The onpit stack
We invented none of it, on purpose. Every component is proven, open or European, and runs entirely on your own hardware. Our work is choosing, fitting together, securing and keeping it current.
Layer by layer
running today on the onpit cluster in progress
Applications
- Maildocker-mailserverOpen sourcerunning
- Files, calendars, contactsNextcloudNextcloud GmbH, Stuttgartin progress
- Editing documents togetherCollabora OnlineOpen sourcein progress
- Video callsJitsi MeetOpen sourcein progress
- ChatMatrix with ElementOpen source, open protocolin progress
- ERP, CRM, accountingOdooOdoo S.A., Belgiumin progress
AI brain
- Language modelsopen models, e.g. from Mistral AIMistral AI, Parisin progress
- Running models locallyOllama, Open WebUIOpen sourcein progress
Identity & security
- One login for everythingZitadelZitadel AG, St. Gallenrunning
- PasswordsVaultwardenOpen sourcein progress
- Security monitoringWazuhOpen sourcein progress
Network & access
- Encrypted network between all devicesNetBirdNetBird GmbH, Berlinrunning
- Access from outside, certificatesTraefikTraefik Labs, Lyonrunning
Cluster & data
- Several computers as one systemk3sSUSE, Nurembergrunning
- Storage mirrored across nodesLonghornSUSE, Nurembergrunning
- Databases with automatic failoverPostgreSQL with CloudNativePGOpen sourcerunning
Hardware & storage
- Compute nodesRaspberry Pi 5, mini PCs or serversARM64 and x86-64running
- Separate storage server, provides storage over NFS and S3OpenMediaVault on DebianOpen source, Volker Theile, Germanyrunning
- Operating system (storage today, nodes with the next rebuild)DebianOpen source, communityrunning
- Checksummed data storageOpenZFSOpen sourcerunning
- Backup storage (S3)GarageDeuxfleurs, Francerunning
How we choose
A component only goes into the stack if it meets all five points.
- It already exists and is proven. We don't rebuild what already exists in good shape.
- It's open source or European, ideally both.
- It runs entirely on your own hardware, with no forced cloud and no secret phoning home.
- It's secure and data-frugal by default.
- It's replaceable. No lock-in, not even to onpit.
onpit, Google Workspace and Microsoft 365
The same jobs, three very different answers to the question of who owns the data.
| Question | onpit | Google Workspace | Microsoft 365 |
|---|---|---|---|
| Where is the data? | On your own hardware, on your own network | With Google | With Microsoft |
| Which law applies? | EU law | US law too (CLOUD Act) | US law too (CLOUD Act) |
| Mail and calendar | docker-mailserver, Nextcloud | Gmail, Calendar | Outlook, Exchange |
| Files | Nextcloud | Google Drive | OneDrive, SharePoint |
| Shared documents | Collabora Online | Google Docs | Office Online |
| Video and chat | Jitsi, Matrix | Meet, Chat | Teams |
| One login for everything | Zitadel | Google account | Entra ID |
| ERP, CRM, accounting | Odoo | not included | Dynamics 365, separate |
| AI assistant | Your own AI brain, local | Gemini, in the cloud | Copilot, in the cloud |
| Security monitoring | Wazuh | separate | Sentinel, separate |
| Cost | Hardware once, service optional | per user per month | per user per month |
| Switching provider | Any time, open formats | hard work | hard work |