By LK Wood IV · Published 2026-05-01 · Corrected 2026-09-08 · 15 min read · St. Louis County, MO

Buying guide ranking the top 5 self-hosted apps of 2026 with their SaaS replacement, difficulty score, and RAM floor: Immich (Google Photos, 6 GB), Nextcloud AIO (Drive/Dropbox, 4 GB), Vaultwarden (1Password, 256 MB), Paperless-ngx (Evernote scan, 2 GB), Jellyfin (Plex, 4 GB), plus the other 7 apps and a 32 GB Ryzen 5825U mini PC needing ~24 GB RAM to run all 12.

Here is the entire argument on one screen. On the left, the recurring bills you can stop paying. On the right, the open-source app that does the same job — for the one-time cost of a little RAM instead of a monthly charge.

Cancel the subscription. Keep the software.
The SaaS you stop paying for → the self-hosted app that replaces it, and the RAM it needs to run.
Google PhotosImmich6 GB
Google Drive / DropboxNextcloud AIO4 GB
1Password / LastPassVaultwarden256 MB
Evernote / Dropbox ScanPaperless-ngx2 GB
Plex Pass / NetflixJellyfin4 GB
Pi-hole / NextDNSAdGuard Home256 MB
Paid VPN / ZeroTierTailscale~0
Apple / Google HomeHome Assistant OS2 GB
AudibleAudioBookshelf1 GB
Zapier / Maken8n1 GB
Notion / ConfluenceBookStack1 GB
UptimeRobotUptime Kuma256 MB
The trade~$30–50/mo of SaaS → one ~$170 mini PC. All 12 fit in ~24 GB of RAM.
techfuelhq.com · RAM floors per each project’s docs

TL;DR · The 12-app stack at a glance

  • Photos: Immich (replaces Google Photos)
  • Files / sync: Nextcloud AIO (replaces Dropbox + Google Drive + Office)
  • Passwords: Vaultwarden (replaces 1Password / LastPass)
  • Documents: Paperless-ngx (replaces filing cabinet + scanner cloud)
  • Media: Jellyfin (replaces Netflix-style streaming)
  • DNS / ad blocking: AdGuard Home
  • Remote access: Tailscale (free tier: 6 users, unlimited devices)
  • Smart home: Home Assistant OS
  • Audiobooks: AudioBookshelf
  • Workflow automation: n8n (replaces Zapier)
  • Notes / wiki: BookStack (replaces Notion / Confluence)
  • Monitoring: Uptime Kuma

Full stack runs on a 32 GB Ryzen 5825U or Intel 12th-gen mini PC + 1 TB NVMe. RAM is the bottleneck — Immich + Nextcloud + HA in a VM eats 12–14 GB before any user load.

Correction, September 8: the Immich v3.1.0 setup now uses /data and matching auxiliary files. Tailscale can use encrypted relays. Existing installations should check their mounts before importing more photos.

TL;DR — The 12 picks, voted

The shortlist for the best self hosted apps 2026 is small on purpose. Twelve services that have outgrown their SaaS originals, not fifty half-finished forks. Pi-hole gets demoted for AdGuard Home. Plex gets cut. Mail-in-a-Box does not make the list — self-hosted email in 2026 is still a bad idea for almost everyone. Most entries use Docker; Home Assistant OS belongs in a VM. The top five include setup examples. Tags vary: Immich uses a fixed release here, while Nextcloud AIO uses its supported moving entry point.

