What it actually runs
Every service here is open source and named. You can look up its security history, read its code, run it yourself, or hand the whole estate to another administrator without asking me for anything.
That is the point of the list, not a boast about the choices. Software nobody else can name is software nobody else can take over.
The foundation
Your own domain, webmail and IMAP, spam filtering.
Runs: Stalwart / mox
Synced storage on every device. Sharing without a third party.
Runs: Nextcloud
One login for everything here. Revoke a device once, everywhere.
Runs: Zitadel
Bitwarden apps, your vault. Shared vaults for family or staff.
Runs: Vaultwarden
Syncs with iPhone, Android, Outlook and Thunderbird.
Runs: CalDAV / CardDAV
Auto-upload, face and place search, shared albums.
Runs: Immich
Nightly encrypted backups, offsite copy, a status page you can check.
Runs: Restic + Gatus
Available on request
Your own exit. Reach every service as if you were at home.
Runs: WireGuard
Ask questions of your own documents. Nothing is sent to OpenAI or Google.
Runs: Ollama + Open WebUI
Scan once. OCR, full-text search, automatic filing.
Runs: Paperless-ngx
Accounts, budgets and reports that stay on your server.
Runs: Firefly III
Tasks and boards for the household or the office. No per-seat billing.
Runs: Vikunja
Your films and music, streamed anywhere. No licence expiring.
Runs: Jellyfin
I fix it on your screen, only when you let me in.
Runs: RustDesk
Private repositories and a wiki, for those who need one.
Runs: Forgejo
What is deliberately not here
No hyperscaler. Not AWS, not Azure, not Google Cloud. The premise of the service is that your data is not sitting in an account somebody else controls, and renting the machine back from Amazon would defeat it.
No private tooling. Nothing here is written by me and understood only by me. Every component has documentation you can read and a community that maintains it.
No proprietary licences that expire. If I disappear, nothing stops working because a subscription lapsed.
How the machine is secured, who holds which key and where it physically sits are on the security page.