VPS fit run one small app and nothing more. 4 GB na di real sweet spot for "self-host a few things" box. 2 GB na di awkward middle wey beginner dey use stack di third service, den dem go hit silent Out-Of-Memory kill, den dem no go know why di container just vanish — sudo dmesg show di Out of memory: Killed process line wey di daemon swallow. Second, anything wey public need name and certificate — bare IP fit work for testing, but e go fail di moment you want phone app or browser to trust am. Third, two ports dey decide half of your options: 80 and 443 must reach di box for automatic TLS, and outbound 25 dey blocked by most providers, na why email dey for di "do not" list for di end.
Files and photos
- Nextcloud dey replace Google Drive, Dropbox, and Google Calendar inside one suite. Budget 1–2 GB RAM plus whatever your files weigh. Di one gotcha: SQLite fine for demo but na trap for production — install am on PostgreSQL from di first boot, because migrating di database after your data don enter there na di most common way people wreck Nextcloud. Di full Nextcloud on a VPS with Docker, TLS and backups guide dey set am up correctly di first time.
- Immich dey replace Google Photos, down to di phone app wey dey auto-upload your camera roll and di face and object search. Budget 6 GB of RAM — Immich docs dey call dat di minimum, 8 GB na di comfortable one, and di machine-learning container na di hungry part — and disk must equal your library plus roughly twenty percent for thumbnails. Di gotcha: Immich still dey bring breaking changes between releases, so no ever blindly pull
latest; pin a version and read di release notes before every upgrade. Di self-hosted Immich photo library guide cover di safe upgrade path. - Seafile dey replace Dropbox with di fastest sync engine for di three. Budget around 1 GB RAM. Di gotcha: Seafile dey store your files as content-addressed blocks, no be plain files for disk, so you no fit browse di data with
lsand you must back up through Seafile's own tools, no be by copying folder.
Passwords
- Vaultwarden dey replace Bitwarden's paid tier, LastPass, and 1Password with one tiny Rust server wey dey speak Bitwarden protocol, so every official Bitwarden app and browser extension go just work. Budget 100–200 MB RAM and almost no disk. Di gotcha: dis box dey hold every password wey you get, so TLS and backups no be optional here, na dem be di whole point — and set di
ADMIN_TOKENas Argon2 hash, because plaintext token for your compose file na master key wey dey sit for cleartext. Di Vaultwarden password manager guide na di best possible first self-host.
Media
- Jellyfin dey replace Plex and, for your own library, Netflix — fully open, no account, no paywalled remote streaming. Budget 1–2 GB RAM when e dey idle, but CPU dey spike hard for transcode. Di gotcha: software transcoding for 4K stream go melt small VPS; either give di box hardware acceleration or keep your files for format wey your clients fit play directly (Direct Play), so di server only dey shovel bytes. Di Jellyfin media server on a VPS guide explain which one be which.
- Navidrome dey replace Spotify for your own music, streaming to any Subsonic-compatible app. Budget 150–300 MB RAM — e dey write for Go and e no dey use much power. Di gotcha: di first library scan dey read every file's tags and fit take one hour for big collection, and if ID3 tags bad, di browsing experience go bad too.
- Audiobookshelf dey replace Audible and your podcast app, dey keep playback position across devices. Budget 200–500 MB RAM. Di gotcha: e dey expect strict folder-per-book layout, and if import folder messy, di library go messy and half-detected, and e go hard to fix later.
Automation and AI
- n8n dey replace Zapier and Make with one visual workflow builder wey you own, and no per-task billing. Budget 400 MB–1 GB RAM. Di gotcha: n8n dey encrypt stored credentials with one key wey e dey generate for first run, and if you lose dat key — or you forget to set
N8N_ENCRYPTION_KEYand e go regenerate am — every saved credential go become unreadable and you go need to re-enter dem all. Di self-hosted n8n with HTTPS guide dey pin di key and put real certificate for front of di webhook URLs. - Ollama dey replace ChatGPT subscription for local, private LLM inference. Budget by model: 7–8B model want about 8 GB of RAM, and each model na 4–8 GB for disk. Di gotcha: for CPU-only VPS, inference dey slow — think words per second, no be di instant replies wey you dey get from hosted API — so set expectations, or rent GPU box. Di run Ollama to self-host an LLM guide get realistic numbers.
Communication
- Rocket.Chat dey replace Slack for team, with threads, calls, and integrations. Budget 2 GB RAM and up, because e dey run on MongoDB and dat one dey heavy. Di gotcha: Rocket.Chat dey pin one specific MongoDB major version per release, and if you skip one version during upgrade, na how you go strand your database — upgrade one step at a time. Di Rocket.Chat with Docker Compose guide dey walk di version ladder.
