18 min read

Running Your Own Business Software: What Self-Hosting Really Takes, and the Licence Catches

Varun Dubey
Founder, Wbcom Designs · Published Oct 8, 2026
Headline reading self-hosting swaps a bill for a job, with the five upkeep jobs: updates, backups, security, monitoring and an owner

Self-hosting trades a monthly bill for a monthly job: the software is free to download, but running it is not free, and several popular tools carry licence conditions that matter long before the first invoice would have arrived. This guide explains what that job contains, what eight well-known tools (n8n, Keycloak, Nextcloud, Mautic, Metabase, PostHog, Coolify and Forgejo) each ask of you, and where the licence catches sit.

It is written for the person who pays for the running, not the person who types the commands. Every project fact below was read on the project’s own website, documentation, repository or licence file on 8 October 2026, and where a project does not say something we write “not stated on the pages we read”. This is general information, not legal advice.

In this guide

  • What “free to download” leaves you responsible for
  • The five jobs every self-hosted tool creates
  • One short section per tool, with the licence point and when hosted is the better call
  • A comparison table of all eight
  • The licence catches, grouped in plain words
  • When self-hosting is worth it, and when it is not
  • What a maintenance arrangement covers, and questions to ask any provider

Is self-hosted software really free?

The download is free. The running is a standing job: new versions arrive, some fix security problems, and someone has to test and install them, keep copies of the data, watch whether the tool is still up, and answer when it breaks. A hosted service bundles that job into its price. Self-hosting hands it back to you.

The second check is the licence, because “free” and “open source” are not the same promise. Among these eight, n8n uses a licence the project itself says is not standard open source; Metabase, PostHog and n8n split their code into a free part and a paid part; PostHog says plainly that self-hosting is officially unsupported; and Nextcloud, Metabase, Mautic and Forgejo use copyleft licences whose conditions apply when you modify the software or offer it to others.

What are the five jobs every self-hosted tool creates?

1. Updates and upgrades

Projects ship small releases (patches, which fix bugs and security problems) and bigger ones (which add features and can change how things work). Neglect shows up as end of life: the project stops patching your version, so any new security problem found in it stays open on your server.

To check, compare the version on your server with the project’s release page. Our open-source maintenance calendar lists dated end-of-life events for common software. To prevent the problem, test every update on a copy and install it in a planned window. n8n’s documentation advises updating at least once a month so you never jump many versions at once.

2. Backups with a tested restore

A backup must include the database, uploaded files, configuration and the secret keys that decrypt stored passwords. Neglect shows as a restore that fails, or a restored tool that cannot read its own saved credentials. Two projects document this: n8n’s configuration holds the key that encrypts saved credentials, and Coolify’s database backup does not include its key file.

To check, restore the latest backup onto a spare server each quarter and log in, and keep copies off the server itself. It passes only if data, users and connected accounts all work.

3. Security: access, secrets and patches

Three parts: who can log in and how strongly, where passwords and keys live and who rotates them, and how quickly security patches go on.

To check, list every admin account, list where each secret lives, and compare your version with the project’s security page. To prevent it, keep admins few, use your company login where the tool supports it, store secrets in a password manager, and name one person who reads the project’s security announcements.

4. Monitoring and alerts

Something must notice when the tool is down, the disk is nearly full, a scheduled task stopped, or the backup quietly failed. Mautic’s documentation, for example, lists cron jobs (scheduled server tasks) as required for segments and campaigns, so a silent failure just means campaigns stop moving.

To check, ask what happens, and who is told, if the service stops at midnight. The fix is an outside uptime check, disk and memory alerts, a check that the latest backup exists, and one alert channel that a human reads.

5. Someone responsible

Every job above needs a named owner and a named stand-in. This is the job most often skipped, because the person who installed the tool left or assumed IT handled it.

To check, ask two people independently who owns the tool; different answers show the gap. To prevent it, write the owner, stand-in, backup location and update routine on one page. If nobody inside can own it, that is the signal to use hosted or hire the job out.

