How to Deploy Radarr on a VPS
Updated Sep 2026
verified on Ubuntu 26.04 · Sep 2026Self-host Radarr on a VPS with Docker Compose and HTTPS — the movie counterpart to Sonarr — set up on one shared /data volume so finished downloads import as instant hardlinks.
- A VPS with 1 vCPU / 1 GB RAM or more (Radarr itself needs about 512 MB)
- Enough disk for downloads and the finished film library, on one filesystem
- A fresh Ubuntu 24.04 or 26.04 server with root/sudo SSH access
- A domain you can point at the server
- Docker Engine + Compose installed (see the base guide below)
- An indexer and a download client (Usenet or BitTorrent) to connect it to
What Radarr is
Radarr is a movie library manager for Usenet and BitTorrent users, built on the same codebase as Sonarr. You add the films you want; Radarr watches your indexers for a release that matches your quality profile, hands it to your download client, then renames the finished file and moves it into your movie library for a media server such as Jellyfin or Plex. It is GPL-3.0, written in C# / .NET with a React UI.
Like Sonarr, it needs two other pieces: an indexer (usually managed with Prowlarr) and a download client. Use it for content you have the right to download.
If you already run Sonarr, this install will look familiar — the container, the reverse proxy and the folder layout are the same shape. The differences are in how films are released and tracked, which the first-run section covers.
Server sizing
On our test box (a GCP e2-standard-2 on Ubuntu 26.04), idle Radarr used about 108 MB of RAM and 297 MB of disk. The catalog's floor is 512 MB of RAM.
- 1 GB RAM / 1 vCPU — Radarr alone, or with Prowlarr.
- 2–4 GB RAM / 2 vCPU — Radarr, Sonarr, Prowlarr and a download client on the same box.
As with Sonarr, disk decides the plan: downloads and the finished library have to share one filesystem, and films are large files. Look at storage-heavy plans or attached block storage.
One /data volume, not /movies + /downloads
The linuxserver image's own example mounts /movies and /downloads
separately. The Servarr wiki explains why that's a trap: inside the container,
two mounts are two filesystems, even if they're the same disk on the host.
Radarr then can't hardlink a finished download into the library, so every
import is a copy and a delete — slow, and while a torrent is still seeding, it
uses the disk twice. Separate mounts also mean the download client and Radarr
disagree about paths, which is what Remote Path Mappings exist to patch.
The wiki's recommendation is one common /data volume mounted the same way
in every container:
/srv/data
├── torrents/movies ← the torrent client saves here
├── usenet/movies ← the Usenet client saves here
└── media/movies ← Radarr's root folder, what the media server reads
If Sonarr already uses /srv/data, add the movie folders next to its TV
folders; the two apps share the tree without conflict.
sudo mkdir -p /srv/data/torrents/movies /srv/data/usenet/movies /srv/data/media/movies
sudo chown -R $(id -u):$(id -g) /srv/data
sudo chmod -R 775 /srv/data
Group-writable folders and a UMASK of 002 are the wiki's suggestion when
several containers need to write each other's files.
Paid link — we earn a commission if you shop through it.
Prepare the server
This guide assumes Docker Engine and the Compose plugin are installed, along
with a non-root user and a ufw firewall. If not, work through
Docker & Compose on Ubuntu first.
sudo ufw allow OpenSSH
sudo ufw allow 80
sudo ufw allow 443
sudo ufw --force enable
sudo ufw status verbose
Install Radarr (Docker Compose)
The Servarr wiki lists two images; this guide uses linuxserver.io's, which
runs as the user you give it through PUID/PGID:
mkdir -p ~/radarr && cd ~/radarr
mkdir -p config
printf 'PUID=%s\nPGID=%s\n' "$(id -u)" "$(id -g)" > .env
cd ~/radarr
cat > docker-compose.yml <<'YAML'
services:
radarr:
image: lscr.io/linuxserver/radarr:latest
container_name: radarr
environment:
- PUID=${PUID}
- PGID=${PGID}
- UMASK=002
- TZ=Etc/UTC
volumes:
- ./config:/config
# One volume for downloads AND library, so imports are hardlinks.
- /srv/data:/data
ports:
# Loopback only — Caddy is the sole route in from outside.
- "127.0.0.1:7878:7878"
restart: unless-stopped
YAML
docker compose up -d
Wait for it to answer:
cd ~/radarr
for i in $(seq 1 60); do curl -fsS -o /dev/null http://127.0.0.1:7878/ping && break; sleep 2; done
curl -s http://127.0.0.1:7878/ping; echo
docker compose ps
Your download client needs the same - /srv/data:/data mount (or its own
subfolder of it), with its save folder set to /data/torrents/movies or
/data/usenet/movies.