- Matrix (Synapse) dey replace Slack and Discord with one federated, end-to-end-encrypted network wey you own your homeserver. Budget 1–2 GB RAM wey go grow as you join big public rooms. Di gotcha: Synapse memory use dey swell for big federated rooms, and e must run on PostgreSQL — di default SQLite dey work only for single-user test and e go fail di moment you federate. If Synapse feel heavy, di lighter Conduit or Dendrite servers dey speak di same protocol.
Networking and access
- WireGuard dey replace commercial VPN, dey give you private tunnel to your own IP and your other services. Budget almost nothing — under 50 MB and di crypto dey run for kernel. Di gotcha: for container-based virtualization (OpenVZ, some LXC), di module dey fail with
RTNETLINK answers: Operation not supported; you want KVM. Di self-hosted WireGuard VPN guide na di reference, and pairing am with services wey bound to di tunnel na how you go keep things off di public internet entirely. - Traefik dey replace hand-written nginx virtual hosts and manual certificate renewal — e dey discover your containers by dem labels for Docker and e dey fetch Let's Encrypt certs automatically. Budget around 100 MB RAM. Di gotcha: di label-based config model dey confuse person at first, and one wrong label fit leave app unrouted without obvious error. Di Traefik reverse proxy for multiple Docker apps guide dey built exactly for running several apps for dis page behind one entry point.
- AdGuard Home dey replace Pi-hole box and paid DNS filtering, dey block ads and trackers for every device for your network at di DNS layer. Budget 100–150 MB RAM. Di gotcha: e want to own port 53, wey dey clash with
systemd-resolvedfor Ubuntu — e go fail to start withlisten udp 0.0.0.0:53: bind: address already in useuntil you free di port first.
Monitoring
- Uptime Kuma dey replace Pingdom, UptimeRobot, and StatusPage with one clean dashboard and alerts to almost any channel. Budget 150–300 MB RAM. Di gotcha, and na di one people dey always miss: monitor your production box from one different box — Uptime Kuma wey dey run for di same server wey e dey watch no fit tell you when dat server die. Di Uptime Kuma status monitoring guide cover external placement.
- Zabbix dey replace Datadog and enterprise monitoring suites, with deep agent-based metrics, triggers, and history. Budget 2 GB RAM and up, plus its own database. Di gotcha: Zabbix powerful and e heavy to set up — e be overkill for watching three containers but na di right tool for fleet. Start with Uptime Kuma; graduate to Zabbix monitoring server when you really get infrastructure to monitor.
Prometheus and Grafana no dey for dis list by purpose: dem be superb fleet-scale tooling, but dem heavy pass to run and tune for personal stack of two or three boxes, and Uptime Kuma plus Zabbix answer di same questions for dis scale with less maintenance.
Dashboards and control panels
Dis ones dey change di whole model — instead of to run compose files by hand, one panel dey manage di apps for you.
- Cloudron dey replace di "I wish dis be one-click" wish with one polished app store, automatic TLS, and backups built in. Budget 2 GB RAM minimum, 4 GB comfortably. Di gotcha: e dey follow strict rules and e want to own di whole box, and e free only up to two apps — beyond dat, na paid product.
- CasaOS dey replace messy homelab dashboard with one friendly app grid, free and lightweight. Budget roughly 150 to 300 MB for CasaOS itself. Di gotcha: e designed for trusted home network and e no hardened for di public internet — no expose am directly; reach am over WireGuard.
- Coolify dey replace Heroku, Vercel, and Netlify — git-push deployments, databases, and previews for your own server. Budget 2 GB RAM minimum. Di gotcha: e be younger project wey dey move fast, so pin versions and read release notes before upgrade. Di Cloudron vs CasaOS vs Coolify comparison break down which one of di three fit which person.
Developer and productivity tools
- Gitea (or Forgejo) dey replace GitHub for private repositories, issues, and CI. Budget 200–500 MB RAM. Di gotcha: Forgejo na di community-governed fork of Gitea and na di one many people dey recommend now; both excellent, but pick one and back up di repositories and di database together — repo backup without di database means you lose every issue and pull request.
- Paperless-ngx dey replace filing cabinet and paid document scanners, dey OCR everything so your documents go become searchable. Budget around 1 GB RAM, with CPU spikes during OCR. Di gotcha: di OCR results depend on how good your scans be, and re-processing big archive dey slow — tune am before you bulk-import ten years of paper.
- Actual Budget dey replace YNAB and Mint with fast, local, private envelope budgeting. Budget around 150 MB RAM. Di gotcha: automatic bank sync na separate add-on wey get its own setup, so out of di box, you dey import transactions manually.
- FreshRSS dey replace Feedly and di gone Google Reader — one fast, private feed reader with mobile apps. Budget around 150 MB RAM. Di gotcha: set up di cron-based feed refresh, or feeds no go update unless you open di page.
- BookStack dey replace Notion and Confluence for documentation, organized as shelves, books, and pages. Budget around 500 MB RAM on PHP and MySQL. Di gotcha: e structure content for its own way instead of free-form notes, wey some people love and some people see as rigid — try am before you commit your whole wiki.
