The Eleven Factors

VII. Self-hosting is a right

๐Ÿค– If you can't run it yourself, you don't own it.

๐Ÿค– The prose on this page was written by a human. Where an LLM's words appear, they are marked, visibly, like this โ€” that's factor X.

Infrastructure models for computing ebb and flow. Thin-client interfacing with a mainframe. On premise everything. The evolution of SaaS where computers more powerful than the servers they run on consume services via thin web clients. And now the same is happening with AI.

Self-hosting is almost always the wrong approach when building resilient systems, and almost always the right approach when building secure, and indeed sovereign ones. The full eleven factors make the case that self-hosting ought not necessarily be required for security, but the seventh factor is that it should always be possible, without compromise.

Eleven factor software, in an absolute sense, should essentially be uncontrollable, unbuyable by an external party. If, at any time, someone who uses an eleven factor app decides that they want to run it on their own hardware, this should be built in.

The ideal of this model is that self-hosting is not penalised in any way, unless a decision is made explicitly.

In practice, this means: self-hosting and "cloud" hosting are functionally the same. Self-hosters gain access to relay services, broker services etc. to allow for a "great-design" experience, but none of the centralised infrastructure is required.

Finally, at any point, the self-hoster should be able to decide to pin to any version and no longer receive updates they don't want. Most folks will want to be on the latest stable release, but that is a choice, not an enforcement.