To migrate from MinIO to RustFS 1.0 with Docker, run RustFS next to MinIO, import the users with mc admin cluster iam, copy the buckets with rclone sync --metadata and compare them with rclone check --download. In my test 4,012 objects arrived identical; versions, tags and public access had to be redone by hand.
To install OpenBao with Docker, run the openbao/openbao:2.6.2 image with Raft storage on a volume, initialise it with bao operator init and unseal it with three of the five keys. OpenBao is the MPL 2.0 fork of HashiCorp Vault and keeps its API, so your applications read secrets the same way.
To migrate Langfuse v3 to v4 with Docker Compose, first upgrade ClickHouse to 26.4 while still on v3, back up PostgreSQL and ClickHouse, start v4 in dual write mode, backfill the history and cut over to events_only once every SDK is compatible. I tested it with 45,931 traces and three Python SDK versions.
File Browser was archived on 31 August 2026 and its v2.63.23 carries at least 8 published vulnerabilities that will never be patched. After testing the alternatives in Docker on the same folder, FileBrowser Quantum is the drop-in replacement, copyparty the lightweight pick for sharing large files, and Filestash the right one when your data lives in S3, SFTP or SMB.
n8n 3.0 is not out yet: n8n plans it for October 2026 and the stable release is 2.39.6. To prepare a Docker install, open Settings > Migration Report, replace the removed nodes, pin the defaults that change, move binaryData to storage and try the v3-nightly image on a copy.
Jellyfin 12.0 came out on 8 September 2026 and rewrites the database on startup, so there is no way back without a backup. In Docker, the safe path is to stop the container, copy /config, remove third-party plugins, change the tag to 12.0, migrate and run a full library scan.
MinIO images no longer pull from Docker Hub, and the quay.io copy is frozen in 2025. To migrate from MinIO to Garage with Docker, run Garage v2.4.1 next to MinIO, copy the buckets with rclone sync, verify them with rclone check, and switch endpoint, keys and region in your clients.
To install Forgejo with Docker, use the codeberg.org/forgejo/forgejo:16.0 image, which since 10 September 2026 is 16.0.4 and fixes a critical remote code execution flaw. Put it behind Caddy with REVERSE_PROXY_TRUSTED_PROXIES set to the proxy's IP, and register Forgejo Runner 13 against the instance's public URL.
n8n is not open source: its Sustainable Use License limits you to your own internal business purposes and forbids charging people to access a hosted instance. Activepieces publishes its core under MIT but keeps agents, projects and API access outside it. Windmill compiles to AGPLv3 from source, yet the distributed Community Edition is not open.
Jellyfin is a GPL-2.0 media server that asks for no account and no subscription. You install it from the official compose file, which publishes port 8096 and mounts three separate volumes for configuration, cache and media. The stable release in August 2026 is 10.11.11, and hardware transcoding is included.
k3s and k0s are Kubernetes distributions you install on a conventional Linux host you keep administering; Talos Linux is an immutable operating system with no shell and no package manager, driven by an API, running upstream Kubernetes. They are not layers: you pick one, and node count decides which.
k3s is a conformant Kubernetes distribution that fits in a 68 MiB binary and installs with one command. It ships containerd, Flannel, CoreDNS, Traefik, ServiceLB and local storage already wired, keeps its state in SQLite, and has a node serving in three seconds.
Karakeep is a self-hosted bookmark manager that stores links, notes, images and PDFs, archives the whole page with monolith and videos with yt-dlp, and tags everything with a language model. It installs from a three-container compose file, and tagging works with either a hosted model or a local Ollama.
Pangolin is an identity-aware tunneled reverse proxy you install on a VPS with Docker Compose. The Newt connector opens the connection outward from your network to the server, so nothing at home listens for inbound traffic, and Traefik issues the Let's Encrypt certificates at the other end.
Immich installs from two files you download from its latest release, docker-compose.yml and .env, plus one docker compose up -d. The server listens on port 2283, the mobile app uploads your camera roll on its own, and your backup has to include the database, not just the photos.
Pocket ID is an OpenID Connect provider that accepts passkeys and nothing else, so it stores no passwords at all. You deploy it with one container, one port and one env file, it demands HTTPS because WebAuthn needs a secure context, and it puts your self-hosted apps behind single sign-on.
