Openship: Self-Hosted Deployment Platform with CI/CD
GitHub Repo
Apache-2.0
October 2, 2026 at 09:19 AM
0 views

Openship: Self-Hosted Deployment Platform with CI/CD

@oblienProject Author

What Openship is

Openship is an open-source deployment platform you can run yourself. You point it at a source, such as a GitHub repository, a local folder or a prebuilt artifact, and it detects the stack, builds the app, runs it, puts it behind a reverse proxy on your domain, and issues a TLS certificate. Push-to-deploy, preview environments, rollbacks, databases, a CDN layer, a mail server and backups are managed from the same control plane.

The target audience is developers and small teams who want a Heroku- or Vercel-style workflow on infrastructure they control: a VPS from Hetzner, DigitalOcean, Linode or OVH, dedicated servers, a homelab, or several machines. There is also a managed Openship Cloud for people who do not want to run anything, but self-hosting is described as free with no billing.

A notable design choice is the split between the control plane (Openship itself) and where your apps run. The README asks you to decide how you run the control plane first, because that determines which features are available.

How it works

There are three ways to run the control plane:

  • Desktop app: the control plane runs on your own machine only while the app is open and drives remote servers over SSH, or deploys to Openship Cloud. Nothing is left running publicly, and no login is needed. The README recommends this for solo developers.
  • Self-hosted server via openship up: an always-on instance that requires login. On Linux with Docker it runs in Compose mode, bringing up Postgres, Redis, the API, the dashboard and a containerized OpenResty edge on ports 80 and 443, and hosts deployed apps on the same box. Elsewhere (macOS, Windows, or Linux without Docker) it runs in bare mode: a single process with an embedded database that deploys out to other servers or Cloud.
  • Openship Cloud: managed sandboxes with no setup.

Every deploy runs the same pipeline:

  1. Detect: read package.json, framework config, lockfiles and any docker-compose.yml or openship.json to infer the stack, package manager, build and start commands and port. No config file is required; openship.json overrides the guesses.
  2. Build: on the target server or locally on the orchestrator, into a Docker image or a bare release. The resolved config is frozen into a snapshot so redeploys and rollbacks re-run exactly what shipped.
  3. Run: as a container published on loopback only, never on a public port, or as a supervised host process.
  4. Route and secure: the OpenResty edge writes a reverse-proxy vhost and issues a Let's Encrypt certificate via HTTP-01. Because this happens after the app is up, a DNS or certificate problem shows up as "action required" rather than failing the deploy.
  5. Push-to-deploy: a GitHub webhook re-runs the pipeline on each push to the tracked branch, rebuilding only the services a monorepo push touched.

Key features

  • Built-in CI/CD: push-to-deploy, preview environments, staging and production flows, and rollbacks.
  • Broad stack support: Node, Python, Go, Rust, PHP, Ruby, Java, .NET, Docker and monorepos, plus existing Docker Compose files deployed as-is.
  • Backend services: Postgres, MySQL, MongoDB, Redis, workers, WebSockets and storage.
  • Domains and SSL: automatic Let's Encrypt certificates, wildcards, unlimited domains and auto-renewal.
  • CDN features: edge caching, HTTP/3, Brotli compression and instant purge.
  • Mail server: built-in SMTP with DKIM, SPF and DMARC.
  • Backups: scheduled backups of databases and volumes with one-click restore and export.
  • Monitoring: live build logs, container metrics, visitor geography and response-code mix; the README claims about 1.4 µs of overhead per request with zero database writes per request.
  • Multiple interfaces: desktop app, web dashboard, CLI, a JavaScript/TypeScript SDK (OpenshipClient and createShip), a REST API and an MCP endpoint for AI agents.
  • Scoped MCP access: only routes that opt in become MCP tools, each call re-checks permissions, and credential or token routes can never be exposed as tools.

Getting started

For solo use, download the desktop app from GitHub Releases (macOS arm64 and Intel, Windows and a Linux AppImage), then connect a server over SSH. For an always-on server, install the CLI and run the setup wizard:

curl -fsSL https://get.openship.io | sh          # install  (or: npm i -g openship — needs Node 22+)
openship                                          # guided setup, then control panel

On CI or headless boxes, skip the wizard:

openship up                                       # install + start as a background service (boots + auto-restarts)
openship up --public-url https://openship.example.com   # + serve the dashboard on your domain (edge + TLS handled)

Then deploy a project:

cd your-project
openship init            # link this directory to a project
openship deploy

The README also documents a raw Docker Compose path without the CLI:

git clone https://github.com/oblien/openship.git && cd openship
cp .env.example .env          # then edit
docker compose --env-file .env -f docker/docker-compose.yml up -d

That path is Linux-only because the edge uses host networking, and it does not provision the container-to-host SSH channel needed for host operations such as port 80/443 takeover and the mail engine.

Use cases

  • Replacing a PaaS bill: move web apps and APIs from a hosted platform to a VPS while keeping git-push deploys and automatic TLS.
  • Solo developer with a few servers: use the desktop app to deploy to remote machines over SSH without running an always-on control plane.
  • Small team platform: run a self-hosted instance with login, a shared dashboard and preview environments.
  • Monorepos: rebuild only the services a push actually changed.
  • All-in-one hosting: run databases, transactional mail and backups next to the apps instead of wiring separate services.
  • Automation and agents: script deployments through the CLI, SDK or REST API, or let an AI agent operate through the permission-checked MCP endpoint.

How it compares

The README does not name competitors. Openship sits in the same category as other self-hosted PaaS tools such as Coolify, Dokku and CapRover, and it targets workflows people often associate with hosted platforms like Heroku or Vercel. Points that stand out from its own documentation are the desktop-app mode that keeps the control plane off the public internet, the bare mode that runs without Docker on macOS and Windows, the built-in mail server and CDN features, and the MCP endpoint. How it stacks up in reliability and depth against longer-established tools is something to test on your own workloads.

Things to know before adopting

  • Mixed licensing: Openship-authored code is Apache-2.0, but the bundled iRedMail engine is GPL-licensed and ships in several control-plane distributions even if mail is not used. The project keeps a licensing inventory and notes that upstream notice review is outstanding.
  • Docker socket access: in the Compose stack, the API container mounts the host Docker socket, which makes it host-privileged; the README says to run it only on a trusted host.
  • Public features need an always-on host: push-to-deploy webhooks and public domains do not work from a desktop or loopback-only instance.
  • Node version: the npm install requires Node 22 or newer; the install script brings its own Node if needed.
  • Docs are in progress: the README notes the documentation is still being filled out.
  • Roadmap: multi-node clusters, a load-balancing UI, private networking, advanced monitoring and visual CI/CD pipelines are listed as coming next. The project describes its core as production-ready and actively developed; the repository dates from March 2026.
  • Security reporting: vulnerabilities go through private GitHub advisories, with a published safe-harbor policy.

Project activity

As of October 2026 the repository has roughly 14,300 stars on GitHub. It was created on March 5, 2026, is written in TypeScript, and Openship-authored code is licensed under Apache-2.0. The CLI and SDK are published on npm as openship, container images are on GitHub Container Registry, and the README is translated into ten languages. Source code is at github.com/oblien/openship, and documentation is at openship.io.

Enjoying this project?

Discover more amazing open-source projects on TechLogHub. We curate the best developer tools and projects.

Project
openship
Created
October 2
Last Updated
October 2, 2026 at 09:19 AM

Find more projects like this

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.