Openship is an open source, self-hostable deployment platform — a PaaS you can run on Openship Cloud or on servers you own. You push your code and Openship handles the builds, the configuration, the deployment, the domains and SSL, the monitoring, the backups, the secrets, and the services your applications depend on. It is built for developers who want the convenience of a managed platform without giving up ownership of their infrastructure: start fully managed on Openship Cloud, self-host on your own cloud or on-premises machines, or mix the two, and move between them without changing how you deploy. Setup starts with a single command, npm i -g openship, and the platform is designed for stacks such as Next.js, Node, Python, Go, Rust, Docker, Postgres, Redis, Rails, Laravel, Django and Bun.
The deployment market has traditionally forced a trade-off. Fully managed platforms such as Vercel and Netlify run your workload for you and run it well, but they are managed-only — there is no version you can host yourself. Self-hosted alternatives such as Coolify, Dokploy and Dokku let you host the control panel yourself, but you still bring, run and pay for every server, and a long-lived control-plane box has to stay up around the clock, with your source code landing there first. Openship is built to remove that binary choice. It describes itself as zero lock-in and completely open source under the Apache-2.0 license: on your own servers, removing a project deletes Openship's record and nothing else, so containers, data and configuration keep serving traffic, and Openship can pick them back up later. The dashboard, the CLI, the agents and the infrastructure adapters are all public, readable and auditable, so you can run the platform on a Raspberry Pi or a fleet and contribute back when you want to.
The Deploy group covers six capabilities. Push-to-deploy means every commit builds and ships, with branch environments included, so a branch can have its own environment without manual wiring. Preview deployments give every pull request its own URL that is automatically torn down on merge. Local builds run the image build on your machine so production servers stay focused. Auto-detected stacks figure out the framework, language, package manager and commands for you — Node, Python, Go, Rust, Docker or a monorepo. Smart fixes diagnose and patch common failures such as missing imports and version drift. Instant rollbacks work because every deploy is immutable, so any version can be restored in one click.
The Run group handles what happens once an application is live: auto-scaling that scales horizontally per service, up on traffic and down when idle; load balancing with health checks, weighted routing and sticky sessions built in; live monitoring of CPU, memory, network and disk with real-time charts and alerts; streaming logs that live-tail across services and replicas with search, filter and persistence; scheduled cron-like jobs with retries, visibility and per-run logs; and zero-downtime deploys using rolling restarts, blue-green releases and connection draining. The Connect group covers the network edge: custom domains with unlimited apex and subdomains plus wildcard support; free SSL from Let's Encrypt by default with auto-renewing wildcard certificates; DNS management with visual records, propagation and domain verification in seconds; edge routing on a global edge with anycast IPs and low-latency routing; private networking so services talk over an isolated network with no exposed ports; and first-class WebSockets with persistent connections and sticky routing.
The Services group provisions the backing infrastructure your app depends on: PostgreSQL versions 14 through 17 with daily backups, point-in-time recovery and scheduled upgrades; Redis in cache or persistent mode with cluster mode, pub/sub and streams; MongoDB and MySQL with replica sets, sharding, automated upgrades and migration tools; S3-compatible object storage with signed URLs, lifecycle rules and replication; a mail server for transactional email from your domain with an auto-configured authentication chain; and a CDN for static asset acceleration with cache invalidation on deploy. The built-in mail server is a real mail server on your own box rather than a send-only API. Outbound mail relays through a trusted provider such as Amazon SES or any SMTP so it lands from a warmed, high-reputation IP, while every mailbox, message and byte stays on your server. One click sets up the domains, certificates and the SPF, DKIM and DMARC chain, with reverse DNS verified and configured for you. You can add unlimited sending domains with no add-on or per-domain pricing, and plug straight in from your code through an open SMTP and REST API, with webhooks for opens, clicks and bounces.
