Layer 5 · self-hosting reality check
What it actually takes to self-host Ory Kratos
The docs say not stated by the vendor. Ory's own single-server production example runs Kratos, PostgreSQL, Nginx and the Node.js login UI on a 1 GB VM with 25 GB of SSD.. In practice you want 1–2 GB for Kratos, PostgreSQL and a login UI together. Kratos itself is a single Go binary and keeps no state of its own.. Here is the honest version — real requirements, real monthly cost, what you will be maintaining, and the one thing that catches people out.
Usually reached from Auth0 alternatives, where Ory Kratos is one of the picks.
Wondering whether you need to at all? Is Auth0 free? — what the free tier actually allows, and where the wall is.
| RAM — documented minimum | not stated by the vendor. Ory's own single-server production example runs Kratos, PostgreSQL, Nginx and the Node.js login UI on a 1 GB VM with 25 GB of SSD. |
|---|---|
| RAM — what it really needs | 1–2 GB for Kratos, PostgreSQL and a login UI together. Kratos itself is a single Go binary and keeps no state of its own. |
| CPU | 1–2 vCPU; not stated by the vendor |
| Disk | Tiny. Identities, sessions and the outgoing email queue live in PostgreSQL; the 25 GB in Ory's example is plenty for a small app. |
| Monthly cost | $6–12/mo for a small app's login service on a 1–2 GB VPS, plus an SMTP provider for verification and recovery emails |
| Setup time | An hour for the quickstart; days to a week for production, because you build or adapt the login UI and write the identity schema |
| How you install it | The oryd/kratos Docker image or binary against PostgreSQL, MySQL or CockroachDB, with `kratos migrate sql` before start and your own login UI (or Ory's reference Node.js UI). Or the official Helm chart, which runs the email courier as a separate StatefulSet. |
| Ongoing maintenance | Back up, read the changelog for breaking changes and run `kratos migrate sql` on every upgrade. Open-source releases have come about twice a year (v25.4.0 in November 2025, v26.2.0 in March 2026), and your UI has to keep up with SDK changes. |
| Where it stops scaling | Very far. Kratos is stateless, so you add containers behind a load balancer and scale the database. The one rule is exactly one email courier worker. |
The thing that catches people out
Ory's quickstart is a demo, not a small production setup. Its compose file runs `kratos serve --dev --watch-courier` on SQLite and delivers every email to MailSlurper, a fake inbox. Promote it to production and you keep the --dev flag Ory says it is 'paramount' to drop, a database it says never to use in production, and verification and recovery emails that reach nobody. Move to PostgreSQL, drop --dev, set real secrets and an SMTP connection, and keep exactly one email courier: --watch-courier on a single instance, or one `kratos courier watch` worker once you run more replicas.
When not to self-host Ory Kratos
You want a login page, admin console and SSO ready on day one. Kratos is headless and API-only, so use Keycloak, Authentik or Zitadel, or stay on Auth0 if you have no developers to build the UI.
Every guide here carries this section. A site that only ever tells you to self-host is selling something — the useful answer is sometimes no.
Other Layer 5 self-hosting guides
- Self-hosting LibreOffice2 GB with a large spreadsheet open
- Self-hosting ONLYOFFICE6 GB for the Document Server with a handful of concurrent editors
- Self-hosting Collabora Online4 GB, and roughly 1 GB per 20 concurrent documents
- Self-hosting CryptPad2 GB for a small instance
- Self-hosting Mattermost4 GB for a team of 50 with PostgreSQL on the same box
- Self-hosting Rocket.Chat6 GB with MongoDB on the same machine
Common questions
- How much RAM does Ory Kratos actually need?
- 1–2 GB for Kratos, PostgreSQL and a login UI together. Kratos itself is a single Go binary and keeps no state of its own. in practice. The documented minimum is not stated by the vendor. Ory's own single-server production example runs Kratos, PostgreSQL, Nginx and the Node.js login UI on a 1 GB VM with 25 GB of SSD., which is the figure at which the process starts rather than the figure at which it works under real use. 1–2 vCPU; not stated by the vendor alongside it.
- What does self-hosting Ory Kratos cost per month?
- $6–12/mo for a small app's login service on a 1–2 GB VPS, plus an SMTP provider for verification and recovery emails This is commodity VPS pricing and excludes your time, which is the larger cost for most people — budget for back up, read the changelog for breaking changes and run `kratos migrate sql` on every upgrade. Open-source releases have come about twice a year (v25.4.0 in November 2025, v26.2.0 in March 2026), and your UI has to keep up with SDK changes.
- How long does it take to set up Ory Kratos?
- An hour for the quickstart; days to a week for production, because you build or adapt the login UI and write the identity schema, via The oryd/kratos Docker image or binary against PostgreSQL, MySQL or CockroachDB, with `kratos migrate sql` before start and your own login UI (or Ory's reference Node.js UI). Or the official Helm chart, which runs the email courier as a separate StatefulSet..
- When should I NOT self-host Ory Kratos?
- You want a login page, admin console and SSO ready on day one. Kratos is headless and API-only, so use Keycloak, Authentik or Zitadel, or stay on Auth0 if you have no developers to build the UI.
- What is the most common mistake when self-hosting Ory Kratos?
- Ory's quickstart is a demo, not a small production setup. Its compose file runs `kratos serve --dev --watch-courier` on SQLite and delivers every email to MailSlurper, a fake inbox. Promote it to production and you keep the --dev flag Ory says it is 'paramount' to drop, a database it says never to use in production, and verification and recovery emails that reach nobody. Move to PostgreSQL, drop --dev, set real secrets and an SMTP connection, and keep exactly one email courier: --watch-courier on a single instance, or one `kratos courier watch` worker once you run more replicas.