The scannable table — 12 apps, what they replace, what they need

#AppReplacesDifficulty (1–5)Hardware floorKiller featureVerdict
1ImmichGoogle Photos / iCloud Photos36 GB RAM, 2 cores, DockerML face + object search that genuinely beats Google’s UIShip it. The 2026 release cadence finally slowed and breaking changes are rare.
2Nextcloud AIOGoogle Drive / Dropbox / Workspace34 GB RAM, 2 coresOne container manages the whole stack including backupsUse AIO. Skip the manual compose.
3VaultwardenBitwarden cloud / 1Password1256 MB RAMBitwarden-compatible, runs on a potato, end-to-end encryptedEasiest win on the list.
4Paperless-ngxEvernote / Dropbox Scan / paper32 GB RAM, OCR is CPU-hungryTika + OCR + tagging makes paper actually searchableReplace your filing cabinet.
5JellyfinPlex / Netflix / Disney+24 GB RAM, Intel iGPU for transcodeNo subscriptions, no phoning home, hardware transcoding worksStill the Plex-killer. AMD GPUs remain weak for transcode.
6AdGuard HomePi-hole / NextDNS1256 MB RAMDNS-over-HTTPS upstream + per-client rules in a clean UIPicked over Pi-hole for the better UI.
7Tailscale (or Headscale)Tailscale itself, ZeroTier, paid VPN1 (Tailscale) / 4 (Headscale)NegligibleWireGuard mesh that punches NAT and “just works”Tailscale free tier is enough for most. Headscale if you want to host the control plane.
8Home Assistant OSApple Home / Google Home / SmartThings42 GB RAM, 32 GB disk, x86-64Local control, no cloud dependency, every protocolRun it as a VM, not a container.
9AudioBookshelfAudible / Libby21 GB RAMTracks progress per-user across devices, podcast support includedDrop-in for an Audible library you already own.
10n8nZapier / Make / IFTTT31 GB RAM400+ integrations, queue mode for real workloadsBeats Zapier for anything serious. Tax: you maintain it.
11BookStackNotion / Confluence (read-mostly)21 GB RAMBooks → Chapters → Pages structure that doesn’t fight youPicked over Outline for simpler hosting.
12Uptime KumaUptimeRobot / Better Stack1256 MB RAMSelf-hostable status page for friends and familyThe first thing every homelab should add after DNS.

Below are the alternatives I would skip, followed by installation examples for the top five.

What got cut and why

  • Plex — not a SaaS replacement; it is the SaaS. Jellyfin replaces Plex.
  • Pi-hole — voted out for AdGuard Home. The DNS-over-HTTPS upstream and per-client rules in AdGuard’s UI are meaningfully better, and the Docker deploy is identical in difficulty. Pi-hole still works fine if you already run it. One deliberate disagreement inside this site: the self-hosting starter order still opens on Pi-hole, because for someone’s first container the smaller footprint and the mountain of beginner documentation matter more than DoH. Both guides are pointing at the same job. This is a preference, not a correctness call.
  • Seafile — solid block-sync, but Nextcloud AIO has closed the gap and the ecosystem (calendar, contacts, office) is broader.
  • Plausible CE / Umami / Mealie / FreshRSS / Linkding — all good, all on the bench. They didn’t beat the 12 above on either daily use or obvious SaaS replacement. If a self-hosted bookmark manager is specifically what you’re after, Linkding is fine but the two strongest options get their own head-to-head in Karakeep vs Linkwarden. If what you actually want is somewhere to read saved articles rather than file links — the job Pocket used to do before Mozilla shut it down — that is a different category, covered in self-hosted read-it-later apps.
  • Mail-in-a-Box / Mailcow — explicitly cut. Self-hosted outbound email in 2026 still gets your IP scored as suspicious by Microsoft and Google more often than not, and inbound MX is fine until your dynamic IP changes or your ISP blocks port 25. Use a paid relay (Fastmail, Migadu, Proton) and move on. The community’s own long-form version of this argument is the r/selfhosted email wiki, linked as further reading rather than as a source: Reddit blocks the automated re-check this site runs on every citation, and its Wayback capture renders empty, so nothing here rests on it.
  • Matrix / Mattermost / Rocket.Chat — a self-hosted chat server is its own category, not a general SaaS swap, so it sits outside this list. There is also no drop-in clone of Discord’s text-plus-voice bundle in 2026, and the voice/video story is the part most roundups skip. If replacing a Discord community or a team chat is what you actually want, the self-hosted Discord alternatives comparison breaks down which tool fits and the voice/video reality. Worth knowing before you pick: Mattermost gates production SSO behind paid plans, and Rocket.Chat moved its advanced identity sync to paid tiers in 2021 — the self-hosted SSO tax tracker documents both with verified receipts and free-SSO alternatives.

A difficulty score of 1 is “single container, defaults work, ten-minute deploy.” A 5 is “you’ll read documentation for a weekend and read it again at the next major upgrade.” Most of the 12 land at 1–3 — the apps that survive in homelabs are the ones where the 80% case is boring.

Where to actually start

Twelve services is a to-do list that stalls before it starts. It shouldn’t. The stack has a natural order — you do not stand up Immich and Home Assistant on day one. You stand up the ten-minute wins first, get the dopamine hit of a working service, then climb. This is the sequence I recommend.

