What self-hosting really costs

What self-hosting really costs

Igor Jakobencsuk  ·  14 min read

Search for what a self-hosted VPN costs and you will find two kinds of answer. Tutorials that say "it's free, just use WireGuard," and forum threads that assume you already have a server rack. Neither tells you what you will actually spend.

This breakdown uses current, sourced prices from September 2026 and shows the arithmetic. It also covers the two costs that decide whether self-hosting works for you at all, and neither of them is money.

One thing up front, because it changes everything and most guides skip it.

The Split Nobody Mentions: Where Does the Tunnel End?

"Self-hosted VPN" covers two completely different outcomes, and people routinely build one while wanting the other.

WireGuard on a rented VPS gives you an encrypted tunnel to a server in a data centre. Your traffic exits there. This protects you on public Wi-Fi and gives you an IP address you control. It does not give you access to your home network. Your NAS, your cameras, your printer and your media server are all still unreachable, because the tunnel does not go to your house.

WireGuard on a machine at home gives you a tunnel back to your own network. You reach everything on your LAN, and your traffic exits through your home connection with your home IP address.

These cost different amounts, and only one of them does what most people are actually trying to achieve. If your goal is reaching your home NAS from a hotel, the cheap VPS route does not solve it at any price.

Route 1: WireGuard on a VPS

The most common approach. Rent a small server, install WireGuard, configure peers.

Current prices for the cheapest plan suitable for a personal VPN endpoint, taken from the providers' own pages in September 2026:

Two things worth knowing about that table.

Hetzner charges separately for IPv4. The advertised price excludes it, and the primary IPv4 address is €0.50 per month on top. Hetzner also raised cloud prices twice during 2026, in April and again in June, with the June round applying to existing customers as well as new ones. If you are planning around a Hetzner price from an older article, it is wrong.

The cheap 1 GB tier is disappearing in Europe. Hetzner, OVH and IONOS have all moved their entry plans to 2 vCPU and 4 GB. You get more machine, but you no longer get the €3 option.

Three-year cash cost: at $5 per month, $180. Add a domain if you want a friendly hostname, roughly $10 to $11 per year at cost through a registrar that does not mark up, so about $210 over three years.

That is genuinely cheap. It is also the option that cannot reach your home network.

What About Oracle's Free Tier?

Oracle Cloud's Always Free tier is the standard answer to "can I do this for nothing," and it does still exist. You get an Arm instance with 2 OCPUs and 12 GB of memory, 200 GB of block storage, and 10 TB of outbound transfer per month.

There are four catches, and two of them are serious.

It was halved in 2026. The Arm allowance was 4 OCPUs and 24 GB until 15 June 2026, when it dropped to 2 and 12. There was no announcement. People found out when their instances stopped.

Idle instances get reclaimed. Oracle's terms state that Always Free compute instances may be reclaimed if, over a seven-day window, 95th-percentile CPU use is under 20 percent, network under 20 percent and memory under 20 percent. A personal VPN endpoint is close to the textbook definition of an idle instance. This is the single biggest practical risk with the free tier and it is rarely mentioned in the tutorials that recommend it.

The other two: capacity for free shapes is frequently unavailable in a given availability domain, and if you terminate a grandfathered resource you may not be able to recreate it at the old size.

Free is a real price. Just do not build something you depend on while travelling on an instance whose provider reserves the right to reclaim it for being quiet.

Route 2: WireGuard on a Machine at Home

This is the route that actually reaches your home network. It removes the monthly server fee and replaces it with hardware, electricity and a networking problem.

Hardware

A Raspberry Pi 5 with 1 GB of memory is $45 and is far more machine than a WireGuard endpoint needs. Usefully, the 1 GB model has been held at that price through both 2026 increases, while the larger ones have not: Pi prices have risen repeatedly since December 2025 because of DRAM costs, with Raspberry Pi citing "a seven-fold increase over the last year in the price of the LPDDR4 DRAM." The 16 GB Pi 5 is now $305. For this job, buy the smallest one.

A mini PC gives you a machine that can do other things too. Current examples run from about $240 for an Intel N95 box to around $500 for an N150 with 16 GB and dual LAN. That is also up sharply on 2025 prices for the same reason.

Add a power supply, a case and a memory card if you go the Pi route, so budget roughly $70 all in for the cheapest viable build.

Electricity

This is the cost people overestimate. The arithmetic for anything running continuously is watts multiplied by 8.76 to get kWh per year.

