macrostack

Layer 4 · self-hosting reality check

What it actually takes to self-host Helicone

The docs say Not stated in the docs. Helicone's own 2025 self-hosting write-up says a t2.medium EC2 instance (2 vCPU, 4 GB) handles about 90% of typical workloads, up to a million logs a day.. In practice you want 8 GB. The all-in-one container runs the web dashboard, the Jawn API and proxy, PostgreSQL, ClickHouse and MinIO together, and ClickHouse's own sizing guide says total memory should not go below 8 GB.. Here is the honest version — real requirements, real monthly cost, what you will be maintaining, and the one thing that catches people out.

Usually reached from Portkey alternatives, where Helicone is one of the picks.

Wondering whether you need to at all? Is Portkey free? — what the free tier actually allows, and where the wall is.

RAM — documented minimumNot stated in the docs. Helicone's own 2025 self-hosting write-up says a t2.medium EC2 instance (2 vCPU, 4 GB) handles about 90% of typical workloads, up to a million logs a day.
RAM — what it really needs8 GB. The all-in-one container runs the web dashboard, the Jawn API and proxy, PostgreSQL, ClickHouse and MinIO together, and ClickHouse's own sizing guide says total memory should not go below 8 GB.
CPU2 vCPU to start; 4 once ClickHouse is answering dashboard queries over months of logs
DiskClickHouse keeps a row per logged request and MinIO holds the logged payloads, so disk grows with every LLM call — long prompts make it grow fast. Nothing survives a container restart unless you mount volumes.
Monthly cost$24–48/mo for a 4–8 GB VPS at DigitalOcean list prices (read 2026-09-30), less on budget hosts; your LLM provider bills are separate
Setup time20 minutes on localhost with the all-in-one image; an afternoon on a server, where every URL variable must point at the public origin and HTTPS comes from a reverse proxy
How you install itdocker run helicone/helicone-all-in-one:latest with volumes mounted, or ./helicone-compose.sh helicone up from the repo's docker folder; set NEXT_PUBLIC_HELICONE_JAWN_SERVICE, BETTER_AUTH_SECRET and the public URLs
Ongoing maintenanceHelicone has been in maintenance mode since Mintlify acquired it on 2026-03-03 — in Helicone's words, security updates, new models, and bug and performance fixes keep shipping. Budget for ClickHouse housekeeping and, eventually, a migration.
Where it stops scalingOne box handles up to about a million logs a day by Helicone's own estimate. Beyond that, split ClickHouse, PostgreSQL and object storage onto separate hosts; the production Helm chart is available only by contacting Helicone's enterprise team.

The thing that catches people out

Port 8585 is both the API and the LLM proxy, and the docs say plainly that it does not require authentication for proxying — anyone who can reach it can push LLM requests through your endpoint. The browser also needs to reach 8585 (and MinIO on 9080), so you cannot simply firewall it off. Put Helicone behind a reverse proxy with HTTPS and access control, and replace the default minioadmin credentials and BETTER_AUTH_SECRET before exposing it.

When not to self-host Helicone

You are choosing an LLM observability or gateway layer for the next few years. Helicone is in maintenance mode after the Mintlify acquisition; an actively developed self-hostable tool such as Langfuse (MIT core) for tracing, or LiteLLM for routing, is the safer long-term bet.

Every guide here carries this section. A site that only ever tells you to self-host is selling something — the useful answer is sometimes no.

Other Layer 4 self-hosting guides

Common questions

How much RAM does Helicone actually need?
8 GB. The all-in-one container runs the web dashboard, the Jawn API and proxy, PostgreSQL, ClickHouse and MinIO together, and ClickHouse's own sizing guide says total memory should not go below 8 GB. in practice. The documented minimum is Not stated in the docs. Helicone's own 2025 self-hosting write-up says a t2.medium EC2 instance (2 vCPU, 4 GB) handles about 90% of typical workloads, up to a million logs a day., which is the figure at which the process starts rather than the figure at which it works under real use. 2 vCPU to start; 4 once ClickHouse is answering dashboard queries over months of logs alongside it.
What does self-hosting Helicone cost per month?
$24–48/mo for a 4–8 GB VPS at DigitalOcean list prices (read 2026-09-30), less on budget hosts; your LLM provider bills are separate This is commodity VPS pricing and excludes your time, which is the larger cost for most people — budget for helicone has been in maintenance mode since Mintlify acquired it on 2026-03-03 — in Helicone's words, security updates, new models, and bug and performance fixes keep shipping. Budget for ClickHouse housekeeping and, eventually, a migration.
How long does it take to set up Helicone?
20 minutes on localhost with the all-in-one image; an afternoon on a server, where every URL variable must point at the public origin and HTTPS comes from a reverse proxy, via docker run helicone/helicone-all-in-one:latest with volumes mounted, or ./helicone-compose.sh helicone up from the repo's docker folder; set NEXT_PUBLIC_HELICONE_JAWN_SERVICE, BETTER_AUTH_SECRET and the public URLs.
When should I NOT self-host Helicone?
You are choosing an LLM observability or gateway layer for the next few years. Helicone is in maintenance mode after the Mintlify acquisition; an actively developed self-hostable tool such as Langfuse (MIT core) for tracing, or LiteLLM for routing, is the safer long-term bet.
What is the most common mistake when self-hosting Helicone?
Port 8585 is both the API and the LLM proxy, and the docs say plainly that it does not require authentication for proxying — anyone who can reach it can push LLM requests through your endpoint. The browser also needs to reach 8585 (and MinIO on 9080), so you cannot simply firewall it off. Put Helicone behind a reverse proxy with HTTPS and access control, and replace the default minioadmin credentials and BETTER_AUTH_SECRET before exposing it.
The Macrostack brief

New swaps, worth your inbox.

A short, occasional email when we add a high-intent alternative or ship a new head-to-head. No spam, no selling your address — unsubscribe in one click.