The build order — don’t deploy all 12 at once
Climb the effort curve. Each phase earns you the confidence for the next.
Phase 1 · Day one
Ten-minute wins. Single container, defaults work.
Vaultwarden AdGuard Home Uptime Kuma Tailscale
Passwords, network-wide ad blocking, monitoring, and remote access. Under 1 GB combined. Back up the password vault and keep a way to restore DNS and remote access.
Phase 2 · First weekend
Your media and library. An afternoon each.
Jellyfin Immich AudioBookshelf BookStack
The apps you’ll actually open daily. Immich’s first library import pins a couple of cores for hours — start it before bed.
Phase 3 · Once you’re hooked
The heavy hitters. Read the docs; plan a weekend.
Nextcloud AIO Paperless-ngx n8n Home Assistant
Real commitments with real upside. Home Assistant especially is a hobby, not a deploy — run it as a VM, not a container.
techfuelhq.com · ordering by setup difficulty (see the table above)

The top 5 — full setups

1. Immich — the Google Photos replacement that finally works

Immich is the reason a lot of people built their first homelab in 2025. The mobile app uploads from iOS and Android in the background, the ML stack identifies faces and objects locally, and the timeline UI beats Google Photos for most operations. The catch is RAM — the ML container alone wants ~2 GB at idle, and library import will pin a couple of cores for hours on a fresh install.

This setup uses the v3.1.0 Compose file. Keep its files together; mixing releases can break the setup. For an upgrade, follow the Immich installation guide and the target release’s instructions.

Save the YAML below as docker-compose.yml in a dedicated directory. Download v3.1.0 example.env into that directory and rename it to .env. Also save v3.1.0 hwaccel.transcoding.yml under that exact filename. The extends block reads it even when you select cpu.

Edit .env before starting:

  • Set UPLOAD_LOCATION to your media directory (./library in the example). It mounts at /data inside the server.
  • Set DB_DATA_LOCATION to local database storage (./postgres in the example). The database does not support network shares.
  • Replace DB_PASSWORD=postgres with a random password using only A-Za-z0-9, as the release’s example instructs.
  • Keep DB_USERNAME=postgres and DB_DATABASE_NAME=immich. Set IMMICH_VERSION=v3.1.0 to match the explicit image pins below.
  • Optionally set TZ to your timezone.

The example selects cpu for software transcoding. On an Intel iGPU host with /dev/dri available, change it to quicksync; both services exist in the linked file. That selects device access for the container; configure hardware transcoding in Immich using its transcoding guide.

Critical detail: Immich is not a backup. The database can corrupt. Use Immich’s official backup guide and keep originals on a separate disk from the Immich Postgres.

# docker-compose.yml - Immich v3.1.0
name: immich

services:
  immich-server:
    container_name: immich_server
    image: ghcr.io/immich-app/immich-server:v3.1.0
    extends:
      file: hwaccel.transcoding.yml
      service: cpu # use quicksync for a compatible Intel iGPU host
    volumes:
      # Do not edit the next line. If you want to change the media storage location on your system, edit the value of UPLOAD_LOCATION in the .env file
      - ${UPLOAD_LOCATION}:/data
      - /etc/localtime:/etc/localtime:ro
    env_file:
      - .env
    ports:
      - '2283:2283'
    depends_on:
      - redis
      - database
    restart: always
    healthcheck:
      disable: false

  immich-machine-learning:
    container_name: immich_machine_learning
    # For hardware acceleration, add one of -[armnn, cuda, rocm, openvino, rknn] to the image tag.
    # Example tag: v3.1.0-cuda
    image: ghcr.io/immich-app/immich-machine-learning:v3.1.0
    # extends: # uncomment this section for hardware acceleration - see https://docs.immich.app/features/ml-hardware-acceleration
    #   file: hwaccel.ml.yml
    #   service: cpu # set to one of [armnn, cuda, rocm, openvino, openvino-wsl, rknn] for accelerated inference - use the `-wsl` version for WSL2 where applicable
    volumes:
      - model-cache:/cache
    env_file:
      - .env
    restart: always
    healthcheck:
      disable: false

  redis:
    container_name: immich_redis
    image: docker.io/valkey/valkey:9@sha256:8e8d64b405ce18f41b8e5ee20aa4687a8ed0022d1298f2ce31cdcf3a76e09411
    healthcheck:
      test: redis-cli ping || exit 1
    restart: always

