Skip to content

Self-host Infisical

updated Sep 2026prices checked · Jul 2026Install verified on Ubuntu 26.04 · Sep 2026 · how we test
We earn commissions when you shop through the links below. Full disclosure →

An open-source platform for managing application secrets, certificates and privileged access, with per-environment secret storage, a CLI, SDKs and Kubernetes integration. The core is MIT-licensed; features under the ee/ directories need a paid enterprise license.

Key facts

CategorySecrets management
LicenseMIT core with proprietary enterprise modules
StackTypeScript, Node.js, PostgreSQL, Redis
Min RAM4096 MB
Official imageyes
Measured idle RAM1388 MB
Difficulty

What you need

  • Any VPS with at least 4096 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • Under an hour if you've used Docker before
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# Infisical — official compose (Infisical + PostgreSQL + Redis)
curl -o docker-compose.prod.yml https://raw.githubusercontent.com/Infisical/infisical/main/docker-compose.prod.yml
curl -o .env https://raw.githubusercontent.com/Infisical/infisical/main/.env.example
# the template ships sample secrets — replace them before the first start:
sed -i "s|^ENCRYPTION_KEY=.*|ENCRYPTION_KEY=$(openssl rand -hex 16)|; s|^AUTH_SECRET=.*|AUTH_SECRET=$(openssl rand -base64 32)|; s|^SITE_URL=.*|SITE_URL=http://SERVER_IP|" .env && chmod 600 .env
# upstream's compose file runs infisical/infisical:latest (its own comment says to pin it): set a release tag there for production
docker compose -f docker-compose.prod.yml up -d  #  →  http://SERVER_IP:80  (first signup becomes the admin)

Head-to-head

More self-hosted tools

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.