What does each of the eight tools involve?

n8n (workflow automation)

What it is. n8n calls itself a fair-code platform to build and deploy workflows and AI agents: a visual canvas that connects your other tools and moves data between them. For the hosted alternatives, see Make vs n8n: Which Workflow Automation Tool Should You Pick in 2026? and Zapier vs n8n: Which Automation Tool Is Right for You in 2026?.

The licence point. This is not standard open source, and n8n says so: its documentation states that open-source licences cannot limit use, so it does not call itself open source. The Sustainable Use License allows use or modification only for your own internal business purposes or non-commercial use, and passing it on only free of charge for non-commercial purposes. Files marked “.ee.” fall under a separate Enterprise License. The documentation says offering n8n to your customers so they can connect their accounts and build workflows is outside internal use, while consulting and support services such as building workflows are allowed. Read the licence before relying on it for anything you sell.

Release pace and upkeep. The releases page shows new versions most days, across a stable channel, a beta channel, several 2.x lines and, at the end of September 2026, the older 1.x line. A self-hosted install uses SQLite by default and can use PostgreSQL. A complete backup is the user folder (config and credential key), the external database, any external binary storage and custom nodes. A support window and self-hosted support stance are not stated on the pages we read; the README points to a community forum and paid enterprise licences.

When hosted is better. When automations touch customer data or money and nobody can own backups and the encryption key, or when your use may count as offering n8n to customers. n8n offers a cloud version.

Keycloak (login and identity server)

What it is. An open-source identity and access management server: one place where staff or customers sign in, with single sign-on, social login, and standard protocols such as OpenID Connect and SAML, so applications do not store passwords themselves. It is a Cloud Native Computing Foundation incubation project.

The licence point. The repository licence is Apache License 2.0, permissive, with no copyleft condition.

Release pace and upkeep. A new minor version appears about every quarter, with patches between: 26.7.0 on 9 July 2026, 26.7.5 on 30 September and 26.8.0 on 1 October. The security policy says fixes land in the current major.minor release, so you move forward with the project. Because every connected application depends on it for sign-in, a mistake costs the most here. The documentation says the default development database must be replaced before production, lists supported databases (PostgreSQL, MariaDB, MySQL, Oracle and SQL Server among them), and tells you to back up the database before upgrading. The security page suggests Red Hat’s paid build for long-term support of specific versions. A per-version support window is not stated on the pages we read.

When hosted is better. When sign-in availability is critical and nobody can be on call, or when simple staff sign-in is all you need and a managed service or your existing company login would do.

Nextcloud (files and collaboration)

What it is. A server you run for file storage, sync and sharing, with apps for calendars, contacts, mail and video calls.

The licence point. The README states AGPL-3.0-or-later and the COPYING file is the GNU Affero General Public License v3. Its section 13 says that if you modify the program, your version must offer everyone using it over a network the chance to receive the source. Running it unmodified for your own staff is the simple case.

Release pace and upkeep. The schedule is public: a new major version about every four months, each supported for one year through monthly maintenance releases, with several lines patched together. In September 2026, versions 33, 34 and 35 were supported and 32 had reached end of life. The admin manual lists what to back up: the config folder, any custom apps, the data folder, the theme folder and the database. Upgrades go step by step with no skipping of major releases, and downgrading is not supported. Community help is the forum, while the bug tracker is not a support channel.

When hosted is better. When you want the files without the monthly attention. File storage holds what people care about most, and a failed restore is the worst outcome in this guide.

Mautic (marketing automation)

What it is. Open-source marketing automation: contact records, segments and multi-channel campaigns, run from your own server so contact data stays in your own database.

The licence point. The repository licence is the GNU General Public License v3 or, at your option, any later version. It is copyleft: if you pass on a modified version, section 5 requires the whole work to go out under the same licence.

