Skip to content
appsgit

Guides

How to self-host a website in 2026: static sites, WordPress, Ghost and where to put them

How to self-host a website in 2026: serve a static site with Caddy, run WordPress or Ghost in Docker, and choose between a VPS and a home server for hosting it.

  • appsgit editors
  • Published
  • 6 min read

To self-host a website in 2026, decide what kind of site it is, then where it runs. A static site (HTML generated by a tool like Hugo or Astro) needs only a web server such as Caddy, which also gets HTTPS certificates automatically. A site that people edit in a browser needs a CMS: WordPress for flexibility, Ghost for a publication with newsletters. Run either in Docker on a small VPS for the best uptime, or on a home server if your connection allows it. Add privacy-friendly analytics and an uptime monitor, and you have a self-hosted website you fully control.

Step 1: Pick the type of site

Site type Software Resources Maintenance Best for
Static A generator (Hugo, Astro, Eleventy) + Caddy or Nginx Tiny Very low Portfolios, docs, personal blogs written in Markdown
WordPress WordPress + MySQL or MariaDB Small to medium Medium (core, theme and plugin updates) Business sites, shops, anything needing plugins
Ghost Ghost + MySQL Small to medium Low to medium Blogs and newsletters with members

Default to static if you are comfortable writing in Markdown. There is no database, no login page and no PHP to patch, and the whole site is a folder you can copy anywhere. Most "self hosted site" projects that people abandon are dynamic sites that nobody updates.

Step 2: Choose where it runs

A VPS is the right home for most public websites. You get a public IP, symmetrical bandwidth, a data-centre power supply and no conversation with your ISP. A 1 to 2 GB instance runs a static site or a small WordPress or Ghost blog; Ghost's own Docker documentation uses a 2 GB, 1 CPU server as its example.

A home server works well for personal sites and costs nothing extra if it is already running. Check:

  • Public IP. Many ISPs use CGNAT, which means you cannot accept incoming connections. A tunnel solves this: Pangolin is a self-hosted, open-source tunnelled reverse proxy that runs on a cheap VPS and forwards traffic to your home, and Cloudflare Tunnel is a hosted alternative.
  • Terms of service. Some residential plans forbid servers.
  • Uptime. Power cuts and router reboots take your site down. For a hobby site that is fine; for a business it usually is not.

A useful hybrid: build at home, publish static files to a VPS.

Step 3: Sort out the domain and DNS

Every option below assumes you own a domain. Register one with any registrar that offers plain DNS management, then create:

  • An A record (and an AAAA record if you have IPv6) pointing the domain, or a subdomain such as blog.example.com, at your server's public IP.
  • A www record if you want both forms to work; let the web server redirect one to the other.

At home, your public IP may change. Most routers support dynamic DNS, and several DNS providers offer an API that a small container can update automatically. If you use a tunnel, the tunnel provider handles this for you.

Do not plan to send email from the same home server. Residential IPs are widely blocked by mail providers, so contact forms and newsletters should go through a transactional email service even when the site itself is self-hosted.

Choosing a static site generator

If you go static, the generator matters more than the server. Hugo is a single binary and builds very large sites quickly. Astro suits people who know JavaScript and want components. Eleventy is minimal and flexible. All of them take Markdown files and a theme, and all of them produce a folder of plain HTML that any web server, including the setups below, can serve. Pick the one whose themes and documentation you like; switching later is mostly a matter of moving Markdown files.

Option A: a static site with Caddy

Caddy serves files and handles HTTPS with almost no configuration. Build your site into a public folder, then run:

services:
  caddy:
    image: caddy:2
    restart: unless-stopped
    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"
    volumes:
      - ./Caddyfile:/etc/caddy/Caddyfile:ro
      - ./public:/srv:ro
      - caddy_data:/data
      - caddy_config:/config

volumes:
  caddy_data:
  caddy_config:

With a Caddyfile of three lines:

example.com {
    root * /srv
    file_server
}

Point your domain's DNS at the server, start the stack, and Caddy requests a certificate from Let's Encrypt or ZeroSSL on its own. Keep the caddy_data volume: it holds your certificates. Our Caddy deploy guide covers compression, headers and redirects, and Caddy vs Nginx explains when Nginx is the better choice. For a single-purpose binary, Static Web Server is another lightweight option, usually behind a proxy.

To publish updates, rebuild locally and sync the folder with rsync, or push to a Git repository and let a CI job do it.

Option B: WordPress in Docker

WordPress still powers a huge share of the web, and the official Docker image makes it straightforward to run. A typical stack is WordPress (PHP and Apache in one image) plus a MySQL or MariaDB database, behind a reverse proxy for HTTPS. Our WordPress deploy guide gives a complete Compose file with MySQL 8.4 and the secrets kept in an .env file.

Security is mostly about discipline:

  • Update WordPress core, themes and plugins promptly, and install as few plugins as possible.
  • Never expose the database port; keep it on an internal Docker network.
  • Use strong admin passwords and two-factor authentication.
  • Back up both the wp-content folder and a database dump, not just one of them.

Option C: Ghost for blogs and newsletters

Ghost is a modern publishing platform with an excellent editor, built-in newsletters and paid memberships. It is MIT-licensed and one of the most active projects in the catalog, with 5,329 commits in the last 12 months.

Ghost now ships an official Docker setup, TryGhost/ghost-docker, that runs Ghost, Caddy and MySQL together, with optional ActivityPub federation and Tinybird-based analytics. Ghost describes it as a preview of its new self-hosting tooling, so read the release notes before upgrading. Sending newsletters needs a transactional email provider such as Mailgun.

Torn between the two? Our Ghost vs WordPress comparison goes through editing, plugins, performance and cost.

Add analytics and monitoring

Skip Google Analytics and run your own privacy-friendly analytics:

Plausible vs Umami compares them directly. Then point Uptime Kuma at your site so you hear about an outage before your readers do.

Keep it fast and safe

  • Expose only ports 80 and 443. Everything else stays behind the proxy or on a VPN.
  • Pin major image versions and update deliberately: docker compose pull && docker compose up -d.
  • Put a CDN in front only if you need it; a static site on Caddy is already fast.
  • Back up content, databases and the reverse proxy's certificate volume nightly, with one copy off-site.

If you are new to running servers, start with our beginner's self-hosting roadmap, and browse the web servers, CMS and blogging categories for more options.

FAQ

Questions and answers

Still curious? Email info@appsgit.com.

Can I host a website from my home server?

Yes, but check three things first: whether your ISP gives you a public IPv4 address or puts you behind CGNAT, whether its terms allow servers, and how reliable your power and connection are. A tunnel such as Pangolin or Cloudflare Tunnel gets around CGNAT without opening ports.

What is the cheapest way to self-host a website?

A static site served by Caddy on a small VPS, or on a home server you already run. Static files need almost no CPU or RAM, have no database to attack and are trivial to back up. Use WordPress or Ghost only when you need an editor, members or comments.

Should I self-host WordPress or Ghost?

Choose WordPress for flexibility: themes, plugins, shops and almost any kind of site. Choose Ghost for a fast, focused publication with built-in newsletters and paid memberships. Ghost now has an official Docker Compose setup, currently labelled a preview.

Is a self-hosted website secure?

It can be. Keep the server and containers updated, expose only ports 80 and 443 through a reverse proxy, use automatic HTTPS, keep WordPress plugins to a minimum and back up both files and the database. A static site removes most of the attack surface.

The weekly digest

Liked this? Get the next one by email

Fresh releases, rising projects and one deploy guide a week. Join home labbers and engineers who self-host.

One email a week. No spam, unsubscribe anytime.