In January 2026, an engineer published a postmortem with an embarrassing headline: "We Set Up Prometheus. It Consumed More Resources Than Our Apps." Cardinality had done what cardinality does — turned a monitoring sidecar into the hungriest workload on the box — and the team ended up monitoring Prometheus itself to keep the thing that watches the apps from eating the apps. It is the purest possible expression of the self-hosted observability tax: ten-odd components (Prometheus, Grafana, Alertmanager, node-exporter, cAdvisor, blackbox-exporter, Loki, Promtail, Trivy, and something for image updates), each with its own config, upgrades, and dashboards, to answer one question — is my stack up, and what is burning?
On September 9, 2026, a Show HN proposed deleting that stack rather than tuning it. Maintenant ("now" in French) is a single Go binary that auto-discovers Docker, Kubernetes, uptime endpoints, TLS certificates, cron jobs, live logs, image updates, and CVEs, with alerting on every one of them — idling under 30 MB of RAM, with no PromQL, no exporters, and no dashboards to build. The repo has passed 500 stars, is under active development (AGPL-3.0, last pushed days before this writing), and its pitch is exactly three words long: drop a container.
The honest question is not whether one binary is simpler than ten components. It obviously is. The question is what the simplicity costs — which components it genuinely replaces, which it only approximates, and where the ceiling is. Here is the full accounting, starting with the map.
The replacement map: ten components versus one binary
This is the core of the post, so it goes first. Each row is one piece of the conventional self-hosted stack and what Maintenant does about it:
| Stack piece | Replaced? | How |
|---|---|---|
| node-exporter + cAdvisor | Yes | Per-container and per-host CPU, memory, network, and disk I/O, top-consumers triage view, per-container thresholds with debounce |
| blackbox-exporter | Yes | HTTP/TCP checks declared as Docker labels, picked up when the container starts; response times, uptime history, 90-day sparklines |
| TLS cert exporter | Yes | Auto-detected from HTTPS endpoints plus standalone domain monitors; full chain validation, expiry alerts at 30/14/7/3/1 days |
| Pushgateway for cron | Yes | Heartbeat URLs: one curl in the job, tracks start, finish, duration, exit code, alerts on missed deadlines |
| Diun / Watchtower | Yes | Digest-based image-update detection against registries, with compose-aware update and rollback commands |
| Status page (Cachet, Uptime Kuma) | Yes | Real-time status page over server-sent events; incident timelines and subscriber notifications on paid tiers |
| Alertmanager | Mostly | One alert pipeline for every source, severity/source/scope routing, silence rules, exponential backoff; escalation policies on Pro |
| Loki + Promtail | Partially | Live container log streaming with stdout/stderr demuxed — great for tailing, not a replacement for long-term retention and search |
| Trivy + exporter | Partially | Network exposure audit is free (wildcard binds, exposed database ports, privileged containers, LoadBalancers without NetworkPolicy); CVE enrichment and per-container risk scores need Personal |
| Grafana | Partially | A prebuilt real-time dashboard covers every standard infrastructure view; you lose custom panels, mixed data sources, annotations, and ad-hoc Explore |
| Prometheus itself | No | No PromQL, no custom exporters, no application metrics. The project's own line: Maintenant monitors your infrastructure; Prometheus monitors your application. Keep Prometheus for that. |
Two rows deserve emphasis because they are where marketing blurbs get slippery. The Grafana row cuts both ways: "no dashboards to build" also means no dashboards you can build — the day you want one panel joining deploy events with your app's p99 latency, the fixed UI has nothing to offer. And the 30 MB figure is the vendor's idle number; loaded footprint with agents attached, logs streaming, and retention accumulating is unstated, so treat it as a lower bound, not a capacity plan.
What the binary actually is
The verified facts, minus the pitch. One statically linked Go binary with a Vue 3 frontend embedded in it and SQLite as its only datastore — no Redis, no queue, nothing else to administer. The same file runs in three modes: embedded (single host, the default), server (central ingestion for a fleet), and agent (a lightweight read-only process on remote hosts). A fleet operator that already runs PostgreSQL can point the server at it; agents always stay on SQLite.
Configuration is Docker labels plus a handful of environment variables. There is no YAML to maintain:
labels:
maintenant.endpoint.http: "https://api:3000/health"
maintenant.endpoint.interval: "15s"
maintenant.endpoint.failure-threshold: "3"Declare that on a container and the endpoint check exists when the container starts. Kubernetes works the same zero-config way — kubectl apply, in-cluster API auto-detected, read-only RBAC, namespace filtering, workloads as first-class citizens — and endpoints, certificates, and heartbeats run even with no container runtime at all.
The security posture is deliberately boring: read-only everywhere (read-only socket mount, read-only RBAC, read-only agents — it never starts, stops, or modifies a container), a hardened container running as nobody with a read-only root filesystem, and no built-in authentication, by design. Like Dozzle and Prometheus itself, it sits behind your reverse proxy and auth middleware. Telemetry is anonymous, counts-only, and opt-out with a single variable.
Two features push it past "prettier Uptime Kuma." First, multi-host: agents enroll with a one-time token and a locally generated Ed25519 keypair over a mutually authenticated gRPC stream — no shared database, no PKI to run. Second, a built-in Model Context Protocol server, so an AI assistant can ask what is burning, read a container's logs, check the alert queue, and acknowledge alerts. For a tool aimed at solo operators, letting an agent do the 3 a.m. triage reads less like a gimmick than a roadmap bet.