Release pace and upkeep. The releases page states patch releases monthly, minor versions every three months and majors every two years, and several lines are patched on the same day (5.2.11, 6.0.9 and 7.1.2 on 28 May 2026). It lists security support for 5.2 until 30 June 2026 and for 6.0 until 30 September 2026, both past when we read it, with a paid extended programme for older versions. The requirements page says Mautic needs MySQL or MariaDB, recommends a virtual private server or dedicated server, and says community support for shared hosting is highly unlikely. Cron jobs are required, and the update guide asks for a tested backup first.

When hosted is better. When the real job is email that must arrive. Delivery, sender reputation and cron are ongoing work, and the site lists managed Mautic options.

Metabase (dashboards)

What it is. Metabase calls itself the easy, open-source way for everyone in a company to ask questions and learn from data: connect your databases and build charts and dashboards.

The licence point. Outside the top-level “enterprise” directory the code is AGPL; inside it, the Metabase Commercial License applies. Its licence page says that to embed its charts in your own application you must abide by the AGPL, abide by the embedding licence (which keeps the “Powered by Metabase” logo), or buy a commercial licence. Enterprise code is source available, but its features need the commercial licence.

Release pace and upkeep. Patches are frequent and span several lines on the same day (six lines on 1 September 2026). The documentation’s version selector marks older versions “unsupported” and one line “lts”, yet the security policy says only the latest release typically gets maintenance updates, with possible hotfixes for earlier ones. Ask which line you are on and what it will receive. The application database holds every question and dashboard; the documentation says to avoid the built-in H2 database in production, move to PostgreSQL, and back that database up before each upgrade. A self-hosted support stance is not stated on the pages we read.

When hosted is better. When dashboards drive weekly decisions and a lost application database would cost a reporting cycle, or when you plan to embed charts for customers.

PostHog (product analytics)

What it is. A product analytics platform; its README lists analytics, session replay, heatmaps and error tracking for your website or app.

The licence point. Content outside the “ee/” directory is MIT. Everything inside “ee/” is under a separate PostHog Enterprise licence that allows production use only with an agreement or the right number of user seats, while copying and modifying for development and testing is allowed. The support page calls the self-hosted open-source deployment MIT licensed and provided without a guarantee. Whether your install touches enterprise code is a question to settle by reading the licence before relying on it.

Release pace and upkeep. There are no tagged releases for self-hosters. Changes, including security fixes, ship continuously to the vendor’s cloud and the latest Docker image, and the project recommends running the latest image. The page is direct: self-hosted deployments are officially unsupported, there are no paid support plans, and you carry all the risk, including data loss. The documented “hobby” install is one Linux virtual machine; the page gives size guidance and says to back up before running the upgrade script. The vendor says it lacks the bandwidth to troubleshoot instance-specific problems.

When hosted is better. Usually. PostHog says its cloud is the best experience for the vast majority of users, and its decision flowchart asks about volume, whether infrastructure is a core skill, and whether you accept the risk of data loss.

Coolify (deployment platform)

What it is. An open-source, self-hostable alternative to Heroku, Netlify and Vercel: point it at servers you rent or own and it deploys applications, databases and services. See Coolify: The Open-Source Alternative to Vercel and Heroku for WordPress Developers.

The licence point. The repository LICENSE file is Apache License 2.0, permissive. Nothing on the pages we read limits business use.

Release pace and upkeep. Very frequent: more than twenty 4.3.x releases between 12 August and 18 September 2026, then 4.4.0 on 6 October. The security policy lists 4.x as actively maintained and anything older as end of life. There are two layers: Coolify itself, and the servers it controls. The update guide says to create an instance backup, read the release notes and check for active deployments first, because they can fail mid-update. The backup guide says to keep a copy off the Coolify server and save its encryption key separately. Help is the documentation, Discord and GitHub Discussions; the paid Coolify Cloud hosts the control plane and adds support, but you still manage your own servers.

