Self-hosting your office: one VPS, zero SaaS
Your team's conversations are its most sensitive data. Here is the stack that runs a whole Remote Desk floor, media server and all, on a server you control.
The Remote Desk team
Most collaboration tools treat self-hosting as an enterprise afterthought: a crippled installer, a pricing call, a PDF. We think it's table stakes. If a tool carries your team's every conversation, "trust us" shouldn't be the only deployment option.
This post walks through what actually runs when you self-host a floor, and why it fits on one modest VPS.
The whole stack, honestly
A self-hosted floor is a handful of services, shipped as one Docker Compose stack:
- A WebRTC media server (a LiveKit SFU). Routes audio and video between participants. This is the only component that touches your calls: media is encrypted in transit and forwarded by your own server, never by anyone else's.
- An application server. Accounts, floors, chat, docs, the tracker, and short-lived media tokens. Database migrations run when it starts.
- PostgreSQL. The one database that holds the workspace.
- Redis. Coordination for the media server. Small, boring, reliable.
- A reverse proxy. Terminates TLS and routes the app, the realtime socket and media signalling. Guides cover nginx and Caddy.
That's the dependency graph. No managed database service and no third-party API in the path of your calls.
Sizing: smaller than you think
Video conferencing has a reputation for being infrastructure-hungry, but an SFU doesn't transcode. It forwards. That keeps CPU cost modest, so a single well-provisioned VPS goes a long way for a team with a few conversations at a time. Bandwidth, not CPU, is the number to watch as more cameras come on, so size the network link with your busiest hour in mind.
What you gain (beyond the obvious)
Data sovereignty is the headline, but day-to-day, teams self-host for quieter reasons:
- Latency you choose. Put the box in the region your team actually lives in, close to the people using it.
- Boring compliance. "Where is the data?" becomes a one-line answer in a security questionnaire instead of a vendor-review saga.
What you take on
Honesty requires the other column: you own updates (a docker compose pull away, but you own them), TLS renewal, database backups, and the firewall rule above. For a team with some ops capability, that is routine upkeep. For a team with none, the hosted version exists: same floor, same features, our pager.
The point isn't that everyone should self-host. The point is that the choice should be real. An office you can't own is a lease; we'd rather sell you the building.
Give your team a place to show up
Build a floor, take a seat, and see what changes. It's free to start.