Authelia protects applications from the reverse proxy, Pocket ID is a certified OIDC provider that only accepts passkeys, and Authentik adds SAML, LDAP, SCIM and RADIUS in exchange for PostgreSQL, Redis and 2 GB of RAM. Picking homelab SSO means deciding which of those three mechanisms you need.
Komodo is a Rust web application that manages containers, compose stacks and image builds across as many servers as you want. You install it with an official compose file that starts MongoDB, the Core server on port 9120 and the Periphery agent, then add each extra machine with an onboarding key.
Dockge edits your compose files and leaves them untouched on disk; Portainer is the mature all-round console, with roles and GitOps reserved for Business Edition, free up to three nodes; Komodo deploys from Git across several servers with nothing held back for paying users, at the cost of a database and one agent per machine.
The Portainer Agent is a container you deploy on each remote machine, exposing port 9001 over TLS. The Portainer server connects to it and manages that host as one more environment, without exposing the Docker socket to the network or maintaining permanent SSH tunnels.
Headscale is a free, self-hosted implementation of the Tailscale control server: it gives you a private WireGuard mesh network without depending on Tailscale's cloud or its plan limits. This guide brings it up with Docker Compose in its version 0.29.2, prepares the config.yaml file, registers the first node and adds a web panel with headscale-ui.
Home Assistant Container is the local home-automation platform installed as a Docker container: an official image, port 8123 and host-mode networking to discover devices. This guide brings it up with docker-compose, covers the first boot and backups, and makes clear it does not include the Supervisor add-on store.
Gitea is a self-hosted Git service written in Go, lightweight and a single binary, an alternative to GitHub and GitLab. With Docker you install it from a docker-compose.yml alongside PostgreSQL: it publishes the web interface on port 3000 and Git over SSH on port 22, and is configured with GITEA__ variables. It ships Actions for CI and webhooks.
Vaultwarden is a Bitwarden-compatible password server written in Rust and released under the AGPL-3.0 license that barely uses any RAM. This guide brings it up with Docker Compose, publishes it behind a reverse proxy with HTTPS (mandatory for the browser encryption to work), protects the /admin panel with an ADMIN_TOKEN and closes off registration.
wg-easy is the simplest way to self-host a WireGuard VPN: a single container that bundles the server and a web panel to create clients in one click. This guide brings it up with Docker Compose in its version 15, completes the first-run setup wizard on port 51821 and connects your first device with a QR code.
AdGuard Home is a free, open-source DNS server that blocks ads and trackers across your whole network from a single container. This guide brings it up with Docker Compose, fixes the port 53 conflict, walks through the setup wizard and turns on encrypted DNS and DNS rewrites.
Pi-hole is a DNS server that blocks ads and trackers across your whole network. With Docker you install it from a single docker-compose.yml: version 6 embeds the web panel into the pihole-FTL binary, exposes DNS on port 53 and the admin UI on port 80, and is configured with FTLCONF_-prefixed variables.
changedetection.io is an open-source tool that watches web pages and alerts you when they change: prices, stock, versions or official notices. This guide installs it with Docker Compose, adds a Playwright browser container for JavaScript sites, creates watches with CSS or XPath filters and sends notifications to ntfy or Gotify.
IT-Tools bundles more than eighty developer utilities (JWT, hashes, cron expressions, colour converters) into a single web app that runs entirely in your browser. With Docker you bring it up from one docker-compose.yml, it listens on port 80 and stores nothing: with no server and no database, it needs no volume either.
Gotify is a self-hosted push notification server written in Go and released under the MIT license that gathers messages from your scripts and services in one place. This guide brings it up with Docker Compose on port 80, creates an application with its token and sends the first message through its REST API with curl.
ntfy is a free, open-source HTTP-based push notification service that lets you send alerts to your phone or desktop with a simple PUT or POST request to a topic. This guide runs your own ntfy server with Docker Compose, publishes and subscribes to topics, and adds authentication and access control.
Dashy is a self-hosted start page, written in Vue, that gathers all your services onto a single page with status checking, widgets, themes and icons. With Docker you bring it up with a single docker-compose.yml and one image, lissy93/dashy; all its configuration lives in a conf.yml file that you edit by hand or from its visual interface.
Homarr is a service dashboard for your homelab that you configure by dragging and dropping, with no YAML files to edit. With Docker you bring it up with a single docker-compose.yml, it listens on port 7575 and stores everything in its own SQLite database; you only need a 64-character encryption key before you start it.