Using the US residential average of 18.34 cents per kWh (EIA, June 2026) and the UK price cap unit rate of 26.11p (Ofgem, July to September 2026):

Continuous draw kWh per year US per year UK per year
3 W (Raspberry Pi 5, idle) 26.3 $4.82 £6.86
5 W (Pi 5, light load) 43.8 $8.03 £11.44
9 W (mini PC, typical) 78.8 $14.46 £20.59
15 W (mini PC, moderate load) 131.4 $24.10 £34.31

So electricity for a Pi is about five dollars or seven pounds a year. Not a factor.

Dynamic DNS

Your home IP address changes, so you need a name that follows it.

No-IP has a free tier with one hostname, and a catch that catches people: free hostnames must be confirmed every 30 days. You get an email at day 23, the hostname stops resolving at day 30 if you ignore it, and it is deleted and claimable by anyone at day 51. Confirming it while you are the one away from home and relying on it is exactly the wrong moment to find this out. Their paid tier removes the requirement at $2.99 per month.

Duck DNS is free and donation-funded. No expiry requirement, but it is a hobby project with no service guarantee.

Cloudflare is free if you own a domain and are willing to write a small script against their API. Their registrar sells domains at cost with no markup, so a .com is about $10.45 a year, and wholesale .com prices rise again in November 2026.

DynDNS is not an option. Oracle shut down Dyn's consumer DNS service in 2020. Articles still listing it are old.

The Wall: CGNAT

Here is the cost that is not money and cannot be budgeted around.

A home WireGuard server needs an inbound connection. That requires a public IP address and an open port. A growing share of residential connections do not have one, because the ISP puts customers behind carrier-grade NAT and shares one public address between many subscribers. Port forwarding simply does not work.

Be careful with statistics here, because a lot of confident numbers get quoted. There is no current, authoritative public measurement of what proportion of home broadband sits behind CGNAT. The most-cited academic study is from 2016 and found CGNAT in 17 to 18 percent of fixed-line eyeball networks and over 90 percent of cellular ones, but it measured networks rather than subscribers and it is a decade old.

What can be stated concretely is who does it. In the UK, a 2024 industry survey found roughly fifteen fibre altnets defaulting to CGNAT, including Community Fibre, Hyperoptic, YouFibre, G.Network and Fibrus. Zen Internet, by contrast, includes a free static IP address with every connection. Community Fibre moved to CGNAT by default for everyone signing up or renewing from June 2026, and sells a public IP as a £4 per month add-on. YouFibre charges £5 per month for a static IP. In Australia, Aussie Broadband states that CGNAT is enabled by default on its broadband services, though opting out is free. Mobile and fixed-wireless home internet and satellite broadband are effectively all CGNAT.

How to check in thirty seconds: log into your router, find its WAN IP address, then search "what is my IP" in a browser. If the two differ, you are behind CGNAT, and a home-hosted WireGuard server will not work without either paying your ISP for a public address, having working inbound IPv6, or renting a VPS to act as a relay, which reintroduces the monthly fee.

Three-year cost, home route

Raspberry Pi 5 with accessories at roughly $70, electricity at about $5 a year, and free dynamic DNS gives you about $85 over three years. Add a public IP address from your ISP at £4 to £5 a month and it becomes roughly $250 to $280 over three years, which changes the picture considerably.

Route 3: Self-Hosted Platforms Like Pangolin

Pangolin and similar projects add a dashboard, identity and access control on top of WireGuard, so you are not hand-editing config files. It has more than 21,000 GitHub stars and an active community.

The cash cost is the same as whichever route you run it on, plus one licensing nuance worth knowing: Pangolin is dual-licensed. The self-hosted Community Edition is free under AGPL-3, while the Enterprise Edition uses a commercial licence that is free for personal use and for businesses under $100,000 in annual revenue.

What goes up is the complexity. You are now running Docker containers, a reverse proxy and TLS certificates alongside the VPN itself. For someone who enjoys that, it is the nicest self-hosted experience available. For someone who does not, "free" is doing a lot of work in that sentence.

The Cost That Cannot Be Quantified Honestly

Plenty of comparisons at this point multiply an invented number of maintenance hours by an invented hourly rate and produce a four-figure "true cost." We are not going to do that, because the number would be made up.

No survey, study or measurement exists of how long a first-time WireGuard setup takes or how much ongoing maintenance a personal VPN server needs. Published tutorials claim anywhere from 5 to 45 minutes, and that range is itself the finding: it reflects how much each guide assumes you already know, not how long the job takes. None of them include account signup, SSH keys, firewall rules, client configuration on each device, or anything going wrong.

What can be stated factually is the work involved, so you can judge it against your own tolerance:

  • Operating system patching, indefinitely
  • WireGuard and kernel updates
  • Generating a key pair and editing config on both ends for every new device
  • Rotating keys if a device is lost or stolen
  • Noticing when the tunnel is down, which you often discover at the worst possible moment
  • Handling changes your provider makes without asking, such as Hetzner's two price rises in 2026 or Oracle halving its free tier without notice

If that list reads as a pleasant hobby, self-hosting is genuinely cheap and you should do it. If it reads as a chore, that is useful information about which option actually suits you.