  database:
    container_name: immich_postgres
    image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23
    environment:
      POSTGRES_PASSWORD: ${DB_PASSWORD}
      POSTGRES_USER: ${DB_USERNAME}
      POSTGRES_DB: ${DB_DATABASE_NAME}
      POSTGRES_INITDB_ARGS: '--data-checksums'
      # Uncomment the DB_STORAGE_TYPE: 'HDD' var if your database isn't stored on SSDs
      # DB_STORAGE_TYPE: 'HDD'
    volumes:
      # Do not edit the next line. If you want to change the database storage location on your system, edit the value of DB_DATA_LOCATION in the .env file
      - ${DB_DATA_LOCATION}:/var/lib/postgresql/data
    shm_size: 128mb
    restart: always
    healthcheck:
      disable: false

volumes:
  model-cache:

From this directory, run docker compose config to check interpolation, then docker compose up -d. Before importing your library, upload a disposable photo, recreate the containers, and confirm it remains available. Keep backups of both the media directory and database; container recreation is only a persistence check.

2. Nextcloud AIO — file sync, calendar, contacts, in one container

The official Nextcloud All-in-One project ships everything — Apache, PHP, the database, Redis, the office stack, Talk, the backup container — managed by a single mastercontainer that you talk to over a web UI on port 8080. It is the right answer for new self-hosters and for experienced ones who got tired of debugging PHP-FPM at 1 a.m.

# One-liner from the official AIO README
sudo docker run \
  --init \
  --sig-proxy=false \
  --name nextcloud-aio-mastercontainer \
  --restart always \
  --publish 80:80 \
  --publish 8080:8080 \
  --publish 8443:8443 \
  --volume nextcloud_aio_mastercontainer:/mnt/docker-aio-config \
  --volume /var/run/docker.sock:/var/run/docker.sock:ro \
  ghcr.io/nextcloud-releases/all-in-one:latest

The latest tag here is the AIO mastercontainer, which the project explicitly maintains as the supported entry point — the actual Nextcloud server image underneath gets pinned by AIO to a tested release. That’s the one place I make an exception to the “no :latest” rule. If you want full version control, watch the Nextcloud AIO releases page and use a digest pin instead.

AIO turns on file sync, CalDAV, CardDAV, and Collabora office editing by default. The performance ceiling on a budget mini PC with 16 GB of RAM is around 4–5 active users on a 2.5 GbE network. Beyond that, tune Redis cache before blaming the box.

For the complete setup — NPM reverse proxy config, Office activation, CalDAV/CardDAV client setup, and AIO backup — see the Nextcloud AIO Docker setup guide.

3. Vaultwarden — Bitwarden, on a potato

Vaultwarden is a Rust reimplementation of the Bitwarden server API by dani-garcia. The current stable line is 1.37.x as of August 2026 (1.37.2, 22 Aug 2026), per the Vaultwarden releases. Do not deploy 1.36.x: 1.37.0 shipped fixes for ten GitHub security advisories (eight listed issues), including two SSRF issues on the icon endpoint, cross-organization cipher access, and an organization-policy bypass on directory import, and the maintainers state it “is required for support with clients with version 2026.7.0+.” Take the newest 1.37.x patch rather than 1.37.0 — 1.37.1 repaired organization invites that 1.37.0 broke, and the maintainers say 1.37.2 “is required for support with clients with version 2026.8.0+.” It is fully compatible with the official Bitwarden mobile, browser, and desktop clients, which is the whole point — your phone doesn’t know it’s not talking to Bitwarden’s cloud. For the server-choice decision behind that — the official Bitwarden server’s eleven-container stack versus this single container, and exactly which features you trade away — see Vaultwarden vs Bitwarden.

# docker-compose.yml — Vaultwarden, version-pinned
services:
  vaultwarden:
    image: vaultwarden/server:1.37.2-alpine
    container_name: vaultwarden
    restart: unless-stopped
    environment:
      DOMAIN: "https://vault.example.lan"
      SIGNUPS_ALLOWED: "false"      # flip to true for first user, then back
      ADMIN_TOKEN: "${ADMIN_TOKEN}" # generate with: openssl rand -base64 48
      WEBSOCKET_ENABLED: "true"
    volumes:
      - ./vw-data:/data
    ports:
      - 8222:80

Two things people miss. Vaultwarden needs a real TLS cert for mobile clients — put it behind Caddy or Traefik with Let’s Encrypt, or use Tailscale Funnel for a zero-config TLS path. And back up ./vw-data somewhere off the host — a vault you can’t restore is a vault you don’t have. The Vaultwarden on Proxmox setup guide covers Caddy reverse proxy, the Tailscale-only setup path, and an automated SQLite backup script with online backup API support.