HTTPS + domain
Point an A record for radarr.example.com at the server's public IP and
wait for it to resolve. Then terminate TLS with Caddy — see
Automatic HTTPS with Caddy:
radarr.example.com {
reverse_proxy 127.0.0.1:7878
}
Running Sonarr on the same box? Add a second block for its hostname to the same
Caddyfile. If Caddy runs as a container, share a compose file and proxy to
radarr:7878.
First run
Open https://radarr.example.com. As of Radarr v5, authentication is
mandatory, so the first screen asks you to choose a method and create
credentials. Pick Forms (Login Page) and keep Authentication Required
on Enabled.
Then configure, in this order:
- Settings → Media Management → Root Folders — add
/data/media/movies. - Settings → Download Clients — add your client, with the path it sees
(
/data/torrents/moviesor/data/usenet/movies). The shared/datalayout means no Remote Path Mapping. - Indexers — add them here, or sync them from Prowlarr.
- Movies → Add New — search for a film and add it.
Two film-specific settings are worth understanding when you add movies:
- Minimum Availability — Announced, In Cinemas or Released. It sets the point at which Radarr starts searching. Films exist in the catalogue long before a release you'd want is available, so Released avoids searching early and grabbing poor early copies.
- Import Lists — Radarr can follow lists (for example from Trakt or TMDb) and add their films automatically, with a quality profile and monitoring already applied.
Securing it
- Keep Authentication Required on Enabled. The other mode, Disabled for
Local Addresses, trusts requests that appear to come from the LAN; the wiki
warns that a spoofed
X-Forwarded-Forheader can fake that unless your proxy is listed under Trusted Networks. With Enabled, the question doesn't arise. - Treat the API key like a password. Prowlarr and request tools use it, and it grants full control of Radarr.
- Keep port 7878 on loopback. The compose file never publishes it.
Backups
Radarr backs up its own database — by default every 7 days, kept for 28 days — and System → Backup → Backup Now makes one on demand. Those are written with the config, on the same disk, so also copy the config folder off the box:
cd ~/radarr
docker compose stop
sudo tar czf radarr-config-$(date +%F).tar.gz config docker-compose.yml .env
docker compose start
Stopping first gives a consistent copy of the SQLite database. Restore either
through System → Backup → Restore Backup or by putting config back before
the container starts. Back up the film library itself like any other large set
of files.
Upgrades
cd ~/radarr
docker compose pull
docker compose up -d
Updating a Docker install means pulling a new image, not using the in-app updater. Back up first — migrations run on startup.
Troubleshooting
Imports take minutes and disk use doubles. Hardlinks aren't working. Check
that the root folder is /data/media/movies and that the download client
reports paths under /data. ls -li on the downloaded file and the imported
one should show the same inode number.
"Path does not exist" on import. The download client and Radarr see
different paths. Mount /srv/data identically in both, rather than adding a
Remote Path Mapping.
A film is monitored but never searched. Check its Minimum Availability: a film set to Released won't be searched while it's only In Cinemas.
The container restarts or the UI won't load. Read the log:
cd ~/radarr
docker compose logs --tail 50 radarr
Verification + next steps
You're done when you can load https://radarr.example.com over a valid
certificate, sign in on the login page, add a film, see your download client
fetch it, and find the renamed file in /srv/data/media/movies as a hardlink
of the download.
Next: Sonarr for TV on the same layout,
Bazarr for subtitles, Seerr if other
people should be able to request films, and
Jellyfin to watch them — mount
/srv/data/media into it read-only.