Skip to main content
Custom & Self-Hosted Infrastructure for Drupal

Self-hosted Drupal hosting & infrastructure

For organizations that must keep Drupal inside their own network, whether that means bare metal, a private cloud, or a public cloud account, Metadrop designs, deploys, and manages self-hosted infrastructure with the security and DevOps discipline that regulated, high-traffic platforms need.
Stack base

What is self-hosted Drupal infrastructure?

Self-hosted Drupal infrastructure means Drupal runs on servers that Metadrop or the client controls directly: bare metal, a private cloud, or a public cloud account inside the client's own network, rather than on a third-party managed PaaS. That's what distinguishes it from managed platforms such as Acquia, Pantheon, and Upsun/Platform.sh, where a platform vendor, not the client or Metadrop, owns the hosting account, the network perimeter, and the compliance boundary. It's also called on-premise, custom, or dedicated Drupal hosting, depending on where the servers physically sit.

This approach suits organizations with data residency, sovereignty, or on-premise mandates: public sector bodies, regulated industries, or any team that needs the hosting environment inside its own infrastructure footprint, including intranet deployments run on internal networks. Metadrop designs the architecture, provisions the servers, and takes on ongoing DevOps management, so choosing self-hosting doesn't mean the client's own team has to run it alone.

Why choose self-hosted Drupal hosting

Self-hosted infrastructure keeps data inside the organization's own network or chosen provider, supporting sovereignty and data-residency requirements without depending on a third-party platform's jurisdiction. Cost is sized to actual traffic, since infrastructure is scoped to the client's own usage pattern rather than a platform's fixed tiers. Architecture, scaling, and tooling choices stay under the client's and Metadrop's control, which matters when a previous hosting relationship is ending or underperforming.

This is a fit for organizations moving off an end-of-support host, consolidating multiple sites, or responding to a failed compliance audit, all recurring triggers for evaluating self-hosted infrastructure. Metadrop has deployed self-hosted infrastructure for public-sector, NGO, and enterprise platforms spanning municipal government, humanitarian networks, and multi-country corporate sites.

Comparing platforms? See Acquia hosting, Pantheon hosting, and Upsun hosting for the managed alternatives.

Web stack components

Our base Drupal hosting stack

The base stack runs Apache as the web server, tuned to Drupal's own configuration recommendations so modules and core need less custom tuning. An FPM PHP engine, oriented to high-traffic sites, manages PHP processes efficiently under load, while NGINX sits in front as a cache layer, SSL terminator, and static-content server, taking work off Apache. MariaDB serves as the database, the community's common choice for Drupal, requiring no additional configuration or module. Redis handles in-memory caching, moving regenerable cache tables into memory to reduce database load during traffic spikes.

This base stack is sized to handle high traffic without over-provisioning, suited to the majority of Drupal platforms Metadrop hosts.

Stack options

Advanced options for high-traffic platforms

For platforms that need it, Metadrop adds Varnish as a specialized reverse proxy, configurable through VCL for fine-tuned caching rules. CDN integration with major providers adds threat prevention, faster global delivery, and resilience for campaigns and traffic spikes. Multiple web frontends with load balancing (HAProxy or an equivalent) support horizontal scaling once vertical scaling reaches its limit. Database replication, a main database plus one or more replicas, offloads read traffic on platforms with high database load.

Metadrop selects which of these to add per platform rather than bundling them by default, so infrastructure cost tracks actual traffic and complexity.

distintivo_ens_certificacion
Logo GDPR
Logo NIS2
Logo WCAG

Security, compliance & data sovereignty

Self-hosted infrastructure keeps application, database, and file storage inside the client's chosen jurisdiction and network boundary, supporting EU data-residency and sovereignty requirements.

Metadrop holds ENS certification and has a delivery track record against GDPR, WCAG, and NIS2 requirements, applied directly to the client's own infrastructure rather than inherited from a third-party platform. Access controls, hardened server configuration, and sanitized non-production environments are configured as part of the setup, designed to support a compliance audit.

For organizations weighing a compliance risk, whether that's a failed audit, a NIS2 scope question, or an expiring vendor contract, self-hosting reduces dependency on a platform vendor's own compliance posture and jurisdiction (an interpretation of applicability to a specific organization's regulatory scope, not legal advice).

Public-sector and international NGO platforms in Metadrop's portfolio run on self-hosted infrastructure delivered under these same compliance requirements.

Backup, reliability & DevOps management

Scheduled backups follow a documented restore process, designed to minimize data-loss exposure between backup intervals. Proactive monitoring and incident response are part of the managed DevOps service, not a reactive add-on.

