Proof of Autonomy · Chapter 10

Hosting your own services

In brief

"The cloud" is someone else's computer. Self-hosting means running some of your services, such as your files, your photos, your notes and later a Bitcoin node, on a small computer that you own and keep at home. Beginner-friendly platforms now make installing an app about as easy as on a phone, although backups, updates and remote access still ask for some reading and become your job. The sensible path is to start with 1 service, make it reliable, then grow.

In someone else's cloud you are a tenant

When your files, photos and calendar live in a company's cloud, that company sets the rules. It can read what is not end-to-end encrypted, raise the price, close the product or lock your account through an automated decision, with a support form as your only recourse. It can also change the terms after you have moved in. Google Photos offered free unlimited storage for years, then announced in November 2020 that every new photo would count toward a 15 GB limit from 1 June 2021.

Chapter 8 showed how to move to more respectful providers, which is already a big step, but you remain a tenant there too.

Self-hosting goes a step further, because the service runs on a machine in your home and the data sits on your disk. There is no account that a provider can suspend and no third party between you and your files.

It is not free, however. You pay for the hardware, the electricity and an off-site backup, you pay with your time, and you become the person responsible when something breaks.

A server is a computer that stays on

A server is only a computer that stays on and answers requests from other devices, and a household does not need a data centre for that. An old laptop, a small mini PC or a Raspberry Pi is enough. A mini PC or a laptop with an SSD is usually the most comfortable start, and on a Raspberry Pi an SSD is preferable to a memory card, because cards tend to wear out quickly.

On that computer you install a platform, a system that gives you a web page with an app store. You open it from your browser, click "install" on Nextcloud or Immich, and the platform downloads the app and runs it in a container, a sealed box that keeps each app separate from the others.

Your phone and laptop then talk to this box instead of talking to a company. At home this happens over your own wifi, and from outside you need a safe way in, which has its own section below.

The technology is the smaller part of the change, since backups, updates and security are now yours.

You become your own trusted third party

Self-hosting takes the company out of confidentiality, since nobody else holds the data, and it hands you the other properties. Availability now depends on your disk, your electricity and your backups, and the provider's engineers are replaced by whatever you remember to do. For a beginner, a well-run provider with end-to-end encryption can be the safer choice, and hosting a few services while renting the rest is a sound result.

Some third parties remain, and it helps to name them. The maker of the platform publishes the system updates and curates the app store, so a careless or malicious update would reach every server at once. Open source code, and the possibility to add another store or to install an app by hand, keep that party replaceable. For remote access, Tailscale's coordination server gives each of your devices the public keys of the others. It never sees your traffic, but Tailscale's documentation acknowledges that a malicious coordinator could insert a device into your network, and it offers Tailnet Lock, with which your own devices must sign any newcomer. Headscale or plain WireGuard remove that party, at the price of more configuration.

Choose your platform

All of these are made for people who are not system administrators, and they differ in focus, licence and who stands behind them. The licence matters in a book that puts open source first. StartOS is published under the MIT licence and YunoHost is free software too, whereas umbrelOS uses the PolyForm Noncommercial licence, which lets you read and modify the code for personal use but is not an open-source licence. Start9 and Umbrel both sell their own servers, and neither requires them, since both systems install free of charge on a computer you already own.

Platform Made by Strength Trade-off Who controls apps and updates
Start9 (StartOS) A single company, which also sells servers Open source. Built around sovereignty, with Tor by default and encrypted backups built in Smaller app catalogue, a little more to learn Start9 for the system. 2 default registries, others can be added, and packages installed by hand
YunoHost A volunteer community, non-profit Open source, based on Debian, many apps, a single login for all of them Designed for services reachable from the internet, so domains and email appear early. Plainer interface Volunteers maintain the system and the catalogue. Any app can also be installed from a URL
Umbrel (umbrelOS) A single company, which also sells its own hardware The most polished interface, large app store, strong Bitcoin and Lightning apps The code is public, but the licence is not a true open-source licence (no commercial use) Umbrel for the system and the official store. Community app stores can be added, without review by Umbrel
CasaOS A single company (IceWhale) Open source. A simple layer you add on top of an existing Linux system In maintenance mode as of September 2026, because the company now focuses on its newer ZimaOS. No built-in backups IceWhale for the layer and its store, which accepts other app sources. Your Linux distribution for the system
Debian or Ubuntu with Docker You Full control, you learn how everything really works, no platform to depend on The command line, and nobody to blame. For the curious Debian or Ubuntu for system packages, and the publisher of each container image you pull

What to host first:

App Replaces Note
Nextcloud Cloud drive, calendar, contacts The classic first app. Keep it simple, do not install every add-on
Immich Cloud photo libraries Automatic backup of phone photos. Moves fast, so read update notes
Jellyfin Streaming your own films and music Low risk, a good learning project
Home Assistant Smart home clouds Keeps your home devices local
Vaultwarden The server side of a password manager Works with the Bitwarden apps. Not a beginner's project, because a broken server without a tested backup can cost you every password. Wait until restores are routine
A Bitcoin node Trusting someone else's node Later. See chapter 18

A reasonable setup for most people is an open-source platform such as StartOS or YunoHost on a mini PC, with Nextcloud or Immich as the first app. umbrelOS is the most polished alternative if its licence suits you.

Reaching it from outside, safely

A home router normally refuses connections that start from the internet, so a server behind it is not directly reachable from outside. That protection has known gaps, however. Many routers ship with UPnP turned on, a feature that allows any device or app on your network to open a port by itself, and with IPv6 each device can receive a public address that only the router's firewall keeps closed. It is worth opening the router settings to turn UPnP off and to confirm that the IPv6 firewall is on.

The classic mistake is to open a port on purpose so that your files are reachable from anywhere. It works, and it also shows your login page to every automated scanner on the internet.

Safer options, from most independent to most convenient:

Whatever you choose, change every default password first.

Step by step

The example uses StartOS because it is open source and installs on ordinary hardware. The logic is the same on YunoHost and umbrelOS.

  1. Pick the hardware. An unused laptop or a mini PC with 8 GB of memory and an SSD is plenty. Connect it to your router with a cable, not wifi.
  2. Install the platform. Download the image from the project's website, write it to a USB stick, start the computer from it and follow the installer. When the project publishes a checksum (a fingerprint of the file), as Start9 does on its release page, compare it before you write the image, because this is the step that replaces trust in the download with verification. This erases the computer's disk.
  3. Create your account. Open the address shown at the end of the installation from another device on the same network. Choose a long, unique password and store it in your password manager. If the platform offers two-factor authentication, as umbrelOS does in its settings, turn it on.
  4. Install 1 app. Only 1. Nextcloud or Immich is a good start, so install the phone app, enter your server's address, and let it copy your photos.
  5. Set up backups. Follow the 3-2-1 rule, which means 3 copies of your data, on 2 different devices, with 1 copy in another place. In practice that is the server, a second disk and an encrypted copy off-site (a disk at a relative's home, or an encrypted cloud backup). StartOS writes encrypted backups to an external disk or a network folder, and umbrelOS can run them automatically every hour. If your platform does not schedule them, add a recurring reminder to your calendar.
  6. Test a restore. Recover 1 file from the backup, because a backup is only proven once something has come back from it.
  7. Keep it updated. Install platform and app updates regularly. Once a month is a good rhythm.
  8. Only then add a second app. Live with the first one for a few weeks before you grow.

Mistakes to avoid

Go further

Sources

Your checklist

Your checklist: all →

PreviousTaking back control of your phone NextAI without giving yourself away

Back to contents