4. Jellyfin — Plex without the company

Jellyfin is the mature fork of Emby. It does what Plex does — library scanning, transcoding, mobile and TV apps — without phoning home, without watching your viewing history, and without a “Pass” subscription gating hardware acceleration.

# docker-compose.yml — Jellyfin with Intel Quick Sync transcoding
services:
  jellyfin:
    image: lscr.io/linuxserver/jellyfin:10.11.11
    container_name: jellyfin
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=America/Chicago
      - JELLYFIN_PublishedServerUrl=http://192.168.1.50:8096
    devices:
      - /dev/dri:/dev/dri   # Intel iGPU passthrough for QSV
    volumes:
      - ./config:/config
      - /srv/media:/data/media:ro
    ports:
      - 8096:8096
    restart: unless-stopped

Intel Quick Sync is what makes Jellyfin viable on a budget mini PC. N100 and 12th-gen-or-newer iGPUs handle 4K HEVC decode without breaking a sweat. AMD GPUs remain the weakest transcode option in 2026 — Jellyfin’s own hardware selection guide calls AMD “the least preferred choice” for its sub-par H.264 encoders before RDNA 4 (RX 9000) and says the poor encoder quality and driver support apply “even on Linux” — so if your homelab is AMD-only, plan for direct-play clients (NVIDIA Shield, Apple TV, a recent smart TV). The Jellyfin team also keeps a clear hardware acceleration matrix; read it before you buy a box.

5. Home Assistant OS — local-first smart home

Home Assistant is on this list because it replaces Apple Home, Google Home, and SmartThings simultaneously, and because the cloud-dependency stories from those vendors keep getting worse. It is not on this list because it is easy. It is rated 4/5 on difficulty for a reason: deep automation requires real time investment.

The recommended path in 2026 is still Home Assistant OS running as a VM, not the Docker container. Per the official installation docs, the container variant loses the Supervisor and the add-on ecosystem, and the add-on ecosystem (Mosquitto, Zigbee2MQTT, ESPHome, the official Z-Wave stack) is most of what makes HA worth running.

For a Proxmox host, the tteck Proxmox Helper Scripts (now community-maintained at community-scripts/ProxmoxVE) install HA OS as a VM in about three minutes. That’s the path. Allocate 2 GB RAM, 2 vCPUs, 32 GB disk, and pass through a USB Zigbee/Z-Wave coordinator if you have one. See the Proxmox vs TrueNAS vs Unraid comparison for which hypervisor fits your situation.

The Home Assistant 2026.3 release notes confirmed the move to zstd-compressed container images; the notes put the floor at Docker 23.0.0 / containerd 1.5.0, so a Docker host that has not been updated past those versions will fail to pull the image, while any modern Docker is fine. Read release notes before every monthly upgrade. HA breaks integrations a few times a year — upgrades are not background tasks.

The other 7 — short notes

AdGuard Home (replaces Pi-hole, NextDNS, your router’s bad ad blocker)

Pin adguard/adguardhome:v0.107.x. Run it on the same box as Uptime Kuma. Point your router’s DHCP DNS at the AdGuard container IP and every device on your network — phones, smart TVs, the IoT garbage — gets DNS-level filtering with zero per-device setup. The DoH/DoT upstream config is in the UI; switch it to Quad9 or Cloudflare 1.1.1.1 and you’ve also leaked less DNS to your ISP than you did last week.

The AdGuard Home + Local DNS on Proxmox tutorial covers the LXC setup from scratch: port 53 in an unprivileged container, OISD and Steven Black blocklists, local A records for pve.lan / nas.lan, and an optional Unbound recursive resolver that cuts upstream providers out entirely.

