Most people who try self-hosting start with the wrong app. They pick the password manager first, because it is the one they care about most, put every login they own on a server they set up that afternoon, and then meet their first broken update with no backup they have ever tested. A lot of them go back to SaaS the same week.
The apps are not the hard part. The order is. Start with something that cannot hurt you when it breaks, learn the three habits that keep a server alive, and only then move the data that matters. Here is the order I would run it in, and what each step is there to teach you.
The short version
| Order | App | What it replaces | Why it goes here |
|---|---|---|---|
| 1 | Uptime Kuma | UptimeRobot, Pingdom | If it goes down, nothing else does. Zero-risk practice. |
| 2 | Memos | Google Keep, quick notes in Notion | Your first real data, but data you could live without for a day. |
| 3 | Umami | Google Analytics, Plausible | Your first app with a real database behind it. |
| 4 | n8n | Zapier, Make | Your first app that holds keys to other systems. |
| 5 | Vaultwarden | Bitwarden, 1Password, LastPass | The highest-stakes data you have. It goes last on purpose. |
1. Uptime Kuma: the app that cannot hurt you
Uptime Kuma checks whether your sites and services are up (HTTP, TCP, ping and more) and tells you when they are not. It also gives you a public status page.
It is the right first app for one reason: when your monitor is down, nothing your users touch is down with it. You can break it, restore it, upgrade it badly and try again, and the only cost is a gap in a graph. That makes it the cheapest place to learn how your server behaves.
One rule, though. Do not run your only monitor on the same server as the things it watches, because it will go quiet at exactly the moment you need it. I wrote more on that in where your uptime monitor should live.
2. Memos: your first real data
Memos is a small open-source notes app, closer to a private timeline than to a full workspace. By default it keeps everything in a single SQLite file.
That single file is the lesson. Stop the app, copy that file somewhere else, delete the original, and put it back. If your notes reappear, you have just done your first restore, and you now know more about backups than most people who have self-hosted for a year.
3. Umami: your first database
Umami is privacy-friendly web analytics with no cookie banner to maintain. Unlike Memos, it needs PostgreSQL running next to it.
This is where self-hosting stops being “copy a folder”. A database has to be dumped properly to be backed up, and it wants more memory than a notes app. If the first two steps went well, this one is a manageable jump. If you skipped them, this is usually where people get stuck.
4. n8n: your first app that holds other people’s keys
n8n is workflow automation, the self-hosted answer to Zapier and Make. To do its job it stores credentials for everything it connects to: your CRM, your mail provider, your payment tool.
n8n encrypts those credentials with an encryption key. Lose that key and the stored credentials cannot be decrypted, even if you still have the database. So by step four your backup has to include secrets and configuration, not only data. That is a different habit, and it is the one you need before step five.
If you are moving off n8n rather than onto it, this guide picks the alternative by your constraint.
5. Vaultwarden: last, on purpose
Vaultwarden is a lightweight server that works with the official Bitwarden apps and browser extensions. It is small, fast and well loved.
It is also the one app on this list where a lost backup or an exposed server is a genuine emergency. Its web vault needs HTTPS to work, it needs backups you have restored at least once, and it needs you to notice when an update lands. By now you have practiced all three on apps where a mistake was cheap. The fuller comparison is in self-hosted password managers compared.
The three habits that matter more than the apps
- Restore before you trust. A backup you have never restored is a hope, not a backup. Do one test restore per app, on day one.
- Update on a schedule. Pick a day each month. Read the release notes, take a backup, update, check that it still works. Apps that are a year behind are the ones that get broken into.
- Put everything on your own domain. If your apps live at an address you control, you can move them to another server later without anyone noticing.
What it costs, and where to run it
The old way is one server that you build yourself: provision it, install the runtime, configure nginx, set up SSL, the firewall and a process manager, point the domain and DNS at it, then repeat most of that for every app. It works, and if you enjoy server admin it is the cheapest route, because one small VPS can run all five of these.
If you would rather skip that part, I run mine on InstaPods, where each app is a one-click deploy on its own real Linux server with SSH access, HTTPS and a custom domain handled for you. Pricing is flat:
| App | Smallest plan it runs on | Price |
|---|---|---|
| Uptime Kuma | Launch (1 vCPU, 512 MB, 10 GB) | $3/mo |
| Memos | Launch | $3/mo |
| Umami | Build (2 vCPU, 2 GB, 25 GB) | $7/mo |
| n8n | Build | $7/mo |
| Vaultwarden | Launch | $3/mo |
All five is $23/mo with no usage meter, but that is not how I would start. Start with step one on a single $3 pod. You need a card to deploy, and adding it gives you a $10 credit, which covers about the first three months of that pod. That is long enough to find out whether you like running your own software before it has cost you anything.
Two honest limits. The $3 plan is for the light apps and does not include a managed database, which is why Umami and n8n sit on the $7 plan. And if you already have a VPS you are comfortable administering, stacking all five there will cost less per app than five separate pods.
When not to self-host
Skip it for email, which is a full-time job to keep deliverable. Skip the password manager step if your company has compliance rules that name a vendor. And skip anything where an hour of downtime costs real money and nobody is on call. Whether the numbers work at all is a separate question, and I went through it in is self-hosting actually cheaper than SaaS.
Where to go after the first five
Once the habits are in place, the list of things you can move gets long: help desks, PDF tools, whiteboards, feedback boards, social scheduling. This directory of self-hosted apps ranks the open-source options by GitHub stars and shows what each one replaces and what resources it needs, which makes it a quick way to pick app number six.
The short of it: monitor first, vault last, and never trust a backup you have not restored.