The Manage group spans the CLI, the web dashboard, the desktop app, an MCP server, a secrets vault and an audit log. The CLI is a single binary covering deploy, logs, secrets, domains and rollbacks. The web dashboard offers visual deploys, metrics, billing and team access. The desktop app is native to Mac and Windows, letting you push from local and stream logs natively. The MCP server drives deploys from AI agents such as Claude, Cursor or any MCP client, exposed as standard authenticated tools. The secrets vault is encrypted at rest and environment-scoped, with secrets rotated without redeploying, and the audit log records every action, is exportable and is retained for compliance. The Secure group adds a default-deny inbound firewall with per-service policies, per-route rate limiting by IP or token with burst and sustained limits, production security headers including HSTS, CSP, COOP and COEP, edge-level DDoS mitigation with automatic challenge, TLS everywhere with encrypted backups and encrypted secrets, and logs and configuration suitable for SOC 2 and ISO 27001. The Collaborate group adds workspaces for multiple isolated organizations per account, team roles from owner and admin through member and a restricted role, per-resource access down to individual projects and resources, restricted-by-default permissions following least privilege, email invitations with expiring links, an accept flow and per-inviter rate limits, and a member audit of every join, role change and removal.
Openship's overall approach follows a six-stage path: Push, Build, Ship, Wire, Route and Roll back. A git push, a CLI command, the desktop app, or an AI agent over MCP triggers the process. In the Connect stage you link a Git repo and pick a target — Openship Cloud or your own server over SSH — and nothing is installed on your box: no agent, no daemon, no dashboard. Build happens on your machine (or in the cloud) on every push; the image runs your tests and is tagged as an immutable, versioned artifact, keeping production servers focused on serving. Ship streams the built image to the target over plain SSH, where it starts as a fresh container on an isolated private network, with no exposed ports and no hand-written Docker or Compose. Wire joins Postgres, Redis, mail and object storage to the app on that isolated private network, reachable by the app but never by the internet. Route points your domains at the edge, wired through OpenResty with automatic Let's Encrypt SSL, which hands each incoming request to the new container and swaps traffic with zero downtime. Roll back keeps the previous version warm so one click restores it, with no rebuild, no waiting and no lost state. Operate then lets you stream logs, watch metrics and roll back to any previous version in one click from the CLI, the web dashboard, the desktop app or an AI agent over MCP.
The benefits follow from that design. Because the build happens on your machine and the artifact ships to the target over SSH, your source code does not have to sit on an always-on control plane, and production servers can stay focused on serving. Because every deploy is immutable and the previous version stays warm, rollbacks are instant. Because applications are plain containers and services are standard images, workloads can be moved between Openship Cloud and your own servers without rebuilding or rewriting — described as migration in one click, any time, with no exit tax. Self-hosting is free and open source under Apache-2.0 with no billing. Concrete scenarios include a developer deploying a Next.js, Node, Python, Go or Rust application straight from a Git repository; a team that wants a preview URL for every pull request with automatic teardown on merge; an operator connecting an existing VPS from Hetzner, DigitalOcean, AWS or bare metal and adding nodes as they grow; a hybrid setup where burst workloads run on Openship Cloud while sensitive data stays on owned servers; a self-hoster running the whole platform on a Raspberry Pi or a fleet; and an AI-agent workflow where Claude or Cursor drives a deployment over MCP. Openship also points at servers with things already on them, picking up containers already running there without rebuilding or restarting them, and can carry on with an existing Traefik, nginx or Caddy proxy on ports 80 and 443, with the switch reversible in one step.
Openship comes in three shapes. Openship Cloud is the managed option: build and deploy web apps from your repository and manage deployments, domains and logs in one place, with managed builds and application runtimes, HTTPS domains and static site hosting, and credit usage tracked in the dashboard, starting from $5/mo on monthly or annual billing. The self-hosted option runs the entire platform on machines you own — any Linux box, any provider, any region — connecting any VPS such as Hetzner, DigitalOcean, AWS or bare metal, with multi-server fan-out across regions and no agent or dashboard on your boxes; it is free and open source under Apache-2.0. The hybrid option mixes the two: apps on your servers with services on the cloud, or production locally with previews managed, under one billing, one team and one dashboard, where one Cloud subscription covers unlimited self-hosted boxes. The platform is designed for stacks including Next.js, Node, Python, Go, Rust, Docker, Postgres, Redis, Rails, Laravel, Django and Bun, and the interfaces include the CLI, the web dashboard, a native Mac and Windows desktop app, and an MCP server for AI agents.
In summary, Openship takes the convenience of a managed deployment platform and makes it something you can own: push your code, let the build happen locally on an immutable versioned artifact, ship it over SSH to cloud or your own servers, and keep full control of the containers, data and configuration. Deploy anything. Own everything. No proprietary runtime, no vendor lock-in, and an open source codebase you can run, fork and ship.