Openship is an open source, self-hostable deployment platform that runs on Openship Cloud or on servers you own. Push your code and Openship handles builds, deployments, domains, SSL, monitoring, backups, secrets, and the services your apps depend on. It is designed for developers and teams who want to ship web applications without giving up control of the runtime they run on. The platform detects the stack you already use — Next.js, Node, Python, Go, Rust, Docker, Postgres, Redis, Rails, Laravel, Django or Bun — so you can deploy anything and own everything.
Most deployment platforms force a trade-off. Fully managed platforms are convenient but managed-only: there is no version you can host yourself, and migrating means redeploying from source. Self-hosting alternatives let you bring your own servers, but their cloud hosts only the control panel — you still run and pay for every server, and a control-plane box often has to stay up around the clock. Legacy self-host tools ask you to hand-write Docker or Compose files and cannot take on an application that is already running. Openship was built to remove that trade-off: no proprietary runtime, no vendor lock-in, no exit tax. Remove the platform from your own servers and your apps keep running.
Deployment starts with a push. Every commit builds and ships, with branch environments included, and every pull request gets its own preview URL that is automatically torn down on merge. Builds run on your machine or in the cloud rather than on your production server, so production stays focused on serving traffic, and each build comes out as an immutable, versioned artifact. Openship auto-detects the framework, language, package manager and commands, and its smart fixes diagnose and patch common failures such as missing imports and version drift. Because every deploy is immutable, you can revert to any previous version in one click.
Once running, services scale horizontally on traffic and back down when idle, with health checks, weighted routing, sticky sessions and load balancing built in. Live monitoring charts CPU, memory, network and disk with real-time alerts, while streaming logs tail across services and replicas with search, filter and persistence. Scheduled cron-like jobs support retries, per-run visibility and per-run logs, and deploys use rolling restarts, blue-green changes and connection draining for zero downtime. On the connectivity side, unlimited apex domains and subdomains are supported including wildcards, Let's Encrypt SSL is issued and auto-renewed by default, DNS records are managed visually, and traffic is routed through a global edge with anycast IPs. Private networking keeps services on an isolated network with no exposed ports, and WebSockets get first-class support with persistent connections and sticky routing.
Openship also ships the services applications depend on: PostgreSQL versions 14 through 17 with daily backups, point-in-time recovery and scheduled upgrades; Redis in cache or persistent mode with cluster mode, pub/sub and streams; MongoDB and MySQL with replica sets, sharding and automated upgrades; S3-compatible object storage with signed URLs, lifecycle rules and replication; a mail server for transactional email from your domain; and a CDN that accelerates static assets and invalidates cache on deploy. You operate all of it from a single CLI binary covering deploy, logs, secrets, domains and rollbacks, a web dashboard for visual deploys, metrics, billing and team access, a native Mac and Windows desktop app, or an MCP server that lets AI agents such as Claude and Cursor drive deployments through authenticated standard tools. A secrets vault keeps values encrypted at rest, scoped per environment and rotatable without redeploying, and an audit log records every action for compliance. Security defaults include a default-deny firewall with per-service policies, per-route rate limiting, production security headers such as HSTS, CSP, COOP and COEP, edge-level DDoS mitigation, TLS everywhere and encrypted backups. For teams, workspaces isolate projects, servers and members across multiple organizations, roles run from owner to a restricted role that starts with zero access, permissions can be granted down to individual projects and resources, invitations use expiring links, and every join, role change and removal is recorded and exportable.
The deploy path is deliberately explicit. A git push, a CLI command, the desktop app or an AI agent over MCP triggers a build; the image builds on your machine (or in the cloud), runs your tests and is tagged as an immutable, versioned artifact. That image then streams to the target over plain SSH and starts as a fresh container on an isolated private network — no agent, no daemon, nothing installed on your box. On the server, managed Postgres, Redis, mail and object storage join the app on that private network, reachable by your app but never by the internet. Your domains resolve to the edge, which terminates free auto-renewing SSL and hands each incoming request to the new container, swapping traffic with zero downtime. The version you were running stays warm, so one click puts it back with no rebuild, no waiting and no lost state. Connecting, building, shipping, routing and operating are the same steps whether you target Openship Cloud, your own VPS, or a homelab.
The outcome is control without losing convenience. On your own servers, removing a project deletes Openship's record and nothing else — containers, data and configuration keep serving traffic, and Openship can pick them back up later. A running app can be moved with its volumes and certificates to another machine and traffic cut over once it checks out. If a server already runs containers, Openship picks them up without rebuilding or restarting anything, and if you already run Traefik, nginx or Caddy on ports 80 and 443, that proxy carries on and the switch is reversible in one step. Configuration lives in openship.json in your repository — build, environment, domains, services and resources — so it is reviewed in a pull request like the rest of your code. Email from your own domain is included rather than bolted on, traffic rules and request logs are built in, and access control and audit are available on every plan.
Typical scenarios include deploying a Next.js, Node, Python, Go or Rust application straight from a repository to a VPS from Hetzner, DigitalOcean, AWS or bare metal; giving every pull request a disposable preview URL; and running a hybrid setup where the cloud absorbs bursts while sensitive data stays on machines you own, or production runs locally while previews are managed. Teams use the built-in mail server to send transactional email from their own domain with unlimited sending domains, and they move workloads between Openship Cloud and self-hosted boxes in one click when priorities change. Developers also drive deployments from the desktop app while their folder or repo goes straight to the machine that will run it, or from an AI agent over MCP.
Openship targets developers, platform teams and organizations that want self-hosted or hybrid deployment without writing Docker and Compose by hand. It works with any Linux box, any provider and any region, adds nodes as you grow, and fans out across regions. Stacks it detects include Next.js, Node, Python, Go, Rust, Docker, Postgres, Redis, Rails, Laravel, Django and Bun, with databases, mail and storage provided as standard images. There are three plans: Openship Cloud, a fully managed option from $5 per month with managed builds and application runtimes, HTTPS domains, static site hosting and credit usage tracking; self-hosted, which is free and open source under Apache-2.0 with no billing; and hybrid, one Cloud subscription plus unlimited self-hosted boxes. The dashboard, CLI, agents and infrastructure adapters are open source and auditable.
Openship packages a complete deployment platform — builds, edge routing, SSL, managed services, mail, security, teams and rollbacks — into something you can run on Openship Cloud or entirely on your own hardware. Deploy anything, own everything, and move between cloud and self-hosted without changing how you deploy.