To self-host a website in 2026, decide what kind of site it is, then where it runs. A static site (HTML generated by a tool like Hugo or Astro) needs only a web server such as Caddy, which also gets HTTPS certificates automatically. A site that people edit in a browser needs a CMS: WordPress for flexibility, Ghost for a publication with newsletters. Run either in Docker on a small VPS for the best uptime, or on a home server if your connection allows it. Add privacy-friendly analytics and an uptime monitor, and you have a self-hosted website you fully control.
Step 1: Pick the type of site
| Site type | Software | Resources | Maintenance | Best for |
|---|---|---|---|---|
| Static | A generator (Hugo, Astro, Eleventy) + Caddy or Nginx | Tiny | Very low | Portfolios, docs, personal blogs written in Markdown |
| WordPress | WordPress + MySQL or MariaDB | Small to medium | Medium (core, theme and plugin updates) | Business sites, shops, anything needing plugins |
| Ghost | Ghost + MySQL | Small to medium | Low to medium | Blogs and newsletters with members |
Default to static if you are comfortable writing in Markdown. There is no database, no login page and no PHP to patch, and the whole site is a folder you can copy anywhere. Most "self hosted site" projects that people abandon are dynamic sites that nobody updates.
Step 2: Choose where it runs
A VPS is the right home for most public websites. You get a public IP, symmetrical bandwidth, a data-centre power supply and no conversation with your ISP. A 1 to 2 GB instance runs a static site or a small WordPress or Ghost blog; Ghost's own Docker documentation uses a 2 GB, 1 CPU server as its example.
A home server works well for personal sites and costs nothing extra if it is already running. Check:
- Public IP. Many ISPs use CGNAT, which means you cannot accept incoming connections. A tunnel solves this: Pangolin is a self-hosted, open-source tunnelled reverse proxy that runs on a cheap VPS and forwards traffic to your home, and Cloudflare Tunnel is a hosted alternative.
- Terms of service. Some residential plans forbid servers.
- Uptime. Power cuts and router reboots take your site down. For a hobby site that is fine; for a business it usually is not.
A useful hybrid: build at home, publish static files to a VPS.
Step 3: Sort out the domain and DNS
Every option below assumes you own a domain. Register one with any registrar that offers plain DNS management, then create:
- An A record (and an AAAA record if you have IPv6) pointing the domain, or a subdomain such as
blog.example.com, at your server's public IP. - A
wwwrecord if you want both forms to work; let the web server redirect one to the other.
At home, your public IP may change. Most routers support dynamic DNS, and several DNS providers offer an API that a small container can update automatically. If you use a tunnel, the tunnel provider handles this for you.
Do not plan to send email from the same home server. Residential IPs are widely blocked by mail providers, so contact forms and newsletters should go through a transactional email service even when the site itself is self-hosted.
Choosing a static site generator
If you go static, the generator matters more than the server. Hugo is a single binary and builds very large sites quickly. Astro suits people who know JavaScript and want components. Eleventy is minimal and flexible. All of them take Markdown files and a theme, and all of them produce a folder of plain HTML that any web server, including the setups below, can serve. Pick the one whose themes and documentation you like; switching later is mostly a matter of moving Markdown files.
Option A: a static site with Caddy
Caddy serves files and handles HTTPS with almost no configuration. Build your site into a public folder, then run:
services:
caddy:
image: caddy:2
restart: unless-stopped
ports:
- "80:80"
- "443:443"
- "443:443/udp"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile:ro
- ./public:/srv:ro
- caddy_data:/data
- caddy_config:/config
volumes:
caddy_data:
caddy_config:
With a Caddyfile of three lines:
example.com {
root * /srv
file_server
}
Point your domain's DNS at the server, start the stack, and Caddy requests a certificate from Let's Encrypt or ZeroSSL on its own. Keep the caddy_data volume: it holds your certificates. Our Caddy deploy guide covers compression, headers and redirects, and Caddy vs Nginx explains when Nginx is the better choice. For a single-purpose binary, Static Web Server is another lightweight option, usually behind a proxy.
To publish updates, rebuild locally and sync the folder with rsync, or push to a Git repository and let a CI job do it.
Option B: WordPress in Docker
WordPress still powers a huge share of the web, and the official Docker image makes it straightforward to run. A typical stack is WordPress (PHP and Apache in one image) plus a MySQL or MariaDB database, behind a reverse proxy for HTTPS. Our WordPress deploy guide gives a complete Compose file with MySQL 8.4 and the secrets kept in an .env file.
Security is mostly about discipline:
- Update WordPress core, themes and plugins promptly, and install as few plugins as possible.
- Never expose the database port; keep it on an internal Docker network.
- Use strong admin passwords and two-factor authentication.
- Back up both the
wp-contentfolder and a database dump, not just one of them.
Option C: Ghost for blogs and newsletters
Ghost is a modern publishing platform with an excellent editor, built-in newsletters and paid memberships. It is MIT-licensed and one of the most active projects in the catalog, with 5,329 commits in the last 12 months.
Ghost now ships an official Docker setup, TryGhost/ghost-docker, that runs Ghost, Caddy and MySQL together, with optional ActivityPub federation and Tinybird-based analytics. Ghost describes it as a preview of its new self-hosting tooling, so read the release notes before upgrading. Sending newsletters needs a transactional email provider such as Mailgun.
Torn between the two? Our Ghost vs WordPress comparison goes through editing, plugins, performance and cost.
Add analytics and monitoring
Skip Google Analytics and run your own privacy-friendly analytics:
- Umami is MIT-licensed, light and easy to deploy. See the Umami guide.
- Plausible Analytics offers a polished dashboard; see the Plausible guide.
Plausible vs Umami compares them directly. Then point Uptime Kuma at your site so you hear about an outage before your readers do.
Keep it fast and safe
- Expose only ports 80 and 443. Everything else stays behind the proxy or on a VPN.
- Pin major image versions and update deliberately:
docker compose pull && docker compose up -d. - Put a CDN in front only if you need it; a static site on Caddy is already fast.
- Back up content, databases and the reverse proxy's certificate volume nightly, with one copy off-site.
If you are new to running servers, start with our beginner's self-hosting roadmap, and browse the web servers, CMS and blogging categories for more options.