- Home Assistant dey replace SmartThings and dozen vendor apps, dey unify your smart home locally. Budget around 1 GB RAM. Di gotcha: much of im magic need local network access to your devices, so e dey live better for hardware for house than for remote VPS — run di dashboard remotely and bridge back if you must.
One representative install
To make am clear, dis na di whole shape for self-host: one compose file, one real certificate, and one backup. Dis na Uptime Kuma, but every app for di list follow di same pattern.
services:
uptime-kuma:
image: louislam/uptime-kuma:2
container_name: uptime-kuma
volumes:
- ./data:/app/data
ports:
- "127.0.0.1:3001:3001"
restart: unless-stoppeddocker compose up -d
docker compose logs -fNote di 127.0.0.1: — di app dey listen only on localhost, and a reverse proxy like Traefik or nginx dey terminate TLS for front of am. Binding straight to 0.0.0.0:3001 na how people dey accidentally publish unencrypted admin panel to di whole internet.
Wetin you NO suppose self-host (yet)
- Email. Dis na di honest one. Outbound port 25 dey blocked by most VPS providers — you go see
Connection timed outfromtelnet aspmx.l.google.com 25and nothing fit fix am, na policy. Even if 25 open, fresh IP wey no get reputation, PTR record, SPF, DKIM, and DMARC go land your mail for spam or dem go reject am outright. Na real, ongoing job, no be weekend work. If you dey set on am, go in with eyes open using di self-hosted email with Mailcow guide, and expect to babysit deliverability for months. - Anything wey you no fit reliably back up and restore. If you never do test restore, you no get backup, you get hope. No put irreplaceable data — di only copy of your photos, your accounts — for one service until you don't prove say e fit restore.
- Your only copy of one critical dependency. One self-hosted DNS server wey, when e crash, dey take your whole network internet with am, na bad first project. Keep one upstream fallback.
- Real-time safety systems. Home alarms, medical alerts, anything wey five minutes downtime na real problem, no belong for hobby box wey you dey upgrade for Sunday night.
How to choose your first one, and di two non-negotiables
Pick di app wey dey remove one bill wey you dey hate or one privacy worry wey you really feel. In practice, di best first installs na Vaultwarden and Uptime Kuma: both tiny, both immediately useful, and both dey forgive if you make mistake. Get one working end to end — install, certificate, backup, restore test — before you add second one. Di skill you dey build na operations, no be just to click install.
Two things na non-negotiable for every single app for above, no exceptions:
- TLS on everything public. Bare-IP, plaintext service na demo, no be deployment. Put real certificate for front of am with Certbot and Let's Encrypt on nginx, or let Traefik do am automatically. Den harden di front door with Fail2ban for SSH on Ubuntu 24.04.
- Backups wey you actually restore. Automate one nightly dump — database and data volume together — send am off di box, and once a month restore am for one throwaway VPS to prove e dey work. Di day your disk die na di wrong day to discover say di backup empty.
Get dem two right and self-hosting go be pleasure. Skip dem and e go be countdown.
Di options dey run from practical to absurd, from one family Minecraft server on a VPS to, if you enjoy cautionary tale, the world's least efficient datacenter.
FAQ
Wetin I suppose self-host first?
Vaultwarden. One password manager dey give you daily value, dey replace subscription, and e dey force you to learn di whole workflow — Docker, one reverse proxy, TLS, and backups — for one app wey small enough to rebuild in ten minutes if you break am. Uptime Kuma na great second, so you go know about outages before your users do.
How much VPS I actually need?
For one small app, 1 GB of RAM dey work. For a comfortable "run a handful of things" box, aim for 4 GB — di 2 GB middle na where people dey hit silent Out-of-Memory container kills and dem no fit work out why. RAM na almost always di limit; add disk to match di data wey you plan to store, and expect Immich, Ollama, and anything wey get big database to want di most of both.
Wetin I suppose I no self-host?
Email, first and foremost — outbound port 25 dey blocked by most providers and deliverability na full-time fight. After dat, anything wey you no fit reliably back up and restore, and any single point of failure wey downtime dey cause real harm, like DNS server wey no get fallback or home safety system. Everything else for dis list na fair game.
I need Docker for all of dis?
No, but you want am. Every app for here get Docker image, and Docker dey give you clean installs, clean removals, easy version pinning, and portability to new host. Some apps (WireGuard, Zabbix) also dey install natively from apt if you prefer. Once you know one compose file, you know dem all, na why di whole list easy to approach.
How I dey keep am secure?
Four habits cover most of am: put TLS for front of everything, keep SSH locked down with key-only login and Fail2ban banning brute-force attempts, expose only di ports wey you truly need publicly and reach di rest over your WireGuard VPN, and update regularly while reading release notes so upgrade no go surprise you. Backups na di fifth habit — dem be your recovery when mistake slip pass di first four.