At 2 a.m., the site is down. The developer gets the alert. Expired certificate, full disk, corrupted database, or botched app deploy? On self-managed hosting, the first available person becomes sysadmin — even if their contract says "full-stack developer," not "operations." On well-scoped managed hosting, the ticket goes to the right contact with an SLA. The difference is not a "premium" logo: it is who is contractually obliged to act.
Responsibility matrix
| Task | Self-managed (you) | Managed (vendor) | Common hybrid |
|---|---|---|---|
| OS / kernel updates | You | Vendor | Vendor |
| Firewall, brute-force protection | You | Partial vendor | Vendor |
| TLS certificates | You or auto Let's Encrypt | Often included | Shared |
| Backups | You configure | Included or option | Vendor |
| Restore | You test | Defined SLA | Vendor, you validate |
| Application (CMS, code) | You | You | You |
| Database performance | You | Rarely included | You |
| Monitoring | You | Basic included | Vendor + you |
"Managed" covering only the admin panel leaves 100% of the server on you. Read contract, not pricing card.
Worst scenario is not full self-managed. It is blur where nobody knows who patches the kernel.
Who should administer? Three team profiles
Product team without dedicated operations. You build, do not want to learn systemd this quarter. Managed removes a class of night incidents. Premium is operations insurance.
Team with a sysadmin lead. Self-managed is rational if someone owns updates, tested backups, documented runbooks. Vendor provides infrastructure; you operate it.
Regulated or critical team. Managed does not exempt GDPR duty, but SLA and documented restore ease audit. Demand proof, not badge.
Hidden cost of self-managed
Calculate monthly hours: disk/cert/service monitoring; security updates; off-hours incident response; quarterly restore tests; documentation and handover.
Multiply by loaded developer or operations cost. Often exceeds price gap vs serious European managed offer. Self-managed is not "cheaper" — it is internalized.
Common boundary mistakes
Assuming host restores without tested SLA. Delegating application to vendor when contract covers system only. Buying managed to do nothing — WordPress updates stay yours on partial WP managed. Staying self-managed without on-call — servers ignore business hours.
The peak: managed buys organized human availability
Decide and move forward without blind spots
List last ten server interventions and who actually did them. Calculate internalized hourly cost over twelve months with on-call included or honestly excluded. Request written managed scope with explicit exclusions — application, database, certificates. Test a restore before relying on vendor. Define on-call if staying self-managed. Compare via directory and comparator. For WordPress: managed WordPress.
Frequently asked questions
What is truly managed hosting?
The vendor assumes defined tasks such as updates, monitoring and backups, sometimes restore. Scope varies widely — verify the contract line by line before assuming the server is covered.
Is self-managed cheaper?
List price yes, rarely total cost once you include internal time, tooling and incident response at loaded salary rates.
Can you be self-managed with a partial team?
Yes with clear boundaries: you run the application while the vendor runs the system — an explicit hybrid beats ambiguous shared responsibility.
How to verify managed scope before signing?
Request a written list covering updates, backups, restore SLA, support hours and explicit exclusions for application, database and DNS before you sign.
Managed or self-managed, the right answer fits in one contract sentence: who opens the ticket at 2 a.m., and under what deadline.