Skip to content
appsgit

Guides

How to start self-hosting in 2026: a beginner's roadmap (hardware, Docker, reverse proxy, backups)

How to start self-hosting in 2026: pick hardware or a VPS, install Docker, add a reverse proxy with HTTPS, reach it remotely and back it up, step by step.

  • appsgit editors
  • Published
  • 6 min read

How to start self-hosting in 2026, in short: follow five steps in order: pick a machine, install Linux and Docker, run your first app with Docker Compose, put a reverse proxy with automatic HTTPS in front of it, and set up backups before you trust it with anything important. You do not need a rack or a networking degree. A used mini PC or a $5 VPS, one weekend and the plan below are enough to replace your first paid subscription with software you control.

Step 1: Choose your hardware

There are three good starting points, and you can mix them later.

  • An old laptop or desktop. Free, and fine for learning. Laptops even come with a built-in battery backup. Expect higher power draw from older desktops.
  • A mini PC. The sweet spot for a home server. Machines built on Intel's N100 (a 6 W processor) idle at a few watts, include Quick Sync for video transcoding and take 16 GB of RAM, which is plenty for a dozen apps. Add an SSD for the system and larger disks for media and photos.
  • A VPS. A small cloud server from providers such as Hetzner or DigitalOcean starts at a few dollars a month. It has a public IP and fast upload, which makes it ideal for websites, monitoring and anything that friends need to reach. It is less ideal for terabytes of photos and films.

A note on Raspberry Pi: the Pi 5 is still a capable little server, but memory shortages pushed its prices up sharply through 2026, and an 8 GB or 16 GB Pi now costs about the same as a used x86 mini PC that is faster and easier to expand.

Rule of thumb for RAM: 4 GB runs a handful of light apps, 8 GB runs most home labs, and 16 GB leaves room for photo libraries with machine learning, such as Immich, or local AI.

Step 2: Install Linux and Docker

Install a long-term-support server distribution: a current Ubuntu Server LTS release or Debian 13 are the safest choices because nearly every guide assumes them. Create a normal user with sudo, enable SSH key login, disable password login, and turn on automatic security updates.

Then install Docker Engine with the Compose plugin from Docker's official apt repository, following the steps in Docker's documentation. Docker's get.docker.com convenience script also works, but Docker itself recommends it only for testing. When you are done, this should print a version:

docker compose version

Why Docker? Every app ships as a container image with its dependencies included, and Docker Compose describes the whole app in one readable file. Upgrading becomes "pull the new image and restart", and removing an app leaves nothing behind.

Step 3: Run your first app

Uptime Kuma is an ideal first app: useful from day one, light on resources, and harmless if something goes wrong. Create a folder and a compose.yaml file:

services:
  uptime-kuma:
    image: louislam/uptime-kuma:2
    container_name: uptime-kuma
    restart: unless-stopped
    ports:
      - "127.0.0.1:3001:3001"
    volumes:
      - ./data:/app/data

Run docker compose up -d, and the app is listening on port 3001. Binding to 127.0.0.1 keeps it private until the reverse proxy is in place. Notice the ./data folder: that is where all of the app's state lives, and it is what you will back up. Our Uptime Kuma deploy guide covers notifications and status pages.

If you prefer clicking to editing YAML, Dockge gives you a clean web UI for managing Compose stacks without hiding the files.

Step 4: Add a reverse proxy and HTTPS

A reverse proxy is the single front door to your server. It listens on ports 80 and 443, terminates HTTPS, and forwards each domain to the right container. Only the proxy is exposed; your apps stay on internal ports.

You have three popular options:

  • Caddy gets and renews certificates from Let's Encrypt or ZeroSSL automatically, and redirects HTTP to HTTPS by default. A complete config for the app above is two lines:
status.example.com {
    reverse_proxy localhost:3001
}

Point a DNS record for each subdomain at your server's public IP. At home, forward ports 80 and 443 on your router to the server, and nothing else.

Step 5: Reach it remotely, safely

Not every app should be on the public internet. Admin panels, Docker dashboards and your file server are better kept on a private network. Tailscale builds an encrypted WireGuard mesh between your devices in minutes, and its free Personal plan covers up to six users with unlimited devices. If you want to run the coordination server yourself too, Headscale is an open-source implementation of it.

A good default: publish only what other people need through the reverse proxy, and reach everything else over the VPN.

Step 6: Back up before you trust it

Backups are the step beginners skip and regret. Follow the 3-2-1 rule: three copies of your data, on two different media, with one copy off-site.

For a Docker server, back up each app's data folders and a dump of each database. Do not copy a running database's files and hope; use the app's export command or stop the container first. Then use a deduplicating, encrypted backup tool:

Restic and Kopia can send encrypted backups straight to S3-compatible storage such as Backblaze B2, and BorgBackup is excellent with a second machine or a storage box. Schedule them nightly, and once a month actually restore something to prove the backup works.

Step 7: Keep it healthy

  • Update regularly. Read release notes, then docker compose pull && docker compose up -d. Pin major versions in your image tags so upgrades happen when you choose.
  • Watch it. Point Uptime Kuma at every service, and add Beszel for lightweight CPU, memory and disk monitoring.
  • Make it pleasant. A dashboard such as Homepage gives you one start page with live status for every app.

What to self-host next

Once backups are running, replace one subscription at a time. The most rewarding next steps are Immich for phone photo backup, Vaultwarden for passwords, Jellyfin for media and Pi-hole for network-wide ad blocking. Our ranking of the 25 best self-hosted apps in 2026 has more ideas, every deploy guide follows the same structure as this roadmap, and the self-hosting platforms category lists tools that automate much of it.

Apps mentioned

11 apps in this article

Live GitHub stats, licences and deploy notes for every project we covered.

Browse all apps

FAQ

Questions and answers

Still curious? Email info@appsgit.com.

What hardware do I need to start self-hosting?

Anything that runs 64-bit Linux. An old laptop or a used office mini PC is the cheapest start; an Intel N100 mini PC with 16 GB of RAM handles a dozen typical apps while drawing little power. If you would rather not run hardware at home, a 2 to 4 GB VPS works for most apps.

Is self-hosting safe for beginners?

Yes, if you follow a few rules: keep the operating system and containers updated, expose only a reverse proxy on ports 80 and 443, use HTTPS everywhere, put admin tools behind a VPN such as Tailscale, and keep tested backups. Most incidents come from exposed admin panels and missing updates.

Do I need a domain name to self-host?

No, but it helps. Without a domain you can reach apps over your LAN or a private VPN. With a domain, a reverse proxy like Caddy can get free, automatically renewed HTTPS certificates from Let's Encrypt, and you get memorable addresses for each app.

What should I self-host first?

Start with something low-risk and useful, such as Uptime Kuma for monitoring or a dashboard like Homepage. Move on to apps that hold important data, like Immich or Vaultwarden, only once your backups are working.

The weekly digest

Liked this? Get the next one by email

Fresh releases, rising projects and one deploy guide a week. Join home labbers and engineers who self-host.

One email a week. No spam, unsubscribe anytime.