The business model is open core, and the tiers matter because they draw the ceiling. Community is free under AGPL-3.0 but capped: one host, 10 endpoints, 5 heartbeats, 5 certificates, 7 days of resource history. Personal is €149 once (up to 20 remote machines, unlimited monitors, 30-day history, CVE enrichment, email and Telegram alerts).
Pro is €29/month or €290/year (unlimited hosts, 90-day history, Slack and Teams, escalation policies, maintenance windows). Paid editions are the same self-hosted binary with a license key; monitoring data never leaves your infrastructure.
The bill: what you give up
Every simplification in the map above has a price. Here it is, itemized:
Coverage caps on the free tier. One host, 10 endpoints, 5 heartbeats, 5 certificates. That fits a homelab or a single VPS comfortably and a small production stack awkwardly — the eleventh endpoint is the moment Community stops being a decision and starts being a trial.
Retention caps on every tier. Seven days on Community, 30 on Personal, 90 on Pro. There is no tier where year-over-year capacity planning or a six-month incident postmortem lives inside this tool. Long-term metrics retention is the first thing the binary structurally cannot replace.
No PromQL and no custom metrics. This is the load-bearing wall. You cannot define an SLO, burn-rate alert, or business metric, because there is no query language and no ingestion path for application data. The project is admirably upfront about the split — infrastructure here, application in Prometheus — but it means "replace your monitoring stack" really means "replace the infrastructure half of it."
No dashboards you can build. The fixed UI is the product: nothing to maintain, and nothing to extend. Custom panels, mixed data sources, annotations marking deploys, ad-hoc exploration of a weird 2 a.m. correlation — all gone. Grafana's flexibility is exactly the tax you are refusing to pay, but name it as a loss, not just a saving.
No built-in auth. Fine behind Authelia or Authentik, a real footgun on a bare VPS if you publish the port without reading the compose file's own warning. The project shouts about this in its quickstart; first-time users should still treat it as a setup step, not a default.
Paid security depth. The network exposure audit is free, but CVE enrichment, per-container risk scoring, and the unified security posture dashboard need Personal, and on-call escalation needs Pro. Reasonable pricing — but the Show HN headline's "CVEs" has an asterisk.
Distilled into the checklist that decides the purchase:
| You will outgrow it when… | …because |
|---|---|
| You write your first SLO or burn-rate alert | No PromQL, no custom metrics, no error budgets |
| You ask "what did last quarter look like" | History caps at 7/30/90 days by tier |
| You ask "can I add a panel joining deploys with app latency" | Fixed UI: no custom Grafana-style dashboards |
| You ask "what happened last Tuesday in the logs" | Live log streaming, not retained searchable history |
| A second team wants its own views and routing | No multi-tenancy; per-entity routing and escalation are Pro-only |
| You need SSO, audit logs, or compliance retention | Enterprise tier or a different tool entirely |
None of these are hidden — they are all in the README and the editions table. That is to the project's credit, and it makes the evaluation cheap: if none of these rows bite in the next year, the binary is enough.
From one box to a fleet
The interesting architectural question is whether the agent model graduates. A central server with read-only agents on every host, each enrolling with a token and streaming over gRPC, genuinely covers the "I now have six machines" phase that kills most single-box tools. Personal's 20-machine ceiling even names the target: the serious homelab, the indie SaaS on a handful of VPSes, the small team that owns its hardware.
But agents solve reach, not depth. A fleet's observability layer is defined by the queries it can answer across machines and across months — per-tenant usage, capacity trends, SLO compliance — and every one of those hits the same walls: no query language, capped retention, SQLite-default storage, no multi-tenancy. The PostgreSQL option raises the storage ceiling without touching the query ceiling. So the decision rule is clean:
- Adopt it if you are one person or one small team watching infrastructure you own: a VPS or two, a home server, a single-cluster side project. The setup cost is one container, the idle cost is tens of megabytes, and the coverage per minute of configuration is unmatched in the self-hosted world right now.
- Keep Prometheus (possibly alongside it — the project explicitly blesses running both) if you serve multiple tenants, define SLOs, retain metrics past a quarter, or need anyone outside the ops chat to build a view. At that point the ten-component stack is not a tax; it is the job.
The single-binary wave
Maintenant is not an anomaly; it is the current crest of a wave. Beszel, Perch, Labwatch, and others have all converged on the same thesis: a Go or Rust binary with SQLite and an embedded UI, aimed squarely at operators tired of running Dozzle, Beszel, and Uptime Kuma side-by-side to cover one VPS. The differentiators are now breadth of auto-discovery (Maintenant's endpoint-label model and update intelligence go further than most), Kubernetes nativeness (many stop at Docker), and honesty about the ceiling (few state the infrastructure/application split this plainly).
The deeper trend is what got removed. Every tool in this wave deletes the query language, the config files, and the dashboard builder — the three surfaces where Prometheus's power lives and where its operational cost lives too. That is a real trade, not a free lunch, and the teams happiest with these tools are the ones who made it deliberately: they know which questions they have stopped being able to ask, and they checked that none of them are questions they ask.
For everyone else, the stack stays. Cardinality still kills, dashboards still rot, and somebody still has to upgrade Alertmanager. But the next time Prometheus starts eating more than the apps, it is worth remembering that the alternative is no longer "pay Datadog or suffer." It is a 30-megabyte binary that already knows what a container, a certificate, and a cron job are — as long as you never need to ask it anything else.
Bex.co is the open-source, AI-native Render alternative — push a git repo, get a running HTTPS service on machines you own. Self-hosting your monitoring next to your apps is exactly the kind of stack it is built for: star the repo on GitHub or deploy your first app today.