When hosted is better. When you want deployment convenience without keeping the control plane itself updated and backed up.

Forgejo (Git hosting and CI)

What it is. Lightweight code hosting: Git repositories, issues, pull requests, wikis, package registries and Forgejo Actions, which runs build and test jobs on “runners”. It is a hard fork of Gitea.

The licence point. From version 9.0 it is GNU General Public License v3 or any later version; earlier versions were MIT. It is copyleft, so passing on a modified copy requires the same licence.

Release pace and upkeep. The most predictable of the eight: stable releases arrive on a fixed quarterly schedule, with a long-term version each first quarter. A stable release gets full support for three months plus two weeks after the next one; a long-term release gets critical fixes for one year and three months. Two lines are patched together (16.0.5 and long-term 15.0.9 on the same day in September 2026). It supports MariaDB, MySQL, PostgreSQL and SQLite, each with a minimum version. The upgrade guide calls a full backup a requirement for a new stable release and says to verify afterwards, because a problem found weeks later cannot be fixed by restoring. If you use Actions, you also run and secure the runners, which execute your code.

When hosted is better. When your code is the business and you would rather not be the person restoring it.

How do the eight compare?

ToolLicence in plain wordsRelease paceSelf-hosted support stanceBiggest upkeep task
n8nFair-code, not standard open source; internal business use; read the licence before relying on it for anything you offer to customersVery frequent, several linesCommunity forum; paid licences for extra support; window not stated on the pages we readFrequent updates; backing up the encryption key
KeycloakPermissive open source (Apache 2.0)New minor about each quarter, patches betweenCommunity lists and chat; paid Red Hat build for long-term supportKeeping sign-in available; upgrading on time
NextcloudCopyleft open source (AGPL)New major about every four months; several lines patched monthlyCommunity forum; paid Enterprise subscriptionStep-by-step upgrades; tested restore
MauticCopyleft open source (GPL)Monthly patches, quarterly minors, two-yearly majorsCommunity forums; shared hosting unlikely supported; paid extended supportCron jobs and email delivery
MetabaseOpen source (AGPL) plus paid commercial part; embedding needs a licence choiceFrequent patches, several lines, one long-term lineNot stated on the pages we readMoving off the default database; backing up the application database
PostHogMIT for most code, separate enterprise licence for one directory; read the licence before relying on itContinuous, no tagged releasesOfficially unsupported, no paid support plansStaying on the latest image with tested backups
CoolifyPermissive open source (Apache 2.0)Very frequentCommunity channels; paid hosted version adds supportUpdating the control plane; saving its key; patching your servers
ForgejoCopyleft open source (GPL, from version 9)Fixed quarterly schedule, yearly long-term versionChat room and issue trackerBackups before each upgrade; securing CI runners

Which licence catches should a business owner know about?

This is a plain-words reading of the licence files and project pages, not legal advice. For anything you resell, embed or offer to customers, ask a lawyer to read the licence.

Source-available and fair-code

The code is visible but use is limited, so it is not open source in the standard sense. Here that is n8n. The catch appears when a tool moves from “helps our staff” to “part of what we sell”.

Copyleft

You may use the software freely, but changes you pass on must stay open under the same licence. Nextcloud and Metabase (AGPL) and Mautic and Forgejo (GPL) use it. The AGPL goes further: its section 13, which we read in Nextcloud’s licence file, applies to users who interact with your modified version over a network. The catch matters when you modify the software or embed it in something you offer to others; Metabase says so on its licence page.

Open core with a paid enterprise part

A free core sits beside code under a commercial licence: Metabase’s “enterprise” directory, PostHog’s “ee/” directory and n8n’s “.ee.” files. A feature you can see in the code may not be one you are licensed to use. Nextcloud and Mautic also sell paid services, but those are subscriptions for support, not a split in the code licence as we read it.

Permissive

Keycloak and Coolify use Apache 2.0, which does not require you to share your changes. It still has notice and patent terms, so read the file before building a product on it.

