One system, not six stitched together
Apps, databases, DNS, TLS, SSO and backups live inside a single reconcile loop.
Open source · Self-hosted · AI-native
App, database, domain, TLS, single sign-on and backups — all handled together. Disconnect from the cloud whenever you like; the machine keeps running.
Install on a blank VPS — one command, no domain needed
curl -fsSL https://get.keenrig.com | shUbuntu 22.04/24.04 · no cloud account · add a domain later if you want
Apps, databases, DNS, TLS, SSO and backups live inside a single reconcile loop.
Describe what you need in plain language and get a running app. For administrators, every state-changing action stops at an approval queue.
Get a ready-made subdomain with a cloud-issued wildcard certificate, or point your own domain and let the instance renew it itself.
Your machine is the source of truth. Disconnecting revokes pairing and stops the agent — it is not a degraded mode.
One command. The installer sets up the gateway, the control process and the local admin UI. When it finishes you already have a working admin UI on the raw IP address — no domain needed yet.
Want multiple environments, ready-made domains, managed backups and cloud AI? Pair with a single-use token. Do not want them? Skip this step forever: no core capability lives behind that door.
Pick from an Ed25519-signed catalog, or describe what you need and let AI propose it. Database, environment variables, subdomain and certificate are provisioned together with the app.
This table is about operating models, not scores. All three columns are reasonable answers to different problems.
| Keenrig | Classic self-hosted PaaS | Cloud PaaS (Railway, Vercel…) | |
|---|---|---|---|
| Where apps run | Your VPS or on-premise server | Your VPS | The vendor's infrastructure |
| Who holds required state | The instance itself | The instance itself | The vendor's cloud |
| If the cloud goes away | Keeps running, full core capability | Not applicable | You lose administration |
| Domain and TLS provided | Yes, or bring your own | You handle it | Yes |
| AI that builds and operates apps | Yes, with an approval queue | No | Partly |
| Cost to self-host | Free | Varies by product | Not applicable |
Every entry is a signed manifest pinned to an image digest — reinstall six months later and you get exactly the same build.
Máy chủ trang tĩnh có nén và cache sẵn. Khác Nginx ở chỗ cấu hình mặc định đã hợp lý cho một site tĩnh, không cần sửa file nào.
Máy chủ web tĩnh. Dùng để kiểm chứng một instance vừa cài: nhẹ, khởi động dưới một giây, và trang mặc định nói rõ nó đang chạy.
Trả về header và địa chỉ của request. App chẩn đoán: nó cho thấy gateway đang chuyển tiếp gì tới container, nên khi định tuyến sai thì đây là chỗ nhìn ra nguyên nhân.
Exactly the things that lived in the cloud: *.keenrig.com subdomains, managed backup storage, cloud-proxied AI, and the multi-environment Console. Apps, databases, single sign-on, certificates for your own domain and the entire local admin UI keep working. Before disconnecting, the platform lists precisely what will break and offers a wizard to migrate onto your own domain.
Yes. Choose the ready-made subdomain and the cloud handles both the DNS records and the wildcard certificate; you never touch a record. If you later want your own domain, a wizard checks the setup automatically and explains failures in plain language.
It keeps what Cloudron does well — an all-inclusive admin experience for self-hosted apps. It adds three things: AI as the primary interface rather than a side utility, ready-made domains and certificates for non-technical users, and an optional cloud layer you can disconnect at any time without losing core capability. The admin UI also works straight away on a raw IP address, so a domain is not a prerequisite.
No. The self-hosted build has no paywall: install it on your machine, no account required, no mandatory outbound network calls. What costs money are the services we genuinely operate for you — managed domains and certificates, backup storage, cloud AI, and the multi-environment Console.
On your machine. The platform database, application data and the identity store all live inside the instance. The cloud only holds the environment list, pairing tokens, billing, managed DNS configuration, and your backups if you chose managed storage — nothing the instance needs in order to run.
No credit card to try. No account at all if you only want to self-host.