How to start self-hosting in 2026, in short: follow five steps in order: pick a machine, install Linux and Docker, run your first app with Docker Compose, put a reverse proxy with automatic HTTPS in front of it, and set up backups before you trust it with anything important. You do not need a rack or a networking degree. A used mini PC or a $5 VPS, one weekend and the plan below are enough to replace your first paid subscription with software you control.
Step 1: Choose your hardware
There are three good starting points, and you can mix them later.
- An old laptop or desktop. Free, and fine for learning. Laptops even come with a built-in battery backup. Expect higher power draw from older desktops.
- A mini PC. The sweet spot for a home server. Machines built on Intel's N100 (a 6 W processor) idle at a few watts, include Quick Sync for video transcoding and take 16 GB of RAM, which is plenty for a dozen apps. Add an SSD for the system and larger disks for media and photos.
- A VPS. A small cloud server from providers such as Hetzner or DigitalOcean starts at a few dollars a month. It has a public IP and fast upload, which makes it ideal for websites, monitoring and anything that friends need to reach. It is less ideal for terabytes of photos and films.
A note on Raspberry Pi: the Pi 5 is still a capable little server, but memory shortages pushed its prices up sharply through 2026, and an 8 GB or 16 GB Pi now costs about the same as a used x86 mini PC that is faster and easier to expand.
Rule of thumb for RAM: 4 GB runs a handful of light apps, 8 GB runs most home labs, and 16 GB leaves room for photo libraries with machine learning, such as Immich, or local AI.
Step 2: Install Linux and Docker
Install a long-term-support server distribution: a current Ubuntu Server LTS release or Debian 13 are the safest choices because nearly every guide assumes them. Create a normal user with sudo, enable SSH key login, disable password login, and turn on automatic security updates.
Then install Docker Engine with the Compose plugin from Docker's official apt repository, following the steps in Docker's documentation. Docker's get.docker.com convenience script also works, but Docker itself recommends it only for testing. When you are done, this should print a version:
docker compose version
Why Docker? Every app ships as a container image with its dependencies included, and Docker Compose describes the whole app in one readable file. Upgrading becomes "pull the new image and restart", and removing an app leaves nothing behind.
Step 3: Run your first app
Uptime Kuma is an ideal first app: useful from day one, light on resources, and harmless if something goes wrong. Create a folder and a compose.yaml file:
services:
uptime-kuma:
image: louislam/uptime-kuma:2
container_name: uptime-kuma
restart: unless-stopped
ports:
- "127.0.0.1:3001:3001"
volumes:
- ./data:/app/data
Run docker compose up -d, and the app is listening on port 3001. Binding to 127.0.0.1 keeps it private until the reverse proxy is in place. Notice the ./data folder: that is where all of the app's state lives, and it is what you will back up. Our Uptime Kuma deploy guide covers notifications and status pages.
If you prefer clicking to editing YAML, Dockge gives you a clean web UI for managing Compose stacks without hiding the files.
Step 4: Add a reverse proxy and HTTPS
A reverse proxy is the single front door to your server. It listens on ports 80 and 443, terminates HTTPS, and forwards each domain to the right container. Only the proxy is exposed; your apps stay on internal ports.
You have three popular options:
- Caddy gets and renews certificates from Let's Encrypt or ZeroSSL automatically, and redirects HTTP to HTTPS by default. A complete config for the app above is two lines:
status.example.com {
reverse_proxy localhost:3001
}
- Nginx Proxy Manager does the same through a web interface, which many beginners prefer. See our Nginx Proxy Manager guide.
- Traefik discovers containers through Docker labels. It has a steeper learning curve and pays off once you run many apps.
Point a DNS record for each subdomain at your server's public IP. At home, forward ports 80 and 443 on your router to the server, and nothing else.
Step 5: Reach it remotely, safely
Not every app should be on the public internet. Admin panels, Docker dashboards and your file server are better kept on a private network. Tailscale builds an encrypted WireGuard mesh between your devices in minutes, and its free Personal plan covers up to six users with unlimited devices. If you want to run the coordination server yourself too, Headscale is an open-source implementation of it.
A good default: publish only what other people need through the reverse proxy, and reach everything else over the VPN.
Step 6: Back up before you trust it
Backups are the step beginners skip and regret. Follow the 3-2-1 rule: three copies of your data, on two different media, with one copy off-site.
For a Docker server, back up each app's data folders and a dump of each database. Do not copy a running database's files and hope; use the app's export command or stop the container first. Then use a deduplicating, encrypted backup tool:
restic
Fast, secure and efficient backup program with encryption and deduplication.
Kopia
Cross-platform backup tool with encryption, deduplication and a web UI.
BorgBackup
Deduplicating backup program with compression and authenticated encryption.
Restic and Kopia can send encrypted backups straight to S3-compatible storage such as Backblaze B2, and BorgBackup is excellent with a second machine or a storage box. Schedule them nightly, and once a month actually restore something to prove the backup works.
Step 7: Keep it healthy
- Update regularly. Read release notes, then
docker compose pull && docker compose up -d. Pin major versions in your image tags so upgrades happen when you choose. - Watch it. Point Uptime Kuma at every service, and add Beszel for lightweight CPU, memory and disk monitoring.
- Make it pleasant. A dashboard such as Homepage gives you one start page with live status for every app.
What to self-host next
Once backups are running, replace one subscription at a time. The most rewarding next steps are Immich for phone photo backup, Vaultwarden for passwords, Jellyfin for media and Pi-hole for network-wide ad blocking. Our ranking of the 25 best self-hosted apps in 2026 has more ideas, every deploy guide follows the same structure as this roadmap, and the self-hosting platforms category lists tools that automate much of it.