Tailscale (replaces Tailscale, ZeroTier, paid commercial VPN)

Yes, Tailscale is technically a SaaS for the coordinator. The free personal tier (6 users and unlimited user devices) is enough for almost every homelab, and direct connections are preferred. When a direct path fails, DERP servers or peer relays can carry the traffic; all three paths remain end-to-end encrypted with WireGuard. See Tailscale connection types. The right way to read this is: Tailscale replaces commercial OpenVPN/WireGuard services and ZeroTier, both of which are also SaaS. If you are choosing between those last two, see ZeroTier vs Tailscale. If you genuinely refuse the coordinator, Headscale is the open-source alternative — but plan for a difficulty score of 4, not 1. And if the real question is how to reach these services from outside your LAN at all, Tailscale vs Cloudflare Tunnel covers the private-network-versus-public-tunnel split and the current free-tier limits.

AudioBookshelf (replaces Audible)

If you already own audiobooks (legitimately, ideally), AudioBookshelf gives you per-user progress sync, mobile apps, and podcast support. Single container, no companion services, about 100 MB idle RAM — the lightest useful self-hosted app on this list. The iOS and Android apps are official and free. Podcast RSS auto-download is built in. Pin ghcr.io/advplyr/audiobookshelf:2.36.0 (current as of 27 Jul 2026) rather than :latest, per the no-:latest rule above. Full setup with library directory structure, mobile app config, metadata matching, and Tailscale remote access is in the AudioBookshelf Docker guide.

n8n (replaces Zapier, Make, IFTTT)

400+ integrations, a real queue mode for production workloads, and the ability to drop into JavaScript when the visual builder won’t do what you need. Pin to a specific tag — n8n’s latest has shipped breaking workflow changes inside a single major release before. The n8n Docker image page maintains tags per release; pick the current stable on install day.

For the full setup — PostgreSQL backend, Nginx Proxy Manager HTTPS, queue mode with Redis, and backup strategy — see the n8n self-hosted Docker guide.

BookStack (replaces Notion as a wiki / docs site)

For pure note-taking, Obsidian beats every self-hosted option. For a team or family wiki — recipes, runbooks, “how the network is set up” — BookStack is the right answer. Outline is also good but the hosting story is harder. The stack is two containers (BookStack + MySQL) with about 180 MB idle RAM — the lightest wiki option on this list. Pin lscr.io/linuxserver/bookstack:26.05.3 (current as of 29 Jul 2026) rather than :latest, per the no-:latest rule above, and configure LDAP if you’re already running Authentik or Keycloak for unified auth. Full setup with MySQL, NPM HTTPS, LDAP, and backup is in the BookStack Docker guide.

Uptime Kuma (replaces UptimeRobot, Better Stack)

Already covered in the self-hosting essentials guide. It belongs here because once you have 12 services running, you need to know which one died at 2 a.m. before your family tells you the internet is “broken.” Pin louislam/uptime-kuma:2 (2.5.3 shipped 22 Aug 2026); the 1.x line is a major behind.

Paperless-ngx (replaces Evernote scan, Dropbox Scan, paper)

Drop a PDF in the consume folder, OCR runs, the document is tagged, you can full-text-search five years of mail in seconds. Pin ghcr.io/paperless-ngx/paperless-ngx:3.0.5 (current release, 2026-08-01; the project publishes no bare :3 tag, so use a full release tag or the floating :3.0. On v3 set PAPERLESS_DBENGINE: postgresql explicitly, because v2 inferred the engine from PAPERLESS_DBHOST and v3 no longer does) and run PostgreSQL next to it — not SQLite, which write-locks under concurrent requests. Add Tika and Gotenberg containers alongside; without them, Word and Excel files ingest silently with no searchable text. The full compose stack with correspondent auto-tagging, subdirectory tag mapping, and NPM HTTPS is in the Paperless-ngx setup guide.

What hardware actually runs all 12

Rough memory budget: ~24 GB RAM if you run everything simultaneously with realistic headroom. CPU is less of a problem than people think — Immich’s ML is the spike, and the rest idle hard.

The Proxmox vs TrueNAS vs Unraid comparison covers the OS choice. For hardware, Best Mini PCs for a Homelab in 2026 lands on a 32 GB Ryzen 5825U or Intel 12th-gen-or-newer box, NVMe boot, separate disk for media. If you’re starting from a single mini PC and have never set up Proxmox, the Proxmox mini PC setup walkthrough is the next read. If you have an old gaming PC sitting in a closet, the repurpose-as-server guide skips the hardware purchase entirely. For the complete Docker Compose stack — NPM + Portainer + Uptime Kuma + Watchtower + Gitea with working compose files and a shared proxy network — the Docker Compose starter stack tutorial has everything wired together.

