How to Deploy Dokploy on a VPS
Updated Sep 2026
verified on Ubuntu 26.04 · Sep 2026Install Dokploy on an Ubuntu VPS — claim the admin account before anyone else does, put the panel on HTTPS, close port 3000, and keep a backup that doesn't depend on the panel itself.
- A VPS with at least 2 GB RAM and 30 GB disk (Dokploy's stated minimum)
- A fresh Ubuntu 24.04 or 26.04 server with root/sudo SSH access, dedicated to Dokploy
- Ports 80, 443 and 3000 free — nothing else listening on them
- A domain you can point at the server (for HTTPS)
What Dokploy is
Dokploy is a self-hosted deployment platform in the mould of Vercel, Heroku or Netlify: you connect a Git repository (GitHub, GitLab, Bitbucket, Gitea) or point it at a Docker image or a Compose file, and it builds, runs and routes the app, with databases and scheduled backups managed from the same UI. It is Apache-2.0, built with TypeScript and Next.js, and runs on Docker Swarm with Traefik as its router.
Like every platform of this kind, it takes over the box: the installer initialises a Swarm, and Traefik claims ports 80 and 443 for every app you deploy. Use a dedicated server. If you are still choosing, Coolify vs Dokploy compares it with the other popular option (see also the Coolify guide), and CapRover and Dokku are the older, lighter alternatives.
Server sizing
Dokploy's docs ask for at least 2 GB of RAM and 30 GB of disk, to leave room for Docker builds, which are what freeze undersized servers. On our test box (GCP e2-standard-2, Ubuntu 26.04, August 2026) a freshly installed, idle Dokploy — panel, Postgres and Traefik — used about 870 MB of RAM and about 5 GB of disk before any app was deployed.
So a 2 GB server leaves roughly 1 GB for your apps and builds. For more than a couple of apps, or anything built from source with Node or Java, start at 4 GB. Disk grows with every build and image; 40–80 GB is a sensible start.
Prepare the server
Dokploy's installer installs Docker itself if it is missing, and fails if anything already listens on 80, 443 or 3000. Its docs list Ubuntu 24.04 and earlier as tested; we ran the installer on Ubuntu 26.04.
Open SSH, the web ports, and 3000 for the panel:
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 3000/tcp
sudo ufw --force enable
sudo ufw status
Check your provider's firewall too. Port 3000 is only needed until the panel has its own HTTPS domain.
Paid link — we earn a commission if you shop through it.
Install Dokploy
The official one-line installer:
curl -sSL https://dokploy.com/install.sh | sudo sh
It initialises Docker Swarm, creates a Postgres service with a generated
password stored as a Docker secret, starts the Dokploy panel as a Swarm
service publishing port 3000, and runs Traefik as a container on 80 and 443.
It always installs the latest stable release; each GitHub release also ships
its own install.sh if you need to pin a version.
Wait for the panel to answer, then check the pieces:
for i in $(seq 1 60); do
[ "$(curl -s -o /dev/null -w '%{http_code}' http://127.0.0.1:3000/)" != "000" ] && break
sleep 5
done
curl -s -o /dev/null -w "panel: %{http_code}\n" http://127.0.0.1:3000/
sudo docker service ls
sudo docker ps --format '{{.Names}}\t{{.Status}}'
You should see the dokploy and dokploy-postgres services at 1/1 and a
dokploy-traefik container running.
Claim the admin account — immediately
Open http://SERVER_IP:3000. The first page is a setup form that creates the
administrator account. Until you submit it, anyone who reaches port 3000
gets that form, so do this as soon as the installer finishes. Use a long,
unique password, and enable two-factor authentication in your profile
settings afterwards.
HTTPS + domain
Point an A record for the panel (say dokploy.example.com) at the server
and wait for it to resolve. Then assign that domain to the Dokploy panel itself
in its web-server settings, with Let's Encrypt as the certificate provider —
Dokploy's Domains documentation walks through the options (Let's Encrypt,
Cloudflare, or your own certificate). Traefik requests the certificate; port
80 must be reachable from the internet for the challenge.
