Services

What is actually included, in detail

One Stop Shop rents server capacity wholesale from Hetzner and delivers it to you as a fully managed service: provisioned, hardened, monitored, backed up and maintained. This page describes each part of that work so there are no surprises about what “managed” means.

01 — Managed server hosting

A server on Hetzner infrastructure, delivered ready to use

You receive a server; the infrastructure relationship stays with One Stop Shop. There is no Hetzner account to open, no invoice from a third party and no console to learn. Hetzner is named because it matters — real, ISO 27001-certified European data centres and hardware that comfortably outperforms its price — but you never have to interact with it.

Locations and network

  • Falkenstein and Nuremberg, Germany; Helsinki, FinlandDefault locations. Latency from Toronto or Vancouver is typically 95–130 ms, which is imperceptible for streaming, file sync and most web applications.
  • Ashburn, Virginia and Hillsboro, OregonAvailable for latency-sensitive North American workloads (interactive apps, game servers, real-time dashboards). Cloud servers only; storage costs are somewhat higher.
  • NetworkRedundant 10 Gbit uplinks, always-on DDoS mitigation at the edge, IPv4 and IPv6 on every server. Cloud servers include 20 TB outbound traffic per month; dedicated servers are unmetered at 1 Gbit.

Server classes

ClassTypical specSuited to
Shared-vCPU cloud4 vCPU · 8 GB · 160 GB NVMeWebsites, small apps, a personal media server with direct-play clients
Dedicated-vCPU cloud8 vCPU · 32 GB · 240 GB NVMe · attachable volumesFull media automation stack, databases, business applications, multiple users
Dedicated bare metal8-core AMD or Intel · 64 GB ECC · 2 × 1.92 TB NVMeHardware transcoding, large libraries, heavier production loads, many containers
Bulk storage1 TB – 40 TB Storage Box or volumesMedia libraries, photo archives, backup targets — attached to any class above

Sizing is part of the service. You do not need to know what a vCPU is. Describe what you want to run, how much data you have and how many people use it, and the right class is recommended — with the reasoning written down. Resizing later is a planned change, not a rebuild.

02 — Media server hosting

Streaming media server infrastructure — hosted properly

This is the specialty. Most managed hosts will not touch a media server; here it is the most common workload. The result is a media system that streams reliably to your household and family wherever they are, keeps its library organized, and does not depend on a box under your desk staying powered on.

What gets deployed

  • Streaming media serverYour preferred media server software, deployed against your library and configured for remote access over HTTPS with a proper certificate — not a forwarded port on a home router. Multiple server applications can share one library if you use more than one.
  • Library organization and automationThe supporting tools that keep a library tidy: metadata and artwork management, naming and folder conventions, subtitle handling, quality profiles and collection management, each placed behind the reverse proxy with single sign-on where supported.
  • Household accessUser onboarding, per-user access controls and a request/discovery front end so family members can ask for titles without touching the back end. Playback statistics and usage dashboards where you want them.
  • Transcoding pipelineOn-the-fly transcoding for remote devices, and optional scheduled library transcoding to standardize formats and reclaim storage.
  • Companion applicationsPhoto libraries, music servers, e-book and audiobook servers, and home-lab dashboards can run alongside the media stack on the same managed server.

Engineering that matters for media

  • Hardware transcodingDedicated servers are selected with Intel Quick Sync or AMD integrated graphics, and the GPU is passed through to the media server container so several simultaneous 4K → 1080p transcodes do not saturate the CPU.
  • Storage layoutLibraries live on bulk storage (Storage Box or volumes) mounted so that hard links work across the whole media path — no duplicated files, instant library imports, predictable growth.
  • Bandwidth headroomUnmetered 1 Gbit on dedicated hardware means a 4K remote stream at 40–80 Mbit/s is not a cost problem, and neither is a full library rescan.
  • Databases and metadata backed upApplication databases (watch history, user settings, library metadata) are dumped nightly and restorable independently of the media files themselves.
  • Sane update cadenceMedia applications release often and occasionally break. Updates are applied on a schedule, with a rollback path, rather than by an auto-updater pulling latest at 3 a.m.

A plain note on content. One Stop Shop provides and manages the infrastructure and software. What you store and stream on it is your responsibility, and the acceptable use terms require that it be lawful and that you hold the rights to it. Abuse notices are passed on and must be resolved.

03 — Self-hosted application hosting

The applications people want to own, run for them

Self-hosting gives you your data back — until it becomes a second job. Applications are deployed as containers behind a single reverse proxy, backed up as a unit, monitored, and updated on a schedule you can see. You get the ownership without the upkeep.

Files, photos & sync

  • File sync and collaboration suites (files, calendar, contacts, office documents)
  • Self-hosted photo libraries with mobile backup
  • Peer-to-peer sync and web-based file managers

Security & productivity

  • Self-hosted password managers
  • Document management, wikis and knowledge bases
  • Git hosting, status pages, workflow automation

Web & business

  • WordPress, publishing platforms, static sites
  • Custom apps with PostgreSQL, MariaDB or Redis
  • Home automation hubs, chat servers, federated social platforms

Not on the list? Almost anything that ships as a container or runs on Debian can be hosted. Ask.

04 — Initial setup & hardening

Every server starts from the same documented baseline

Setup is included with every plan and applies whether the server will host a media stack or a production web application. It is a fixed, repeatable procedure — not an improvised install — and you receive a summary of exactly what was done.