Does it actually save money?

The Self-Hosting Break-Even Calculator answers this for your specific situation — add your subscriptions, set your hardware budget, and see exactly when self-hosting pays for itself. Spoiler: replacing $30–50/month in SaaS with a $170 mini PC usually breaks even in under 6 months.

Pick the box that runs the stack

The 12-app stack needs a real host. The TechFuelHQ PC Builder checks socket / RAM / PSU / GPU clearance compatibility for the AM4, AM5, and Intel platforms that pair well with Docker stacks. For mini-PC turnkey picks, the mini-PC homelab guide covers Minisforum MS-01 (10GbE for storage-heavy stacks) and the cheap used-OptiPlex path. If your stack outgrows a single 2.5GbE link, the 10GbE homelab networking guide covers the cheap switch options.

Sources and methodology

App recommendations synthesize maintainer documentation, deployment guides, and the maintained Docker image tags as of 2026-06-10. RAM and CPU footprint figures are taken from each project’s published documentation.

Primary sources cited:

Email corrections to hello@techfuelhq.com.

Frequently asked questions

What are the best self hosted apps in 2026?
The 12 covered: Immich, Nextcloud AIO, Vaultwarden, Paperless-ngx, Jellyfin, AdGuard Home, Tailscale, Home Assistant OS, AudioBookshelf, n8n, BookStack, and Uptime Kuma. Picked for daily-use value, mature documentation, and a clear SaaS counterpart.
Can a single mini PC run all twelve?
Yes, with a real budget. A 32GB Ryzen 5825U or Intel 12th-gen mini PC with a 1TB NVMe runs the full stack with headroom for a couple of VMs. The bottleneck is RAM — Immich’s ML container plus Nextcloud’s PHP plus Home Assistant in a VM eats 12–14GB before users touch anything.
Is Jellyfin really better than Plex in 2026?
For most homelab setups, yes. No subscription, no remote-access gatekeeping, hardware transcoding works on Intel Quick Sync without paywalls, and the apps on Apple TV, Android TV, and Roku have reached parity with Plex’s basics. Plex still wins on “relatives can install one app.”
Should I self-host email?
No. Outbound deliverability to Gmail and Microsoft 365 is consistently bad from residential IPs in 2026, and inbound on a dynamic IP breaks at the worst times. Use a paid relay (Fastmail, Migadu, Proton) and self-host everything else.
How do I back up these self-hosted services?
Treat the data volumes as the backup target, not the containers. A weekly restic or borg job to a second disk plus an offsite copy (a small VPS, encrypted Backblaze B2, or a friend’s homelab over Tailscale) covers realistic failure modes.
Is Tailscale really self-hosted?
The coordinator is SaaS. Tailscale prefers direct connections, but DERP servers or peer relays can carry traffic when direct paths fail. Traffic remains end-to-end encrypted with WireGuard on all three paths. Headscale is an alternative for a self-hosted control plane.