Database replication (see Advanced options above) doubles as a reliability layer, not only a performance one, on platforms that adopt it. Metadrop's DevOps team applies the same CI/CD, monitoring, and patching discipline used on managed-platform engagements to self-hosted infrastructure. A contractual SLA defines response times and escalation paths for incidents on the self-hosted environment.

They've Trusted Metadrop

From municipal government to international NGOs and global enterprise distribution networks, organizations across Europe and beyond have relied on Metadrop for self-hosted Drupal infrastructure.

Managed a self-hosted multisite platform for a Basque municipal government, including a dependent intranet build and a Drupal 10 upgrade.

Set up self-hosted server infrastructure for an international social-inclusion NGO, alongside a CMS migration and CRM integration.

Delivered self-hosted infrastructure combined with cloud object storage for a large Southern-European digital media group running multiple country sites.

Ran self-hosted deployment and setup for a global workplace-products distributor's 19-country platform ecosystem.

Metadrop Logo

Why Metadrop for self-hosted Drupal hosting

Metadrop brings 15+ years of Drupal delivery and Drupal Silver Certified Partner status to bare-metal and private-cloud environments as well as managed platforms. Its international reach spans platforms across 50+ countries and 30+ languages, including multilingual and multisite architectures.

Independent technical governance means Metadrop advises on the self-hosted-versus-managed decision itself, weighing compliance and team capacity rather than defaulting to one option. Self-hosted infrastructure is quoted per engagement, scoped to the client's traffic, compliance, and team-capacity needs rather than a fixed tier; a discovery call produces a written proposal.

Frequently asked questions

  • What is self-hosted Drupal infrastructure?

    Self-hosted Drupal infrastructure is Drupal running on servers the client or Metadrop controls directly, whether that's bare metal, a private cloud, or a public cloud account inside the client's own network. This differs from managed platforms such as Acquia, Pantheon, and Upsun/Platform.sh, where a platform vendor owns the hosting account and network boundary. It's also called on-premise, custom, or dedicated Drupal hosting, depending on where the servers physically sit.
  • What are the benefits of self-hosted Drupal infrastructure?

    Data and infrastructure stay inside a chosen jurisdiction and network boundary, supporting sovereignty and data-residency requirements. Cost is sized to actual traffic rather than a platform's tiered pricing, and organizations carry less exposure to a single platform vendor's roadmap, pricing changes, or jurisdiction.
  • Self-hosted vs. managed Drupal hosting: which is right for us?

    Self-hosted suits organizations with sovereignty, data-residency, or on-premise mandates, or that already run their own infrastructure team. Managed platforms suit teams that want to hand off provisioning and patching entirely: see Acquia, Pantheon, and Upsun hosting for those alternatives. Metadrop advises on the trade-off based on the organization's compliance and team-capacity needs, rather than defaulting to one option.

  • How do you secure a self-hosted Drupal environment?

    Hardened server configuration, access controls, and sanitized non-production environments are configured as part of the setup. Ongoing patching and monitoring are delivered as a managed DevOps service, not a one-time setup. This work is designed to support a compliance audit, covering GDPR, WCAG, and NIS2 obligations.
  • What compliance and data-sovereignty requirements does self-hosted infrastructure address?

    Application, database, and file storage stay inside the client's chosen jurisdiction and network boundary. Metadrop holds ENS certification and a delivery track record against GDPR, WCAG, and NIS2 requirements. Whether a given regulation applies to a specific organization is an interpretation, not legal advice; Metadrop provides the technical translation, not the legal opinion.
  • How much does self-hosted Drupal infrastructure cost

    Self-hosted Drupal infrastructure is priced per engagement, scoped to traffic volume, compliance requirements, and how much DevOps management the client's own team retains. Pricing doesn't follow fixed tiers, since server sizing and architecture vary by platform. A discovery call produces a written, scoped proposal.
  • How do you migrate an existing Drupal site to self-hosted infrastructure?

    An audit of the current stack, traffic profile, and integrations scopes the target architecture. Data, files, and configuration move into a production-identical environment for validation before cutover. A planned cutover window is used to minimize disruption, with a rollback path if issues surface.

Ready to move to self-hosted Drupal hosting?

Tell us about your traffic, compliance, and network requirements, and Metadrop responds with a scoped assessment, not a generic pitch. There's no obligation: a discovery call confirms fit before any proposal is written.

Escribe tu mensaje aquí...
I have read and accepted the privacy policy regarding data processing.