Self-Hosted Infrastructure Stack for Cost Control

Self-hosted infrastructure stack for cost control and data sovereignty
78% business_ops · carter.keel.me · 35s · tfww
Do this: Our VPS-heavy architecture is validated by this homelab trend, but we should selectively adopt only the tools that beat our current Express/cron and NextAuth setup—specifically Karakeep for research organization and Matomo for GDPR-compliant analytics.

Comparison to Current State

new value DIFFERENT ANGLE

Current:

New: New reel suggests specific self-hosted SSO (Authentik) for unifying authentication across AIAS, TFWW, and CloserSim dashboards, improving security and reducing separate credential management, which is a new security/infra consideration not detailed in the dashboard standard.

new value DIFFERENT ANGLE

Current:

New: The new reel introduces specific tools (Authentik for SSO, Karakeep for research) that could be integrated into an agent dashboard ecosystem, providing concrete technical solutions for user authentication and knowledge management that weren't specified in the abstract 'Agent OS' plan.

new value DIFFERENT ANGLE

Current:

New: This reel provides concrete self-hosted infrastructure components (e.g., Coolify for Docker, MeTube for archive management) that could underpin and manage the deployment and operation of AI agent workflows, adding a layer of practical infrastructure deployment not covered in the abstract workflow orchestration framework.

Similar to: Nellavio Dashboard Standard for New SaaS Tools (0% overlap)
Overlap: dashboard infrastructure, SaaS tools
Different enough to proceed.
Reduces SaaS subscription leakage (potentially $200-500/month in auth/analytics/storage tools) and improves data sovereignty for client information.

Deploy Karakeep for AI-tagged research archives and test Matomo for GDPR-compliant analytics to reduce SaaS costs and improve data sovereignty.

Business Applications

MEDIUM Internal tooling consolidation (general)

Deploy Authentik on VPS2 to provide unified OIDC/SAML auth across AIAS, TFWW, and CloserSim dashboards, eliminating separate credential databases and enabling MFA everywhere.

LOW Research workflow enhancement (general)

Self-host Karakeep instance and integrate with ReelBot's 'knowledge_base' task handler to auto-archive reel references with AI tagging instead of flat Markdown files.

LOW Analytics compliance (meta_ads)

Test Matomo on GnomeGuys as GA4 replacement to eliminate cookie consent requirements and reduce third-party scripts; monitor impact on Meta CAPI integration.

Implementation Levels

Tasks

0 selected

Social Media Play

React Angle

Our take: Solid stack validation—we run similar infrastructure (VPS2 + Coolify) but recently ditched n8n for native Express cron jobs. Would add Authentik for SSO if we expand multi-tenant dashboards.

Repurpose Ideas
Engagement Hook

Solid stack! We just decommissioned n8n in favor of Express cron jobs—found it more reliable for SMS automation. How's your n8n stability been?

What This Video Covers

Carter Keel (carter.keel.me) - Tech/Homelab content creator sharing personal infrastructure stack ('Nerdrotic' hat visible in frame)
Hook: Direct listicle format: 'Every app on my current home lab with a brief description'
“Every app on my current home lab with a brief description”
“I use all these self-hosted tools and services almost every single day”

Key Insights

Analysis Notes

What it is: A catalog of open-source self-hosted alternatives to commercial SaaS products (Plex, Google Analytics, Pocket, Zapier, LastPass/Azure AD) running on Docker/VPS infrastructure.

How it helps us: Validates our decision to decommission n8n and use native Express/Supabase (reducing moving parts). Surfaces Authentik as potential unified auth layer for AIAS + TFWW + CloserSim dashboards. Karakeep could enhance ReelBot's research storage with auto-tagging.

Limitations: Most tools are for personal media consumption (Jellyfin, Audiobookshelf) or infrastructure we already have covered (Proxmox → Coolify, Dockhand → Coolify). MeTube video downloading has legal/ToS concerns for commercial use.

Who should see this: DevOps/VPS admin (Dylan) for infrastructure decisions; ReelBot agent for research tooling integration

Reality Check

🤔 [PLAUSIBLE] "Authentik is a drop-in replacement for Azure/Entra ID" — Authentik supports OIDC/SAML/LDAP and 1M+ installs. However, enterprise SSO migrations require audit trails and backup auth methods we don't currently need. Overkill for 3-person team unless client-facing.
Instead: Continue with NextAuth/Supabase Auth for now; switch to Authentik only if we white-label dashboards for external agencies
⚠️ [QUESTIONABLE] "Self-hosting N8N for automations (listed in stack)" — Creator includes n8n but we decommissioned ours in March 2026 for Express/cron jobs due to reliability issues and 500MB RAM waste. Self-hosting n8n requires maintenance overhead that native code eliminates.
Instead: Our current Express + node-cron architecture (documented in AIAS status) is more stable and debuggable than n8n for our specific SMS/voice workflows

Cost Breakdown →

StepPromptCompletionCost
analysis14,6293,124$0.0135
similarity1,585600$0.0006
plan11,4096,368$0.0191
Total$0.0332