Keenrig

Open source · Self-hosted · AI-native

Run open-source apps on your own VPS with one command

App, database, domain, TLS, single sign-on and backups — all handled together. Disconnect from the cloud whenever you like; the machine keeps running.

Install on a blank VPS — one command, no domain needed

curl -fsSL https://get.keenrig.com | sh

Ubuntu 22.04/24.04 · no cloud account · add a domain later if you want

Four things that make Keenrig different

One system, not six stitched together

Apps, databases, DNS, TLS, SSO and backups live inside a single reconcile loop.

AI as the primary interface, not a bolted-on button

Describe what you need in plain language and get a running app. For administrators, every state-changing action stops at an approval queue.

Domains and TLS without touching a record

Get a ready-made subdomain with a cloud-issued wildcard certificate, or point your own domain and let the instance renew it itself.

A disconnect switch that actually means something

Your machine is the source of truth. Disconnecting revokes pairing and stops the agent — it is not a degraded mode.

Three steps, and you may skip the second one

  1. Install on a blank VPS

    One command. The installer sets up the gateway, the control process and the local admin UI. When it finishes you already have a working admin UI on the raw IP address — no domain needed yet.

  2. Pair with the cloud — or do not

    Want multiple environments, ready-made domains, managed backups and cloud AI? Pair with a single-use token. Do not want them? Skip this step forever: no core capability lives behind that door.

  3. Install apps

    Pick from an Ed25519-signed catalog, or describe what you need and let AI propose it. Database, environment variables, subdomain and certificate are provisioned together with the app.

Compared with the alternatives

This table is about operating models, not scores. All three columns are reasonable answers to different problems.

 KeenrigClassic self-hosted PaaSCloud PaaS (Railway, Vercel…)
Where apps runYour VPS or on-premise serverYour VPSThe vendor's infrastructure
Who holds required stateThe instance itselfThe instance itselfThe vendor's cloud
If the cloud goes awayKeeps running, full core capabilityNot applicableYou lose administration
Domain and TLS providedYes, or bring your ownYou handle itYes
AI that builds and operates appsYes, with an approval queueNoPartly
Cost to self-hostFreeVaries by productNot applicable
  • Where apps run

    Keenrig
    Your VPS or on-premise server
    Classic self-hosted PaaS
    Your VPS
    Cloud PaaS (Railway, Vercel…)
    The vendor's infrastructure
  • Who holds required state

    Keenrig
    The instance itself
    Classic self-hosted PaaS
    The instance itself
    Cloud PaaS (Railway, Vercel…)
    The vendor's cloud
  • If the cloud goes away

    Keenrig
    Keeps running, full core capability
    Classic self-hosted PaaS
    Not applicable
    Cloud PaaS (Railway, Vercel…)
    You lose administration
  • Domain and TLS provided

    Keenrig
    Yes, or bring your own
    Classic self-hosted PaaS
    You handle it
    Cloud PaaS (Railway, Vercel…)
    Yes
  • AI that builds and operates apps

    Keenrig
    Yes, with an approval queue
    Classic self-hosted PaaS
    No
    Cloud PaaS (Railway, Vercel…)
    Partly
  • Cost to self-host

    Keenrig
    Free
    Classic self-hosted PaaS
    Varies by product
    Cloud PaaS (Railway, Vercel…)
    Not applicable

Frequently asked questions

What do I lose if I disconnect from the cloud?

Exactly the things that lived in the cloud: *.keenrig.com subdomains, managed backup storage, cloud-proxied AI, and the multi-environment Console. Apps, databases, single sign-on, certificates for your own domain and the entire local admin UI keep working. Before disconnecting, the platform lists precisely what will break and offers a wizard to migrate onto your own domain.

I do not know what DNS is. Can I still use this?

Yes. Choose the ready-made subdomain and the cloud handles both the DNS records and the wildcard certificate; you never touch a record. If you later want your own domain, a wizard checks the setup automatically and explains failures in plain language.

How is this different from Cloudron?

It keeps what Cloudron does well — an all-inclusive admin experience for self-hosted apps. It adds three things: AI as the primary interface rather than a side utility, ready-made domains and certificates for non-technical users, and an optional cloud layer you can disconnect at any time without losing core capability. The admin UI also works straight away on a raw IP address, so a domain is not a prerequisite.

Do I have to pay to self-host?

No. The self-hosted build has no paywall: install it on your machine, no account required, no mandatory outbound network calls. What costs money are the services we genuinely operate for you — managed domains and certificates, backup storage, cloud AI, and the multi-environment Console.

Where does my data live?

On your machine. The platform database, application data and the identity store all live inside the instance. The cloud only holds the environment list, pairing tokens, billing, managed DNS configuration, and your backups if you chose managed storage — nothing the instance needs in order to run.

Stand up your first environment today

No credit card to try. No account at all if you only want to self-host.