For your apps, each Application or Compose service gets domains in its own
Domains tab. For Applications, Dokploy writes a Traefik config file per
domain and changes apply without a redeploy; for Docker Compose, domains are
Traefik labels and you must redeploy after changing them. Dokploy can also
hand out free traefik.me hostnames for quick tests, but those are HTTP-only.
Once https://dokploy.example.com works, stop publishing port 3000, as the
docs recommend. Do this only after the HTTPS domain works, or you lock
yourself out:
docker service update --publish-rm "published=3000,target=3000,mode=host" dokploy
sudo ufw delete allow 3000/tcp
Deploy a first app
In the panel: create a Project, add an Application, choose the source (a Git provider you connect under Settings, a public Git URL, or a Docker image), set the build type (Nixpacks, Dockerfile, Buildpacks and others), and deploy. Then add a domain in its Domains tab with HTTPS on. Add Databases (Postgres, MySQL, MariaDB, MongoDB, Redis) as separate services in the same project, so they sit on the same internal network as the app.
Any app that stores files needs a volume or bind mount in its Advanced settings before it holds real data; otherwise the data lives in the container and is replaced on the next deploy.
Securing it
- Close port 3000 after HTTPS works (above), and turn on 2FA.
- Keep
ufwactive with a default-deny incoming policy. Dokploy's own server security checklist asks for exactly that. Remember that ports Docker publishes bypassufw, so don't publish database ports "just to check". - Treat the panel as root. It controls the Docker socket, so anyone with an admin login can run anything on the host. Invite team members with limited roles rather than sharing the admin.
- Keep it updated (see Upgrades); the panel is internet-facing.
Backups
Dokploy's built-in backup (Web Server → Backups) saves the Dokploy Postgres
database and the /etc/dokploy directory as one archive, but only to an S3
destination, which you configure first. Set that up, and set database
backups for each database service too.
It's worth also having a copy that doesn't depend on the panel working. The
two pieces are the dokploy Postgres database and /etc/dokploy:
cd ~
PG=$(sudo docker ps -qf name=dokploy-postgres)
sudo docker exec "$PG" pg_dump -U dokploy dokploy | gzip > ~/dokploy-db-$(date +%F).sql.gz
sudo tar czf ~/dokploy-etc-$(date +%F).tar.gz -C / etc/dokploy
ls -lh ~/dokploy-db-*.sql.gz ~/dokploy-etc-*.tar.gz
Copy both off the server. These cover Dokploy's configuration, not your apps' data — back up each app's volumes and databases separately.
Upgrades
The panel shows when a new version is out. From the shell, the documented update command is:
curl -sSL https://dokploy.com/install.sh | sudo sh -s update
Take a backup first, and read the release notes: Dokploy is young and moves fast, and some releases change how the core services are laid out.
Troubleshooting
The panel on port 3000 doesn't load. Check sudo docker service ls and
sudo docker ps: you want dokploy and dokploy-postgres at 1/1 and
dokploy-traefik up. Read docker service logs dokploy.
Logs show getaddrinfo ENOTFOUND dokploy-postgres. After a reboot, the
panel sometimes starts before Postgres. The documented fix is to restart the
panel service:
docker service scale dokploy=0
docker service scale dokploy=1
The panel became unreachable after many deploys. Usually a full disk,
which can push Postgres into recovery. Check df -h, then clear build cache
and unused images with docker builder prune -a and docker image prune -a.
Avoid pruning volumes — they may hold app data.
An app's domain returns 404 or has no certificate. Check the DNS record,
that port 80 is reachable, and docker logs dokploy-traefik for ACME or
config errors. For Compose apps, redeploy after any domain change.
Verification + next steps
You're done when: the panel loads at https://dokploy.example.com with a
valid certificate and 2FA, port 3000 is closed, a test app serves on its own
HTTPS domain, and you have one backup in S3 and one copy off the box.
From there, connect your Git provider, move your apps over one at a time, and set database backups for each. For hosting picks, see Best VPS for Docker and Best VPS for Node.js.