ServiceOperations & hosting
Hosting and DevOps, done for you: your sites and apps kept online, backed up and watched
Our hosting and DevOps service runs your websites and web apps in Docker containers on a server you control, with SSL certificates renewed automatically, DNS changes handled carefully, daily snapshots, backups and monitoring. It is the setup we use for our own products: we moved many of our apps off Cloud Run and Vercel onto our own server, and after an audit of 34 projects we roughly halved our own monthly Google Cloud spend.
What we do for you
- An inventory of what you run today: servers, cloud projects, domains, certificates, databases, who has access
- Apps packaged with Docker and Docker Compose, one clear folder per app, configuration kept out of the code
- Builds done on a CI service, not on the production server, so a failed build never takes a site down
- HTTPS on every domain with certificates renewed automatically
- DNS migrations planned record by record, with nameserver changes only after your explicit OK
- Daily server snapshots plus database backups, and a restore actually tested
- Monitoring and a health page showing which services are up
- A plain-language handover: where things run, how to deploy, who to call
Who it is for
- Fits: small businesses and agencies with several sites or apps spread across hosts and cloud accounts
- Fits: teams whose cloud bill grew without anyone knowing what each line is for
- Fits: owners who want their data and servers in their own name, not locked into a platform
- Does not fit: regulated workloads that require a specific certified hosting provider; we will tell you so rather than improvise
What we have done on our own infrastructure
Before offering this, we did it for ourselves. We audited 34 Google Cloud projects, moved many apps from Cloud Run and Vercel onto one server running Docker, and roughly halved our own monthly Google Cloud spend. That server now runs our sites and internal tools, with daily snapshots, backups, monitoring and a health page.
This is our figure, on our setup. Your savings depend on what you run today, and sometimes the right answer is to stay on a managed platform. The audit tells you which.
The building blocks
| Piece | What we do | Why it matters |
|---|---|---|
| Containers | Each app in Docker, started by Docker Compose | The same app runs the same way on a laptop and on the server; moving host is easier |
| Builds | Images built on a CI service, then pulled by the server | A broken build fails in CI, not in production |
| SSL | Free certificates renewed automatically | Let's Encrypt certificates last 90 days by default; renewal has to be automatic |
| DNS | Records copied and checked before any switch | A missed record can stop email or a subdomain silently |
| Backups | Daily snapshots plus database dumps, with a restore test | A backup that was never restored is a hope, not a backup |
| Monitoring | Health checks and a status page | You learn about an outage before your customers do |
SSL and DNS without surprises
Let's Encrypt states that its default certificates are valid for 90 days and recommends renewing them every 60 days; it does not charge for certificates. With lifetimes that short, renewal must be automated and watched, which is what we set up.
DNS is where small mistakes cause big outages. We copy every record, check mail records (MX, SPF, DKIM) before anything else, lower the time-to-live ahead of a move, and never change nameservers without your explicit OK.
Your data stays yours
Servers, domains and cloud accounts stay in your name; we work with the access you grant and you can withdraw it at any time. If personal data is involved, the GDPR expects security measures that ensure the ongoing confidentiality, integrity, availability and resilience of systems, and the ability to restore access to data in a timely manner after an incident (article 32). Backups that are tested and a written restore procedure are part of that.
How we work
- Audit: inventory, costs, risks, and a written recommendation, including what not to move.
- Plan: one app at a time, with a rollback for each step.
- Move: containers, data, certificates, then DNS once the new version is checked.
- Watch: monitoring, snapshots, backups, and a monthly note of what changed.
Rules we keep
- No deletion of a server, database, domain or DNS record without your decision.
- No nameserver change without asking first.
- Secrets kept out of code repositories.
- Old hosting kept as a fallback until the new setup has run cleanly.
Questions we get
Do I have to leave my current host?
No. The audit may conclude that your current platform is the right one. We only move what is clearly better elsewhere, one app at a time, with a way back.
Who owns the server?
You do. The server, domains and accounts are in your name; we operate them with the access you give us.
Will my site be down during the move?
We plan moves so that the old version keeps serving until the new one is checked, then switch DNS. Some changes take time to spread across the internet, which is why we lower DNS time-to-live in advance.
How much will I save?
It depends on what you run. Our own monthly Google Cloud spend roughly halved after our audit, but that is our case, not a promise for yours.
What happens if the server fails?
Daily snapshots and database backups let us rebuild it, and we test a restore before relying on them. The health page and monitoring tell us quickly when a service is down, and the written procedure says what to restore first.
Sources
- Let's Encrypt: FAQ (certificate lifetime and renewal) (checked 2026-10-06)
- CNIL: GDPR text, chapter 4 (article 32, security of processing) (checked 2026-10-06)