Homepage is a fast, fully static service dashboard written in Next.js that gathers all your containers into a single front page. With Docker you bring it up with a docker-compose.yml, configure it with YAML files, it listens on port 3000 and discovers your services automatically by reading each container's labels.
Beszel is a lightweight server monitoring platform built on PocketBase that splits into two pieces: a hub with a web dashboard on port 8090 and an agent that runs on each watched machine and listens on 45876. This guide brings both up with Docker Compose, pairs them and sets up alerts.
Glances is a real-time system monitor written in Python that, in web server mode, shows CPU, memory, disk, network and containers from the browser on port 61208. With Docker you bring it up with a single docker-compose.yml, mounting the Docker socket, and it also exposes a REST API at /api/4 to automate things.
Netdata is a real-time monitoring system that, with Docker, shows hundreds of per-second metrics from your server and its containers with almost no configuration. It comes up with a single docker-compose.yml that mounts the host system paths, exposes a full dashboard on port 19999 and automatically detects every service you run.
Dozzle is a real-time log viewer for containers, written in Go: it stores nothing, it reads the logs straight from the Docker socket and streams them to your browser. With Docker you bring it up with a single docker-compose.yml, it listens on port 8080 and shows the live logs of every one of your containers.
Grafana Loki is an open-source log aggregation system that indexes only labels and keeps the content compressed, which makes storage ten to a hundred times cheaper than Elasticsearch. With Docker you bring it up with a single docker-compose.yml, ship your logs with the Docker driver or Grafana Alloy and query them with LogQL in Grafana on port 3100.
Grafana is the most widely used open-source platform for building dashboards and visualising metrics, and with Docker you bring it up with a single docker-compose.yml. It listens on port 3000, stores its data in /var/lib/grafana and connects to Prometheus, Loki or InfluxDB as data sources. Here you install it, provision it and publish it with Traefik.
Node Exporter and cAdvisor are the two exporters that feed Prometheus: the first collects host metrics (CPU, RAM, disk and network) on port 9100, and the second collects per-container metrics on port 8080. This guide brings both up with a single docker-compose.yml, connects them to Prometheus and explains which metrics to watch.
Prometheus is the most widely adopted open-source monitoring and alerting system for self-hosted infrastructure, and with Docker you bring it up with a single docker-compose.yml and a prometheus.yml. It collects metrics using a pull model, stores them in its time-series database and exposes them on port 9090, ready to query with PromQL and visualise in Grafana.
Duplicati is a free backup tool that encrypts your data with AES-256 before sending it and only uploads the blocks that have changed. With Docker you bring it up from a single docker-compose.yml, mount your folders read-only and schedule encrypted backups to S3, MinIO, B2 or SFTP. This guide covers installation, encryption, retention and restore.
Seafile is an open-source file sync and storage platform that keeps data in blocks, Git style, which makes it very fast when you handle lots of files. With Docker it comes up in four containers (server, a MariaDB database, a Redis cache and a Caddy proxy) from a single docker-compose.yml file.
Syncthing is a free peer-to-peer file synchronisation tool: it keeps folders identical across your devices without going through the cloud and with all traffic encrypted. With Docker you bring it up from a single docker-compose.yml using host networking, PUID/PGID for permissions and a persistent volume. This guide covers the installation, device pairing and the ports you need.
MinIO is an object storage server compatible with the Amazon S3 API that you can self-host with Docker. With a single docker-compose.yml you bring up the API on port 9000 and the console on 9001, create buckets and access keys with the mc client, and use it as an S3 backend for backups, attachments and photos.
Adminer and pgweb are two web-based database managers that run in Docker with a single container each. Adminer is one PHP file that handles MySQL, PostgreSQL and six other engines; pgweb is a Go explorer dedicated to PostgreSQL. This guide brings a ready-to-copy docker-compose.yml and explains how to secure them properly.
Redis is an in-memory key-value data store used as a cache, a job queue and a session manager. With Docker you bring it up from a single docker-compose.yml file, with persistence on a volume, a mandatory password and a healthcheck. This guide covers the installation, how to secure it and how it differs from Valkey.
9 min27
We use first- and third-party cookies to analyze site traffic. You can accept them, reject them, or configure your choice.
Learn more about cookies
Cookie preferences
NecessaryEssential for the site to work. Always on.
AnalyticsHelp us understand how the site is used (Google Analytics).