  • Operating systemDebian stable (or Ubuntu LTS on request), minimal install, full-disk layout planned for the workload, NTP, locale and timezone set, hostname and reverse DNS configured.
  • Access controlSSH key-only authentication on a non-standard port, root login disabled, a dedicated administrative user with sudo, fail2ban with permanent bans for repeat offenders. You receive your own key-based access if you want it.
  • Automatic security updatesUnattended upgrades for security repositories, with reboot windows scheduled at a time you choose and notification when a reboot is pending.
  • Firewallnftables default-deny inbound, only 80/443 and the SSH port exposed; Hetzner's network-level firewall as a second layer. Application ports are never published to the internet — everything goes through the proxy.
  • Container runtimeDocker Engine and Compose from the official repositories, log rotation configured, a project layout per application so each stack can be started, stopped and backed up independently.
  • Reverse proxy & TLSTraefik (or nginx where preferred) terminating TLS for every service with automatic Let's Encrypt certificates, HTTP→HTTPS redirect, HSTS and modern cipher suites. Optional single sign-on (Authelia or Authentik) in front of administrative interfaces.
  • DatabasesPostgreSQL, MariaDB or Redis as needed, bound to the internal network only, with per-application credentials and nightly logical dumps in addition to volume snapshots.
  • Monitoring & alertingExternal uptime checks every 60 seconds, host metrics (CPU, memory, disk, I/O, temperature on bare metal), container health, certificate expiry and disk-fill prediction. Alerts route to the operator, and optionally to you.
  • BackupsEncrypted, deduplicated backups (Restic or Borg) of application data and configuration to off-site storage nightly, plus provider-level snapshots where available. Retention matches your plan. See maintenance for verification.
  • DocumentationA written summary of the server: what runs where, how to reach it, where backups live, and how to restore. It is yours, and it is what makes the handover clean if you ever leave.
05 — Ongoing maintenance

The monthly work that keeps a server boring

This is what the subscription pays for. Depth and response time vary by plan — the pricing page has the exact comparison — but the categories below apply to every managed server.

  • Patching and updatesOperating system packages on a weekly cycle (security fixes sooner), Docker Engine and application images on a reviewed schedule with release notes read first. Reboots happen in your agreed window. Nothing is auto-updated blindly.
  • Security monitoringFailed-login and intrusion attempt review, file-integrity checks on critical paths, weekly vulnerability scans of exposed services, and CVE tracking for the software you run. Exposed administrative interfaces are audited quarterly.
  • Uptime and performance monitoringExternal checks from multiple regions every 60 seconds; alerts on downtime, slow responses, expiring certificates, disk filling, memory pressure and failing containers.
  • Backup verificationA backup that has never been restored is a hope, not a backup. Backup jobs are checked daily for success; on Professional and Dedicated plans a real restore onto a scratch server is performed monthly (Professional) or weekly (Dedicated), and the result is in your report.
  • Incident responseWhen something breaks, it is fixed — with a plain-language explanation of what happened and what changed afterward to prevent a repeat. Response-time commitments are set by plan and honoured.
  • Monthly report and change workA short report each month: uptime, patches applied, backup and restore results, capacity trend, and recommendations. Professional and Dedicated plans include a monthly allowance of change work — new applications, configuration changes, user onboarding — with no separate invoice.
06 — Project work

Migrations, custom deployments and audits

One-time, fixed-quote work, either for new clients moving in or for existing clients who need something beyond their monthly allowance. Every project ends with written documentation of what was done.

Migrations

Moving from a home NAS or home-lab server, a shared web host, a VPS at another provider, or a hyperscaler account. The process is the same every time: inventory what exists, build the destination, copy data with a full rehearsal run, compare, then cut over in a window you approve with DNS TTLs lowered in advance. Media libraries of 10–30 TB typically move over several days of background transfer with no interruption to the existing system; the final sync and cut-over takes minutes.

From $900 for a single-application move; multi-application and multi-terabyte migrations are quoted after inventory.

Custom deployments

Applications that need more than a stock container: multi-service stacks with queues and workers, staging and production environments, CI-driven deployment from your repository, custom networking or VPN meshes (WireGuard, Tailscale) between your office and the server, or a specific database topology.

Quoted per project; most fall between $1,200 and $4,500.

Performance audits

For a server you already run — anywhere — that is slow or expensive. Covers resource utilization, database query and index review, caching, reverse-proxy and TLS configuration, container resource limits, storage I/O and transcoding bottlenecks on media servers. You receive a prioritized written report with expected gains for each recommendation, and the option to have the fixes implemented.

$1,200 for a single server; discounted when combined with a migration.

Security audits

An external and authenticated review of an existing server: exposed services and ports, SSH and authentication configuration, patch level and known CVEs, firewall rules, TLS configuration, container privileges and secrets handling, backup coverage and encryption, and logging. Findings are rated by severity with concrete remediation steps.

$1,600 for a single server; remediation can be quoted separately or performed under a plan.

Additional work outside a plan's monthly allowance is billed at $150/hour in 15-minute increments, always agreed in advance.

Not sure which of these you need?

Send a short description of what you want to run and what you have today. You will get a straightforward recommendation, even if the answer is “you don't need a managed server for that.”