Self-Hosted Research Workspaces

A single route for project-scoped source notebooks and broad personal AI workspaces. These products can be useful interfaces over sources, models, and tools; neither becomes Kevin's canonical brain merely because it is self-hosted.

Routing Summary

Need Route Boundary
Durable Kevin-specific memory, operating instructions, source decisions, and agent retrieval wiki + qmd + brain objects Canonical writeback stays in reviewed files and objects, not an application database
A bounded research project over PDFs, web pages, audio, video, notes, transformations, and source chat Open Notebook Project workspace; export durable conclusions and citations back through Source Compile Workflow
Academic-paper discovery, annotation, corpus chat, and writing in Kevin's own product context Sevenfold Product/project owner, not a generic replacement for the wiki
One self-hosted console spanning chat, agents, research, files, email, calendar, shell, MCP, models, and scheduled tasks Odysseus, guarded evaluation only Treat as an admin console with broad authority; do not point it at canonical credentials or private corpora during an exploratory install
Fast read/search/synthesis from the existing corpus qmd and normal source tools Do not deploy another workspace when the task is only retrieval

Open Notebook is the recommended first pilot when the actual job is a source-grounded notebook. Odysseus is broader and more powerful, but its scope overlaps the harness, personal operator, email, scheduling, model-serving, and tool-authority layers; breadth is a reason for stronger isolation, not automatic promotion.

Open Notebook

Open Notebook combines multi-source notebooks, full-text and vector search, source chat, configurable transformations, notes, podcast generation, a REST API, MCP integration, and multiple hosted or local model providers. The project's own comparison acknowledges that its citations are less complete than NotebookLM's; citation quality therefore has to be evaluated on Kevin's documents rather than inferred from the feature list. Source: Open Notebook README and docs, reviewed 2026-08-10

Current reviewed snapshot:

Field Value
Repository lfnovo/open-notebook at a7de90d38aaf18ee85fd661854d35c11e44613e2
Release v1.14.0
License MIT
Reach 36,660 stars and 4,205 forks
Stack Python/FastAPI, Next.js/React, SurrealDB, Docker
Upstream proof Backend tests/typecheck/lint, frontend tests/lint/build, and regular/single image builds passed on the reviewed revision; some separate Dependabot jobs failed and are not product-test proof

The quick-start Compose file binds SurrealDB to loopback but publishes the web and API ports, uses root:root database credentials unless changed, and ships a placeholder encryption key. Password protection is optional and the security policy calls it basic access control rather than a full identity system. A real deployment must set unique database credentials, a durable encryption key, password/access control, restricted CORS, a reverse proxy or private network, backups, and explicit model-provider egress rules before loading sensitive sources. Source: Open Notebook docker-compose.yml, SECURITY.md, and security guide, reviewed 2026-08-10

Odysseus

Odysseus is a much wider self-hosted AI workspace: chat, agents, files, shell, skills, MCP, memory, model discovery/serving, deep research, blind model comparison, documents, IMAP/SMTP email, CalDAV, notes, tasks, calendar, gallery, API tokens, webhooks, and scheduled work. The saved link pointed to a now-missing pewdiepie-archive/odysseus repository. The live odysseus-dev/odysseus repository matches the saved product name and pictured surface; that is a reviewed correlation, not proof of a GitHub redirect. Source: saved X artifact and current Odysseus repository, reviewed 2026-08-10

Current reviewed snapshot:

Field Value
Repository odysseus-dev/odysseus dev at 1fef4929cf1d176145df4d5f8b3e8c446cc45d9c
Release No GitHub release object; main is the curated branch and dev is the default/latest branch
License AGPL-3.0-or-later
Reach 85,131 stars and 410 forks
Upstream proof amd64/arm64 container builds and GitHub CodeQL checks passed on the reviewed revision

Odysseus generates an initial admin password and documents role/privilege controls, but it also exposes shell, file, email, model, MCP, token, webhook, backup, and scheduling authority. Keep the first evaluation loopback-only on a disposable dataset and credentials. Disable open signup, retain only one admin, enable 2FA, review every user privilege and tool, isolate model/service ports, and do not import canonical mail, calendar, provider, or brain credentials until the deployment and recovery model have passed an explicit security review.

Pilot Contract

  1. Choose one real, rights-cleared research corpus with answerable questions and known citations.
  2. Freeze the exact repository revision, deployment files, model/provider, embedding model, credentials boundary, and network exposure.
  3. Measure source-ingest fidelity, citation correctness, retrieval recall, unsupported-claim rate, latency, cost, and export quality against the current qmd/source-tool baseline.
  4. Keep application output provisional. Promote a conclusion only through the same source-review and writeback contract used elsewhere in the brain.
  5. Stop if the workspace needs broader credentials or authority than the pilot requires, cannot export sources and citations durably, or performs worse than the simpler route.

No repository, container, model, credential, or global skill was installed by this review. The source trees were inspected at frozen revisions; adoption requires a separate project-scoped pilot.


Timeline