Evidence ledger

Last updated
Methodology
See our methodology for research and review standards. It draws on 18 cited sources, listed below, each checked against the original page on 2026-05-02.
Sources
Update log
  • 2026-09-08 — Corrected the Immich v3.1.0 storage target and matched its setup files and Compose values. Corrected Tailscale relay routing in prose and both FAQ representations. No deployment test or general version refresh was performed.
  • 2026-08-23 — Cross-page consistency (site audit 2026-08-23, finding SITE-13). This page votes Pi-hole out for AdGuard Home while /articles/self-hosting-essentials/ heads its first section “Pi-hole - Deploy This First, Period”, with no cross-reference either way. Both pages now say the disagreement exists, say why each pick wins its own question, and link to each other. Neither recommendation was reversed.
  • 2026-08-23 — Machine-date consistency: the hand-maintained inline Article JSON-LD carried dateModified 2026-08-19T03:50 while the front-matter lastmod read 2026-08-22T16:19, so the page markup and the sitemap handed Google two different modification dates for the same URL. Both now carry the same stamp. Site audit 2026-08-23, finding SITE-02.
  • 2026-08-22 — Cross-cite sweep: the Uptime Kuma line still told readers to pin louislam/uptime-kuma:1.23.x while this site’s Uptime Kuma guide and Docker starter stack both pin :2, and 2.5.3 is the current release per the GitHub releases API (published 2026-08-22). Corrected to :2.
  • 2026-08-22 — Paperless-ngx pin brought to the current major: :2 -> :3 (v3.0.0 released 2026-07-22) with the v3 requirement to set PAPERLESS_DBENGINE explicitly (paperless-ngx docs/migration-v3.md). Cross-cite found by Goal-5 segment 8; the linked setup guide carries the full compose.
  • 2026-08-24 — CORRECTION to the 2026-08-22 entry above: that pin was wrong. paperless-ngx publishes no bare major tag — GHCR manifest queries return 404 for both :3 and :2, and 200 for :3.0, :3.0.5 and :latest. The compose block here and the two in the linked setup guide would have failed to pull with ‘manifest unknown’. All three now pin :3.0.5 (GitHub releases/latest = v3.0.5, published 2026-08-01T21:59:04Z). The v3.0.0 date and the PAPERLESS_DBENGINE requirement above both re-verified and stand.
  • 2026-08-22 — Cold claim-citation audit (Goal-5 segment 6); every external citation re-fetched 2026-08-22. (1) Immich currency: the page said the current stable is v3.0.3; the GitHub releases API shows v3.1.0 published 2026-07-29 as the newest non-prerelease, so the currency line and both compose pins moved to v3.1.0 (ghcr manifests for immich-server and immich-machine-learning v3.1.0 returned 200). (2) Vaultwarden: the 1.37.0 release notes carry no count; they list eight issues under ten distinct GHSA ids, so ’nine security advisories’ became ’ten GitHub security advisories (eight listed issues)’; 1.37.2 shipped 2026-08-22 and its notes say it is required for 2026.8.0+ clients, so the currency line and the compose pin moved to 1.37.2 (Docker Hub tag 1.37.2-alpine pushed 2026-08-22T12:21Z). (3) The Home Assistant 2026.3 notes say the zstd image change needs Docker 23.0.0 / containerd 1.5.0 and do not mention Synology; the Synology clause was an imported inference and now states the source’s own version floor. (4) The Jellyfin hardware-acceleration matrix does not call AMD weaker; Jellyfin’s hardware-selection guide does (’the least preferred choice’, ’even on Linux’), so the AMD sentence now cites that page and quotes it. (5) Tailscale’s live pricing page shows the Personal plan at up to 6 users and unlimited user devices, the same numbers this page states, so the clause claiming the limits had moved past them was removed.
  • 2026-08-14 — Version-pin drift sweep. (1) The Vaultwarden section asserted ’the current stable line is 1.36.x as of early 2026’ and its compose block pinned vaultwarden/server:1.36.0-alpine. Verified against the GitHub releases API (retrieved 2026-08-14): 1.37.0 shipped 2026-07-24 with fixes for nine security advisories (two SSRF on the icon endpoint, cross-organization cipher access, organization-policy bypass on directory import, Send access-count bypass, unauthenticated WebSocket flooding, cross-organization secret sharing, organization import authorization, Manager-role data enumeration) and its notes state it ‘is required for support with clients with version 2026.7.0+’; 1.37.1 followed 2026-07-29 fixing organization invites that 1.37.0 broke. Handing readers a copy-paste compose file pinned to 1.36.0 was actively harmful for a password-manager server, and it contradicted our own Vaultwarden vs Bitwarden page, which already carried 1.37.1. Currency claim and compose pin both moved to 1.37.1. (2) This page declares a “no ‘:latest’” rule and names Nextcloud AIO as its single exception, then told readers to ‘Pin ghcr.io/advplyr/audiobookshelf:latest’ and ‘Pin lscr.io/linuxserver/bookstack:latest’ – two further ‘:latest’ uses beyond the stated exception, described with the word ‘Pin’, which is the opposite of what ‘:latest’ does. Both now name a real release tag (audiobookshelf 2.36.0, 2026-07-27; BookStack 26.05.3, 2026-07-29, both per the GitHub releases API retrieved 2026-08-14).
  • 2026-05-06 — Content update: 2 draft placeholders replaced with finalized content.
  • 2026-05-06 — Content update: Sources lifted into evidence ledger; inline duplicate Sources / Methodology blocks removed.
Corrections
Spotted an error or a stale number? Email hello@techfuelhq.com. Confirmed corrections are added to the update log above.

About the author

Written by Lowell K. Wood IV, who builds and runs TechFuelHQ from St. Louis, Missouri.