Three-Year Cash Cost Compared

Approach 3-year cash Reaches your home LAN? Works behind CGNAT? Skill needed
WireGuard on a $5 VPS $180 to $210 No Yes Linux command line
Oracle Always Free $0 No Yes Linux, plus reclamation risk
Raspberry Pi at home About $85 Yes No Linux, networking, port forwarding
Pi at home plus ISP public IP About $250 Yes Yes, by paying for it Same
Pangolin on a VPS $180 plus No Yes Docker, reverse proxy, TLS
Purpose-built hardware $249 once Yes Yes None

The column that matters most is not the money. It is the two middle ones, because they determine whether the cheap options do the job at all.

Where Purpose-Built Hardware Fits

A device like vploq occupies the row at the bottom of that table: it plugs into your home router, reaches your home network, is built to work behind CGNAT without port forwarding, and costs $249 once.

It is not the cheapest option and the table shows that plainly. A Raspberry Pi at home is about $85 over three years and a VPS is around $180. What the hardware buys is the removal of the two things that make those cheap routes fail: the CGNAT problem, and the ongoing job of keeping a Linux server patched and reachable.

The honest limits: up to 5 devices at a time, up to 300 Mbit/s, and it wants at least 50 Mbit/s upload at home because everything routes through your own connection. It currently ships to the United Kingdom only, with pre-orders shipping from November 2026.

If you have a public IP address, enjoy Linux and want the cheapest possible answer, self-host. That is a legitimate conclusion from this article and we are not going to argue you out of it. If you are weighing devices rather than servers, we compared what you can actually buy in whether your home network needs a hardware VPN device.

Frequently Asked Questions

How much does it cost to self-host a VPN?
On a rented VPS, about $5 to $6 per month, so roughly $180 to $210 over three years including a domain name. On hardware at home, roughly $70 upfront for a Raspberry Pi plus about $5 a year in electricity, so around $85 over three years. Neither figure includes your time, and neither accounts for whether your ISP allows inbound connections.

Is a self-hosted VPN actually free?
Almost never. The software is free, but you pay for either a server or hardware plus electricity, and often for dynamic DNS or a public IP address. Oracle's Always Free tier is genuinely $0, but Oracle reserves the right to reclaim idle instances, and a personal VPN endpoint is close to the definition of idle.

Can I access my home NAS through a self-hosted VPN on a VPS?
No, not with a standard setup. A VPS-hosted VPN routes your traffic through a data centre, which has no connection to your home network. To reach a NAS, cameras or a media server you need the tunnel to terminate at your house, which means running the server on hardware at home or using a device built for that job.

What is CGNAT and why does it stop a self-hosted VPN working?
Carrier-grade NAT is when your ISP shares one public IP address among many subscribers instead of giving you your own. A home VPN server needs to accept incoming connections, which requires a reachable address and an open port. Behind CGNAT, port forwarding does not work at all. Check by comparing your router's WAN IP to what a "what is my IP" search reports: if they differ, you are behind CGNAT.

How much electricity does a home VPN server use?
Very little. A Raspberry Pi 5 draws roughly 3 W idle, which is about 26 kWh a year, costing around $4.82 in the US or £6.86 in the UK at current rates. A mini PC at 9 W costs about $14.46 or £20.59 a year. Electricity is not a meaningful part of the decision.

Is a VPS cheaper than a home server for a VPN?
Over three years, no. A $5 per month VPS costs about $180, while a Raspberry Pi plus electricity is about $85. The VPS is cheaper only in the first few months. The more important difference is functional: the VPS cannot reach your home network, and the Pi cannot accept connections if your ISP uses CGNAT.

How long does it take to set up a WireGuard VPN?
Nobody has measured it properly. Published tutorials claim between 5 and 45 minutes, but they assume a clean server, an experienced operator and nothing going wrong. What is certain is the ongoing work: OS patching, key management for each new device, monitoring that the tunnel is up, and reacting when your provider changes something.

Do I need a static IP address to self-host a VPN at home?
Not static, but you do need a public one. Dynamic DNS handles an address that changes. It cannot help if you have no public address at all, which is the case behind CGNAT. Some ISPs sell a public IP as an add-on, typically around £4 to £5 a month in the UK or about $10 a month from some US providers, and others do not offer one on residential plans.

STAY UPDATED

Stay in the loop.

Shipping Q4 2026. Get updates when they happen.

Keep me posted