When is self-hosting worth it, and when is it not?

It is worth it when the data must stay in-house because a contract, regulator or customer demands it, when usage is large enough that a hosted bill outgrows the cost of someone’s time, or when you need customisation a hosted plan forbids, and a named person or provider will do the five jobs.

It is not worth it when the team is small and has no time for a monthly routine, when nobody can own the tool and a stand-in, or when compliance duties (such as how fast a vulnerability must be fixed) would land on you rather than a vendor. A hosted plan shortens the list of things you operate. A middle path exists: a vendor-managed version, or a provider who runs the self-hosted software for you, so you keep control of the data while handing over the upkeep.

What does a maintenance arrangement cover for self-hosted tools?

This is the approach, described as duties and not as a price. A sensible arrangement, whoever provides it, looks like this:

  • Each month, updates. Read release and security notes, apply patches to a copy first, then to the live service in an agreed window, and record the version.
  • Each month, backup check. Confirm the latest backup exists, includes database, files and secret keys, and sits off the server.
  • Each quarter, restore test and access review. Restore onto a spare server and log in; remove leavers and rotate shared secrets.
  • Continuously, monitoring. Uptime, disk, memory, and a check that scheduled jobs and backups ran, with alerts to a named person.
  • Ahead of deadlines, upgrade planning. Plan bigger upgrades before your version reaches end of life, using dates like those in our open-source maintenance calendar.
  • When something breaks, incident response. A clear contact route, an agreed response expectation and a short written note afterwards.

What should you ask any provider?

  • Which of these tools do you run today, and how do you handle the licence conditions?
  • Who reads the project’s security announcements, and how fast do you apply a security patch?
  • Where do backups live, do they include the secret keys, and when did you last restore one?
  • What happens if the project ends support for the version we run?
  • Who holds the admin credentials and server access, and how do we get them back if we part?
  • What is not covered, such as the operating system, third-party plugins or custom code?
  • What will we see each month to know it is working?

Questions people ask

Is n8n open source?

Not by the standard definition, and n8n says so in its documentation. Its source is available under the Sustainable Use License, which the project calls fair-code. Internal business use is allowed, enterprise features need a paid licence, and you should read the licence before relying on it for anything you offer to customers.

Which of these tools say self-hosting is unsupported?

PostHog: its page says self-hosted deployments are officially unsupported and there are no paid support plans for them. Several others rely on community help, and Metabase does not state a self-hosted stance on the pages we read.

Can you skip versions when upgrading?

It depends. Nextcloud’s documentation says you cannot skip major releases. Forgejo’s upgrade guide lists known problematic upgrade paths, and n8n advises frequent updates to avoid large jumps. Check the tool’s upgrade guide before planning the work.

What is the most common self-hosting failure?

A backup that was never restored, or one that leaves out the secret keys. Both n8n and Coolify document that stored credentials cannot be read without a key held outside the database.

Does a copyleft licence like the AGPL stop us using the software at work?

No. Using it unmodified for your own staff is the straightforward case. The conditions bite when you modify it, or embed or offer it to others, which is why the AGPL’s network clause deserves a read. We are not lawyers, so confirm your own situation with one.

Is the hosted version always better?

No. It wins when nobody can own the five jobs or when uptime and compliance duties are heavy. Self-hosting wins when data location, scale cost or customisation decides it and someone is named to run it.

If you are weighing a self-hosted tool and want someone to look at the licence, the upkeep and the monthly routine before you commit, we are glad to talk it through. Reach us on our contact page, or describe the project on our start a project page, and we will tell you plainly whether self-hosting, a managed version or a different tool fits.

Varun Dubey
Founder, Wbcom Designs

Varun Dubey is a full-stack WordPress developer with a passion for diverse web development projects. As a Core developer, he continuously seeks to enhance his skills and stay current with the latest technologies in the modern tech world. Connect with him on X @vapvarun.

Related reading