Almost all of my passwords are:
password = base64.b64encode(pbkdf2(master_password + '/' + domain, b'', 100000+n, keylen=16))[0:16].decode() + '$1Aa'
where master_password is not written or stored anywhere, domain is the domain name of the service in question, and n is the nth password generated for the service in question (since some services force you to change passwords every N months).
'$1Aa' is to appease stupid websites that require a symbol, number, uppercase, and lowercase letter.
Truncation to 16 characters is to appease stupid websites that limit passwords to 20 characters.
I also use the same thing for the answers to all "security" questions online, where I just plug in the security question as domain. (They're basically de-security questions, since, you know, a lot of people in this world know what my favorite color is and what streets I used to live on).
I should probably use HMAC but whatever.
The only passwords I have that are not part of this system are my computer's root password, e-mail password, and bank account passwords; for those I just memorized random strings).
This system gives me the following advantages:
* Peace of mind that I don't have to trust a 3rd party, closed-source password manager
* No need to cloud-sync anything across machines. No need to access the internet.
* I can calculate my passwords without a database, so if I have to randomly reformat my machine while travelling I can still compute my passwords and login to everything I need to.